Privacy policy
Last updated: 2026-07-30
AskMyDocs (“we”, “us”) provides an AI document-intelligence service at askmydocs.io and app.askmydocs.io. This policy explains what we collect, why, where it lives, and how you get it back or get rid of it. The short version: your documents are yours, we process them only to answer your questions, and we never sell your data.
What we collect
- Account data — name, email address, and password hash (or your Google account identifier if you sign in with Google), workspace and team membership, and your role.
- Your documents — files you upload and files synced from cloud drives you connect, along with the text, OCR output, and search index data derived from them, and their version history.
- Connector tokens — OAuth tokens for Google Drive, OneDrive, Dropbox or Box connections you authorize. Tokens are stored encrypted (AES-GCM) and used only to read the content you scoped.
- Usage records — questions asked, answers and citations returned, feedback you give on answers, and an append-only audit log of security-relevant events (uploads, downloads and denied attempts, permission changes, invites, API keys).
- Billing data — plan, invoices and payment status. Card and payment details are handled by Razorpay; we never store them.
How we use it
- To index your documents and answer your questions with citations — the core service.
- To enforce access control: permissions are applied during retrieval, so content is only used for answers to people allowed to see it.
- To operate workspace features admins rely on: usage insights, knowledge-gap lists, and the audit log.
- To bill you, notify you (for example an invite or a quota warning), and provide support when you contact us.
We do not sell your data, we do not use your documents to advertise to you, and we do not use your documents to train general-purpose AI models. Document content is sent to our AI model provider only as needed to answer the questions your workspace asks, under agreements that prohibit training on it.
Where it lives
Your data is stored in AWS’s Asia Pacific (Mumbai) region, encrypted in transit (TLS) and at rest. Workspace isolation is enforced at the database row level, and access checks are made against the database — not client-side tokens.
Who can see it
People in your workspace, according to the teams, roles and per-document permissions your admins configure. Our staff do not read your documents except when strictly necessary to operate the service or investigate abuse, and such access is logged. We share data with processors only as needed to run the service (cloud hosting, AI model inference, email delivery, payments) and with authorities only when legally required.
Cloud drive connections
Connector sync is read-only, one-way and additive: we read the folders you scope and never modify, reorganize or delete anything in your drive. You can disconnect a connector at any time, which stops all further reading; previously synced content stays in your library until you delete it.
Retention, export and deletion
Your content stays as long as your workspace does. You can delete individual documents and conversations in the product. On request, we export everything we hold for your workspace, and on offboarding we delete it all — documents, versions, conversations and index data. Audit log entries and invoices may be retained where the law requires it.
Your rights
Depending on where you live, you may have rights to access, correct, export, restrict or delete your personal data. Write to us and we’ll act on it — the same email works for questions about this policy: privacy@askmydocs.io. Security reports go to security@askmydocs.io.
Cookies
The marketing site sets no trackers and no third-party analytics cookies. The app uses cookies and local storage strictly for signing you in and remembering preferences like your theme.
Changes
If we change this policy in a way that matters, we’ll say so in the product and update the date at the top. Continued use after a change means you accept the updated policy.