Privacy Policy
Last Updated: July 15, 2026
At Document Master (a project by Lucentinian), we take your privacy and the security of your proprietary data extremely seriously. This Privacy Policy describes how we collect, use, and safeguard the information you provide when using our multi-tenant document indexing and AI-powered assistant platform, particularly when connecting Google Drive, Dropbox, and other remote sources.
1. Information We Collect
To provide user authentication and our core RAG (Retrieval-Augmented Generation) search capabilities, we collect and process the following information:
- Account & Identity Credentials: Email address, hashed password credentials, language preferences, and your Google Account identifier (
google_id) and profile details when using Google Sign-In / Sign-Up. - OAuth Tokens: When you authorize document connectors (e.g., Google Drive, Dropbox, Confluence, Jira), we store secure access tokens and refresh tokens encrypted in our database to download document files.
- Document Text & Indexes: We temporarily process document files to extract their text content and construct search indexes.
2. How We Use Google User Data
Our app's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Single Sign-On & Account Authentication: When you sign up or log in with Google, we use your email address (
userinfo.email) and profile information (userinfo.profile) strictly to verify your identity, create your user account, and maintain your session. - Limited Document Access: For document indexing, we only access the specific folders or files you select to index for your workspace.
- Indexing Only: The text extracted from your Google Drive files is compiled into search indices to support exact-cite context matching in your workspace's RAG chat console.
- No Data Sharing or Advertising: We do not transfer, sell, or share your Google user data, profile information, or document contents with any third-party marketing or advertising services.
3. Zero-Local-Footprint Security & Encryption
To comply with strict enterprise standards, compiled document indexes and summaries are never stored locally on our servers. All index data is written directly to your own configured remote storage (e.g., your own Dropbox, Google Drive, or FTP server). All API keys and OAuth tokens stored in our database are encrypted using envelope encryption with master keys managed by a Key Management Service (KMS).
4. Third-Party LLM Processing
When you query your documents, the matching text snippets are sent to your configured LLM provider (such as Google Gemini, API.market, or your own local Ollama / AnythingLLM instances) to generate responses. We do not control how external cloud LLMs process or store queries, but we keep your connection keys private and isolated per tenant.
5. Data Control & Deletion
You have full control over your data. You can disconnect your Google Drive or Dropbox accounts, remove specific file index targets, or delete your entire workspace at any time. Upon deletion, all associated remote index files are purged, and all OAuth tokens are deleted from our database.
6. Changes to this Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by updating the policy page within the application.
7. Contact Us
If you have any questions or feedback regarding this policy, please contact us at lucentinian.com.