Back to home

ohmydocument

Privacy Policy

How ohmydocument collects, uses, discloses, retains, transfers, and protects personal information.

Last updated: 2026-09-01

1. Controller and contact

ohmydocument acts as the controller for account and service administration data and may act as a processor for documents uploaded by an organization. Privacy questions may be sent to privacy@ohmydocument.com.

2. Personal information we collect

We may collect or generate the following categories of personal information when you use the service.

  • Account data: email address, name or display name, encrypted password, and contact details
  • Organization data: organization name, role, invitation or approval status, and access permissions
  • Usage data: access logs, device and browser information, IP address, and security events
  • Document data: filenames, document images or source files, extracted values, correction reasons, and audit history
  • Integration data: connected services, permission scopes, integration results, Google account email, Google file, folder, and spreadsheet identifiers, tokens, and identifiers
  • Billing data: plan, payment-method identifiers, invoices, billing records, and usage metrics

3. Purposes and lawful bases

We process personal information only as needed for the following service, security, billing, and legal purposes.

  • To create accounts, verify identity, approve access, and manage permissions
  • To provide document upload, extraction, review, approval, and audit trail features
  • To configure and execute third-party integrations and notify users of errors
  • To administer plans, measure usage, process payments, and manage billing
  • To monitor security, prevent abuse, troubleshoot incidents, and protect the service
  • To provide notices, support, and comply with legal obligations

4. Google user data

ohmydocument's use of Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. Google user data is processed only to provide Google sign-in, Google Drive upload, and Google Sheets writing features that you request or configure.

  • Data accessed: Google account email, profile identifier, display name, Drive folder and file metadata selected by you, and selected Sheets document, sheet tab, header, and cell values
  • Purpose of use: sign-in, account identification, uploading source documents to the Drive location you choose, checking column mappings in the Sheets document you choose, and writing finalized document data
  • Data stored: integration account identifiers, authorization tokens, selected file, folder, and spreadsheet IDs, sheet names, column mappings, integration results, and error records
  • Protection: OAuth tokens and sensitive identifiers are encrypted at rest, and data is transmitted using HTTPS or equivalent encrypted transport.
  • Sharing limits: Google user data is not sold or shared for advertising. It is shared only as necessary for user-configured integrations, security, troubleshooting, or legal compliance.
  • Workspace API Limited Use: Raw or derived user data received from Google Workspace APIs is used only to provide user-facing features requested or configured by the user and is not used to train generalized AI or ML models.
  • AI/LLM limits: Google user data is used only when necessary to provide requested service features such as document classification, column mapping, or accounting description generation. It is not used to train general-purpose AI models or for advertising profiling.

5. Retention

We retain personal information for as long as necessary to provide the service, comply with legal obligations, resolve disputes, enforce agreements, and preserve audit records requested by the organization. Data is deleted or anonymized when it is no longer required.

6. Sharing and service providers

We do not sell personal information. We share personal information only where necessary to provide the service, comply with law, protect rights and security, process payments, or operate integrations authorized by the user or organization.

  • Cloud infrastructure, storage, database, logging, and security providers
  • OCR, document interpretation, notification, and email delivery providers
  • Third-party integrations connected by the user, such as Google Workspace
  • Payment processors, billing, tax, and accounting service providers

7. International transfers

Personal information may be processed in countries other than where you live, depending on cloud infrastructure, third-party integrations, and support operations. Where required, we use appropriate safeguards for international transfers.

8. Your privacy rights

Depending on your location, you may have the following rights under applicable privacy laws.

  • Access personal information we hold about you
  • Correct inaccurate or incomplete information
  • Delete personal information where legally available
  • Object to or restrict certain processing
  • Request portability of certain information
  • Withdraw consent or lodge a complaint with a supervisory authority

9. Security measures

We use reasonable technical and organizational measures, including access controls, encrypted communications, encryption for sensitive stored data, logging, monitoring, backup practices, and vendor controls.

10. Cookies and similar technologies

We use cookies and similar technologies to maintain login sessions, protect the service, remember preferences, and improve usability. You may restrict cookies through your browser settings, but some features may not work properly.

11. Contact

For privacy requests, questions, or complaints, contact privacy@ohmydocument.com. We will respond within the timeframe required by applicable law.