Privacy policy

How AI Document Manager handles your documents.

Dated 2 October 2026. The Android app records consent against policy version 2026-09-28.

Who operates it

This policy describes the Android app and the service that stores the account for AI Document Manager. It does not publish a postal address or a company registration number.

Google sign-in

The app is in English and signs in with a Google account. There is no separate email-and-password account for the mobile app. From the Google ID token, the service stores the Google account id, the email address when Google provides one, and the name when Google provides one. It also stores a role of user or admin, a status of active, and the time the account was created and updated.

Sign-in requires accepting the storage and analysis disclosure. The account then stores that terms choice as granted, the time, and the policy version. It also stores an analytics choice of granted or denied. That choice defaults to denied. The current welcome screen does not show an analytics switch.

Original files

Photos and PDFs stay in the app’s private storage on the device, under the app documents directory. They are not uploaded to the service. The database stores an id for the local file so the phone can match its copy. It does not store the file itself.

The camera is used only when you scan a page. A temporary image used to read a PDF page is removed from the phone after recognition.

Text recognition

Text recognition runs on the phone with on-device ML Kit. The image is not sent to Google for recognition, and it is not sent to the API. The recognized text is what the app sends to the service for analysis.

What is stored

For each document the service can store:

  • the recognized text, page by page
  • a title, summary, and category
  • facts, including a short quote from the recognized text as evidence
  • tasks and reminders, including a due date when one was found, and a quote as evidence
  • whether analysis has been added or has succeeded, a page count, and the model name used

Extracted facts are stored as confirmed. Suggested tasks are stored as accepted. The service also stores the consent record described above, credit use for the Europe/Berlin day, and analysis job records used to avoid repeating the same analysis.

A session stores a SHA-256 hash of the refresh token and an expiry. The refresh token itself is not stored. The default refresh lifetime is 30 days, and expired session records are removed. Short-lived access tokens are signed and returned to the app. They are not kept in the session record.

Questions

Questions are answered from confirmed facts only. The model is instructed not to use the rest of the page and not to invent values. A question about tasks or reminders is answered from the tasks stored for the account. Recent chat turns can be sent with a follow-up so the wording can refer to the previous answer. The answer still has to come from those confirmed facts or stored tasks.

Chat messages

Questions and answers are stored with the account. Messages older than 7 days are dropped, and the chat record is set to expire 7 days after the latest message. MongoDB removes an expired chat record.

Credits

One analysis costs 10 credits. One question costs 2 credits. A free account has 20 credits each Europe/Berlin day, which is two analyses. One designated mobile admin account has 2,000 credits each Europe/Berlin day. The allowance is for that calendar day in Europe/Berlin. It is not a balance that rolls over by itself: a new Berlin day starts again from the daily allowance. The app shows the remaining credits for the day.

Subscription

Google Play billing is not implemented. A monthly subscription has been discussed, and the price is not final. The app shows the subscription as not connected. There is no record of a paid subscriber unless a subscription field actually exists on the account, and none is written by the current app.

Deletion

Deleting the account in the app removes that person’s related records on the server and removes the original files stored in the app on that phone. The server deletion removes the user, sessions, documents, recognized text, facts, tasks, analysis jobs, daily credit use, and chats. If older collections for per-document text, chat messages, or consent events still exist, rows for that user are removed there too.

Deleting one document removes that document, its facts, its tasks, the related analysis jobs, and references to it inside the chat. Deleting the account or a document from the server does not, by itself, reach into a phone that is offline and delete a file that is still only on that device. The app removes local originals when the account is deleted on the phone.

If the Android app is already gone, the original file on that phone is gone with it. You can still delete your account and the copy kept by the service.

Processors

  • Google, for account sign-in. The profile data stored is the account id, email, and name.
  • On-device ML Kit, for text recognition. The image stays on the phone.
  • MongoDB Atlas, which hosts the database.
  • OpenAI, which receives the recognized text for analysis and receives confirmed facts, document titles, and recent chat turns when a question is asked. The model currently used is GPT-6 Luna. The original file is not sent.

The app does not include another analytics SDK.

Analytics

The app does not use an analytics switch to send usage data, and it does not ship a measurement SDK. Sign-in can store an analytics consent choice on the account. That choice does not start analytics collection. Document text, titles, and questions are not sent as analytics.

No sale of personal data

AI Document Manager does not sell personal data. Account data is used to run the app: sign-in, document text, extracted details, tasks, questions, credits, and deletion.

About this policy

This page is the product’s description of its practices as of 2 October 2026. The version constant stored with consent in the service is 2026-09-28. The short privacy note inside the app is a draft disclosure, not this full page. This policy is not a claim that the product complies with the law of every jurisdiction.

Contact

Privacy questions can be sent to sulemanshoukaat@gmail.com.