This Privacy Policy describes how Document Blueprint ("we", "us", "our") collects, uses, shares, and protects information about you when you use our service. We respect your privacy and are committed to handling your data carefully and transparently.
When you create an account we collect: your email address, your display name (if provided), and your authentication identifier from Google (when you sign in with Google). If you sign up for a paid plan, Stripe collects your payment information directly; we never see or store your payment-card details.
The service is a document-automation platform. You upload documents (PDFs and other file types), define templates, and create cases. The content you upload, including any personal data contained within those documents, is processed and stored to provide the service.
The service supports storing sensitive personal data (Social Security Numbers, dates of birth, financial account numbers, tax identifiers, driver's license numbers, passport numbers, payment card numbers, medical record numbers, patient identifiers, and similar data) under enhanced encryption controls described in Section 5 below.
You are responsible for ensuring that you have legal grounds to process any personal data you upload, including data of third parties (your customers, employees, clients, patients).
When you connect your Gmail account, we request the gmail.readonly and gmail.modify OAuth scopes. We use these to read incoming messages matching your automation rules and to compose draft emails on your behalf. The same connection also requests the calendar.events and calendar.readonly scopes, which we use to add case events to your Google Calendar and to power calendar-based reminders you configure.
When an automation ingests a message, the sender address and subject line are always stored on the resulting case: they identify where a document came from and cannot be switched off. Each automation then offers two capture choices: Files (attachments), ON by default, and Body, which is OFF by default; you must explicitly enable it per automation if you want the email body stored. When Body capture is enabled, the body of matching messages is stored on the corresponding case until you delete the case. When Body capture is disabled, the email body is never written to our database. Deleting a case removes its stored sender, subject, and any captured body.
When you connect your Google Drive account, we request drive.readonly and drive.file OAuth scopes. We use these to read files you have configured for ingestion and to save files we generate.
We never send emails directly. The service composes Gmail drafts in your account; you review and dispatch every email yourself.
We collect technical data automatically when you use the service: IP address, browser type and version, device characteristics, the pages you visit, and timestamps. We use this for security, performance monitoring, and product analytics. See Section 6 for cookie details.
The portal includes a "Review & Sign" flow for signing documents electronically. When you sign, we record the signature evidence contemplated by the E-SIGN Act and UETA: your name and email, the consent disclosure you accepted, the time of each signature action, your IP address and browser user agent, and tamper-evident hashes of the signed document and the signature images. These records are kept for seven years (see the data retention policy). If you save a signature image for reuse, it is stored with your account until you replace it or delete your account.
We use the information we collect to:
We do not sell your personal information. We do not use your content for advertising. We do not use your content to train any AI model; see Section 3.
The service uses Google's Gemini API to extract structured data from your documents and to fill template fields. Specifically:
We share your information only as described below:
We do not sell your personal information. We do not share your information for cross-context behavioral advertising.
Security controls in place today:
No system is perfectly secure. If we discover a breach affecting your data, we will notify you and any required regulator within the timeframe required by applicable law.
We use a limited set of first-party cookies:
session (authentication), _legal_consent (your cookie-banner choice). These are always set; you cannot opt out without losing access to the service._ga and _ga_* (Google Analytics 4 via Google Tag Manager), and x_attr (remembers the campaign or referrer that brought you to the site, so we can attribute signups to marketing sources). Set only if you accept analytics in the cookie banner.x_rid (a random identifier that assigns A/B variants on marketing pages). Set only if you accept experiments in the cookie banner.We do not use third-party advertising cookies and we do not share cookie data with ad networks. See our Cookie Policy for full details, including how to change your preferences.
For the full retention schedule (authentication tokens, AI processing, operational logs, email logs, backups, and manual vs automated enforcement), see our data retention policy.
Your data is stored in Google Cloud Firebase, US-Central region (Iowa, USA). We do not currently offer EU data residency. Customers subject to EU data localization requirements should contact us before onboarding.
Depending on your jurisdiction, you may have rights to:
To exercise these rights, email privacy@documentblueprint.com. We will respond within 30 days (or 45 days for CCPA requests). For the full process, including what info to include, our identity verification steps, response timelines, and how to appeal, see our Data Subject Rights process.
We do not sell personal information. California residents have the right to opt out of the "sale" or "sharing" of personal information. If your browser sends a Global Privacy Control (GPC) signal, we treat it as a decision to decline non-essential cookies, unless you have already made an explicit cookie choice of your own.
See Section 4 of our Terms of Service for the full list of restricted-data categories. In short:
The service is not directed at children under 13 (or under 16 in the EU/UK). We do not knowingly collect personal information from anyone in those age groups. If you believe a child has provided us with personal information, contact privacy@documentblueprint.com and we will delete it.
If you are located outside the United States and use the service, your information will be transferred to and processed in the United States. By using the service you consent to this transfer. We rely on Standard Contractual Clauses or other valid transfer mechanisms where required.
We may update this Privacy Policy from time to time. When we make changes that materially affect your rights or our processing of your personal information, we will require you to re-accept the updated policy before continuing to use the service.
For privacy inquiries or to exercise your rights: privacy@documentblueprint.com For legal notices: legal@documentblueprint.com