Legal
Privacy Policy
Last updated: August 3, 2026
This Privacy Policy explains what Filepad, Inc. ("Filepad," "we," "us") collects, how we use it, who we share it with, and the choices you have. It applies to filepad.ai and the Filepad product.
1. What we collect
Account information — name, email, and authentication details, including through Microsoft Entra ID single sign-on if your organization uses it.
Your content — the documents, files, and other content you upload, create, or edit in a workspace, and the conversations you have with FilepadAI.
Usage and activity data — structured records of actions taken in a workspace (files created or shared, agent jobs run, approvals decided, logins), including IP address, user agent, and timestamps. This is metadata about what happened, not a copy of your document content.
Billing information — handled directly by Stripe, our payment processor. We do not store your full card number.
2. How we use it
- To provide the workspace, editing, and AI assistant functionality you use
- To authenticate you and enforce workspace and agent access controls
- To process payments and manage subscriptions
- To maintain an audit trail of activity in your workspace
- To detect abuse, enforce rate limits, and keep the service secure
- To comply with legal obligations
3. How AI processing works
When you use FilepadAI, or a connected agent performs an action that requires model inference, relevant content from your workspace is sent to one of our AI infrastructure providers — currently OpenAI or Google Cloud (Vertex AI) — to generate a response. If your workspace is configured to use your own API key for another provider ("bring your own key"), content is sent to that provider instead, under your agreement with them.
Filepad does not use your content to train our own models. We do not currently have a model-training pipeline of our own.
Content sent to OpenAI or Google Cloud during processing is subject to those providers' own API terms. As of the date of this policy, both providers state that content submitted through their API products is not used to train their models by default. This is a policy commitment made by those providers, not a technical restriction enforced by Filepad's code — if you need a contractual guarantee for your organization, contact us about a Data Processing Addendum.
4. Storage and security
Your account and workspace data is stored in PostgreSQL. File content is stored as encrypted-in-transit blobs in cloud object storage (Amazon S3 or Google Cloud Storage, depending on deployment region). Workspace access is enforced at the application layer — every request is checked against the workspace it targets, so one workspace cannot read another's data.
Secrets — OAuth tokens, Agent Access API keys, and connected-integration credentials — are encrypted at rest using AES-256-GCM. See our Security page for more detail on our access-control and authentication model.
5. Who we share it with
We share data with the following categories of service providers, only as needed to operate Filepad:
| Provider | Purpose |
|---|---|
| OpenAI | AI model inference |
| Google Cloud (Vertex AI) | AI model inference |
| Amazon Web Services (S3) | File storage |
| Google Cloud Storage | File storage (alternate region/deployment) |
| Stripe | Payment processing and billing |
| Microsoft (Entra ID) | Single sign-on authentication |
| Gmail / Google Drive connector access, if you connect one | |
| GitHub | GitHub connector access, if you connect one |
We do not sell your personal information. We do not share your content with third parties for their own marketing purposes.
6. Data retention and deletion
When you delete your account, deletion begins a 30-day grace period during which you can cancel the request. After the grace period, account and membership records are deleted, and your personal workspace is marked for deletion. A further 30 days after that, the workspace and all of its content are permanently deleted.
Some records — billing history, security and integration audit logs — are retained longer where needed for financial, security, or legal reasons, consistent with the purposes described in this policy.
8. Your privacy rights
Depending on where you live, you may have rights under laws like the EU/UK GDPR or the California Consumer Privacy Act (CCPA), including the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing.
To exercise any of these rights, email admin@filepad.ai. We will verify your request and respond within the timeframe required by applicable law. You can delete your own account and its content at any time directly from account settings, without contacting us.
We do not sell personal information, and we do not engage in behavioral advertising, so there is no "do not sell" opt-out required for our processing.
9. International data transfers
Our infrastructure providers operate globally. Where personal data is transferred outside the jurisdiction it was collected in, we rely on the transfer mechanisms those providers make available, such as Standard Contractual Clauses. Contact us if you need details for your organization's compliance review.
10. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or through the product before the changes take effect.
11. Contact
Questions about this policy, or a privacy request? Email admin@filepad.ai. For enterprise customers who need a Data Processing Addendum, see our DPA page.