Skip to content

Legal

Privacy Policy

Last updated: August 3, 2026

This Privacy Policy explains what Filepad, Inc. ("Filepad," "we," "us") collects, how we use it, who we share it with, and the choices you have. It applies to filepad.ai and the Filepad product.

1. What we collect

Account information — name, email, and authentication details, including through Microsoft Entra ID single sign-on if your organization uses it.

Your content — the documents, files, and other content you upload, create, or edit in a workspace, and the conversations you have with FilepadAI.

Usage and activity data — structured records of actions taken in a workspace (files created or shared, agent jobs run, approvals decided, logins), including IP address, user agent, and timestamps. This is metadata about what happened, not a copy of your document content.

Billing information — handled directly by Stripe, our payment processor. We do not store your full card number.

2. How we use it

  • To provide the workspace, editing, and AI assistant functionality you use
  • To authenticate you and enforce workspace and agent access controls
  • To process payments and manage subscriptions
  • To maintain an audit trail of activity in your workspace
  • To detect abuse, enforce rate limits, and keep the service secure
  • To comply with legal obligations

3. How AI processing works

When you use FilepadAI, or a connected agent performs an action that requires model inference, relevant content from your workspace is sent to one of our AI infrastructure providers — currently OpenAI or Google Cloud (Vertex AI) — to generate a response. If your workspace is configured to use your own API key for another provider ("bring your own key"), content is sent to that provider instead, under your agreement with them.

Filepad does not use your content to train our own models. We do not currently have a model-training pipeline of our own.

Content sent to OpenAI or Google Cloud during processing is subject to those providers' own API terms. As of the date of this policy, both providers state that content submitted through their API products is not used to train their models by default. This is a policy commitment made by those providers, not a technical restriction enforced by Filepad's code — if you need a contractual guarantee for your organization, contact us about a Data Processing Addendum.

4. Storage and security

Your account and workspace data is stored in PostgreSQL. File content is stored as encrypted-in-transit blobs in cloud object storage (Amazon S3 or Google Cloud Storage, depending on deployment region). Workspace access is enforced at the application layer — every request is checked against the workspace it targets, so one workspace cannot read another's data.

Secrets — OAuth tokens, Agent Access API keys, and connected-integration credentials — are encrypted at rest using AES-256-GCM. See our Security page for more detail on our access-control and authentication model.

5. Who we share it with

We share data with the following categories of service providers, only as needed to operate Filepad:

ProviderPurpose
OpenAIAI model inference
Google Cloud (Vertex AI)AI model inference
Amazon Web Services (S3)File storage
Google Cloud StorageFile storage (alternate region/deployment)
StripePayment processing and billing
Microsoft (Entra ID)Single sign-on authentication
GoogleGmail / Google Drive connector access, if you connect one
GitHubGitHub connector access, if you connect one

We do not sell your personal information. We do not share your content with third parties for their own marketing purposes.

6. Data retention and deletion

When you delete your account, deletion begins a 30-day grace period during which you can cancel the request. After the grace period, account and membership records are deleted, and your personal workspace is marked for deletion. A further 30 days after that, the workspace and all of its content are permanently deleted.

Some records — billing history, security and integration audit logs — are retained longer where needed for financial, security, or legal reasons, consistent with the purposes described in this policy.

7. Cookies

filepad.ai does not use tracking or advertising cookies, and we do not run third-party analytics scripts on the marketing site. The Filepad application uses a session cookie to keep you signed in — this is functional, not tracking, and is required for the product to work.

8. Your privacy rights

Depending on where you live, you may have rights under laws like the EU/UK GDPR or the California Consumer Privacy Act (CCPA), including the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing.

To exercise any of these rights, email admin@filepad.ai. We will verify your request and respond within the timeframe required by applicable law. You can delete your own account and its content at any time directly from account settings, without contacting us.

We do not sell personal information, and we do not engage in behavioral advertising, so there is no "do not sell" opt-out required for our processing.

9. International data transfers

Our infrastructure providers operate globally. Where personal data is transferred outside the jurisdiction it was collected in, we rely on the transfer mechanisms those providers make available, such as Standard Contractual Clauses. Contact us if you need details for your organization's compliance review.

10. Changes to this policy

We may update this policy from time to time. If we make material changes, we will notify you by email or through the product before the changes take effect.

11. Contact

Questions about this policy, or a privacy request? Email admin@filepad.ai. For enterprise customers who need a Data Processing Addendum, see our DPA page.