Privacy policy
How SourceDoc uses, protects, retains, and deletes account information and connected Google Drive and Microsoft 365 document data.
Effective September 8, 2026
Who we are and how to contact us
SourceDoc is provided by Triton Software. This policy covers getsourcedoc.com, app.getsourcedoc.com, and SourceDoc's document connectors and retrieval service. For privacy questions, access requests, or deletion requests, contact chris@tritonsoftware.com. If your firm gives you a SourceDoc account, your firm controls its workspace, documents, membership, and access scopes. Contact your firm administrator about those settings.
Information we collect
- Account and business information: your name, email address, firm name, optional profile picture and firm logo, account settings, workspace membership, and information you provide in an inquiry or support request. Passwords, when used, are stored as hashes.
- Connected archive information: the connected account identity, folder and file identifiers, names, paths, timestamps, source links, file content needed for processing, extracted text, searchable passages, and document metadata such as matters, parties, counsel, and dates. We retain encrypted authorization credentials to maintain a connection you approve.
- Service activity: searches and saved searches, document views, generated summaries, indexing status, administrative actions, and sign-in events. Security records can include timestamps, browser information, and a hashed IP fingerprint. Our web infrastructure also processes network information, including IP addresses, to deliver and protect the service.
- Billing information: selected plan, billing interval, subscription and invoice status, and Stripe customer and transaction identifiers. Stripe collects payment details through its checkout and customer portal; SourceDoc does not store your full card number.
Google Drive and Microsoft 365 access
You connect storage through the provider's authorization screen, then choose folders or libraries in SourceDoc. Google Drive authorization requests read-only access to files that the connected Google account can access, together with basic account identity. Microsoft 365 uses delegated read permissions for files and SharePoint sites. These provider permissions can cover more than the folders you select; SourceDoc uses your folder selections to determine which locations it indexes.
We use connected file content and metadata to index your selected archive, perform OCR and search, display source-backed results and document details, prepare selected-document summaries, and maintain the connection. Temporary copies are used during processing; original documents remain with your storage provider. Read-only connectors do not edit or delete your originals. Extracted text and search metadata are retained in your workspace's index until removed.
SourceDoc's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements, and the applicable Google Workspace API user data and developer policy. Google user data is used to provide the user-facing archive features you authorize. We do not sell it, use it for advertising, or use it to train or improve generalized AI or machine-learning models. Human access to that data is limited to your authorized users and the circumstances permitted by those policies, such as support you explicitly authorize, security investigations, or legal requirements.
Why we use information
We use information to create and secure accounts; deliver search, document review, connectors, and audit features; process subscriptions; send verification and service messages; respond to inquiries; troubleshoot failures; prevent abuse; and meet applicable recordkeeping obligations. We do not sell personal information or connected document data, and do not use your documents for advertising or model training.
Who can receive information
Your workspace's authorized users can access information permitted by their roles and scopes. Private customer workspaces have separate retrieval indexes. Demonstration workspaces use an approved shared demonstration archive; customer archives are not added to it automatically.
Service providers process information needed to operate SourceDoc, including hosting and backup infrastructure, transactional email delivery, and Stripe for payments. Connected storage providers process your authorization and file requests. These services receive information relevant to their function; payment processing does not require your indexed documents. We may disclose information when legally required or as necessary to investigate abuse and protect users and the service, subject to applicable restrictions on connected-provider data.
Indexing, search, OCR, and built-in document summaries run on SourceDoc-operated retrieval infrastructure. If you connect an external AI client through MCP, that client receives the permitted search results or document text you request. Your chosen AI provider then handles those results under its own terms and privacy settings. Review them before enabling an AI client for confidential matters.
Retention, deletion, and your choices
Account information and indexed content are retained while needed to provide the workspace, unless removed or subject to a legal retention requirement. Workspace admins can disconnect a connector and choose to purge its indexed records. Disconnecting or revoking provider authorization stops future access but does not by itself guarantee that previously indexed content has been removed; use the purge option or contact us for help. You may also revoke SourceDoc in your Google Account connections or your Microsoft account's app-permission controls.
Built-in generated summaries are cached encrypted for up to 24 hours. Audit retention depends on the plan: 90 days for Starter, one year for Practice, and unlimited retention for Vault and Enterprise while that service is provided. Billing, security, and support records may be retained when needed for accounting, dispute resolution, fraud prevention, or legal obligations. Backup copies follow backup rotation and may not disappear at the same time as active records.
To request account access, correction, export, or deletion, email chris@tritonsoftware.com. We verify the requester's authority before disclosing or deleting workspace information. Depending on where you live and the nature of our relationship, you may have additional privacy rights under applicable law. Your firm's instructions and legal obligations may affect requests involving its records.
Cookies, local preferences, and security
The app uses secure, HttpOnly session cookies for authentication and browser storage for interface preferences such as dismissing a guided tour. Our pages do not include advertising trackers. The marketing website loads fonts from Google Fonts, which receives the network information needed to serve them. Browser and network controls may affect these features.
We use access controls, encrypted credentials, separate private-workspace indexes, and activity auditing. See our security overview for details. Do not send confidential documents through the public inquiry form. Report security concerns to security@getsourcedoc.com.
Policy updates
We will update this page when our practices change and show the effective date above. Where required, we will provide additional notice or obtain consent before using information for a materially different purpose.