Privacy Policy
How we handle your data
DraftProof processes academic documents to provide writing integrity signals and review guidance. This page explains what data we collect, how we use it, and the choices you have.
Data We Collect
Account Information
When you sign in with Google or Microsoft, we receive your name and email address from the OAuth provider. We also fetch your profile photo when available to personalise your experience.
Documents
Files you upload for scanning, typically content drafts, reports, or research papers, are stored temporarily so we can analyse them and generate your report.
Scan Results
The analysis reports we produce are stored so you can revisit them from your dashboard.
Payment Information
We use Stripe to process payments. We never see or store your credit card number, only a tokenised confirmation and a record of your credit purchases.
How We Use Your Data
- Document scanning: uploaded files are analysed to produce integrity reports.
- Report delivery: scan results are saved so you can view and download them.
- Account management: email and name from OAuth are used to identify your account.
- Credit billing: Stripe processes one-time credit purchases; we track your balance.
Data Storage
Uploaded documents and generated reports are stored temporarily in Cloudflare R2 object storage with server-side encryption. Generated scan and rewrite reports stay available in DraftProof for 3 days before the system copy is purged.
Our application servers and database are hosted on Koyeb infrastructure with encrypted connections. All data is processed and stored within the regions configured for our hosting and storage providers.
Third-Party Services
| Service | Purpose | Data shared |
|---|---|---|
| Google / Microsoft | Sign-in (OAuth 2.0) | Name, email, profile photo |
| Stripe | Payment processing | Card details handled entirely by Stripe |
| Cloudflare R2 | File storage | Uploaded documents and reports |
DraftProof Add-ins (Microsoft Word & Google Docs)
What the add-ins access
DraftProof offers add-ins for Microsoft Word and Google Docs. They access only the text you select and choose to scan — nothing else in your document. In Google Docs the add-on uses the documents.currentonly permission, so it can read only the document you have open while the add-on is running, and never your other files or Drive.
How that text is used
When you scan, the selected text is sent over HTTPS to the DraftProof API, authenticated by your personal API key, to produce the AI-writing-risk read and writing guidance. To generate that analysis the text is processed by our third-party AI processing providers for that sole purpose. Your content is not used to train any model, and is never sold or shared for advertising.
Storage, retention, and control
Add-in scans are stored and purged on the same schedule as any other scan (see Data Retention & Deletion). You can revoke an add-in's API key at any time at draftproof.app/api-keys, which immediately stops its access.
Google API Services User Data Policy
DraftProof's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Data Retention & Deletion
Generated scan and rewrite reports stay available in DraftProof for 3 days, then are purged from the system. Report copies are sent to your mailbox when email delivery is enabled so you can keep your own record.
You are in control. You can delete individual documents and reports from your dashboard at any time. If you request account deletion, we will remove your personal data, uploaded files, and scan history.
To request deletion, contact us at the email below.
Cookies
DraftProof uses a single httpOnly session cookie to maintain your authenticated session. We do not use tracking cookies, advertising pixels, or third-party analytics scripts.
Contact
Questions about this policy? Reach us at support@draftproof.app.