Privacy Policy

AI Sortify

Last updated: July 2, 2026

This Privacy Policy explains how AI Sortify processes personal data for its desktop app, mobile app, website, account services, AI-assisted document workflows, Google Drive workflows, subscription features, support, and related backend/API services.

1. Controller and contact

AI Sortify is operated by Anas Boumediene. Unless a separate written agreement says otherwise, the operator is the controller for account, subscription, support, security, and service-operation data. For business document workflows, AI Sortify may also act as a processor for customer content processed on behalf of a workspace or organization.

Privacy contact: anexbm@gmail.com
Legal notice / Impressum: https://aisortify.com/impressum
Terms of Service: https://aisortify.com/terms
Data Processing Agreement: https://aisortify.com/dpa

2. Scope

This policy applies when you use AI Sortify, including the desktop app, iOS and Android apps, public website, account registration and login, Google sign-in and Google Drive connection, document scanning and upload, AI classification, folder generation, subscription and plan management, team/workspace features, support requests, and legal or support websites.

This policy does not replace privacy notices from Apple, Google, RevenueCat, Supabase, or other third-party services when you use their services directly.

3. Data we process

Category Examples Purpose Typical source
Account and identity data Name, email address, user ID, avatar URL, authentication provider, login state, accepted policy timestamp, language preference. Account creation, login, user profile, security, support, policy acceptance, workspace access. You, Apple, Google, Supabase authentication.
Workspace and organization data Organization name, short name, business email, phone, website, team members, roles, invitations, workspace settings. Team management, organization profile, billing/workspace administration, collaboration, white-label settings where enabled. You or workspace administrators.
User content and document data Uploaded or selected documents, PDFs, images, scans, spreadsheets, filenames, folder names, extracted text, classification results, generated folder paths, document status, review notes, custom rules. Document classification, renaming, splitting, extraction, folder recommendation, file organization, history, review, and automation. You, your device, Google Drive, or workspace users.
Camera, photo, file, and microphone input Photos selected from the library, camera captures, document-picker files, optional voice messages or microphone recordings. Only to perform user-requested features such as document capture, upload, scanning, text extraction, or voice-assisted instructions. Your device, after permission or file selection.
Google account and Google Drive data Google account email, OAuth authorization code, access/refresh tokens where required, Drive folder IDs, root folder ID, file IDs, filenames, MIME types, parent folder IDs, selected files/folders, storage quota information, Drive operation results. Connecting Google Drive, creating AI Sortify folders, scanning selected folders/files, moving/renaming/organizing files, syncing Drive connection state, reconnecting Drive. Google APIs, Google Drive, and your authorization.
AI workflow data Selected documents or document images, text extracted from documents, filenames, document metadata, folder/workspace context, assistant messages, optional voice recordings or transcripts, prompt context needed for classification, AI output, confidence/review status, generated labels and folder paths. AI-assisted classification, extraction, file naming, routing, review, and improving reliability of the requested workflow. Your documents, your instructions, AI Sortify backend processing, Google Vertex AI / Gemini, and OpenAI for voice transcription or voice assistant features.
Subscription and purchase data Plan, entitlement, subscription status, product ID, purchase history, renewal/cancellation state, RevenueCat app user ID, App Store or Play Store purchase information where available. Unlocking paid features, enforcing usage limits, restoring purchases, customer center/subscription management, fraud prevention, billing support. Apple App Store, Google Play, RevenueCat, app backend.
Usage, quota, and product interaction data Document counts, split counts, email rule counts, feature usage, processing status, failed/reviewed/done files, dashboard summaries, plan limits, timestamps. Providing dashboards, usage limits, plan enforcement, reliability, support, abuse prevention, product operation. Your use of the app and backend systems.
Technical, security, and diagnostic data Device type, desktop operating system, browser where applicable, app version, platform, locale, IP address in server logs, request metadata, authentication tokens, error messages, security events, network status. Security, authentication, debugging, abuse prevention, uptime, service reliability, legal compliance. Your device, app, backend, platform services.
Support and communication data Email address, support messages, account deletion requests, subscription questions, bug reports, legal requests. Responding to requests, resolving issues, maintaining records of support and legal communications. You or your workspace administrators.
Location or address-search data, if enabled Approximate/current location or typed address query for address suggestions. Providing address suggestions when you use address-related fields. This is optional and depends on app permissions and feature use. Your device and address-search provider.

4. Purposes and legal bases

Purpose Data involved Legal basis where GDPR applies
Create and manage user accounts Account, identity, authentication, policy acceptance, language preference. Contract performance; legitimate interests in security; legal obligation for records where applicable.
Provide document classification and organization User content, document data, extracted text, AI workflow data, usage data. Contract performance; consent or user instruction for optional uploads/permissions; legitimate interests in reliable service operation.
Connect and operate Google Drive workflows Google account, OAuth tokens, Drive metadata, selected files/folders, Drive operation results. Contract performance; consent through Google OAuth authorization; legitimate interests in secure token and workflow management.
Manage subscriptions and paid plans Purchase status, entitlements, plan, product identifiers, RevenueCat data, usage limits. Contract performance; legal obligation for financial records; legitimate interests in fraud prevention and entitlement accuracy.
Operate teams and organizations Organization profile, team member data, roles, invitations, workspace settings. Contract performance; legitimate interests in workspace administration and access control.
Security, debugging, support, and abuse prevention Technical logs, account identifiers, error reports, support messages, request metadata. Legitimate interests; legal obligation where applicable.
Comply with law and enforce terms Account, billing, support, security, and relevant workflow records. Legal obligation; legitimate interests; establishment, exercise, or defense of legal claims.

5. Google API and Google Drive data

AI Sortify uses Google APIs only for user-facing features that are visible in the app, such as Google sign-in, connecting Google Drive, creating the AI Sortify root folder, creating folder structures, listing selected files or folders, moving or renaming files, reading selected file metadata, and organizing documents at the user's request.

AI Sortify's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. AI and document processing

AI Sortify may send selected documents, document images, extracted text, filenames, metadata, folder or workspace context, assistant messages, and optional voice recordings or transcripts to AI Sortify hosted backend services. The backend processes AI document classification, extraction, file naming, folder routing, review suggestions, and assistant requests using Google Vertex AI / Gemini. Voice transcription and voice assistant features may use OpenAI. AI processing is used only to provide the feature the user requested.

AI output can be incomplete or inaccurate. Users remain responsible for reviewing classification results, extracted fields, suggested filenames, and destination folders before relying on them. Users must not upload documents they are not authorized to process.

AI Sortify does not sell document content and does not use document content for third-party advertising. If a future feature would use content for a new purpose that is materially different from this policy, the policy will be updated and users will be notified where required.

7. Device permissions

Permission Why it may be requested
Camera To scan or capture documents when you choose to use camera capture.
Photo library To select images or scans for upload or classification.
Document picker / files To select PDFs, spreadsheets, images, or other files for processing.
Microphone To record optional voice assistant messages or voice instructions when enabled.
Location Only if an address-suggestion feature is used and permission is granted.
Secure storage To store authentication/session information securely on the device where supported.

8. Service providers and subprocessors

Provider Role Data involved
Supabase Authentication, database, storage, backend platform. Account data, workspace data, app records, storage objects, authentication/session data.
Google APIs / Google Drive / Google Sign-In Sign-in and user-authorized Drive workflows. Google account data, Drive metadata, selected files/folders, OAuth tokens, Drive operation data.
Google Cloud / hosted backend services Backend API, document workflow processing, Drive OAuth exchange, service operation. Account identifiers, request metadata, Drive connection data, document workflow data.
Google Vertex AI / Gemini AI-assisted document classification, extraction, naming, folder routing, review suggestions, and assistant requests. Selected documents or document images, extracted text, filenames, metadata, folder/workspace context, assistant messages, and user instructions needed for the requested AI task.
OpenAI Voice transcription and voice assistant support when you use voice features. Optional voice recordings, transcripts, assistant messages, and context needed for the requested voice feature.
Apple App Store / Apple Sign-In Authentication and iOS purchase processing. Apple account identity data made available to the app, purchase and subscription data.
Google Play, if Android purchases are enabled Android app distribution and purchase processing. Purchase and subscription data.
RevenueCat Subscription entitlement, customer center, restore purchases. App user ID/workspace ID, product identifiers, subscription status, purchase events.
Expo / EAS and app platform services App builds, updates, platform functionality. Technical app/build metadata and update-related data.
Website hosting provider Hosting the public website and legal pages. Standard web access logs handled by the hosting provider.
Email provider used by the operator Support and legal contact. Email address, message content, support request details.

9. Sharing, sale, and tracking

We do not sell personal data. We do not use personal data for third-party advertising or cross-app tracking. We share personal data only when needed to provide the service, process subscriptions, operate Google Drive workflows, comply with law, protect users or the service, or with your instruction or consent.

10. Retention

Data Retention approach
Account and profile data Kept while the account is active and then deleted or anonymized after account deletion, unless legal retention applies.
Policy acceptance records Kept as needed to prove consent/contract acceptance and comply with legal requirements.
Documents, extracted text, classifications, and workflow records Kept as needed to provide history, review, automation, and workspace functionality until deleted by the user, workspace administrator, or account deletion process, subject to backups and legal retention.
Google Drive tokens and connection data Kept while Drive is connected and deleted or invalidated after disconnect/account deletion where technically possible, subject to backup and security logs.
Subscription and purchase records Kept as long as needed for entitlements, billing support, tax/accounting, fraud prevention, and legal obligations.
Security, diagnostic, and server logs Kept for a limited period appropriate for security, debugging, fraud prevention, and reliability unless longer retention is needed for legal or security reasons.
Support communications Kept as needed to respond to requests, maintain support history, and handle legal or account issues.

Backup deletion can take additional time because backups are rotated on a schedule. Google Drive files remain in your Google Drive unless you or an authorized workflow move, rename, trash, or delete them.

11. Security

We use technical and organizational measures designed to protect personal data, including encrypted transport, authenticated access, secure token storage on device where supported, backend access controls, least-privilege access, provider security controls, and operational monitoring. No internet service can guarantee absolute security.

12. International transfers

Providers may process data in countries other than your country of residence. Where required, we rely on appropriate safeguards such as data processing agreements, standard contractual clauses, adequacy decisions, or other lawful transfer mechanisms.

13. Your choices and rights

To make a privacy or deletion request, contact anexbm@gmail.com. We may need to verify your identity before acting on a request.

14. Automated decision-making

AI Sortify uses AI to assist with document classification, extraction, naming, and routing. These outputs are workflow suggestions and processing results for document organization. AI Sortify is not intended to make solely automated decisions about people with legal or similarly significant effects. Users should review AI results before relying on them.

15. Business customer and processor terms

If you use AI Sortify for business documents, you are responsible for ensuring that you have a lawful basis and authority to upload, connect, process, or organize those documents. Where AI Sortify processes personal data on behalf of a business customer, the Data Processing Agreement applies unless a separate written agreement is signed.

16. Children

AI Sortify is not directed to children and should not be used by children below the age required by applicable law. If you believe a child has provided personal data, contact us so we can take appropriate action.

17. Changes

We may update this Privacy Policy when the app, website, backend/API, providers, data practices, or legal requirements change. The updated version will be posted at this URL with a new "Last updated" date. If required, we will provide additional notice or request renewed consent.

18. Contact

Anas Boumediene
Email: anexbm@gmail.com
Website: https://aisortify.com