§CorporaSign in

Corpora Privacy Policy

Abstract Interactive IncEffective October 5, 2026

Corpora is operated by Abstract Interactive Inc, doing business as Abstract Partners, a company based in the United States. This policy explains what we collect, what we keep, and what we never do. It covers the Corpora product at corpora.abstract.partners. If anything here is unclear, write to support@abstract.partners and a person will answer.

1. What Corpora does with your documents

You connect folders from your Google Drive. Corpora reads the files in them, uses AI models to find the rules your company runs on, and shows those rules to your team for confirmation.

Here is the part that matters most: we do not store your documents. File contents are processed in memory during a scan and are gone when the scan finishes. The architecture has no place to keep them.

What we do keep after a scan:

  • Extracted rules. The sentences Corpora writes to describe each rule it found.
  • Quoted citations. Short word-for-word excerpts from your documents, typically 1 to 3 sentences each, kept as evidence for each rule. These are the only fragments of your document content that persist, and they exist so your team can verify every rule against its source.
  • Document metadata. File names, folder paths, file types, sizes, and modification dates.
  • Content fingerprints. Cryptographic hashes that let us recognize a file we have seen before without keeping its contents.

2. Information we collect

Customer content. The documents in folders you connect, processed as described in Section 1. The rules, citations, metadata, and fingerprints derived from them belong to your workspace.

Account data. Your email address and display name from Google sign-in. Workspace names, membership, and roles. Review history: who confirmed or rejected each rule and when. Review history is a permanent audit trail by design; it is the record of who ratified your constitution.

Usage data. Scan telemetry such as token counts, per-scan cost, timing, and error logs. Standard technical logs such as IP addresses and request metadata, kept for security and operations.

We do not use cookies for advertising. We do not collect data from data brokers.

3. How we use information

  • To run the product: scan files, extract rules, serve your constitution.
  • To secure it: authentication, abuse prevention, debugging.
  • To bill for it: usage metering and, when billing launches, payment processing.
  • To talk to you: service messages and support replies.

We do not sell your data. We do not use your data for advertising. We do not train our own models on your data.

4. Google user data and Limited Use

Corpora accesses Google user data through Google sign-in and the Google Drive API, using read-only access to the folders you pick. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • We use Google Drive data only to provide the user-facing features described in Section 1: reading the folders you selected, extracting rules, and showing you the results.
  • We do not transfer Google user data to advertising platforms, data brokers, or information resellers.
  • We do not use Google user data for advertising, credit decisions, or any purpose unrelated to the features you see in the product.
  • Humans at Abstract do not read your Drive data except with your explicit permission for support, for security investigation, or where required by law.
  • Drive access tokens are encrypted and stored in Google Secret Manager. Disconnecting a source deletes its token immediately.

5. AI processing

During a scan, document text is sent to AI models to classify documents and extract rules. Today those models run on Google Vertex AI in the United States, currently Google Gemini models, with Anthropic Claude models available on the same platform. We may also use Anthropic's API directly in the future; if we do, we will update the subprocessor list below.

Per Google Cloud's data governance commitments, customer data sent to Vertex AI is not used by Google to train its foundation models without permission, and transient prompt caching is limited to at most 24 hours. Anthropic's commercial terms likewise do not grant training rights on API customer data. We choose providers whose terms match our own rule: your documents teach your constitution, not anyone's models.

6. Subprocessors

ProviderWhat it doesWhere
Google Cloud PlatformHosting, database, encrypted secret storageUnited States
Google Vertex AIAI model processing during scansUnited States
Google Identity Platform / FirebaseSign-inUnited States
Stripe (when billing launches)Payment processingUnited States

We will update this list before adding a new subprocessor that handles customer content.

7. Retention

  • Rules, citations, metadata, review history: kept while your workspace exists.
  • Document contents: not retained. Gone when the scan finishes.
  • Drive access tokens: kept until you disconnect the source or delete the workspace.
  • Usage and security logs: kept up to 13 months, then deleted or aggregated.

8. Deletion

Deleting a workspace permanently removes its constitution, all rules and citations, all review history, and all source connections and their tokens. There is no undo. Your files in Google Drive are never affected by anything Corpora does, because Corpora never had them.

To delete your account entirely, write to support@abstract.partners.

9. Security

Data is encrypted in transit and at rest. Access tokens live in Google Secret Manager, not in our database. Every workspace is isolated by database-level access controls enforced on every query. Production access is limited to the people who operate the service.

No system is perfectly secure. If we learn of a breach affecting your data, we will tell you promptly and plainly.

10. Your rights

You can access, correct, export, or delete your account data and workspace content at any time, in the product or by writing to us. If you are in a jurisdiction with specific privacy rights, such as the EU, UK, or California, we will honor the rights that law gives you. Corpora is built for business customers; we are happy to sign data processing agreements with customers who need them. Write to support@abstract.partners.

Corpora is not directed at children and we do not knowingly collect data from anyone under 16.

11. Changes

When this policy changes, we will update the date at the top and note material changes in the product. We will not quietly weaken what this policy promises about your documents.

12. Contact

Abstract Interactive Inc, dba Abstract Partners support@abstract.partners

A person reads that inbox and a person will answer.