Privacy Policy
Effective Date: August 11, 2026 Last Updated: August 11, 2026 Data Controller: GeoTech B.V., Piet Mondriaanstraat 204, 1061 TT Amsterdam, Netherlands; KVK 84238445; VAT NL860500214B01 Contact: [email protected]
GeoTech B.V. ("we", "us", "our") operates AssistHub ("the Service"), a mobile-first scanning application that lets you photograph business cards, badges, and receipts, extract their data with AI, and file the results into your own Google Drive. The privacy of your data — and it is your data, not ours — is a big deal to us. This policy explains what we collect, how we use it, who we share it with, and your rights.
1. Summary
- We collect the minimum needed to run the Service: your name, email, authentication records, subscription status, and usage counts.
- The documents you scan are processed to extract their data and are then stored in your own Google Drive, in an app-created AssistHub folder. We do not retain your scanned files on our servers as a system of record.
- To extract data, the image is sent to a third-party vision AI provider (OpenRouter) for processing.
- We request the narrowest possible Google access (
drive.file): the Service can create and manage only the files and folders it creates itself. It cannot see anything else in your Drive. - We use AI to read your scans, but we do not make automated decisions about you (or about anyone whose details appear in your scans) that produce legal or similarly significant effects.
- We never sell your personal data, and we do not use your content or Google user data for advertising or to train AI models.
2. Information we collect
2.1 Information you provide
- Account information: your name and email address, collected when you register. Authentication (email/password and email verification) is handled through our authentication framework (Better Auth).
- Billing information: payment is processed by Stripe. We never see or store your full card number. We receive limited billing metadata from Stripe, such as subscription status, plan, billing country, the last four digits and brand of your card, and transaction identifiers.
- Communications: messages you send us (for example, support requests).
2.2 Information we generate
- Usage metadata: counts of scans performed, quota usage, timestamps, plan tier, and similar operational counters used to enforce free-tier limits and billing.
- Optional product analytics: if you consent, we record a limited allowlist of product actions using an internal account identifier. We do not send your name, email, scan contents, form contents, IP geolocation, or browser recordings to product analytics.
- Technical/log data: IP address, device and browser type, and basic request logs, retained for security, abuse prevention, and debugging.
- Identifiers: internal user identifiers, session identifiers, and a Google account identifier used to associate your authorization with your account.
2.3 Google user data we access
When you connect Google Drive, we request one narrow OAuth scope:
| Scope | What it allows | Why we need it |
|---|---|---|
https://www.googleapis.com/auth/drive.file | Create and modify only the files and folders the Service creates, and files you explicitly open with the Service. | To create an AssistHub folder in your Drive, save scanned images/PDFs there, and maintain the monthly receipt log the Service creates. |
The public scanner does not request the Google Sheets scope; drive.file permits it to edit only spreadsheets it creates itself.
We do not request the broad "see and manage all your Drive files" scope (https://www.googleapis.com/auth/drive), nor any Gmail scope. The drive.file scope cannot read or see files in your Drive other than those created through the Service.
We also receive your basic Google profile information (name, email address, and Google account ID) through the OAuth sign-in/authorization flow, used to identify your account.
3. Limited Use disclosure (Google API Services User Data Policy)
AssistHub's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
For data obtained through Google API scopes:
- We only use Google user data to provide and improve the user-facing features that are prominent in the Service (saving scans and receipt-log rows to the files and folders that AssistHub creates in your Drive).
- We do not transfer or sell Google user data to third parties for advertising, retargeting, or any interest-based purpose.
- We do not use Google user data to train, develop, or improve generalized or non-personalized AI/ML models.
- We do not allow humans to read your Google user data, except (a) with your explicit prior consent (for example, to debug a problem you report), (b) where necessary for security purposes (such as investigating abuse), or (c) to comply with applicable law.
4. How scans are processed
- You capture or upload an image/PDF in the app.
- The image is transmitted to our backend and forwarded to our AI sub-processor, OpenRouter, which routes it to a vision language model that extracts structured data (fields and text) from the image.
- The extracted result and the original file are written to the app-created AssistHub folder in your Drive, and a summary row is appended to the monthly receipt spreadsheet that the Service creates for that folder.
- We retain only minimal metadata about the scan (such as a count, timestamp, and status) on our servers. The scan content lives in your Google Drive, under your control.
We send only the content necessary to perform extraction, and we instruct our AI sub-processor not to retain inputs for model training (see Section 8).
About the AI, plainly: we use AI to read the images you upload and turn them into structured text. You can review and correct every result. We do not use automated processing to make any decision about you — or about anyone whose details appear in what you scan — that produces legal effects or similarly significantly affects anyone. There is no scoring, profiling, ranking, or eligibility decision anywhere in the Service.
5. If someone scanned your business card or badge
When an AssistHub user photographs a business card or event badge, the Service extracts the contact details printed on it — typically a name, employer, title, email address, and phone number — and may look up publicly available professional links (such as a company website or public profile) to complete the contact. The results are filed into that user's own Google Drive, which the user controls.
If your details appear in someone's scan:
- we process them transiently to perform the extraction and keep no copy after processing completes;
- we do not use them for any other purpose, do not build profiles of you, and make no decisions about you;
- the person who scanned your card holds the resulting file, much as if they had typed your card into their own spreadsheet.
You have the rights described in Section 10 — including access, rectification, and erasure of any data we still hold — and we will help you identify or reach the user who scanned you where we lawfully can. Contact [email protected].
6. How we use your information
- create and maintain your account and authenticate you (lawful basis: performance of a contract);
- run the scanning workflow — capture, AI-based extraction, and filing into your Drive (performance of a contract);
- process subscription payments and prevent payment fraud (performance of a contract; fraud prevention also serves our legitimate interest in operating safely);
- enforce free-tier quotas and measure usage (performance of a contract and our legitimate interest in preventing abuse of the free tier);
- send transactional emails such as verification, password resets, receipts, and renewal or cancellation confirmations (performance of a contract);
- secure the Service, prevent abuse, monitor availability, and debug problems using privacy-scrubbed operational telemetry (our legitimate interests in keeping the Service secure and working, and legal obligation where applicable);
- improve product flows using the limited optional analytics described above, only after your consent (consent);
- comply with legal and tax obligations, including invoice retention (legal obligation).
We do not use your scanned content or Google user data for advertising or for training AI models. If we ever wanted to process your data for a new purpose, we would tell you first and, where required, ask for your consent.
7. Data sharing and disclosure
We do not sell your personal data. We share data only with:
- Sub-processors listed in Section 8, who process data on our behalf under contract;
- Authorities or third parties where required by law, legal process, or to protect the rights, property, or safety of our users, the public, or us;
- A successor entity in connection with a merger, acquisition, or asset sale, subject to this Privacy Policy.
8. Sub-processors
| Sub-processor | Purpose | Data involved | Location |
|---|---|---|---|
| Google LLC | Drive storage of your scans; OAuth sign-in/authorization | Google profile basics; files and receipt spreadsheets the Service creates in your Drive | EU / United States |
| Stripe (Stripe Payments Europe, Ltd. and Stripe, LLC) | Subscription billing and payment processing | Name, email, billing metadata, card metadata (Stripe stores full card data, not us) | EU / United States |
| OpenRouter, Inc. | AI vision processing to extract data from scans | Scan image/PDF content submitted for extraction | United States |
| Resend (Plus Five Five, Inc.) | Transactional email delivery (verification, password reset, billing) | Name, email address, email content | United States |
| Sentry (Functional Software, Inc.) - EU region | Error detection and debugging | Scrubbed exception type, code stack, service, environment, and operation name; no request body, account profile, cookies, or scan content | EU (event data); US (account metadata) |
| PostHog, Inc. - EU region | Optional product analytics | Internal account identifier and allowlisted product action; only after consent | EU (data storage); US entity |
| Better Stack, Inc. | Independent uptime monitoring | Public health-check URL, availability result, timing, and incident alert metadata; no user or scan data | United States |
| DigitalOcean, LLC (Cloudflare-fronted) | Application hosting, networking, and security | Technical/log data, IP address, request data | EU (Frankfurt) data center; US entity |
Links to sub-processors' privacy policies: Google, Stripe, OpenRouter, Resend, Sentry, PostHog, Better Stack. Sentry and PostHog are configured to store project data in the European Union. We will keep this list current in this policy; if a change materially affects your data, we will tell you.
International transfers. Some sub-processors process data in the United States. Where a provider holds an active certification under the EU-U.S. Data Privacy Framework, we rely on the European Commission's adequacy decision for that transfer; in addition, or where a provider is not certified, we rely on Standard Contractual Clauses and supplementary measures. You can request a copy of the relevant safeguards at [email protected].
9. Data retention
- Account data (name, email, identifiers): retained while your account is active, then deleted or anonymized on account deletion, subject to the narrow legal carve-outs below.
- Billing and invoice records: retained as required by tax and accounting law (typically up to seven years). This carve-out covers billing records only — never your scan content or Google credentials.
- Usage metadata and logs: retained for up to 12 months, then deleted or aggregated. Optional PostHog analytics use the EU project's configured retention and are deleted when you delete your account. Sentry error events follow the EU project's configured retention.
- Google user data / scan content: we do not retain your scanned files as a system of record. Completed scan originals are removed from our server after filing. Originals queued offline or retained for failed or duplicate scans may remain for retry for up to 168 hours, then are removed automatically. Extracted scan metadata is retained for up to 30 days unless you delete the scan or your account sooner. Your saved scans reside in your Google Drive; deleting them there removes them, and revoking our Google access (Section 10) stops all further access. Google OAuth tokens are deleted when you disconnect Drive or delete your account.
10. Your rights and choices
10.1 Revoking Google access
Disconnect Google Drive at any time in the app, or at https://myaccount.google.com/permissions. Revocation stops all further access to your Google data. Files already saved to your Drive remain yours and are unaffected.
10.2 Optional analytics
You can allow or reject optional product analytics from the Analytics settings page and change your choice at any time. Rejecting analytics stops new events immediately; for a signed-in account, we also request deletion of the account's prior PostHog events.
10.3 Account deletion
Delete your account from the app's settings, or by emailing [email protected]. On deletion, we remove or anonymize your account data and usage metadata, subject to the retention carve-outs in Section 9. Deleting your account does not delete scans already stored in your own Google Drive — those are yours and stay put.
10.4 GDPR / data subject rights
If you are in the European Economic Area or the United Kingdom, you have the right to access your data, rectify inaccurate data, erase your data, restrict or object to processing, data portability, and to withdraw consent where processing is based on consent. To exercise these rights, contact [email protected]. You also have the right to lodge a complaint with your data protection authority — in the Netherlands, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). GeoTech B.V. is established in the European Union and handles privacy requests directly at [email protected], so no separate EU representative is required. No separate UK representative has been appointed.
10.5 California / other US rights
Depending on your state, you may have rights to know, access, delete, and opt out of "sale" or "sharing" of personal information. We do not sell personal information. Contact [email protected].
We respond to verified requests within the timeframes required by applicable law (generally within 30 days).
11. Security
We use industry-standard safeguards including encryption in transit (TLS), encrypted storage of OAuth tokens, access controls, and least-privilege OAuth scopes. No system is perfectly secure; if we become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
12. Children's privacy
The Service is not directed to children under 16 (or the minimum age in your jurisdiction), and we do not knowingly collect their data. If you believe a child has provided us personal data, contact [email protected] and we will delete it.
13. International users
We operate from the Netherlands and host the Service in the European Union. Your information may be processed in the United States and other countries where our sub-processors operate, with the safeguards described in Section 8.
14. Changes to this policy
We may update this Privacy Policy. If we change how we use Google user data, we will notify you and obtain your consent to the updated policy before applying the new use. Material changes will be announced via the app or email, and the "Last Updated" date will change.
15. Contact us
Questions or requests: [email protected] GeoTech B.V., Piet Mondriaanstraat 204, 1061 TT Amsterdam, Netherlands; KVK 84238445; VAT NL860500214B01
Portions of this policy are adapted from the Basecamp open-source policies / CC BY 4.0, modified by GeoTech B.V.