Legal

Privacy Policy

Last updated: July 24, 2026

This Privacy Policy explains how Corpusly (“Corpusly”, “we”, “us”) handles information in connection with this website at corpusly.ai (the “Site”) and the Corpuslyapplication (the “App”), a local-first desktop utility that indexes your Google Drive on your own device and connects it to AI assistants. Corpusly is operated by Corpusly.

In short

  • The App processes your documents entirely on your own device — we never receive your files, your search index, your embeddings, your searches, or your Google credentials.
  • The App uses read-only access to your Google Drive and cannot change or delete anything in it.
  • You stay in control: at any time you can disconnect, which revokes the App's Google access, and purge, which deletes its local index.
  • The only personal information the Site collects is what you choose to submit to the waitlist — your email, and optionally your use case and platform.
  • We don't serve ads and we don't sell your personal information. Analytics cookies load only if you opt in.

The App processes your data on your device

Corpusly is local-first, and there is no Corpuslyserver or backend. When you use the App, your Google Drive content is streamed to your own machine and processed there: text extraction, optical character recognition (OCR) on scanned files and images, and the computation of vector embeddings all run in-process on your device. The resulting index — the embeddings, the extracted text chunks, and a local catalog — is stored only in the App's data directory on your device.

Your Google authorization token is stored locally too: in your operating system's keychain where one is available, and otherwise in an encrypted file on your device. Because Corpusly operates no server that receives, stores, or processes your documents, your Drive content, your index, and your credentials are never transmitted to us or to any Corpusly-operated backend, and there is no telemetry of your Drive content.

What leaves your device

Here is everything the App sends off your device. Nothing else leaves it:

  • Requests to Google's own APIs.To read your Drive, the App calls Google's APIs authenticated with your own OAuth token. This is your data moving between your device and your own Google account; it is not routed through us and is not shared with any third party.
  • One-time downloads of open-source components. The first time it needs them, the App downloads its open-source embedding model (from Hugging Face) and OCR training data (from a public content-delivery network). These fetch public files only. They carry no Drive content and no personal data, in either direction.
  • Passages you ask about, sent to your AI assistant. At your direction, the App shares the passages it retrieves with the AI assistant you have connected, as described below.

Corpusly (the company) never receives your Drive content, your search index, your search queries, or your credentials.

Google user data

The App requests read-only access to your Google Drive, using the https://www.googleapis.com/auth/drive.readonly OAuth scope, for the sole purpose of reading and indexing your files locally so your AI assistant can search them. It cannot modify, move, or delete anything in your Drive.

Corpusly's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements described in the next section.

Limited Use requirements

Corpusly's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Because the App runs entirely on your device and we operate no server that receives your Google user data, these commitments hold by design:

  • Appropriate use. The App uses the Google Drive content it accesses solely to provide the feature you asked for — building a local search index so the AI assistant you connect can retrieve relevant passages. We do not use it for any other purpose.
  • Limited transfer. Your Google user data never reaches us, so we have nothing to transfer. Acting at your direction, the App shares retrieved passages only with the AI assistant you have configured. We would transfer Google user data only as necessary to provide a feature you requested, to comply with applicable law, or in connection with a merger or acquisition.
  • No human review. No one at Corpusly reads your Google Drive content — it stays on your device and never reaches us. We would access it only with your explicit consent, where necessary for security (such as investigating abuse), or where required to comply with applicable law.
  • No advertising. We do not use Google user data for advertising of any kind, including personalized, retargeted, or interest-based advertising.

AI assistant integrations

The App connects to AI assistants (for example, Claude Desktop or Claude Code) using the Model Context Protocol (MCP). When you ask your assistant a question, the App shares the passages it retrieves from your indexed documents with that assistant so it can answer you. Only the content your assistant requests is shared, and only with the assistant you have configured.

Those assistants are operated by third parties under their own terms and privacy policies, which govern how they handle the content you send them. Corpusly does not control those services and is not responsible for their data practices.

Your controls and deleting your data

Because the App's data lives on your device, you stay in control of it:

  • Disconnectrevokes the App's access at Google and deletes the stored authorization token from your device.
  • Purge deletes the local index — the embeddings, extracted text, and catalog — from your device.
  • Uninstalling the App, or deleting its local data directory, removes everything it stored.
  • You can also review or revoke Corpusly's access to your Google Account at any time from your Google Account permissions.

Information the Site collects

  • Waitlist details. If you join the waitlist, we collect the email address you submit — and, if you choose them, the optional use case and platform — so we can contact you about early access and prioritize what to build.
  • Theme preference.The Site stores your light/dark mode choice in your browser's local storage. It stays on your device and is not sent to us — it is not a tracking cookie.
  • Analytics (optional). If you accept analytics cookies, Google Analytics collects standard usage data (such as pages viewed and approximate location) to help us improve the Site. It is off unless you opt in.
  • Server logs. Our web host may automatically record standard technical information (such as IP address, browser type, and timestamps) for security and to operate the Site.

Cookies and analytics

The Site shows a cookie banner on your first visit. Until you accept, no analytics load and no analytics cookies are set. If you accept, we use Google Analytics 4 (provided by Google) to understand how the Site is used — for example, how many people visit and which pages help — so we can improve it.

When enabled, Google Analytics sets its own cookies (such as _ga) to measure visits. You can change or withdraw your choice at any time using the Cookie choiceslink in the footer; declining removes those cookies and stops analytics from loading. The one strictly necessary cookie the Site sets simply remembers your choice so we don't ask again.

How we use information

We use the limited information above to respond to your waitlist request and send early-access and launch updates; to operate, maintain, and secure the Site; and to comply with legal obligations.

How we share information

  • Form processing. Waitlist submissions are handled by Formspree, a third-party form provider, on our behalf. Their handling of that data is governed by their own privacy policy.
  • Analytics. If you opt in, Google Analytics (operated by Google) processes Site usage data on our behalf under its own privacy terms.
  • Service providers. Our web hosting provider processes requests to the Site.
  • Legal and safety. We may disclose information if required by law or to protect our rights, our users, or the public.
  • Business transfers. Information may be transferred as part of a merger, acquisition, or sale of assets.

We do not sell your personal information.

Data retention

We keep your waitlist email until you ask us to remove it or until it is no longer needed for the purpose it was collected. Data created by the App lives on your own device under your control, and we do not retain a copy.

Security

We take reasonable measures to protect the limited information we handle. The App is designed to keep your document data on your device and to store your Google authorization token in your operating system's keychain where one is available, or otherwise in an encrypted file. Data the App keeps on your device is protected by your operating system's user-account isolation and any disk encryption you have enabled, rather than by a separate Corpusly encryption layer. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Your rights and choices

You can ask us to access, correct, or delete the email address you provided, or to stop contacting you, at any time by emailing us. Depending on where you live (for example, the EEA, the UK, or California), you may have additional rights over your personal information under laws such as the GDPR or CCPA/CPRA; contact us to exercise them.

Children

The Site and App are not directed to children under 13, and we do not knowingly collect personal information from them.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above, and significant changes may be highlighted on this page.

Contact

Questions about this policy? Email hello@corpusly.ai.