Corpus Sign in

Legal

Privacy Policy

Effective 21 September 2026

Corpus is a company knowledge service. It ingests documents, indexes them for search, extracts structured facts, and serves them to internal systems over MCP.

This policy explains what personal data Corpus handles, why it handles it, how long it is kept, and how to have it removed. It covers two groups of people: operators who sign in to Corpus with a Google account, and visitors to this website.

Google account data

Corpus uses Google Sign-In to authenticate operators. It requests three scopes and no others:

From those scopes Corpus receives your name, email address, profile picture URL, Google account identifier, and the Google Workspace domain your account belongs to.

Why Corpus needs it

That is the full extent of it. Corpus does not request access to Gmail, Drive, Calendar, Contacts, or any other Google service, and it cannot read, create, or modify your files or messages.

Limited Use

Google API Services User Data Policy

Corpus's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practice that means Corpus does not sell this data, does not use it for advertising or any form of ad profiling, does not use it to train machine learning or AI models, and does not transfer it to third parties except as required to operate the service, comply with law, or in connection with a merger or acquisition where this policy continues to apply. No human reads your Google account data except where you have asked for support, where it is needed to investigate abuse or a security incident, or where the law requires it.

How long it is kept

Your account record is kept for as long as you have access to Corpus. When your access is removed, the record is deleted within 30 days. Entries in the audit trail may retain your name and email address for longer where they are needed to keep an accurate record of changes to company knowledge.

Withdrawing access

You can revoke Corpus's access to your Google account at any time from your Google account permissions page. Revoking access signs you out of Corpus and prevents further sign-in. To have your stored account record deleted as well, email the address at the bottom of this page.

Website visitors

This website sets no cookies, runs no analytics, and carries no advertising or tracking scripts. Two third parties receive data when you use it:

The site is hosted on GitHub Pages, which keeps standard server request logs.

Document content

Corpus indexes documents supplied by the company that operates it. Those documents may name people, including employees, clients, and contacts. Corpus stores that content, extracts structured facts from it, and returns it to authorized operators and systems with a reference back to the source document. It is not published, not made publicly searchable, and not made available to anyone outside the permitted Workspace domain and the holders of individually issued API tokens.

Security

Access requires Google Sign-In from the permitted Workspace domain, or an individually issued API token. Traffic to Corpus is encrypted in transit with TLS. Tokens can be revoked individually and at any time.

Your rights

You can ask for a copy of the personal data Corpus holds about you, ask for it to be corrected, ask for it to be deleted, or object to how it is used. Write to the address below and we will respond within 30 days. If you are unhappy with the response, you may complain to your local data protection authority.

Children

Corpus is a workplace tool. It is not directed at children and is not intended for anyone under 16.

Changes to this policy

Changes are posted on this page with a new effective date. Where a change materially affects how operator data is handled, operators are notified by email before it takes effect.

Contact

Questions about this policy, or requests about your data, go to privacy@dascorpus.xyz.