This Privacy Policy describes how dropwrk ("we", "us", the "Service") collects, uses and protects information when you use the dropwrk application and its website. dropwrk is designed around one principle: your invoices never leave your Google account.
1. Controller and contact
The data controller is dropwrk. For any privacy-related questions, contact us at privacy@dropwrk.com.
2. What data we collect
2.1. Identity data
When you sign in with Google Sign-In we receive your name, email address and profile picture via the standard openid, email, profile scopes. This data is used solely to create and manage your user profile.
2.2. Organization data
- Names of organizations, locations and memberships (owner/member roles);
- Email invitations to team members;
- Usage counters (number of uploaded invoices and pages);
- An audit trail of administrative actions (who, what, when).
2.3. Access tokens
To write files into your Google Drive we store the organization owner's Google refresh token in encrypted form. We also store QR tokens for scanner sessions. Access to this data is restricted via Row Level Security.
3. What we do NOT collect or store
- We do not store copies of your invoices. Image bytes pass transiently through our upload endpoint and are written directly into your Google Drive. dropwrk keeps no copy of any page.
- We perform no OCR, no AI extraction and no analysis of invoice content whatsoever;
- We never transmit invoice files to any AI provider — the Service has no such integration;
- We use no analytics tools, trackers or session replay — especially on the scanner and invoice pages;
- Invoice content never appears in logs, metrics or backups.
4. Use of Google API data
dropwrk's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4.1. Scopes
- openid, email, profile — used only for sign-in identification;
- https://www.googleapis.com/auth/drive.file — grants access only to the files and folders the application itself has created (the "Invoice Inbox" folder and the "Invoice Register" spreadsheet). dropwrk has no access to the rest of your Google Drive.
4.2. How we use this access
- Creating a folder structure in your Google Drive for incoming invoices;
- Writing scanned JPEG pages into those folders;
- Creating and appending rows in the "Invoice Register" spreadsheet in your Google Sheets.
We never use Google API data for advertising, never sell it and never share it with third parties except as necessary to provide the Service or as required by law.
5. Storage and protection
- Identity and organization data are stored in a secure database (Supabase) with Row Level Security;
- Google refresh tokens are stored encrypted;
- All communication happens over HTTPS with a strict Content Security Policy;
- Scanner sessions are authenticated with a signed cookie valid for 2 hours.
6. Sharing with third parties
We do not sell or rent personal data. We use the following processors solely for the technical operation of the Service: Google Drive, Google Sheets, Sign-In APIs, Supabase (authentication and database) and Vercel (hosting). None of them receives your invoice content from dropwrk.
7. Cookies
We use only strictly necessary cookies: a session cookie for sign-in and a signed scanner cookie valid for 2 hours. We use no advertising or analytics cookies.
8. Retention and deletion
- Profile and organization data are kept while the account is active;
- You can revoke dropwrk's access to your Google account at any time from Google Account → Security → Third-party access. The files in your Google Drive remain yours and untouched;
- Upon an account deletion request to privacy@dropwrk.com we delete the profile, organization data and stored tokens without undue delay.
9. Your rights (GDPR)
If you are located in the EU/EEA, you have the right of access, rectification, erasure, restriction of processing, data portability and objection. You can exercise these rights via privacy@dropwrk.com, and you may lodge a complaint with your supervisory authority — for Bulgaria this is the Commission for Personal Data Protection (CPDP).
10. Changes to this policy
For material changes we will publish the updated policy on this page and update the "Effective date". Continued use of the Service after a change constitutes acceptance of the updated policy.