Your privacy and data security are fundamental to how we build and operate eKTextAI.
Last updated: September 12, 2026
GDPR/UK-GDPR Compliant · Google API Services User Data Policy (Limited Use)
At eKTextAI (operated by MarvelSoft Ventures, Bangalore, India), we believe privacy is a fundamental right. This policy explains how we collect, use, and protect your information when you use our enterprise knowledge AI platform. eKTextAI is a multi-tenant product: each customer (tenant) has an isolated workspace. Google user data obtained through Google OAuth and Google APIs is stored only in that tenant’s space and is used solely to provide or improve the features you requested.
Service Provider: eKTextAI
Operated by: MarvelSoft Ventures
Location: Bangalore, India
Phone: +91 95350 41234
Contact Email: info@ektextai.com
Legal Contact: info@marvelsoft.co.in
eKTextAI may request access to certain Google user data when a tenant user connects a Google account via OAuth 2.0. This section states what Google user data we access, how we use it, with whom we share it, how we protect it, and how long we keep it. It is written to comply with the Google API Services User Data Policy, including the Limited Use requirements.
Google user data obtained through Google APIs (including Google Drive, Google Calendar, Google user profile / userinfo, and related OAuth tokens) is used only to provide or improve user-facing features of eKTextAI that are apparent in the product: connecting Drive files to a tenant knowledge base, scheduling and managing calendar events, identifying the connected Google account, and operating those features efficiently for that tenant.
Access is granted only after the user completes Google’s OAuth consent screen. We request only the scopes needed for the feature the tenant enables. Depending on which integration the tenant connects, eKTextAI may access:
We access your Google account identifier, name, email address, and profile picture (if provided). We use this only to identify which Google account is connected, display connection status in the tenant workspace, and bind tokens to the correct tenant user.
We access file and folder metadata (such as name, ID, MIME type, modified time, and parent folder) and the content of files the tenant selects to import or sync into that tenant’s knowledge base. Access is read-only. We do not use Drive to browse or copy files unrelated to the tenant’s configured import.
We access calendar lists and event data needed to create, read, update, or delete events the tenant (or the tenant’s authorized automation) requests—such as title, description, start/end time, timezone, attendees, and Google Meet conference details. This lets users schedule meetings, check availability, and send invitations from eKTextAI without leaving the application.
We store access tokens and refresh tokens issued by Google so the tenant’s connection remains active. Tokens are stored encrypted, scoped to that tenant, and used only to call Google APIs for the features above.
If the tenant also connects optional Google services (for example Gmail read-only for email features, or Google Business Profile for listing management), we access only the data required for that feature. The same Limited Use, non-sharing, encryption, tenant-isolation, retention, and deletion rules in this section apply to that Google user data.
We use Google user data solely to operate the Google-connected features the tenant enabled, including:
Google user data is not used to train, develop, or improve generalized or non-personalized AI/ML models. Content imported from Drive remains in the connecting tenant’s workspace and is used only to provide that tenant’s knowledge and automation features.
We do not sell Google user data. We do not share, transfer, or disclose Google user data to unaffiliated third-party applications for their own use. We do not transfer Google user data to third parties for advertising, data brokerage, credit decisions, lending, or training generalized AI/ML models.
Google user data may be processed only as follows:
We retain Google user data only for as long as needed to provide the connected features, or until the tenant disconnects Google or deletes their eKTextAI account, unless a longer period is required by law.
You can also revoke eKTextAI’s access at any time at Google Account permissions.
🛡️ We do not sell your personal information. We only share data in specific, limited circumstances outlined below.
When you explicitly authorize us to share information with third parties.
To comply with legal obligations, court orders, or governmental requests.
With infrastructure providers that host eKTextAI, solely to operate the product for the tenant. They may not use tenant or Google user data for their own products. We do not share Google user data with third-party applications for reasons other than providing or improving eKTextAI’s user-facing features.
To protect our rights, prevent fraud, or ensure user safety.
Encryption in transit (TLS) and at rest. OAuth tokens and other sensitive credentials are stored encrypted.
Role-based access, authentication, and least-privilege controls on each tenant account.
Each customer works in their own space. Tenant data, including Google user data, is not shared across tenants.
Security procedures are in place to protect the confidentiality of your data, including monitoring, encrypted backups, and restricted production access.
If you are located in the European Union (EU) or United Kingdom (UK), you have specific rights under the General Data Protection Regulation (GDPR) and UK-GDPR. We are committed to ensuring your rights are respected and easily exercisable.
Legal Basis for Processing: We process your personal data based on your explicit consent, contract performance, legal obligations, legitimate interests, or vital interests as permitted under GDPR Article 6.
Request a copy of all personal information we hold about you. We will respond within 30 days.
Exercise this right →Correct or update any inaccurate personal information. We will update your data promptly.
Request correction →Request deletion of your personal information (subject to legal requirements). We will process your request within 30 days.
Request deletion →Export your data in a machine-readable format (JSON or CSV). We will provide your data within 30 days.
Export your data →Object to processing of your personal information for specific purposes. We will respect your objection.
Object to processing →Withdraw your consent at any time. Withdrawal does not affect processing that occurred before withdrawal.
Withdraw consent →You can exercise your GDPR rights through:
/api/gdpr
Response Time: We will respond to your request within 30 days as required by GDPR. If your request is complex, we may extend this period by up to 60 days, and we will inform you of the extension.
If you believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local supervisory authority:
We retain your personal information only as long as necessary to provide our services and comply with legal obligations. Account data is typically retained for the duration of your subscription plus 30 days, unless longer retention is required by law. Google user data (OAuth tokens, profile identifiers, and imported Drive/Calendar data) is retained only while the Google integration is connected or until you request deletion, as described in Section 3.
GDPR Compliance: Under GDPR Article 17 (Right to Erasure), you can request deletion of your data. We will process deletion requests within 30 days, subject to legal requirements that may require longer retention.
When you request data deletion:
Your data may be transferred to and processed in countries other than your own. We ensure adequate protection through appropriate safeguards such as standard contractual clauses and adequacy decisions.
Current Data Storage: We store your data in secure cloud infrastructure. For EU/UK users, we offer data residency options to keep your data within the EU/UK region.
If you are located in the EU or UK, you can request that your data be stored within the EU/UK region to comply with GDPR/UK-GDPR data residency requirements.
In the event of a data breach that may affect your personal data, we are committed to:
If a breach affects your personal data, we will notify you via:
What to Do: If you receive a breach notification, please review your account for any suspicious activity, change your password if necessary, and contact us if you have concerns.
Our services are not intended for children under 16. We do not knowingly collect personal information from children. If we become aware of such collection, we will take steps to delete the information promptly.
We may update this Privacy Policy from time to time. We will notify you of any material changes via email or through our platform. The "Last updated" date at the top of this policy indicates when it was last revised.
If you have any questions about this Privacy Policy or our data practices, please don't hesitate to contact us.