Privacy Policy
Last updated: 10 August 2026
Overview
Extractor is an AI-powered document data extraction platform operated by DECODED LIMITED. It lets you upload documents — or connect an email mailbox so documents arrive automatically — and turns them into structured data using extraction templates you define.
This policy explains what data Extractor collects, why we collect it, how long we keep it, and the choices you have. It applies to the Extractor web application at extractor.decoded.digital and its API.
Information we collect
Account information. When you create an account we store your name, your email address, and the organisation (tenant) you belong to. If your organisation invites you, we also record who invited you and your assigned role.
Sign-in codes. Extractor is passwordless — we never ask for, receive or store a password. To sign in you enter your email address and we send a single-use six-digit code to it. That code is held only until it is used or expires, whichever comes first, and is then deleted.
Documents you provide. Files you upload — PDFs, images and other supported formats — are stored so they can be processed and so you can review results later.
Extracted data. The structured fields our AI extracts from your documents, along with any corrections you make.
Email data from connected accounts. If you connect a Google or Microsoft mailbox, we access messages and their attachments in order to identify and extract documents. This is described in detail in the next section.
Technical data. A session cookie used to keep you signed in, API keys you generate, and server logs recording requests made to the service.
Connected Google accounts and Limited Use
Where you choose to connect a Gmail account, Extractor requests the gmail.readonly scope. We use this read-only access solely to retrieve incoming messages and their attachments so that documents can be extracted according to the routing rules you configure. We do not send, modify or delete mail.
Extractor's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not use Google user data to serve advertising, we do not sell it, we do not transfer it to third parties except as necessary to provide or improve the extraction features you have enabled, and we do not allow humans to read it except with your explicit consent, where required for security or to comply with applicable law, or where the data has been aggregated and anonymised.
You can disconnect a Google account at any time from Settings, which removes our stored tokens. You may also revoke access directly at myaccount.google.com/permissions.
The same principles apply to Microsoft accounts connected through the Outlook integration.
How we use your information
We use the data described above to operate the service: to authenticate you, to process documents into structured data, to show you extraction history, to deliver results to any webhooks you have configured, to send transactional email such as sign-in codes and organisation invitations, and to secure and troubleshoot the platform.
We do not sell your data, and we do not use the contents of your documents or email to train third-party AI models.
Service providers
Extractor relies on a small number of processors, each handling data only as needed to provide the service:
OpenAI— document content is sent to OpenAI's API to perform extraction. Microsoft Azure — uploaded files are stored in Azure Blob Storage. MongoDB Atlas — account records and extracted data are stored in our database. Resend and SendGrid — used to deliver transactional email. Google and Microsoft — where you have connected a mailbox.
Data retention
Documents, extracted data and connected-account records are retained for as long as your account is active, so that you can review and re-export past extractions. You can delete individual documents and extractions at any time from within the application, which also removes the underlying stored files.
To delete an entire account or organisation and the data associated with it, contact us using the details below and we will action the request. Server logs are retained for a limited period for security and diagnostic purposes.
Security
Data is encrypted in transit using TLS and encrypted at rest by our storage providers. Access to production systems is restricted to authorised personnel. Sessions are managed with signed tokens, and API keys are scoped to the tenant that created them.
No system is perfectly secure. If we become aware of a breach affecting your data, we will notify affected users without undue delay.
Your rights
You may request access to, correction of, or deletion of your personal data, and you may ask us to export it in a portable format. You can disconnect any linked mailbox or revoke any API key yourself at any time. To make a request, contact us using the details below.
Children
Extractor is a business product and is not directed at children under 16. We do not knowingly collect personal data from children.
Changes to this policy
We may update this policy as the service evolves. Material changes will be announced in the application or by email, and the "last updated" date above will change.
Contact
Questions about this policy or about your data — including requests to access, correct, export or delete it — can be sent to support@decoded.digital.