Privacy
Privacy Notice for G3 Docs.
This notice explains how G3 handles account data, documents, mobile capture, AI/OCR processing, signatures, billing, security, retention, and privacy requests.
This notice is drafted for the current G3 product surface. the G3 production operator must keep its legal entity details, processor list, retention schedule, and jurisdiction-specific disclosures current before and after public release.
Controller, processor, and scope
the G3 production operator is responsible for the G3 service pages, accounts, billing, support, and product operations. For documents and workspace content controlled by an organization or customer, G3 may act as a service provider or processor and handle that content only to provide the requested service, unless a separate agreement says otherwise.
Information we process
G3 may process account identifiers, email, name, authentication and SSO details, workspace roles, uploaded PDFs and files, captured images, OCR text, extracted fields, page blocks, metadata, comments, approvals, signatures, signature evidence, share links, workflow rules and run history, business-report fields, usage records, support messages, ratings, and feedback.
Device, store, and diagnostic data
We may process IP address, request identifiers, browser or device details, session cookies, preferred language, upload checksums, file size, local draft status, push tokens, app-store purchase receipts, billing events, and diagnostics or crash context if monitoring is enabled. These records support authentication, security, abuse prevention, uploads, purchases, support, and service reliability.
Camera, files, and mobile permissions
Camera access is used only when you capture documents. Existing files or photos are imported through the operating-system picker or WebView file chooser. The mobile app is designed not to request unrelated permissions such as contacts, precise location, microphone, broad storage, overlays, or background tracking.
Purposes and legal bases
We use information to provide capture, upload, OCR, AI assistance, search, editing, redaction, translation, export, signatures, collaboration, approvals, sharing, automation, webhooks, billing, support, security, audit evidence, legal compliance, fraud prevention, and service improvement. Depending on the jurisdiction, processing may rely on contract performance, consent, legal obligations, legitimate interests, or other permitted bases.
Sensitive and customer-controlled documents
You control what you upload and must have authority to process it. G3 may handle financial, tax, identity, signature, legal, employment, health, or other sensitive information only because it appears in documents or workflows you choose to use, and only for the service, security, support, billing, compliance, or retention purposes described here.
AI, OCR, and automated assistance
G3 may use local OCR, Apple Vision, Tesseract, OpenAI-backed OCR or AI, and similar configured providers to extract, summarize, translate, edit, classify, or review documents. G3 does not make solely automated legal, financial, employment, credit, health, identity, or similarly significant decisions for you. Outputs may be incomplete or inaccurate and require human review.
Processors and integrations
When enabled, data may be processed by hosting, database, S3-compatible storage, identity/OIDC, email, push-notification, billing, app-store, signature, OCR, AI, accounting-export, webhook, analytics, or diagnostics providers. Production operators must name the active processors and keep their data-processing terms, transfer mechanisms, and security reviews aligned with the deployed stack.
Sharing, transfers, and recipients
We do not sell document content or share it for cross-context behavioral advertising. Data may be shared with workspace members, recipients you select, public share-link or signing-link visitors, approval recipients, custom webhook destinations, service providers, app stores and payment processors, professional advisers, authorities when legally required, or parties to a business transfer. Processing and storage may occur outside your country when permitted by applicable law.
Cookies and communications
G3 uses essential cookies and similar storage for sign-in, CSRF or OIDC state, language, security, and session continuity. We do not use advertising cookies by default. Product, billing, support, signature, workflow, and security communications may be sent as needed for the service; marketing communications should be sent only where permitted and with available opt-out choices.
Security, retention, and deletion
G3 is designed for HTTPS transport, httpOnly session cookies, role-based access, scoped share links, rate limits, upload checksums, audit logs, and managed storage encryption. Data is retained for the account or workspace lifecycle and then only as needed for backups, audit evidence, signatures, billing, tax, disputes, fraud prevention, legal compliance, and legitimate operations. You may request deletion through the account deletion page or gustavo.g.gallaga@gmail.com.
Privacy rights
Depending on where you live, you may request access, correction, deletion or cancellation, objection, restriction, portability, withdrawal of consent, limits on sensitive-data use, or information about categories of data and recipients. Mexican users may exercise ARCO rights. EU/UK users may exercise GDPR rights. California users may exercise CCPA/CPRA rights where the law applies. Send requests to gustavo.g.gallaga@gmail.com.
Children, changes, and contact
G3 is intended for business and productivity use and is not directed to children below the minimum age required by applicable law. We may update this notice when the product, providers, law, or operating entity changes. Material changes will be posted here or communicated where required. Contact gustavo.g.gallaga@gmail.com for privacy questions.