Privacy Policy

Last updated: July 29, 2026

Arrahmah Doc Flow is an internal application used to review student submission documents received through Gmail. This Privacy Policy explains what information the application accesses, how it is used, and how it is protected.

Who Operates This Application

This application is operated by [Organization Name]. It is intended only for authorized internal users. Access is limited to approved e-mail addresses configured by the administrator.

Information We Access

When an authorized user connects a Gmail mailbox, the application may access Gmail messages and attachments that match the filters selected by the user, such as date range, subject, sender, and configured labels or folders.

The application may process the following information:

How We Use Information

Information is used only to verify whether student submissions are complete, readable, and follow the expected template. The application does not grade student answers and does not decide whether answers are correct.

Specifically, the application may use information to:

Gmail Data

Gmail access is used only for the mailbox processing features described above. The application does not send e-mail, sell Gmail data, or use Gmail data for advertising.

Depending on configuration, Gmail access may use Google OAuth/Gmail API or IMAP with a Gmail app password. OAuth tokens and IMAP credentials are treated as secrets and must not be logged or displayed.

AI Processing

The application may send page images from student submission documents to an AI vision provider to analyze document completeness and readability. The AI is instructed not to grade answers, score students, or infer information that is not visible.

AI responses are stored as analysis results so authorized users can review processing outcomes and troubleshoot errors.

Data Storage and Retention

The application stores processing records in its configured database. These records may include Gmail metadata, attachment names and hashes, analysis summaries, manual review reasons, and job status information.

Temporary files created while downloading attachments, rendering PDFs, or analyzing images are intended to be deleted after processing unless a debug setting is enabled by an administrator.

Retention periods are determined by [Organization Name]. Administrators should remove data that is no longer needed for reporting, audit, or operational review.

Data Sharing

Information is not sold or shared for advertising. Information may be processed by service providers needed to operate the application, such as hosting providers, database providers, Google Gmail services, and the configured AI provider.

Security

The application uses authenticated access and an approved e-mail allow-list. Sensitive values such as API keys, OAuth tokens, and Gmail app passwords should be stored securely using hosting configuration, user secrets, or environment variables, and should not be committed to source control.

Authorized users should sign out when finished and should not upload or process documents outside the intended student submission workflow.

Your Choices

Authorized users can sign out of the application at any time. Gmail access can also be revoked from the connected Google account or by changing mailbox credentials, depending on the authentication method used.

Contact

For privacy questions or access requests, contact [Privacy Contact Name or E-mail].

This page is provided as a standard internal application privacy notice. Please review it with your organization before publishing.