Privacy Policy

Last updated: 30 August 2026

ButterFile ("we", "our", or "us") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains what data we collect, why we collect it, how we use and store it, and the choices you have.


1. Who We Are

ButterFile is an AI-powered document extraction service that converts documents (PDFs, images, and other files) into structured spreadsheet data. The service is operated under the brand name ButterFile.


2. Information We Collect

2.1 Account Information (Authenticated Users)

When you sign in with Google, we receive from Google:

  • Your full name
  • Email address
  • Google account identifier (sub)
  • Profile picture URL (if available)

We use this information to create and maintain your account.

2.2 Organization and Usage Data

  • Organization name and membership (when you create or join a workspace)
  • Subscription plan and billing status
  • Credit usage and processing job history (number of documents processed, job timestamps, job status)

2.3 Uploaded Documents

When you upload files for processing, those files are transmitted to our servers and stored in Google Cloud Storage (GCS) so that our AI/OCR engine can extract structured data and so that you can view, download, and refer back to the original document later. ButterFile acts as a document store for your account: uploaded originals are kept for the life of your account and through the post-termination period described in Section 9. No timer decides to delete your documents. They are removed when you delete them, or when a contract has ended and a person has reviewed and approved the deletion — never because a file simply grew old. Extracted results are also stored in GCS and in our database and linked to your account.

We do not use the content of your uploaded documents for training AI models or for any purpose other than performing the extraction you requested.

2.4 Guest Usage (No Account)

If you use ButterFile without signing in, we assign an anonymous device identifier (UUID) stored in your browser's localStorage. This identifier is used solely to associate your processing jobs with your browser session and apply free-tier usage limits. It is not linked to any personal identity.

2.5 Technical, Session, and Usage Data

We may collect:

  • Browser type and version
  • Device type and operating system
  • IP address
  • Session cookies and CSRF tokens (used for authentication and security)
  • Correlation IDs (randomly generated per-request identifiers for debugging)
  • Pages visited, features accessed, and interactions with the service interface
  • Aggregated usage metrics collected through analytics tools to help us understand how the service is used and improve it over time

The analytics tools we use for this purpose, and the choices you have over them, are described in Section 2.6.

2.6 Cookies, Analytics, and Session Replay

We use cookies and similar browser storage for two purposes.

Necessary cookies keep the service working: authentication sessions, CSRF protection, your language and theme preference, and the record of your cookie choice itself. These are always active. The service cannot function without them.

Analytics cookies help us understand how the service is used so we can improve it. They remain disabled until you explicitly choose "Accept all". If you choose "Necessary only", the analytics tools either do not run or continue in a restricted, cookieless mode that cannot recognise you across visits. You can change your choice at any time through the "Cookie settings" link in the site footer.

Our analytics providers:

ProviderWhat it does
Google Analytics 4Aggregated usage statistics: pages visited, navigation patterns, general geographic region, device characteristics. Processed by Google under its own Privacy Policy.
Meta PixelMeasures the effectiveness of our advertising and how visitors reach our site. Processed by Meta under its own Privacy Policy.
Microsoft ClarityBehavioural analytics: heatmaps and session replays showing clicks, scrolling, and navigation, so we can find where our interface is confusing.

About Microsoft Clarity session replays. Clarity reconstructs a visual playback of a browsing session. We run Clarity in its strictest masking mode, which replaces text with placeholder characters in your browser, before anything is transmitted. The contents of your uploaded documents, your extracted data, your file names, and anything you type are therefore never sent to Microsoft. What is transmitted is limited to interaction signals: where you clicked, how far you scrolled, which pages you moved between, and where you appeared to get stuck. We selectively un-mask only our own public marketing pages, which contain no user data.

Microsoft acts as an independent data controller for data collected through Clarity, meaning Microsoft determines how it uses that data under its own terms. See the Microsoft Privacy Statement.

Independently of your cookie choice, you may opt out of Google Analytics using the Google Analytics Opt-out Browser Add-on.


3. Third-Party Integrations You Connect

When you choose to connect third-party services through the Connections feature, we request only the permissions required to perform the integration:

3.1 Google Drive

If you connect Google Drive, we request OAuth access to:

  • Browse and select folders in your Google Drive (via Google Picker)
  • Read files from the folders you designate as an input source

We store only the OAuth access token and refresh token necessary to maintain this connection on your behalf. We access your Drive only to fulfil actions you explicitly initiate (e.g., reading source documents, writing output files to a selected folder).

3.2 Google Sheets

If you enable Google Sheets output, we request access to:

  • Create a new Google Spreadsheet in the folder you selected
  • Write and update the spreadsheet with extracted data when you trigger a sync

We do not read, modify, or access any other files or spreadsheets in your Google account beyond what you have explicitly designated.

3.3 Google API Limited Use

ButterFile's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

  • We use Google user data only to provide or improve the features visible to the user in ButterFile
  • We do not use Google user data for serving advertisements
  • We do not allow humans to read Google user data unless the user has given explicit permission, it is necessary for security purposes, or it is required by law
  • We do not transfer Google user data to third parties except as necessary to provide the service, as required by law, or with the user's explicit consent

3.4 Revocation

You may revoke Google OAuth access at any time via Google's security settings and by deleting the connection from within ButterFile.


4. Legal Basis for Processing

We process your personal data under the following legal bases:

BasisExamples
Contract performanceCreating and managing your account, processing uploaded documents, managing subscriptions
Legitimate interestSecurity, fraud prevention, service reliability, debugging
Legal obligationRetaining payment records as required by financial regulations
Legitimate interestAnalytics and usage measurement to understand how the service is used and to improve it
ConsentConnecting Google Drive or Google Sheets integrations (you may withdraw at any time)

5. How We Use Your Information

We use the information we collect to:

  • Authenticate your identity and maintain your session
  • Process the documents you upload and return structured results
  • Manage your workspace, subscription plan, and usage credits
  • Sync extracted data to Google Sheets or Google Drive on your behalf (when you have connected these services)
  • Process payments and manage your subscription via Stripe
  • Enforce usage limits and prevent abuse
  • Respond to support requests
  • Maintain the security and reliability of our service

6. Payments and Billing

Subscription payments are processed by Stripe. We store only your Stripe customer ID and subscription ID in our database. We do not store or have access to your full payment card details. These are handled entirely by Stripe under their own Privacy Policy.


7. Data Sharing

We do not sell your personal information.

We may share data with the following categories of service providers, only to the extent necessary to operate ButterFile:

ProviderPurpose
Cloud database providerUser accounts, organizations, and job metadata
Google Cloud StorageStorage of uploaded documents and OCR results
Google OAuth / Picker APIAuthentication and Drive folder selection
StripeSubscription billing and payment processing
Google AnalyticsAggregated, anonymised usage analytics to improve the service
Meta PixelAdvertising measurement and attribution
Microsoft ClarityHeatmaps and masked session replays used to improve the interface (see Section 2.6)

All service providers are bound by appropriate confidentiality and data security obligations.

We may disclose information if required to do so by law, court order, or governmental authority.


8. Data Security

We implement reasonable technical and organizational measures to protect your information, including:

  • HTTPS encryption for all data in transit
  • CSRF token protection on all state-changing API requests
  • Session-based authentication with HTTP-only cookies
  • Access to stored documents is governed by Google Cloud project-level permissions (IAM). We are moving to dedicated service accounts with least-privilege access to each storage bucket, so that only the specific services that need a document can reach it; until that work is complete, access is limited to the people and services granted a role on our Google Cloud project
  • Deleting a stored file is not something our services can do. The permission to delete belongs to one dedicated account used by the scheduled clean-up described in Section 9 and by approved erasure requests. The application that serves your documents cannot delete them
  • We do not open your documents. ButterFile staff read the content of an uploaded file only when you ask us to — for example when you report a problem with an extraction and give us permission to look at that document. Support work otherwise uses job metadata (status, page counts, error messages), not the document itself

No method of transmission over the internet is 100% secure. We encourage you to use a strong, unique password for your Google account and to revoke any connections you no longer need.

In the event of a data breach that is likely to affect your rights or interests, we will notify affected users without undue delay and take appropriate steps to mitigate harm.


9. Data Retention

Data typeRetention
Account informationRetained while your account is active
Uploaded documents (in GCS)Retained for the life of your account so you can view and download them at any time. When you delete a document, project, or account, the file is deleted too. It disappears from your workspace at once and is removed from storage 7 days later — the gap is a grace period, so a deletion you did not mean can still be undone. For a further 7 days after that, Google Cloud Storage keeps a copy that only we can restore, in case of an incident on our side; after that the file is gone. Copies inside database backups expire on their own schedule (see below). If you need a file erased sooner, ask us; see Section 11
Processing job results (extracted data)Retained while your account is active, and for up to 5 years after your contract or account ends. This covers the accounting retention period our customers are subject to and the window in which an extraction may be disputed. You may ask us to erase them sooner; see Section 11
Guest uploads (no account)Kept for at least 1 year from upload. After that the file is put in front of a person for review and is deleted only once they approve it — nothing in ButterFile is deleted by a timer, guest uploads included. A guest upload belongs to no account, so nobody can sign in and delete it themselves; the review is how it eventually goes. For 7 days after deletion a copy remains recoverable by us in case of an incident. Erased sooner on request
Guest device identifierStored in your browser's localStorage; cleared when you clear site data
Cookie consent choiceStored in your browser's localStorage until you change it via "Cookie settings" or clear site data
Session cookiesExpire at end of session or on logout
Payment recordsRetained as required by applicable financial regulations
Database backupsTaken daily and retained for up to 400 days. Data you have deleted may persist in these backups until they expire; backups are used only for recovery and are not used to restore deleted data to the live service

9.1 When a paid organisation's contract ends

If your organisation's subscription or contract ends, we keep your documents for at least 90 days. During this period you can sign in, view your documents and results, and export your data. We will contact the organisation's address on record before anything is deleted, and give you time to export what you need; today we do this by hand rather than on an automatic schedule, and we would rather tell you that than describe a system we do not yet run.

After the 90 days, your uploaded documents and case attachments become eligible for deletion. Nothing is deleted on a timer. A person reviews the exact list of files, approves it, and only then does the deletion run; each file is verified as removed afterwards. Links to original documents in previously exported files will stop working once deletion runs.

Extracted results are retained for 5 years from the contract end date, as described in the table above.

If you resubscribe during those 90 days, nothing is deleted and your account continues as before. If you need your documents held for longer, contact us to arrange an archive agreement.

You may request deletion of your account and associated data at any time (see Section 11).


10. Children's Privacy

ButterFile is not directed at children under 13 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.


11. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Delete your account and personal data. Deleting a document, project, or account from within the app erases the stored files too — Section 9 says exactly when. If you need something erased sooner than that, across a wider scope than the app can express, or from an account you can no longer sign in to, email us at the address below naming the account, project, or documents concerned. We will confirm receipt and complete the erasure within 30 days, and tell you what was erased and what — if anything — we are required to keep. Two things we may keep, and why: extracted results for up to 5 years after your account or contract ends (accounting retention and the window in which an extraction may be disputed — see Section 9), and copies inside database backups until those backups expire (up to 400 days; backups are used only to restore the service, never to bring deleted data back). If you ask us to erase results sooner we will honour it where the law allows and no accounting, legal, or dispute obligation requires otherwise
  • Withdraw consent for Google Drive / Google Sheets integrations at any time
  • Data portability: you may export your extracted results from within the application at any time as an Excel file

To exercise any of these rights, contact us at the address below.


12. International Data Transfers

ButterFile is operated from Thailand. Your data may be stored and processed in data centres located outside your country of residence (including regions where Google Cloud infrastructure operates). By using ButterFile, you consent to such transfers.


13. Changes to This Policy

We may update this Privacy Policy from time to time. We will update the "Last updated" date at the top of this page whenever changes are made.

What changed on 30 August 2026. We reviewed this policy against what our systems actually do and corrected it where the two did not match. In summary:

  • We found that deleting a document, project, or account removed the item from your workspace but did not erase the stored file, which this policy had claimed it did. That is now fixed: deletion removes the file from storage after a 7-day grace period, and Section 9 describes exactly what happens and when. Between the two versions of this page, files were erased on request (Section 11).
  • We now state how long extracted results are kept after an account or contract ends (up to 5 years), and why.
  • We added what happens when a paid organisation's contract ends (Section 9.1) and that deleted data persists in database backups until those expire. Guest uploads are now kept for at least 1 year and then reviewed by a person before deletion; the earlier draft of this page said 30 days, which was neither built nor long enough to be useful to someone who came back for their result.
  • We corrected our description of access controls in Section 8 to describe the controls we have today rather than the ones we are moving to, and added two commitments that were already how we work but were not written down: the application that serves your documents has no permission to delete them, and we do not open the content of your files unless you ask us to.

None of these changes reduce your rights. Several of them describe limits that were always true but were not written down.

For material changes that affect how we process your personal data, we will notify you by email or via an in-app notice before the changes take effect. Your continued use of ButterFile after the effective date of material changes constitutes acceptance of the updated policy.


14. Contact

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:

ButterFile Email: contact@butterfile.io