Scope and administration
This notice covers Factory Legal Docs, the Google Docs publishing connection within the internal Factory service. Access to Factory is limited to authorized team members; it is not offered as a public customer service. Public readers of published documents do not receive access to Factory.
The team administering Factory is responsible for operation of this connection. Questions and requests should be submitted to the Factory administrator through the team's established internal support channel. Policies inside published application documents concern those applications and are separate from this notice.
Information processed
The connection processes document titles and content supplied by the team, Google file IDs, file type and deletion status, application properties linking a document to a Factory run, content hashes, and sharing permissions. Documents may contain application information and contact details that the team intends to publish.
Factory retains source documents, publication links and run records on its host. The OAuth connection stores a refresh token and client credentials and uses temporary access tokens to authenticate API requests. This connection does not request Google account profile, contacts, Gmail, calendar, or access to the entire Drive account.
Google access and purposes
Factory requests https://www.googleapis.com/auth/drive.file. Google limits this permission to files created by the application or otherwise explicitly authorized for it. The current publishing workflow operates on documents created for Factory runs and checks their run identity before reusing saved IDs.
Access is used to create native Google Docs, replace their content when republished, maintain stable URLs, and set or verify public read-only permissions. Background publication requires offline authorization. Application JSON files are hosted separately.
Public sharing and recipients
Selecting Google Docs hosting instructs Factory to publish Privacy, Terms and Support documents with an “anyone with the link” reader permission. Anyone receiving a link can read, copy, or redistribute the content. Factory sets link sharing without file discovery; this is not a guarantee that content will remain unindexed or confidential.
Google receives document content and API requests to provide Drive and Docs. Team members with authorized Factory or host access may access publication records and source documents. A recipient's own copies cannot be recalled by revoking the original link.
Google data use restrictions
Google API data is used only for the described document publishing and related troubleshooting or security functions. It is not sold, used for advertising or credit decisions, or used to train generalized AI models. The publishing adapter does not send data retrieved from Google APIs to AI providers.
Factory Legal Docs' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Non-public Google API data is not made available for unrelated human review. Support access must be authorized for the specific data, or necessary for security or applicable legal obligations.
Other Factory functions, including document generation before upload, are outside the Google publishing connection described here. Team members should follow their organization's rules for those functions.
Storage and protection
Google documents remain in the connected Google Drive account. Factory's local credentials are stored in a file restricted to the host user and are not placed in generated application code or repositories. API communication with Google uses HTTPS. These measures do not make public document content private.
Local files, run records, operational logs and backups are subject to the team's host access and backup arrangements. This connection does not claim a particular storage country, an encryption-at-rest certification, or a fixed backup retention period.
Retention and deletion
Google documents remain until the account owner deletes them or Google applies its own account policies. Factory's publication IDs and source documents remain with the relevant run records until removed by an authorized administrator. OAuth credentials remain until removed or replaced; access may also expire or be revoked by Google or the account owner.
This connection has no automatic retention-based deletion schedule. The administrator handles removal of local publication records and credentials on request, subject to applicable recordkeeping requirements. Backup copies may remain until the team's backup rotation removes them and should not be restored for ordinary use after an approved deletion.
Disconnecting, unpublishing and export
Revoke the connection in Google Account connections to prevent future authenticated operations. Ask the Factory administrator to remove local credentials to disconnect the host. Neither action automatically deletes existing documents or closes their public links.
To unpublish, change sharing permissions in Google Drive. Also disable Google Docs publication for the relevant Factory run before republishing; otherwise the publisher may restore public reader access. To delete a document, use Google Drive and its trash controls. Export document content using Google Docs' download functions; local source documents can be obtained from the administrator.
Requests and applicable rights
Use the internal support channel to request access, correction, export, deletion, or restrictions relating to information held by Factory. Identify the affected run or document; do not send OAuth tokens or other credentials. The administrator may need proportionate verification of your authority before changing another person's data or account.
Where applicable data protection law grants additional rights, including objection, withdrawal of consent, or a complaint to a supervisory authority, those rights remain available. Requests are handled within the time limits required by the law that applies. Google OAuth authorization permits API access; it does not replace any separate legal basis required for processing personal data.
Website preferences and changes
These public information pages store your theme preference in browser local storage under factory.theme. They do not embed advertising or analytics scripts. The web server may process connection information, including requested URLs and IP addresses, for delivery, operation and security. Google document pages follow Google's own privacy policy.
The date above identifies the current notice. Material changes to access or use of Google data must be communicated to the team before the new use begins, with renewed authorization where required. Publication of a revised notice alone does not authorize broader access.