Skip to main content
AtlasServicesAbout
Sign inTalk to Us
AtlasServicesAboutSign in

Privacy

Atlas for Google Docs™ Privacy Notice

Effective
August 18, 2026
Version
1.0

Contents

  1. 1. SCOPE
  2. 2. WHAT THE ADD-ON OBTAINS FROM GOOGLE
  3. 3. WHAT THE ADD-ON SENDS TO UNICORE
  4. 4. HOW THE PLATFORM REACHES YOUR DOCUMENTS
  5. 5. WHAT ATLAS WRITES BACK
  6. 6. LANGUAGE MODEL PROVIDERS
  7. 7. RETENTION AND DELETION
  8. 8. SHARING AND LOCATION
  9. 9. LIMITED USE
  10. 10. REMOVING THE ADD-ON
  11. 11. SECURITY AND ACCESS
  12. 12. CHANGES TO THIS NOTICE
  13. 13. CONTACT UNICORE
  14. 14. TRADEMARKS

1. SCOPE

1.1 What this covers.

This notice describes how the Atlas for Google Docs™ add-on (the "Add-On") and the Unicore Atlas platform (the "Platform") access, use, store, and share data from Google Docs™ and Google Drive™.

The Unicore Privacy Policy at unicoregp.com/privacy describes Unicore's processing of Personal Information as a Controller and does not cover the processing this notice describes. This notice is not a contract and does not modify the agreement between Unicore and the organization that holds the Atlas account.

This notice covers the Add-On alone.

1.2 Account and workspace.

The Add-On is an interface to the Platform and requires an Atlas account. Your organization holds that account, and the Platform keeps your organization's material in a workspace. Unicore performs the commitments this notice describes.

2. WHAT THE ADD-ON OBTAINS FROM GOOGLE

Google grants the Add-On a narrow authorization that reaches only the document in which you opened it. Its remaining authorizations let it display inside Google Docs™ and connect to Atlas, and return no data. Google shows you the authorizations the Add-On requests before you install it.

Under that authorization, the Add-On reads the identifier and the name of the document you have open. It does not read the text of your document, and nothing you do in the Add-On causes it to. It does not obtain your name.

The Add-On holds no Google Drive™ authorization. It cannot create a file, list a folder, or open a file other than the one you have open. It sends Unicore no document identifier other than the one for the document you have open.

When you sign in, the Add-On obtains the email address of the Google account you are signed in as, and the identifier Google assigns to that account. Unicore uses them for two purposes: to record that you accepted this notice and which version of it, and to confirm that your Atlas account is being used from a Google account you have signed in from before. Unicore does not use them for marketing, does not sell them, and does not disclose them outside the recipients listed in "Sharing and Location."

The Add-On stores a small amount of its working state inside the document you have open: which Atlas draft the document corresponds to, what kind of document it is, whether a review is in progress, and the names of the Drive files a drafted plan drew on. It stores your Atlas sign-in token in the private storage Google provides to the Add-On for your account. This working state is not part of your document's text.

3. WHAT THE ADD-ON SENDS TO UNICORE

The Add-On sends to Unicore:

  • your Atlas sign-in token, when you open the Add-On, when you sign out so that Atlas can revoke it, and with each call in between;
  • the email address of the Google account you are signed in as, and the identifier Google assigns to that account, for the purposes described in "What the Add-On Obtains from Google";
  • the identifier and the name of the document you have open;
  • the text you type into the panel, which is your questions and your messages to Atlas;
  • identifiers of the records you ask Atlas to create, read, or draft from, such as a workspace, a policy, a plan, or a Drive folder, which carry no document content; and
  • at the moment you confirm a change, the passages and replacement text that Atlas itself proposed, so that Atlas records your decision.

The Add-On does not read or send the body of your document, and it sends nothing from any other file in your Drive. It holds no Google Drive™ authorization, and the authorization it does hold reaches only the document in which you opened it.

Google hosts the Add-On and receives its error records.

4. HOW THE PLATFORM REACHES YOUR DOCUMENTS

4.1 The two connections.

Your organization connects one or more Google Drive™ folders to the Platform and chooses which of them the Platform keeps synchronized. The Platform reaches a document in one of two ways. Where you have connected your own Google account, the Platform acts under that connection and reaches only the files you created or selected. Where you have not, the Platform acts under a service account and reaches only the files and folders your organization shared with it. The Platform holds no authorization to act as any other user of your organization's Google Workspace™ domain.

4.2 When the Platform reads.

The Platform reads the content of a document when you submit it for review. Where your organization enables synchronization for a connected folder, the Platform also reads that folder on a schedule, taking files of a supported type up to the size and number limits Unicore sets, and reads its subfolders where your organization enables that. When you ask the Platform to gather material from a folder, it reads that folder and the subfolders beneath it. The Platform also reads Google Drive™ activity records for these files, which show who opened, edited, or commented on them.

Where you ask Atlas to draft from a folder, the Platform reads the documents in that folder as sources, under the access your organization granted when it configured the Platform. The Add-On does not read that folder and holds no Google Drive™ authorization. It sends only the identifier naming the folder you chose.

4.3 Unicore's role.

This access exists independently of the Add-On. Unicore processes this content as a Processor, on your organization's instructions, under your organization's agreement with Unicore.

5. WHAT ATLAS WRITES BACK

Atlas evaluates the document against the compliance rules your organization configured and writes its findings into that document as tracked suggestions and anchored comments. Where you ask Atlas for a drafted plan, Atlas writes that plan into the document you have open. Atlas writes into a document you submit for review or have open in the Add-On. It does not write into any other file. Nothing in your document changes until a person accepts a suggestion, and Atlas records who accepted it. Atlas produces suggestions for a person to review. Its findings are not an audit, an attestation, or legal or regulatory advice, and a person your organization authorizes decides whether to accept each one.

6. LANGUAGE MODEL PROVIDERS

6.1 What Atlas sends, and why.

To produce a review, Atlas sends document content and the text of questions you ask to language model providers. Atlas sends only what the feature you requested needs, and sends it only to deliver that feature.

Atlas uses providers in two roles. A review provider reads the document and produces the findings Atlas writes back. An index provider converts document text into the search index entries that let Atlas find relevant material. Each provider receives document content.

6.2 Who the providers are.

Unicore names the providers it uses, the role they serve, their retention period, and their processing location at trust.unicoregp.com. That page is public and requires no account. Unicore updates that page before engaging a new provider or changing the role a provider serves.

Unicore engages providers through their commercial application programming interface. Where Atlas uses a model Unicore hosts on its own infrastructure, no provider receives that content.

6.3 Limits on their use.

Providers process that content only to return the review Unicore requested on your behalf. Unicore's agreements with them prohibit them from using content submitted through Unicore's accounts to train, fine-tune, or improve models. Unicore does not use document content, your questions, or outputs generated from them to train, fine-tune, or improve models.

6.4 Where the content sits, and for how long.

Providers keep a copy of what Unicore sends and returns for a limited period so that they can investigate misuse of their own services, then delete it. Providers do not use that copy for any other purpose. Unicore states a provider's processing location and retention period at trust.unicoregp.com. Providers process this content in the United States.

7. RETENTION AND DELETION

7.1 What Atlas keeps.

Atlas stores the text of documents it ingests, the search index entries derived from that text, and the complete prompt and response of language model calls, as the audit record that lets a compliance review be reproduced and challenged.

7.2 How long.

Atlas retains that record while your organization's Atlas subscription is active, and deletes it within ninety (90) days after the subscription ends. For thirty (30) days after the subscription ends, Unicore makes your organization's data available for export on written request.

7.3 Deleting earlier.

Your organization may request deletion earlier, by writing to [email protected] or through its Atlas administrator. Unicore acknowledges the request within five (5) business days and completes it within thirty (30) days. Deletion works at two levels, and each level removes different records.

Deleting your organization's workspace removes the documents Atlas holds for your organization, the search index entries derived from them, the review records and findings, and the document text held in Unicore's records of language model calls.

Deleting a document removes that document and the search index entries derived from it. It does not remove the document text held in Unicore's records of that document's language model calls. Unicore removes that text when it deletes the workspace.

7.4 What survives.

After deletion, Unicore keeps records of authentication, notice acceptance, administrative access, and system activity. Those records hold the email address of the account that acted and hold no document content.

8. SHARING AND LOCATION

8.1 Who receives what.

Unicore discloses the documents, questions, and review records described in this notice to the language model providers described in "Language Model Providers." Unicore discloses those records, your email address, and your Google account identifier to the cloud infrastructure provider that hosts the Platform and stores its data.

Unicore discloses request addresses, which can include a document identifier, and technical diagnostic data when an error occurs, to an application monitoring provider that records faults in the Platform. That provider does not receive document content, request bodies, cookies, or your network address.

Google hosts the Add-On and receives its error records.

Unicore engages these providers under a written agreement that limits their use of the data to delivering and supporting the Platform. Unicore names the providers, the role they serve, their retention period, and their processing location at trust.unicoregp.com. That page is public and requires no account. Unicore updates it before engaging a new provider.

8.2 Where the data sits.

Unicore stores and processes this data in the United States. Where Unicore processes data in another region, it states that region at trust.unicoregp.com before processing begins there, and applies the transfer safeguards the applicable law requires.

8.3 What Unicore does not do.

Unicore does not sell this data, does not share it for advertising, and does not disclose it to any other party except where law requires.

9. LIMITED USE

Unicore's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Unicore's use of information received from Google Workspace scopes adheres to the Google User Data Policy, including the Limited Use requirements.

10. REMOVING THE ADD-ON

You may uninstall the Add-On through Google, and revoke its access at myaccount.google.com/permissions.

Uninstalling stops the Add-On obtaining further data from Google and removes your Atlas sign-in token from the private storage Google provides to the Add-On. The working state the Add-On stored inside your documents remains in those documents, and you may remove it by deleting the documents or by asking Unicore at [email protected]. Uninstalling does not delete records the Platform holds. "Retention and Deletion" describes how to request that deletion.

11. SECURITY AND ACCESS

11.1 Protection and isolation.

Unicore encrypts this data in transit and at rest. Atlas answers questions about your organization's compliance corpus using only your organization's material, and uses no shared index or cache across customers.

11.2 Who can read your documents.

Unicore personnel holding an administrative role can read document content through an internal administrative interface, to operate the Platform, to investigate a fault, or to act on your organization's request. Unicore grants that role only to personnel whose work requires it. That access requires an account on a Unicore-controlled domain, an administrative role, and two-factor authentication. Unicore records that access, including the individual, the record reached, and the time. No individual holds direct access to the database.

Atlas records the set of Google accounts that have signed in to each Atlas account and refuses a sign-in from a Google account it does not recognize. This binds each review, each accepted change, and each record of a language model call to a person rather than to a token.

11.3 Certifications.

Unicore maintains an information security and artificial intelligence management program certified under ISO/IEC 27001 and ISO/IEC 42001, and undergoes independent SOC 2 Type II examination. No security program eliminates all risk, and this notice creates no guarantee against unauthorized access.

12. CHANGES TO THIS NOTICE

Unicore updates this notice before a change to the Add-On or the Platform changes how either handles the data described here, and posts the revised version at this address with a new version number and effective date.

Where a change extends the data the Add-On obtains from Google, or the parties Unicore discloses that data to, Unicore presents the change in the Add-On and asks you to accept it. The new processing does not begin for you until you accept.

Where Unicore engages a new language model provider, it updates trust.unicoregp.com before that provider receives any content, and states the date of each update on that page.

Unicore keeps superseded versions of this notice and provides them on request to [email protected].

13. CONTACT UNICORE

If you have questions or requests about this notice, contact Unicore at:

Email: [email protected]

Mail:

Unicore Growth Partners, Inc.
Attn: Privacy
4300 Biscayne Blvd, Suite 203
Miami, FL 33137

14. TRADEMARKS

Google Docs™, Google Drive™, and Google Workspace™ are trademarks of Google LLC. Unicore is not affiliated with, endorsed by, or sponsored by Google LLC.

ISO27001ISO42001SOC 2Type II
PrivacyTrustTerms
© Unicore Growth Partners, Inc.

Unicore provides compliance services and technology. We do not provide legal advice, regulatory determinations, or guarantees of regulatory, partnership, or business outcomes. Engagement summaries are illustrative, do not represent every detail of the work, and do not imply endorsement, certification, or reliance by any regulator, partner, or other third party. Past results do not predict future outcomes.