This Privacy Policy explains how the IRIS Google Docs Add-on ("IRIS," "we," "our," or "us") collects, uses, and protects your information when you use our AI-powered writing tutor within Google Docs.
2. What Data We Collect
2.1 Document Content
When you use IRIS features, we collect:
The text content of the currently active Google Doc you are working on
Specific text selections when you request AI analysis
Document metadata (file ID, document name)
Scope Limitation: The add-on only accesses the specific document you are actively working in when you invoke IRIS features. We do not access other documents in your Google Drive.
2.2 Authentication Information
Your email address (to identify you and link you to your class/assignment)
Google OAuth access tokens (used for backend authentication and identity verification)
Document sharing permissions (to validate you have access to the relevant document)
2.3 User Interactions
When you open the IRIS sidebar to view feedback
Replies you post through IRIS
Your voluntary ratings of IRIS-generated feedback
3. How We Use Your Data
3.1 AI-Powered Tutoring
Primary Purpose: To provide personalized writing feedback and educational assistance.
How It Works:
Your instructor uses the IRIS Admin Console to generate feedback for a document
The document must be shared with our service account (iris-ai-tutor@iris-466123.iam.gserviceaccount.com) - this can be done by either you or your instructor, depending on who owns the document
The instructor's request triggers our backend to read the document content via service account access
Our backend processes the document using Google Gemini AI to generate educational feedback
The feedback is created as comments on the document by our service account
You view and interact with this feedback through the IRIS add-on sidebar in Google Docs
Your Role: As a student, you use the add-on to view feedback, read AI-generated comments, reply to suggestions, and track your writing progress. The add-on does not initiate AI processing - it displays feedback that your instructor has requested.
Document Ownership: You may be working on your own document (which you own and share with IRIS) or on your instructor's document (which they own and have shared with IRIS). In either case, the document must be explicitly shared with our service account for feedback generation to work.
3.2 Backend Server Operations and Dual-Credential Architecture
IMPORTANT DISCLOSURE: The add-on connects to external servers at iris-tutor.com.
What the Add-on Sends to Our Backend:
When you open the IRIS sidebar or interact with feedback, the add-on sends ONLY:
Your Google OAuth access token (for authentication only)
Your email address (for identification)
Document file ID (to retrieve relevant feedback)
Your comment replies (when you reply to feedback)
What Is NOT Sent by the Add-on:
❌ Document content (backend reads it directly via service account when needed)
❌ Student information (backend looks up via your email)
❌ Assignment details (backend looks up via document file ID)
❌ Document statistics or metadata beyond the file ID
The add-on sends minimal data - the backend retrieves everything else using its service account and database lookups.
Dual-Credential Security Model:
IRIS uses two separate credentials for enhanced security and privacy:
1. Your OAuth Token (Current Document Access):
Scope: documents.currentonly - limited to the current document only
Purpose: Backend authentication and user identity verification
Limitation: Restricted by @OnlyCurrentDoc - cannot access other documents
Usage: Validates your identity and ensures API requests are legitimate
Write operations (comments) performed by separate service account
Why: To access your current document for AI analysis and interaction
What This Allows:
Reading the text content of your currently active document
Viewing document metadata (file ID, name)
Analyzing your writing for AI feedback generation
Interacting with the document you're actively working in
What This Does NOT Allow:
Accessing documents other than the one currently open
Accessing any files in your Google Drive that you haven't explicitly opened with IRIS
Important: Our service account only reads your document content. All comments and feedback are stored in our database and displayed through the add-on sidebar, not written to Google Docs. This provides better privacy and control over your feedback data.
Limitation: The @OnlyCurrentDoc restriction further limits this scope to only the currently active document, never accessing other documents in your Drive.
Why: To obtain your OAuth access token for backend authentication and identity verification
How It's Used:
Your OAuth token is sent to our backend at iris-tutor.com
Backend validates the token with Google to verify your identity
Token is used ONLY for authentication, not for Google API calls
Token is processed in-memory and not permanently stored
Important Clarification: Although your OAuth token is sent to our backend, it has read-only scope and cannot be used to modify documents. All write operations use our service account credentials, which are completely separate.
Why: To identify you and link your work to your instructor's class roster
What's Collected: Your email address only, used for user identification and class enrollment linkage. No other profile information is accessed.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Significant changes will be reflected by:
Updated policy posting with new effective date
Date stamp at the top of this document
We encourage users to review this policy periodically.
10. Contact Information
If you have questions about this Privacy Policy or our data practices, please contact us:
Email: mmoses1127@gmail.com
Website: https://iris-tutor.com/
Frequently Asked Questions
Why do you send my OAuth token to your backend?
Your OAuth token is sent to our backend servers at iris-tutor.com solely for authentication purposes. This allows us to verify that API requests are coming from legitimate Google users and to identify you within your class context. Importantly, your token is restricted by the @OnlyCurrentDoc annotation and uses the documents.currentonly scope, meaning it can only access the specific document you're actively working in. Our service account reads your document to generate AI feedback, which is then stored in our database and displayed through the add-on sidebar. You must explicitly share your document with the service account for this to work.
Is it safe to send my OAuth token to your backend?
Yes, this is a secure industry-standard pattern called "backend authentication." Your token is:
Transmitted over HTTPS (encrypted)
Validated on every request to confirm authenticity
Used only for authentication, not for accessing Google APIs
Not permanently stored (processed in-memory only)
Limited to read-only access due to scope restrictions
Additionally, write operations require a separate credential (our service account) that you explicitly approve by sharing your document.
How is this different from apps that request full document access?
Many apps request the auth/documents scope, which gives them full read AND write access to all your documents. IRIS only requests auth/documents.currentonly with the @OnlyCurrentDoc restriction, which:
✅ Only accesses the specific document you're currently working in
✅ Cannot access documents other than the one currently open
✅ Cannot access any files in your Google Drive without explicit action
✅ Provides better security through the principle of least privilege
Additionally, our service account requires explicit document sharing consent to read your document for AI analysis. All feedback is stored in our secure database, not in Google Docs, giving you better control over your data.
What is the IRIS service account and why does my document need to be shared with it?
The IRIS service account (iris-ai-tutor@iris-466123.iam.gserviceaccount.com) is a separate credential we use to read your document content for AI analysis.
Why separate from OAuth?
Your OAuth token is limited to the current document only
The service account reads document content to generate feedback with explicit document sharing consent
The email address is visible when sharing documents
Access can be revoked at any time by the document owner
All feedback is stored in our database, not written to Google Docs
Who shares the document?
If you own the document (your own writing assignment), you share it with the service account
If your instructor owns the document (shared assignment template), they share it with the service account
Either way, the sharing is explicit and transparent
Where is feedback displayed?
All AI-generated feedback is stored in our secure database
You view feedback through the IRIS add-on sidebar
Nothing is written to your Google Doc directly
You maintain full control over your document
This two-step consent process (OAuth + document sharing) gives maximum control and transparency.
Can I revoke access at any time?
Absolutely! You have control over your personal access: