Back to Add-on Page

Privacy Policy for IRIS Google Docs Add-on

Last Updated: October 22, 2025

1. Introduction

This Privacy Policy explains how the IRIS Google Docs Add-on ("IRIS," "we," "our," or "us") collects, uses, and protects your information when you use our AI-powered writing tutor within Google Docs.

2. What Data We Collect

2.1 Document Content

When you use IRIS features, we collect:

  • The text content of the currently active Google Doc you are working on
  • Specific text selections when you request AI analysis
  • Document metadata (file ID, document name)

Scope Limitation: The add-on only accesses the specific document you are actively working in when you invoke IRIS features. We do not access other documents in your Google Drive.

2.2 Authentication Information

  • Your email address (to identify you and link you to your class/assignment)
  • Google OAuth access tokens (used for backend authentication and identity verification)
  • Document sharing permissions (to validate you have access to the relevant document)

2.3 User Interactions

  • When you open the IRIS sidebar to view feedback
  • Replies you post through IRIS
  • Your voluntary ratings of IRIS-generated feedback

3. How We Use Your Data

3.1 AI-Powered Tutoring

Primary Purpose: To provide personalized writing feedback and educational assistance.

How It Works:

  1. Your instructor uses the IRIS Admin Console to generate feedback for a document
  2. The document must be shared with our service account (iris-ai-tutor@iris-466123.iam.gserviceaccount.com) - this can be done by either you or your instructor, depending on who owns the document
  3. The instructor's request triggers our backend to read the document content via service account access
  4. Our backend processes the document using Google Gemini AI to generate educational feedback
  5. The feedback is created as comments on the document by our service account
  6. You view and interact with this feedback through the IRIS add-on sidebar in Google Docs

Your Role: As a student, you use the add-on to view feedback, read AI-generated comments, reply to suggestions, and track your writing progress. The add-on does not initiate AI processing - it displays feedback that your instructor has requested.

Document Ownership: You may be working on your own document (which you own and share with IRIS) or on your instructor's document (which they own and have shared with IRIS). In either case, the document must be explicitly shared with our service account for feedback generation to work.

3.2 Backend Server Operations and Dual-Credential Architecture

IMPORTANT DISCLOSURE: The add-on connects to external servers at iris-tutor.com.

What the Add-on Sends to Our Backend:

When you open the IRIS sidebar or interact with feedback, the add-on sends ONLY:

  • Your Google OAuth access token (for authentication only)
  • Your email address (for identification)
  • Document file ID (to retrieve relevant feedback)
  • Your comment replies (when you reply to feedback)

What Is NOT Sent by the Add-on:

  • ❌ Document content (backend reads it directly via service account when needed)
  • ❌ Student information (backend looks up via your email)
  • ❌ Assignment details (backend looks up via document file ID)
  • ❌ Document statistics or metadata beyond the file ID

The add-on sends minimal data - the backend retrieves everything else using its service account and database lookups.

Dual-Credential Security Model:

IRIS uses two separate credentials for enhanced security and privacy:

1. Your OAuth Token (Current Document Access):

  • Scope: documents.currentonly - limited to the current document only
  • Purpose: Backend authentication and user identity verification
  • Limitation: Restricted by @OnlyCurrentDoc - cannot access other documents
  • Usage: Validates your identity and ensures API requests are legitimate
  • Write operations (comments) performed by separate service account

2. IRIS Service Account (Document Reading):

  • Email: iris-ai-tutor@iris-466123.iam.gserviceaccount.com
  • Purpose: Read document content for AI analysis
  • Requires: The document must be explicitly shared with this service account (by you or your instructor)
  • Transparent: The email address is visible when sharing and access can be revoked anytime
  • Operates independently from your OAuth token
  • Note: Comments are stored in our database and displayed through the add-on, not written to Google Docs

What Our Backend Does:

  • With Your OAuth Token (Authentication):
    • Verifies your identity with Google
    • Confirms you are a legitimate user
    • Extracts your email address for class linkage
    • Validates you have access to the document
  • With Our Service Account (Document Reading):
    • Reads your document content to analyze your writing
    • Generates AI-powered feedback and suggestions
    • Feedback is stored in our database and displayed through the add-on sidebar
    • Links your work to your instructor's class assignments (if applicable)

Why This Architecture?

This dual-credential approach provides better security and privacy:

  • Your OAuth token has minimal permissions (current document only)
  • Service account only reads document content for analysis
  • All feedback is stored in our secure database, not in Google Docs
  • If your OAuth token is compromised, it cannot access other documents
  • You have two independent control points for revoking access
  • Follows the principle of least privilege

4. External Data Transmission

4.1 Our Backend API

Server Location: iris-tutor.com

Data Transmitted by the Add-on:

The add-on sends minimal data to our backend:

  • Your Google OAuth access token (for authentication and identity verification only)
  • Your email address (for student identification)
  • Document file ID (for feedback retrieval and context lookups)
  • Your comment replies (when you interact with feedback)
  • Feedback ratings (your star ratings on comments and replies)

Security:

  • All data transmission uses HTTPS/TLS encryption
  • OAuth tokens are transmitted securely over encrypted connections
  • Our servers validate all requests before processing
  • Tokens cannot be used for write operations (scope restriction)
  • Service account credentials are stored separately and securely

4.2 Google Gemini AI

Third-Party AI Service: We use Google Gemini AI to analyze your writing and generate feedback.

What Gemini Receives:

  • Your document content
  • Context about your assignment (if applicable)
  • Previous feedback and conversation history

Gemini's Privacy Policy: https://ai.google.dev/gemini-api/terms

5. Data Retention and Storage

5.1 What We DO Store

  • Educational data generated by the Instructor via the Admin Portal (classes, assignments, feedback history)
  • Comments and feedback generated by IRIS
  • Your email address and name (linked to your instructor's class roster)

5.2 What We DO NOT Store

  • Your OAuth access tokens - Used only during your active session, never permanently stored
  • Your document content - Processed in real-time and not retained after generating feedback
  • Unrelated documents - Only the document you're actively working in is accessed

5.3 How Long We Keep Data

  • Educational data is retained as long as your instructor's class is active
  • Feedback history is kept to provide context for future tutoring sessions
  • Data is deleted when your instructor deletes the class or their account

6. How We Protect Your Data

6.1 Security Measures

  • Encryption: All data transmission uses industry-standard HTTPS/TLS encryption
  • Access Control: Only authorized instructors can view data from their own classes
  • Token Security: OAuth tokens are used only during active sessions and are not stored
  • Server Security: Our backend uses secure authentication, regular updates, and monitoring

6.2 What We Don't Do With Your Data

We DO NOT:

  • Sell or rent your data to third parties
  • Share your work with anyone except your instructor (if linked to a class)
  • Access your documents without your explicit action
  • Use your data for advertising or marketing
  • Track you across other websites or applications

7. Your Control and Choices

7.1 User Control

You have multiple levels of control over IRIS's access to your documents:

  • Explicit Activation: IRIS only accesses your document when you or your instructor explicitly click an IRIS feature
  • Document-Specific: Access is limited to the specific document you're working in
  • Dual Access Control: Two independent permission points you can revoke:
    1. OAuth Access: Revoke via Google Account Settings → IRIS - AI Writing Tutor → Remove Access
    2. Service Account Access: Remove by unsharing your document or removing iris-ai-tutor@iris-466123.iam.gserviceaccount.com from share settings
  • Uninstall Anytime: You can remove the add-on at any time to revoke all access

7.2 Data Access and Deletion

  • Contact your instructor to request access to your educational data
  • Instructors can delete educational data through the IRIS Admin Console
  • Revoking access or uninstalling stops all data collection immediately

8. OAuth Scopes Explained

The IRIS add-on requests the following Google OAuth scopes:

8.1 Documents Current Document Scope

Scope: https://www.googleapis.com/auth/documents.currentonly

Why: To access your current document for AI analysis and interaction

What This Allows:

  • Reading the text content of your currently active document
  • Viewing document metadata (file ID, name)
  • Analyzing your writing for AI feedback generation
  • Interacting with the document you're actively working in

What This Does NOT Allow:

  • Accessing documents other than the one currently open
  • Accessing any files in your Google Drive that you haven't explicitly opened with IRIS

Important: Our service account only reads your document content. All comments and feedback are stored in our database and displayed through the add-on sidebar, not written to Google Docs. This provides better privacy and control over your feedback data.

Limitation: The @OnlyCurrentDoc restriction further limits this scope to only the currently active document, never accessing other documents in your Drive.

8.2 External Request Scope

Scope: https://www.googleapis.com/auth/script.external_request

Why: To communicate with our backend API at iris-tutor.com for AI processing

What's Transmitted:

  • Your reply content (for AI analysis)
  • OAuth token (for authentication only)
  • Email address (for user identification)

Security: All requests are restricted to iris-tutor.com only via URL whitelist configuration. No other external services can be contacted.

8.3 Container UI Scope

Scope: https://www.googleapis.com/auth/script.container.ui

Why: To display the IRIS sidebar interface within Google Docs

What This Allows: Creating and displaying the sidebar where you interact with AI feedback, view comments, and access IRIS features.

8.4 Script App Scope

Scope: https://www.googleapis.com/auth/script.scriptapp

Why: To obtain your OAuth access token for backend authentication and identity verification

How It's Used:

  • Your OAuth token is sent to our backend at iris-tutor.com
  • Backend validates the token with Google to verify your identity
  • Token is used ONLY for authentication, not for Google API calls
  • Token is processed in-memory and not permanently stored

Important Clarification: Although your OAuth token is sent to our backend, it has read-only scope and cannot be used to modify documents. All write operations use our service account credentials, which are completely separate.

8.5 Email Scope

Scope: https://www.googleapis.com/auth/userinfo.email

Why: To identify you and link your work to your instructor's class roster

What's Collected: Your email address only, used for user identification and class enrollment linkage. No other profile information is accessed.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Significant changes will be reflected by:

  • Updated policy posting with new effective date
  • Date stamp at the top of this document

We encourage users to review this policy periodically.

10. Contact Information

If you have questions about this Privacy Policy or our data practices, please contact us:

Email: mmoses1127@gmail.com

Website: https://iris-tutor.com/

Frequently Asked Questions

Why do you send my OAuth token to your backend?

Your OAuth token is sent to our backend servers at iris-tutor.com solely for authentication purposes. This allows us to verify that API requests are coming from legitimate Google users and to identify you within your class context. Importantly, your token is restricted by the @OnlyCurrentDoc annotation and uses the documents.currentonly scope, meaning it can only access the specific document you're actively working in. Our service account reads your document to generate AI feedback, which is then stored in our database and displayed through the add-on sidebar. You must explicitly share your document with the service account for this to work.

Is it safe to send my OAuth token to your backend?

Yes, this is a secure industry-standard pattern called "backend authentication." Your token is:

  • Transmitted over HTTPS (encrypted)
  • Validated on every request to confirm authenticity
  • Used only for authentication, not for accessing Google APIs
  • Not permanently stored (processed in-memory only)
  • Limited to read-only access due to scope restrictions

Additionally, write operations require a separate credential (our service account) that you explicitly approve by sharing your document.

How is this different from apps that request full document access?

Many apps request the auth/documents scope, which gives them full read AND write access to all your documents. IRIS only requests auth/documents.currentonly with the @OnlyCurrentDoc restriction, which:

  • ✅ Only accesses the specific document you're currently working in
  • ✅ Cannot access documents other than the one currently open
  • ✅ Cannot access any files in your Google Drive without explicit action
  • ✅ Provides better security through the principle of least privilege

Additionally, our service account requires explicit document sharing consent to read your document for AI analysis. All feedback is stored in our secure database, not in Google Docs, giving you better control over your data.

What is the IRIS service account and why does my document need to be shared with it?

The IRIS service account (iris-ai-tutor@iris-466123.iam.gserviceaccount.com) is a separate credential we use to read your document content for AI analysis.

Why separate from OAuth?

  • Your OAuth token is limited to the current document only
  • The service account reads document content to generate feedback with explicit document sharing consent
  • The email address is visible when sharing documents
  • Access can be revoked at any time by the document owner
  • All feedback is stored in our database, not written to Google Docs

Who shares the document?

  • If you own the document (your own writing assignment), you share it with the service account
  • If your instructor owns the document (shared assignment template), they share it with the service account
  • Either way, the sharing is explicit and transparent

Where is feedback displayed?

  • All AI-generated feedback is stored in our secure database
  • You view feedback through the IRIS add-on sidebar
  • Nothing is written to your Google Doc directly
  • You maintain full control over your document

This two-step consent process (OAuth + document sharing) gives maximum control and transparency.

Can I revoke access at any time?

Absolutely! You have control over your personal access:

  1. Revoke OAuth access via Google Account Settings → IRIS - AI Writing Tutor → Remove Access
    • Stops IRIS add-on from working for you
    • Revokes authentication for backend requests
    • Can be done instantly at any time
  2. Remove service account access (if you own the document):
    • Unshare your document with iris-ai-tutor@iris-466123.iam.gserviceaccount.com
    • Stops IRIS from creating new comments on that document
    • Existing comments remain but no new ones can be created
    • If your instructor owns the document, they control service account access

Both types of access are independent and can be managed separately.

Note: This Privacy Policy is specific to the IRIS Google Docs Add-on. Users should also review Google's privacy policies and terms of service.