Effective 2026-08-09. Last updated 2026-08-09.
Document AI: Word DOCX Editor ("the app") is developed by an independent developer ("we/I"). Contact: ecosocialindia@gmail.com. This policy explains exactly what data the app handles, in plain language.
The short version: your documents stay on your device unless you explicitly tap an AI action, some AI actions run entirely on your phone and send nothing at all, ads are consent-gated and never appear over your document, there are no accounts, and there is no analytics or usage tracking of any kind.
Your documents and files
Documents open and save in place on your device through Android's Storage Access Framework. The app never uploads, syncs or copies your files to any server of ours - we don't operate any servers.
To protect unsaved work from crashes and from Android stopping the app, a draft copy is kept in the app's private storage on your device. Drafts are offered back to you when you return and are deleted when you discard them.
The Share action writes a temporary copy to the app's private cache solely so that the app you share to can read it. The copy is reachable only by the app you picked, for that one share.
A Recents list - file names and links, never file contents - is stored in the app's private preferences on your device.
AI Scan photographs are written to the app's private cache. The app has no camera permission: the picture is taken by whichever camera app you choose, into a file this app prepared for it. The photograph is deleted when you retake, when you import, and when the scan flow ends.
AI features
The app has six AI features. Where each one runs decides what, if anything, leaves your device, and every AI answer is labelled with where it ran - "On-device - private" or "Uses cloud AI".
The features that use cloud AI
AI Brief, AI Ask and AI Describe it always use cloud AI. AI Rewrite and AI Fix it use cloud AI whenever your phone cannot run them itself - which depends on the phone, on the tone you picked, and on how much text is in the request.
These features are powered by Google's Gemini service through Firebase AI Logic (Google LLC). Data leaves your device only when you tap an AI action, and only after you have agreed once to a consent dialog that says so. Nothing is ever sent in the background, and nothing is sent when you open, edit, save, export or print a document.
What is sent, per feature:
AI Brief: your document's text, in up to four blocks, plus the app's own request. Long documents are covered in part and the card says so.
AI Ask: the question you typed, plus the part of your document most likely to answer it - always including its opening paragraphs and every heading.
AI Rewrite: the paragraphs you selected, plus the tone you chose.
AI Fix it: the paragraphs being proofread.
AI Describe it: only the sentence you typed. There is no document yet when this runs, so there is no document text to send.
What is sent is your document's text - not the file itself, and not its pictures, headers, footers, footnotes or comments, none of which the app reads into an AI request at all. Requests are also bounded: any single paragraph is trimmed at 2,000 characters, one block of document text is capped at 24,000 characters, and an AI Brief makes at most four of them. Most documents go in full; very long ones are trimmed, and the answer card tells you when it came from part of your document rather than all of it.
A note about tracked changes. If a document tracks changes, text that has been marked as deleted is still inside the file until someone accepts the change. For AI Brief and AI Ask, which read the document, that deleted text counts as part of the document's text and is sent with it. AI Rewrite and AI Fix it leave paragraphs carrying tracked changes out of the request entirely - those paragraphs are never sent.
Each request also carries a Play Integrity / App Check attestation - a Google-defined signal that the app is a genuine Play install, so that only real installs can use the AI service. It contains no document content and no personal data of yours.
Google processes these requests to generate the answer. The app uses the Gemini API's free tier, under which Google may also use the submitted content to provide and improve its products and services, which can include review by people - so don't send AI requests over documents containing things you wouldn't want reviewed. For users in the EEA, Switzerland and the UK, Google applies its stricter paid-tier data treatment to these requests. See Google's Gemini API terms at https://ai.google.dev/gemini-api/terms
A daily allowance of 10 AI cloud actions, with 5 more for each short ad you choose to watch, is counted on your device only and resets each day.
You can turn cloud AI off. The switch is at Settings > AI & your data > Send document text to AI. Turning it off takes effect on the very next AI action: the app re-reads your answer at the moment it is about to send, never from something it remembered earlier.
The features that run on your phone
AI Rewrite and AI Fix it run on your device, through Google's ML Kit GenAI (Gemini Nano), when the phone supports it and the request is small enough. On that route nothing is sent anywhere: no consent is needed, no allowance is spent, and it works offline. The answer is labelled "On-device - private".
AI Scan reads a photographed page with ML Kit Text Recognition, on your device. The photograph never leaves your phone and is not sent to any service.
For both, the models themselves are delivered to your phone by Google's own system components - Android's AICore service and Google Play services - the first time they are needed, typically as a one-off download over Wi-Fi. That is a system-level model download and carries no document content of yours.
AI output is generated, and you decide what to do with it
Answers, rewrites and corrections here are generated by AI, and they can be wrong. The app never applies an AI change to your document on its own - every AI output is a preview you commit with an explicit tap. Documents drafted by AI Describe it carry a visible "Created with AI" note in the editor and a machine-readable marker inside the saved file (AIGenerated in the file's custom document properties), so the disclosure travels with the document after you share it.
Every generative AI output can be reported from the menu beside it, and a report can also be raised without an answer on screen from Settings > AI & your data > Report a problem with AI output. A report records only the reason you picked - never the AI's answer, never your document, never the document's name. If you write an optional note, it goes into an email your own mail app composes, which you can read and cancel before sending.
Advertising
The app is free and shows ads through Google AdMob, in exactly three places: a banner on the Home screen, at most one interstitial per session when you deliberately leave the editor (never in your very first session), and a rewarded ad you choose to watch for extra AI actions. There are no ads on the editing surface, none over any AI surface, and no app-open ads.
Before any ad is requested, the app runs Google's UMP consent flow, and the ads SDK is not even started until consent permits it. Where consent is required (for example the EEA and the UK), ads load only according to your choices, which you can revisit any time at Settings > Ads privacy options.
The Google Mobile Ads SDK collects the data described in Google's AdMob data disclosure at https://developers.google.com/admob/android/privacy/play-data-disclosure including IP address, advertising ID, ad-interaction data and diagnostics, for advertising, fraud prevention and measurement on Google's side. You can reset or delete your advertising ID in Android's settings. See also How Google uses data from partner apps at https://policies.google.com/technologies/partner-sites
Crash reporting
Release builds use Firebase Crashlytics (Google LLC) to receive crash reports - stack traces, device model, OS version, app version and a random per-install identifier - so that crashes can be fixed. Crash reports contain no document content: it is a rule enforced throughout the app's code that no log line and no error message may carry text taken from your document, and the one signal the app deliberately sends to Crashlytics - that an AI output was reported - is built so that it can carry nothing but the reason and the feature name.
Analytics
There are none. The app contains no analytics library, Google Analytics is switched off for its Firebase project, and the app's own event-counting code deliberately does nothing. No feature counter, usage statistic or behavioural event is collected or sent anywhere. If that ever changes, this policy and the app's Data Safety declaration will be updated before it does.
Backups
Android's standard Auto Backup may include the app's own files - including the draft copies of documents you were editing - in the device backup tied to your own Google account, encrypted by the operating system. The app's preferences (recents, settings, your AI consent answer and the daily allowance) are excluded from that backup. You control backups in Android's settings; we never see them.
Permissions
The app requests no runtime permissions at all - nothing that asks you for anything. Files are reached only through Android's document picker, and pages are photographed by your own camera app. The permissions the installed app declares are these, and each is either the app's own or comes from a Google library it uses:
INTERNET - AI cloud calls and ad serving. Nothing else in the app touches the network.
com.google.android.apps.aicore.service.BIND_SERVICE - Lets the on-device AI route talk to Android's AICore system service (ML Kit GenAI).
ACCESS_NETWORK_STATE - Declared by the Google Mobile Ads SDK.
com.google.android.gms.permission.AD_ID - The advertising ID, used by AdMob.
ACCESS_ADSERVICES_AD_ID, ACCESS_ADSERVICES_ATTRIBUTION, ACCESS_ADSERVICES_TOPICS - Android's Privacy Sandbox interfaces, declared by the Google Mobile Ads SDK.
WAKE_LOCK, FOREGROUND_SERVICE - Declared by an Android background-work library that arrives inside the Google Mobile Ads SDK. The app itself schedules no background work.
com.jeet.documentaiworddocxeditor.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION - An app-private, signature-level permission declared by an AndroidX library so that its own components are not exposed to other apps. It grants nothing to anyone else.
There is no camera permission, no location, no contacts, no microphone and no storage permission.
What the app does NOT do
No accounts, no sign-in, no registration, no server of ours.
No access to contacts, location, the microphone, or any file you did not open yourself.
No selling of data, and no sharing beyond the Google services named above - Gemini via Firebase AI Logic, AdMob, Crashlytics and App Check - which process data under Google's Privacy Policy at https://policies.google.com/privacy
No tracking of what you do in the app.
Data retention and deletion
Everything the app stores, it stores on your device: clear it through Android Settings > Apps > Document AI > Storage, or by uninstalling the app. AI requests are transient service calls handled by Google under the terms linked above. For any privacy question or request, email ecosocialindia@gmail.com
Children
The app is a general-audience productivity tool and is not directed at children under 13.
Changes
Material changes to this policy will be posted at this URL with an updated effective date.