InkDraft

Privacy policy

Effective September 26, 2026. InkDraft is operated by Bradley Brewington. Contact: bmbrewington4@gmail.com.

What InkDraft handles

The iPad app saves your handwriting and sketches locally. When you tap Update, it uploads a PNG image, editable PencilKit drawing, an update identifier, and revision metadata. The account service stores published versions in a private Google Cloud Storage bucket in the United States.

Google and Auth0 handle sign-in. InkDraft uses the verified provider identity to separate account storage and may receive your name, email, and profile information through authentication. Native credentials are kept in the iPad Keychain; your connected agent manages its own authorization credentials. InkDraft does not receive your Google password.

How information is used and shared

We use account information to authenticate you and deliver your paper to clients you authorize. An authorized MCP client can retrieve your account display name and account identifier, publication metadata, and the original published paper image, including prior revisions. Read-only agent access does not permit updating your paper.

Google Cloud provides hosting/storage and Auth0 provides authentication. Your chosen agent provider receives the content it retrieves and applies its own privacy and retention terms. InkDraft does not receive your chat history or collect full conversations. Tool inputs are limited to the requested operation and optional revision number.

InkDraft does not sell personal information, run advertising trackers, or send handwriting to an AI service on its own. The public documentation pages use no analytics scripts or tracking cookies. Authentication pages use cookies necessary for sign-in.

Logs and retention

Published versions remain until account or paper deletion is requested; updating does not remove history. Operational logs can include request time, URL, status, client network information, and authentication events. Application code does not intentionally log paper contents or bearer tokens. The service's standard Google Cloud log bucket retains request logs for 30 days; authentication and administrative audit records follow the respective provider's retention settings.

After published data is deleted, Google Cloud recovery copies may remain for the bucket's seven-day soft-delete period. Legal, security, or abuse-related records may need to be retained separately. Copies already retrieved by an agent provider are controlled by that provider.

Your choices

Write offline without publishing. Disconnect an agent to stop future access through that connection; already issued short-lived tokens can remain valid until expiry. Signing out or deleting the app does not delete published cloud history. Unpublished ink is not recoverable from the server.

For access, correction, export, or deletion requests, contact support from the account email. We will verify ownership before handling account data. Remove local copies on your device and contact connected providers separately about their copies. No public paper links are created.

Changes

Material changes will be reflected here with an updated effective date. Contact support with privacy questions before publishing sensitive information.