How NorgAI, the AI presentation add-in for Microsoft PowerPoint, collects, uses, stores and protects your data
Last Updated: 17 June 2026 · Effective Date: 17 June 2026
This Privacy Policy explains how Inscripta AI Technologies Private Limited (“Inscripta AI”, “we”, “us” or “our”) collects, uses, stores, shares and protects personal data and customer content in connection with NorgAI , our artificial-intelligence add-in for Microsoft PowerPoint, together with its related task-pane application and cloud services (collectively, the “Service”). It applies specifically to the NorgAI Service and its users.
This Privacy Policy supplements, and should be read together with, the NorgAI Terms of Use . For the privacy practices of our general marketing website, see our website Privacy Policy . Where you and Inscripta AI have entered into a separate signed agreement or data-processing addendum for the Service, that agreement governs to the extent of any conflict.
You retain ownership of everything you upload. Content is scoped to your project and never shared across organisations.
We do not use your documents or AI output to train or improve foundation models for other customers.
Uploaded documents and AI knowledge are retained until you delete them, and removed after account termination.
Data is encrypted in transit (TLS 1.2+) and at rest, with access limited to members of your project.
Inscripta AI Technologies Private Limited is the controller responsible for personal data processed through the NorgAI Service. Where you use the Service as part of your organisation’s subscription, your organisation is the controller of the customer content you upload, and Inscripta AI acts as a processor on your organisation’s behalf in respect of that content.
NorgAI is a task-pane add-in that runs inside Microsoft PowerPoint. It reads reference documents you upload into a project and uses generative-AI and large language models to help you generate, adapt and modify presentations. This Policy covers the Service’s task-pane application, backend cloud services and supporting infrastructure.
We collect the following categories of data when you use the Service:
| Category | Examples | Source |
|---|---|---|
| Identity data | Name, email address, user ID | Your identity provider at sign-in |
| Authentication data | Access tokens, session state, cached OIDC claims | Generated during sign-in (no passwords) |
| Document content | Documents you upload and the content of your open presentation | Uploaded or opened by you |
| Conversation data | Chat messages, retrieval queries, AI responses | Generated as you use the Service |
| Usage data | API calls, document uploads, query and token counts | Collected automatically |
| Device & technical data | IP address, browser type, operating system | Collected automatically |
We do not collect your password — authentication is handled by your identity provider using OAuth 2.0 / OpenID Connect. You should not upload documents containing special categories of sensitive personal data unless you have a lawful basis and any required data-processing terms are in place.
We use the data described above to:
We do not use your document content or AI output for advertising, and we do not sell your personal data.
Where data-protection law — such as the EU/UK General Data Protection Regulation (GDPR) or India’s Digital Personal Data Protection Act, 2023 (DPDP Act) — applies, we rely on the following legal bases: performance of a contract (to provide the Service to you or your organisation); our legitimate interests (to secure, operate and improve the Service, balanced against your rights); compliance with a legal obligation; and consent, where specifically requested. Where Inscripta AI acts as a processor (or, under the DPDP Act, a Data Processor) it processes data on the documented instructions of your organisation as controller (Data Fiduciary).
Customer content and account data are hosted on cloud infrastructure operated by our infrastructure provider, E2E Networks , located in India . We apply appropriate technical and organisational measures to protect your data, including:
| Store | What it holds |
|---|---|
| Document database | User identity, document metadata, AI conversation logs, usage metrics, audit events (with anonymised IP and hashed user-agent) and cached OIDC claims |
| Vector database | Document text chunks and vector embeddings used for retrieval |
| In-memory store | Hashed authentication state tokens, token blacklists and session data |
We retain data only for as long as needed to provide the Service and to meet our legal obligations. Retention by data type:
| Data type | Storage | Retention |
|---|---|---|
| Uploaded documents | Stored securely, scoped to your project | Until you delete them |
| Open presentation content | Sent for processing during an operation | Not stored after the operation completes |
| AI knowledge entries | Stored per-user and per-project | Until you delete them |
| Authentication tokens | Stored in your browser’s local storage | Until session expiry or logout |
| Passwords | Never stored by us | — |
You can delete your uploaded documents and AI knowledge at any time from within the Service. Following account termination, we delete or de-identify the associated customer data within 30 days , unless a longer period is required by law. Backup copies are purged on our standard backup-rotation cycle.
NorgAI uses generative-AI and large language models, including models operated by third-party model providers engaged as sub-processors, to generate output from your documents. NorgAI’s memory and knowledge features are designed to leverage your organisation’s own institutional knowledge to improve output for you, within your own account and projects.
We do not use your documents or AI output to train, fine-tune or improve foundation models for the benefit of other customers, and we do not share your documents or output with other customers. We may use aggregated and de-identified information that does not identify you or any individual to operate, secure and improve the Service.
Output is generated automatically, may be inaccurate or incomplete, and should be reviewed before use. NorgAI proposes a plan for your review and approval before applying changes, and the Service does not make automated decisions producing legal or similarly significant effects about individuals.
We do not sell, rent or trade your personal data or document content. We share data only as follows:
Where required, we enter into data-sharing agreements or data-processing addenda with sub-processors and with customers. A current list of sub-processors is available on request at norgai.support@inscripta.ai .
NorgAI runs as an add-in inside Microsoft PowerPoint and is distributed through Microsoft AppSource. Your use of Microsoft PowerPoint, Microsoft 365 and Microsoft AppSource is governed by Microsoft’s own terms and privacy statement, for which Inscripta AI is not responsible.
Your data is primarily stored and processed in India. Where data is transferred to, or accessed from, a country other than the one in which you are located — for example by a sub-processor — we put in place appropriate safeguards required by applicable data-protection law, such as standard contractual clauses, to protect your data.
Subject to applicable law, you have the right to:
To exercise these rights, contact us at norgai.support@inscripta.ai . We will respond within the timeframe required by applicable law. Where you use the Service under your organisation’s subscription, you may need to direct certain requests to your organisation as the controller, and we will assist them in responding. You also have the right to lodge a complaint with your local data-protection authority.
Region-specific rights. If you are in the EEA or UK, you have the rights described above under the GDPR. If you are in India, you may exercise your rights under the DPDP Act, including by contacting our Grievance Officer (see “Contact Us” below). If you are a California resident, you may have rights under the CCPA/CPRA, including the right to know, delete and correct your personal information, and the right not to be discriminated against for exercising those rights; we do not sell or share personal information as those terms are defined under the CCPA/CPRA.
The Service is intended for business use by individuals who are at least 18 years of age . We do not knowingly collect personal data from children or minors. If you believe a minor has provided us with personal data, please contact us so we can delete it.
The NorgAI task-pane stores authentication tokens in your browser’s local storage to keep you signed in; these persist until session expiry or logout. We and our analytics providers may use cookies and similar technologies to operate and improve the Service. For cookies used on our marketing website, see our website Privacy Policy .
We maintain a documented security incident-response process. In the event of a personal-data breach that is likely to result in a risk to affected individuals, we will notify the relevant supervisory authority and affected individuals (or, where Inscripta AI is a processor, the controller) without undue delay and, where feasible, within 72 hours of becoming aware of it, in accordance with applicable law.
We may update this Privacy Policy from time to time to reflect changes to the Service or to legal requirements. For material changes we will update the “Last Updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
For questions about this Privacy Policy, or to exercise your privacy rights, contact Inscripta AI Technologies Private Limited at:
Grievance Officer (India). In accordance with India’s Digital Personal Data Protection Act, 2023 and applicable IT rules, our Grievance Officer can be reached at norgai.support@inscripta.ai . We aim to acknowledge and address grievances within the timeframe prescribed by applicable law.