NorgAI Privacy Policy

How NorgAI, the AI presentation add-in for Microsoft PowerPoint, collects, uses, stores and protects your data

Last Updated: 17 June 2026  ·  Effective Date: 17 June 2026

This Privacy Policy explains how Inscripta AI Technologies Private Limited (“Inscripta AI”, “we”, “us” or “our”) collects, uses, stores, shares and protects personal data and customer content in connection with NorgAI , our artificial-intelligence add-in for Microsoft PowerPoint, together with its related task-pane application and cloud services (collectively, the “Service”). It applies specifically to the NorgAI Service and its users.

This Privacy Policy supplements, and should be read together with, the NorgAI Terms of Use . For the privacy practices of our general marketing website, see our website Privacy Policy . Where you and Inscripta AI have entered into a separate signed agreement or data-processing addendum for the Service, that agreement governs to the extent of any conflict.

Your documents stay yours

You retain ownership of everything you upload. Content is scoped to your project and never shared across organisations.

No training on your data

We do not use your documents or AI output to train or improve foundation models for other customers.

Delete anytime

Uploaded documents and AI knowledge are retained until you delete them, and removed after account termination.

Encrypted & access-controlled

Data is encrypted in transit (TLS 1.2+) and at rest, with access limited to members of your project.

1. Scope & Who We Are

Inscripta AI Technologies Private Limited is the controller responsible for personal data processed through the NorgAI Service. Where you use the Service as part of your organisation’s subscription, your organisation is the controller of the customer content you upload, and Inscripta AI acts as a processor on your organisation’s behalf in respect of that content.

NorgAI is a task-pane add-in that runs inside Microsoft PowerPoint. It reads reference documents you upload into a project and uses generative-AI and large language models to help you generate, adapt and modify presentations. This Policy covers the Service’s task-pane application, backend cloud services and supporting infrastructure.

2. Information We Collect

We collect the following categories of data when you use the Service:

Category Examples Source
Identity data Name, email address, user ID Your identity provider at sign-in
Authentication data Access tokens, session state, cached OIDC claims Generated during sign-in (no passwords)
Document content Documents you upload and the content of your open presentation Uploaded or opened by you
Conversation data Chat messages, retrieval queries, AI responses Generated as you use the Service
Usage data API calls, document uploads, query and token counts Collected automatically
Device & technical data IP address, browser type, operating system Collected automatically

We do not collect your password — authentication is handled by your identity provider using OAuth 2.0 / OpenID Connect. You should not upload documents containing special categories of sensitive personal data unless you have a lawful basis and any required data-processing terms are in place.

3. How We Use Your Information

We use the data described above to:

  • provide, operate and maintain the Service, including generating, adapting and modifying presentations from your documents;
  • authenticate you and secure your account and sessions;
  • store and retrieve your uploaded documents and AI knowledge, scoped to your project;
  • respond to your requests and provide customer support;
  • monitor usage, detect and prevent fraud, abuse and security incidents, and enforce our Terms; and
  • meet our legal, regulatory and contractual obligations.

We do not use your document content or AI output for advertising, and we do not sell your personal data.

5. Storage, Location & Security

Customer content and account data are hosted on cloud infrastructure operated by our infrastructure provider, E2E Networks , located in India . We apply appropriate technical and organisational measures to protect your data, including:

  • encryption of data in transit using TLS 1.2 or higher , and encryption of data at rest;
  • authentication via OAuth 2.0 / OpenID Connect, with no password storage;
  • access scoped to members of the relevant project, so document content is not shared across organisations;
  • role-based access controls, secrets management, and audit logging of access to customer data; and
  • network and application security controls, vulnerability management and monitoring.
Store What it holds
Document database User identity, document metadata, AI conversation logs, usage metrics, audit events (with anonymised IP and hashed user-agent) and cached OIDC claims
Vector database Document text chunks and vector embeddings used for retrieval
In-memory store Hashed authentication state tokens, token blacklists and session data

6. Data Retention & Deletion

We retain data only for as long as needed to provide the Service and to meet our legal obligations. Retention by data type:

Data type Storage Retention
Uploaded documents Stored securely, scoped to your project Until you delete them
Open presentation content Sent for processing during an operation Not stored after the operation completes
AI knowledge entries Stored per-user and per-project Until you delete them
Authentication tokens Stored in your browser’s local storage Until session expiry or logout
Passwords Never stored by us

You can delete your uploaded documents and AI knowledge at any time from within the Service. Following account termination, we delete or de-identify the associated customer data within 30 days , unless a longer period is required by law. Backup copies are purged on our standard backup-rotation cycle.

7. AI Processing & Model Training

NorgAI uses generative-AI and large language models, including models operated by third-party model providers engaged as sub-processors, to generate output from your documents. NorgAI’s memory and knowledge features are designed to leverage your organisation’s own institutional knowledge to improve output for you, within your own account and projects.

We do not use your documents or AI output to train, fine-tune or improve foundation models for the benefit of other customers, and we do not share your documents or output with other customers. We may use aggregated and de-identified information that does not identify you or any individual to operate, secure and improve the Service.

Output is generated automatically, may be inaccurate or incomplete, and should be reviewed before use. NorgAI proposes a plan for your review and approval before applying changes, and the Service does not make automated decisions producing legal or similarly significant effects about individuals.

8. Sharing & Sub-processors

We do not sell, rent or trade your personal data or document content. We share data only as follows:

  • Sub-processors who process data on our behalf to provide the Service — including our cloud-infrastructure provider and large-language-model providers — under contractual confidentiality and data-protection obligations;
  • within your organisation , with members of the relevant project;
  • where required by law , or to protect the rights, safety and security of users, the public or Inscripta AI; and
  • in connection with a corporate transaction such as a merger, acquisition or sale of assets, subject to this Policy.

Where required, we enter into data-sharing agreements or data-processing addenda with sub-processors and with customers. A current list of sub-processors is available on request at norgai.support@inscripta.ai .

NorgAI runs as an add-in inside Microsoft PowerPoint and is distributed through Microsoft AppSource. Your use of Microsoft PowerPoint, Microsoft 365 and Microsoft AppSource is governed by Microsoft’s own terms and privacy statement, for which Inscripta AI is not responsible.

9. International Data Transfers

Your data is primarily stored and processed in India. Where data is transferred to, or accessed from, a country other than the one in which you are located — for example by a sub-processor — we put in place appropriate safeguards required by applicable data-protection law, such as standard contractual clauses, to protect your data.

10. Your Privacy Rights

Subject to applicable law, you have the right to:

  • access the personal data we hold about you;
  • correct or update inaccurate or incomplete personal data;
  • delete your personal data;
  • restrict or object to our processing of your personal data;
  • data portability — receive your data in a portable format; and
  • withdraw consent at any time, where processing is based on consent.

To exercise these rights, contact us at norgai.support@inscripta.ai . We will respond within the timeframe required by applicable law. Where you use the Service under your organisation’s subscription, you may need to direct certain requests to your organisation as the controller, and we will assist them in responding. You also have the right to lodge a complaint with your local data-protection authority.

Region-specific rights. If you are in the EEA or UK, you have the rights described above under the GDPR. If you are in India, you may exercise your rights under the DPDP Act, including by contacting our Grievance Officer (see “Contact Us” below). If you are a California resident, you may have rights under the CCPA/CPRA, including the right to know, delete and correct your personal information, and the right not to be discriminated against for exercising those rights; we do not sell or share personal information as those terms are defined under the CCPA/CPRA.

11. Children’s Privacy

The Service is intended for business use by individuals who are at least 18 years of age . We do not knowingly collect personal data from children or minors. If you believe a minor has provided us with personal data, please contact us so we can delete it.

12. Cookies & Local Storage

The NorgAI task-pane stores authentication tokens in your browser’s local storage to keep you signed in; these persist until session expiry or logout. We and our analytics providers may use cookies and similar technologies to operate and improve the Service. For cookies used on our marketing website, see our website Privacy Policy .

13. Data Breach Notification

We maintain a documented security incident-response process. In the event of a personal-data breach that is likely to result in a risk to affected individuals, we will notify the relevant supervisory authority and affected individuals (or, where Inscripta AI is a processor, the controller) without undue delay and, where feasible, within 72 hours of becoming aware of it, in accordance with applicable law.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes to the Service or to legal requirements. For material changes we will update the “Last Updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.

15. Contact Us

For questions about this Privacy Policy, or to exercise your privacy rights, contact Inscripta AI Technologies Private Limited at:

Grievance Officer (India). In accordance with India’s Digital Personal Data Protection Act, 2023 and applicable IT rules, our Grievance Officer can be reached at norgai.support@inscripta.ai . We aim to acknowledge and address grievances within the timeframe prescribed by applicable law.