Storage and security

The short version: your clients' documents belong in your cloud, not ours. Here is exactly what that means and where the files actually sit.

Bring your own storage

Connect your firm's Google Drive™ under Settings → Document storage and every upload routes straight into it, filed in a ChaseDocs Uploads folder in your own account.

Connecting Drive is separate from signing in with Google

These are two different things, and Drive will ask for its own permission prompt even if you already signed in with Google. That's deliberate, not a glitch.

Signing in tells us who you are, and asks Google for nothing more than your name and email address. Connecting Drive is a separate decision that grants file access — and it asks for the narrowest permission Google offers: only the files ChaseDocs itself creates. We cannot see, open, or search anything else in your Drive, including files you put in the ChaseDocs Uploads folder yourself.

Keeping them apart is what makes that possible. Signing in never grants file access, and disconnecting Drive never signs you out.

What ChaseDocs keeps is a reference — where the file lives, what it was for, what the check said — not the bytes. Your documents sit under your own account, your own retention policy, your own access controls. If you stopped using us tomorrow, the files would still be exactly where they are.

Files arrive named Client — Item — the client's own filename, so a folder full of “IMG_4821.jpg” and “scan.pdf” reads as “Jane Tan — Bank statement — IMG_4821.jpg” without anyone renaming anything. What the client actually called the file is still shown in ChaseDocs on the request.

Available on every plan, including the free trial. Connecting or disconnecting is a couple of clicks and doesn't disturb requests already in flight.

Firms where staff can't approve apps themselves

Some Google Workspace™ domains block individuals from granting third-party apps access. If the Drive permission prompt is refused before you ever see it, that's why — and the fix is for your administrator to install ChaseDocs from the Google Workspace Marketplace once, for the whole domain. See Getting started for what that does and doesn't change.

The uploads folder is yours to move

Rename it, move it, nest it inside your client folders — uploads keep arriving there, because we follow the folder itself rather than its name or location. The one thing that does break it is deleting it: if the folder is in the bin or gone, the next upload creates a fresh ChaseDocs Uploads folder and carries on. Documents already filed in the old one stay where they are — they're yours, and we never delete from your Drive — so recover it from the bin if you want everything back in one place.

Reconnecting with a different Google account works the same way: the new account gets its own folder, and nothing moves out of the old one.

Use one Google account per firm

If you run more than one firm on ChaseDocs, give each one its own Google account. Connecting the same account to two firms is possible, and their documents do stay in separate folders — but it goes wrong in ways that are hard to spot:

  • Disconnecting breaks both. Pressing Disconnect withdraws ChaseDocs's access to that Google account entirely, so the other firm's storage stops working too — with no warning on the firm that didn't touch anything.
  • You get two folders with the same name. Each firm creates its own ChaseDocs Uploads folder, and in Google Drive they look identical.
  • The separation is ours, not Google's. Google sees one account that authorised ChaseDocs once. Keeping the two firms' documents apart is then something our software does, rather than something the account itself enforces. Separate accounts get you both.

None of this applies if you only run one firm, which is almost everyone — connect the account the firm already uses and there's nothing to think about.

If you don't connect anything

You don't have to configure storage to start. Uploads land in an encrypted, short-retention ChaseDocs bucket instead — a zero-config fallback so an evaluation isn't blocked on IT.

Files there are kept briefly and then purged automatically (14 days by default). It's a staging area, not a filing cabinet. If ChaseDocs is where your documents live long-term, connect your own storage.

Files in your own Drive are never deleted by us. The retention clock only applies to the fallback bucket. Once a document is in your cloud, its lifecycle is yours.

What we store, and what we never store

We keepWe don't
Request and checklist metadata — what you asked for, and when The contents of your clients' documents
Validation verdicts — the four checks, issues, suggested filename Anything read out of a document, beyond the verdict
A storage reference and its retention/expiry Long-term copies of files, when you've connected your own storage
Client contact details you entered, and your consent record Document contents in logs — never, under any circumstances

The AI pass

Checking a document means reading it, which means a copy has to exist for a moment. That copy is encrypted, access-scoped, held in memory for the duration of the check, and dropped immediately after. What survives is the verdict, not the document.

Client links, and why there's no captcha

A client link is a long random secret that opens one request and nothing else. We never store the link itself — only a one-way fingerprint of it — so it cannot be read back out of our database by anyone, us included. Links expire, and deleting a request kills its link immediately. Restoring the request brings the same link back, so a client who already has it in their chat thread doesn't need a new one.

Your client never has to prove they're human to hand you a document. That's deliberate: a captcha in front of an upload is precisely the friction that makes people give up, and the point of a no-login link is that it just works on a phone, first time. The protection is behind the scenes — the link's secrecy, its expiry, your ability to revoke it, and hard limits on how much any single link can upload or cost.

Your own staff accounts are a different matter, and there we do use a bot check: creating a firm account or joining one by invite is a place worth defending, and it happens once.

Access inside your firm

  • Your data is scoped to your organisation at the database level, not by a filter in the interface. One firm cannot read another's rows.
  • Client links open exactly one person's request — see What your client sees.
  • Destructive actions are restricted to owners and admins. Deleting a request destroys a client record, so it isn't something any team member can do by accident.
  • On the Firm plan, the audit log records who did what, from where, and when — including every time one of your staff opens an uploaded document. Entries are append-only, exportable as CSV, and kept for 365 days. See Team, branding and billing for the detail.

Data protection

ChaseDocs is designed around two habits nearly every privacy regime asks for: collect as little as possible, and keep the sensitive material under the control of the firm that is accountable for it. Our first formal alignment target is PDPA in Singapore and Malaysia. Two consequences you'll actually notice: consent is recorded before we message anyone on your behalf (see Sending and reminders), and document custody defaults to your cloud rather than ours.

Firms elsewhere — the EU, the UK, North America, Australia — run the same setup, and BYO storage is the part that usually matters most to them: the documents live in your own cloud, in whatever region you already keep client data. ChaseDocs is operated by an Indonesian company and we don't yet publish a standard data processing agreement, so if your compliance review needs one, email support@usechasedocs.com and ask.

Worth being clear about who is responsible for what: for the documents your clients upload, you are the organisation accountable to them and to the regulator — ChaseDocs processes that data on your instruction. What we owe you is security, short retention, and prompt notice if something goes wrong on our side. The audit log exists so that when someone asks you to account for a document, you have the record rather than having to ask us for it.

For the formal terms, see the Privacy Policy and Terms & Conditions. For a question those don't answer, email support@usechasedocs.com.

Still stuck? Email support@usechasedocs.com and a human will answer.