Storage and security
The short version: your clients' documents belong in your cloud, not ours. Here is exactly what that means and where the files actually sit.
Bring your own storage
Connect your firm's Google Drive under Settings → Document storage and every upload routes straight into it, filed in a ChaseDocs Uploads folder in your own account.
What ChaseDocs keeps is a reference — where the file lives, what it was for, what the check said — not the bytes. Your documents sit under your own account, your own retention policy, your own access controls. If you stopped using us tomorrow, the files would still be exactly where they are.
Available on every plan, including the free trial. Connecting or disconnecting is a couple of clicks and doesn't disturb requests already in flight.
If you don't connect anything
You don't have to configure storage to start. Uploads land in an encrypted, short-retention ChaseDocs bucket instead — a zero-config fallback so an evaluation isn't blocked on IT.
Files there are kept briefly and then purged automatically (14 days by default). It's a staging area, not a filing cabinet. If ChaseDocs is where your documents live long-term, connect your own storage.
Files in your own Drive are never deleted by us. The retention clock only applies to the fallback bucket. Once a document is in your cloud, its lifecycle is yours.
What we store, and what we never store
| We keep | We don't |
|---|---|
| Request and checklist metadata — what you asked for, and when | The contents of your clients' documents |
| Validation verdicts — the four checks, issues, suggested filename | Anything read out of a document, beyond the verdict |
| A storage reference and its retention/expiry | Long-term copies of files, when you've connected your own storage |
| Client contact details you entered, and your consent record | Document contents in logs — never, under any circumstances |
The AI pass
Checking a document means reading it, which means a copy has to exist for a moment. That copy is encrypted, access-scoped, held in memory for the duration of the check, and dropped immediately after. What survives is the verdict, not the document.
Access inside your firm
- Your data is scoped to your organisation at the database level, not by a filter in the interface. One firm cannot read another's rows.
- Client links open exactly one person's request — see What your client sees.
- Destructive actions are restricted to owners and admins. Deleting a request destroys a client record, so it isn't something any team member can do by accident.
- On the Firm plan, the audit log records who did what and when.
Data protection
ChaseDocs is built for firms in Southeast Asia, with PDPA in Singapore and Malaysia as the first alignment target. Two consequences you'll actually notice: consent is recorded before we message anyone on your behalf (see Sending and reminders), and document custody defaults to your cloud rather than ours.
For the formal terms, see the Privacy Policy and Terms & Conditions. For a question those don't answer, email dev@inpresencelab.com.
Still stuck? Email dev@inpresencelab.com and a human will answer.
ChaseDocs