Privacy Policy
Last updated: August 12, 2026
1. Introduction
Mica ("Mica Docs," the "Service") is operated by Bullwhip Technologies LLC ("Bullwhip," "we," "us," "our," or the "Company"). We value your privacy and the importance of safeguarding your data. This Privacy Policy (the "Policy") describes our privacy practices for the activities set out below, including how we collect, store, access, and otherwise process information relating to individuals.
In this Policy, personal data ("Personal Data") refers to any information that, on its own or in combination with other available information, can identify an individual.
Mica is a collaborative markdown editor that operates on documents stored in your Google Drive. A defining characteristic of the Service — and of this Policy — is that Bullwhip does not hold the canonical copy of your document content. Your files remain in your Drive, under your Google account's permissions, subject to Google's terms and to Google's own privacy practices.
Regulations we align to
We design our privacy practices to meet the obligations of, among others:
- Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), applicable provincial legislation, and Quebec Law 25
- The EU/UK General Data Protection Regulation (GDPR)
- Switzerland's Federal Act on Data Protection (FADP)
- Brazil's Lei Geral de Proteção de Dados (LGPD)
- California's CCPA/CPRA and CalOPPA
- The comprehensive U.S. state privacy laws then in effect, including those of Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia
- South Africa's Protection of Personal Information Act (POPIA)
- Saudi Arabia's Personal Data Protection Law (PDPL)
We also comply with the Google API Services User Data Policy, including its Limited Use requirements. See Section 4.
Scope
This Policy applies to micadocs.app, app.micadocs.app, the Mica MCP server, the Mica realtime relay, and related applications, services, and products.
This Policy does not apply to third-party applications, websites, products, services, or platforms accessed through links we provide, including Google Drive itself and any third-party AI assistant you choose to connect. Those services are operated independently, with their own privacy and data-collection practices. Personal Data you provide to them is governed by their policies, and we are not responsible for their content or practices.
Processing activities
This Policy applies when you:
- Use Mica as an authorized user, including through a shared folder or an AI integration
- Visit any of our websites that link to this Policy
- Receive communications from us, including service notices, newsletters, or support correspondence
2. Personal Data We Collect
Account and identity data
- Name, email address, and Google account identifier
- Authentication state, including OAuth access and refresh tokens issued by Google (stored encrypted)
- Plan, subscription status, and role within any organization or shared folder
Folder and document metadata
- Drive folder and file identifiers for the folders you connect
- File names, paths, sizes, modification timestamps, and content hashes
- The wiki-link and backlink graph derived from your notes (which documents reference which)
- Named checkpoint labels and the revision identifiers they point to
Document metadata of this kind is necessary to render a folder, resolve links, and synchronize changes. It can include Personal Data where you put Personal Data in a file name or link.
Document content
The canonical copy of your content stays in your Google Drive. To provide live multiplayer editing, Mica's realtime relay processes and temporarily retains document content and edit history in the form of conflict-free replicated data type (CRDT) state. This is how live cursors, presence, and offline merging work. Relay state is held only as long as needed to converge and persist edits back to your Drive, and is deleted on the schedule in Section 8. Content in transit and at rest in the relay is encrypted.
Collaboration data
- Presence and cursor position while you have a document open
- Comment and suggestion content, and the identity of the collaborator who authored it
- Share events and permission changes we initiate on your behalf at your request
Payment data
Billing name, billing address, and subscription history. We do not store full payment card numbers. Card data is collected and processed directly by our payment processor (see Section 7).
Device and usage data
When you visit a Mica website or use the app, we automatically collect and store information about your session using cookies, server logs, and similar technologies: IP address, browser and device type, operating system, referring pages, pages and features used, login information, timestamps, authentication records, error and crash diagnostics, and other operational data.
You can instruct your browser to refuse cookies or to notify you when one is sent. Most browsers explain how in their Help feature. If you refuse cookies, some features of the Service will not work, and we recommend leaving strictly necessary cookies enabled. See Section 6.
Support and voluntary data
Content you send us when you contact us with an inquiry or a problem report (by email, social media, or messaging service), including any files or screenshots you attach, plus optional survey or feedback responses.
How we collect it
- From you, when you create an account, connect a folder, edit or create content, subscribe to a mailing list, complete a survey, or contact us.
- Automatically, as you interact with the Service, via cookies, server logs, and similar technologies.
- From third parties, including: Google (your basic profile, and the Drive data described in Section 4); our payment processor (billing and subscription status); analytics and error-monitoring providers (device and usage data); other Mica users who invite you to a folder or share a document with you (your email address, and your name where they supply it).
If you provide us — or our service providers — with Personal Data relating to other individuals, you represent that you have the authority to do so and acknowledge it will be used in accordance with this Policy. If you believe your Personal Data has been provided to us improperly, contact us using Section 13.
3. Purpose and Legal Basis
| Purpose | Examples | Legal basis (GDPR/LGPD) |
|---|---|---|
| Deliver the Service | Authenticate you, render your folder, sync edits to Drive, resolve wiki-links, run realtime collaboration | Performance of a contract |
| Billing | Process subscriptions, invoices, refunds, and taxes | Performance of a contract; legal obligation |
| Security and integrity | Verify identity, detect and investigate breaches, attacks, abuse, and fraud; maintain audit logs | Legitimate interests; legal obligation |
| Support | Respond to your requests and diagnose reported problems | Performance of a contract; legitimate interests |
| Maintain, debug, and improve | Fix defects, measure aggregate feature usage, plan capacity | Legitimate interests |
| Service communications | Outage, security, and material change notices | Legitimate interests; legal obligation |
| Marketing communications | Newsletters and product announcements | Consent (withdrawable at any time) |
Where consent is the basis, you may withdraw it at any time, free of charge; withdrawal does not affect processing already carried out. If you decline consent or decline required permissions, some features or the Service as a whole may be unavailable to you. New consent will be sought if we materially change the categories of data we collect.
We do not sell your Personal Data, and we do not share it for cross-context behavioral advertising or targeted advertising. We do not use your document content or Google user data to train generalized artificial-intelligence or machine-learning models.
4. Google Drive Access, OAuth Scopes, and Limited Use
Mica is built on Google Drive, so this section governs the most sensitive data the Service touches.
Scopes we request
We request the narrowest scopes that allow Mica to function. As of the date above:
| Scope | What it permits | Why Mica needs it |
|---|---|---|
openid, .../auth/userinfo.email, .../auth/userinfo.profile | Your Google account identifier, email address, and basic profile | Sign-in and account identity |
.../auth/drive.file | Access limited to files and folders you specifically open with Mica through the Google Picker, and files Mica creates | Read, edit, and create the .md files in a folder you connect |
.../auth/drive.metadata.readonly (where enabled) | Read-only file and folder metadata such as names, IDs, and modified times | Build the folder's file tree, detect external changes, and resolve wiki-links across it |
Mica requests access only to the Drive folders you connect. We do not request, and do not have, blanket read access to your entire Drive. You can review and revoke Mica's access at any time at myaccount.google.com/permissions; revocation immediately ends our ability to read or write your files, though it does not by itself delete the account metadata described in Section 8.
Limited Use commitment
Mica's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google user data is used only to provide or improve user-facing features that are prominent in Mica's interface, and:
- We do not transfer Google user data to third parties except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition with notice as described in Section 9.
- We do not use Google user data for serving advertising of any kind.
- We do not allow humans to read your Google user data unless (a) you give us affirmative consent for specific files, for example in a support request; (b) it is necessary for security purposes such as investigating abuse or an incident; (c) it is required to comply with applicable law; or (d) the data is aggregated and anonymized and used for internal operations such as capacity planning.
- We do not use Google user data to develop, improve, or train generalized AI or machine-learning models.
Sharing and revision history
Sharing, permissions, and revision history for your documents are Google Drive's own. When you share a folder or document by email as a viewer, commenter, or editor, that permission change is made in your Drive through the Google API, and the resulting access is governed by Google's terms. Named checkpoints are pointers to Drive revisions; they persist for as long as the underlying file and its revision history exist in your Drive, which is under your control and Google's retention rules, not ours.
5. AI Collaborators and the Model Context Protocol (MCP)
Mica lets you connect Claude or another AI assistant to a folder via the Model Context Protocol. If you use this feature, please understand the following:
- Connections are opt-in and per-folder. No AI assistant can reach a folder until you connect it.
- The same permissions apply. An AI collaborator operates within the Drive permissions of the account that authorized it. It cannot read or write anything that account could not.
- Content leaves our boundary. When an assistant reads or drafts a document, the relevant content is transmitted to that assistant's provider — for example, Anthropic — and is then subject to that provider's terms and privacy policy, not this one. We encourage you to review them before connecting a folder, particularly regarding retention and model training.
- We log the fact of access, not a copy of the content. Mica records which folder was accessed, by which connection, and when, for security and audit purposes.
- Our own commitment stands. Bullwhip does not use your document content to train models, and does not permit its subprocessors to do so on our instruction.
- Revocation. You can disconnect an AI integration at any time in Mica's settings; this takes effect immediately for future requests.
6. Cookies
A cookie is a small file your browser stores on your device. We use:
- Strictly necessary cookies. Session, authentication, and security cookies. Mica cannot function without these.
- Preference cookies. Editor and interface settings, such as theme and recently opened folders.
- Analytics cookies. Aggregate measurement of how the Service is used, so we can improve it.
We do not use advertising or cross-site tracking cookies. Where required by law, we ask for your consent before setting non-essential cookies, and you can change your choice at any time.
7. Sharing, Disclosure, and Subprocessors
We share Personal Data with third parties only as set out in this Policy or as disclosed at the point of collection.
Subprocessors
| Provider | Role | Data involved |
|---|---|---|
| Google Cloud Platform | Hosting, storage, database, and realtime relay infrastructure | All categories described in Section 2 |
| Google LLC (Drive & Identity APIs) | Document storage and authentication | Google user data per Section 4 |
| Stripe, Inc. | Payment processing | Billing and payment data |
| Google Analytics | Website and product analytics | Device and usage data |
| Anthropic PBC and other AI providers you connect | AI collaboration, at your direction only | Document content you or your assistant requests |
You can read how Google uses data at google.com/policies/privacy and opt out of Google Analytics at tools.google.com/dlpage/gaoptout.
We may also use independent contractors, agencies, or consultants to deliver and improve the Service — for example email delivery, error monitoring, and backup and disaster recovery providers — under written terms requiring them to protect your data and process it only on our instructions. For a current list of recipients, contact us using Section 13.
Legal requirements
We may use or disclose Personal Data to comply with a legal obligation, in connection with a request from a public or government authority, in connection with court or tribunal proceedings, to prevent loss of life or injury, or to protect our rights or property. Where possible and lawful, we will tell you in advance.
International transfer and storage
Where possible, we store and process data on servers in the general geographic region where you reside, which may not be the country in which you reside. Your Personal Data may be transferred to and maintained on servers outside your state, province, or country, where data protection laws may differ. Where we transfer Personal Data out of the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism, together with appropriate supplementary measures. The clauses are available at eur-lex.europa.eu.
8. Retention and Deletion
We retain Personal Data only as long as necessary for the purpose for which it was collected and to the extent required by applicable law. When we no longer need it, we delete it from our systems or take steps to anonymize it.
| Data | Retention |
|---|---|
| Account and connected-folder metadata | For the life of your account, then deleted within 30 days of account deletion |
| OAuth tokens | Until you revoke access, disconnect the folder, or delete your account; deleted promptly thereafter |
| Realtime relay CRDT state | Until edits converge and persist to Drive; purged no later than 30 days after the last edit to a document |
| Derived link graph and search index | Rebuilt continuously; deleted when the folder is disconnected |
| Comments and suggestions | For the life of the document or until deleted by an authorized collaborator |
| Access, audit, and security logs | Up to 12 months |
| Billing and tax records | As required by law, typically 7 years |
| Support correspondence | 24 months |
| Marketing contact data | Until you unsubscribe, then suppression-list only |
Your document content is not deleted by deleting your Mica account. Your files, their revision history, and the Drive revisions your named checkpoints point to remain in your Google Drive, because that is where they live. To delete content, delete it in Drive.
9. Merger or Acquisition
If we are involved in a merger, acquisition, or asset sale, your Personal Data may be transferred. We will provide notice before your Personal Data is transferred and becomes subject to a different privacy policy. Any such transfer of Google user data will be made consistent with the Limited Use requirements in Section 4.
10. How We Keep Your Data Safe
We maintain organizational safeguards and technical security measures designed to protect Personal Data from accidental loss and from unauthorized access, use, alteration, or disclosure. These include encryption in transit (TLS) and at rest, encryption of stored OAuth tokens, least-privilege access controls with audit logging, and periodic review of our security posture.
We require any third party contracted to process Personal Data on our behalf to have appropriate security measures in place and to treat the data in accordance with applicable law.
No method of transmission or storage is completely secure. In the event of a Personal Data breach, we will notify you and any applicable regulator where we are legally required to do so, without undue delay.
11. Children's Privacy
We do not knowingly collect Personal Data from children under the age of 18. If you believe a child has provided us with Personal Data, contact us and we will delete it.
12. Your Rights
Depending on your location and citizenship, your rights are subject to local data privacy regulation and may include:
- Right to access (PIPEDA, GDPR Art. 15, CCPA/CPRA, and comparable U.S. state laws, LGPD, POPIA) — to learn whether we process your Personal Data and to obtain a copy.
- Right to rectification (PIPEDA, GDPR Art. 16, CPRA, LGPD, POPIA) — to have incomplete or inaccurate Personal Data corrected.
- Right to erasure (GDPR Art. 17, CCPA/CPRA, LGPD, POPIA) — to have your Personal Data deleted, unless we must retain it to comply with a legal obligation or to establish, exercise, or defend legal claims. Note the Drive limitation in Section 8.
- Right to restriction of processing (GDPR Art. 18, LGPD) — in which case we will only store your data.
- Right to portability (PIPEDA, GDPR Art. 20, LGPD) — to receive Personal Data you provided in a structured, electronic format and transmit it to another controller, where we process it on the basis of consent or contract. Your documents are already plain
.mdfiles in your own Drive; there is nothing to export. - Right to opt out (CPRA and comparable U.S. state laws) — of targeted advertising, sale of Personal Data, and profiling with legal or similarly significant effects. We do not engage in these activities.
- Right to object (GDPR Art. 21, LGPD, POPIA) — where our basis is legitimate interests, on grounds relating to your particular situation. We will honor the objection unless we have compelling legitimate grounds that override your interests or need the data for legal claims.
- Non-discrimination and non-retaliation — you will not be denied service or given a degraded experience for exercising your rights.
- Right to appeal (Colorado, Connecticut, Virginia, and other states providing one) — you may appeal our response. If you disagree with the outcome, you may contact your state attorney general.
- Right to complain (GDPR Art. 77, LGPD, POPIA) — you may bring a claim before your competent data protection authority. EEA residents can find their authority via the EDPB member list.
- Right to withdraw consent — at any time, free of charge, including opting out of marketing messages.
How to exercise your rights
Email privacy@bullwhip.io with your request and the email address associated with your Mica account. We will respond within the period required by applicable law. For your own privacy and security, we may need to verify your identity before we act on a request. You may use an authorized agent where the applicable law permits it.
13. Contact Us
To request a copy of your information, unsubscribe from our email list, request deletion, or ask a question about your data privacy:
Email: privacy@bullwhip.io
Mail:Data Privacy Officer
Bullwhip Technologies LLC
441 Central Park Ave # 1305
Scarsdale, New York 10583
United States
14. Changes to This Policy
We may modify this Policy at any time. If we make changes, we will post an updated version at this address and update the "Last updated" date. When material changes affect how we handle Personal Data, we will notify you through the Service or by email before they take effect. When using the Service you may be asked to review and accept this Policy, which lets us record your acceptance and notify you of future changes.
Last updated: August 12, 2026