Annoteer
Privacy Policy
Annoteer (the “Service”) is a Microsoft Teams meeting extension that enables real-time collaborative document annotation and AI-assisted data extraction. The Service is operated by N.T.I MEASURE (Nicolas Tanala), established in France (collectively “we”, “us”, “our”). This policy explains what information we collect when you use the Service, how we use it, and the choices available to you.
1. Information we collect
1.1 Identity and meeting context
When you open Annoteer inside a Microsoft Teams meeting, Microsoft Teams provides us with the following context, as scoped by your tenant administrator and Microsoft’s consent framework:
- Your Azure AD object identifier (
oid) and tenant identifier (tid). - Your display name and user principal name.
- The meeting identifier, conversation identifier, and your meeting role (organizer, presenter, attendee).
- An Azure AD access token that proves your identity to our servers.
We do not store a long-term user profile. Access tokens are validated on each request and discarded.
1.2 Documents and annotations
- Documents you upload (PDF, PNG, JPG, PPTX, DOCX, XLSX) are stored by us for the duration of the meeting and any follow-up review session, so that other participants can see and annotate the same file.
- Annotations (drawings, text, highlights, sticky notes, shapes) are stored alongside the document so they persist across sessions.
- Ephemeral collaboration state (cursor positions, current page, “follow-me” presenter state) is broadcast to other meeting participants while you are connected, and discarded when you disconnect.
1.3 AI extraction content
If you invoke the AI extraction feature, the content of the document is sent to Anthropic for processing by the Claude API (see Section 3). We do not retain the extraction prompt or response beyond what is needed to return the result to you.
1.4 Technical logs
Our servers log technical information required to operate the service: request timestamps, IP addresses, HTTP status codes, error messages, and performance metrics. We do not use these logs for advertising or profiling.
1.5 What we do not collect
- We do not use analytics, tracking pixels, or third-party advertising cookies.
- We do not sell, rent, or trade personal information.
- We do not read the content of Teams chats, channels, or other meetings.
2. How we use information
- To authenticate you and authorize access to documents within your meeting.
- To provide real-time synchronization of annotations between meeting participants.
- To persist documents and annotations so you can continue where you left off.
- To operate, secure, and debug the service (rate limiting, error diagnostics, infrastructure monitoring).
- To process AI extraction requests that you explicitly initiate.
3. Third-party processors
We share data with the following service providers only to the extent necessary to operate the service:
- Microsoft Azure — hosting (Azure App Service), document storage (Azure Blob Storage), and the real-time meeting relay (Azure Fluid Relay) that powers Microsoft Live Share. Governed by the Microsoft privacy statement.
- Microsoft Entra ID (Azure AD) — authentication and single sign-on. Governed by the Microsoft privacy statement linked above.
- Anthropic — AI extraction via the Claude API, when you invoke the extraction feature. Governed by the Anthropic privacy policy. By default, Anthropic does not train models on data submitted through the API.
We do not authorize these processors to use your data for their own marketing or profiling purposes.
4. Data location and retention
- Documents and annotations are stored in Microsoft Azure data centers in the West Europe region.
- Documents are retained until you or a meeting participant deletes them, or until your organization’s administrator removes the app.
- Annotations persist until the associated document is deleted.
- Technical logs are retained for up to 90 days and then deleted.
- Ephemeral collaboration state (cursor positions, presence) is never persisted.
5. Security
We protect your information with industry-standard controls, including:
- HTTPS/TLS encryption for all network traffic.
- Azure AD-based authentication on every API and WebSocket connection.
- Server-side validation of uploaded file types and sizes.
- Rate limiting and Content Security Policy headers to mitigate abuse.
- Principle-of-least-privilege access to production infrastructure.
No service is perfectly secure. If you become aware of a security issue, please contact us at the address in Section 9.
6. Your rights
Depending on your jurisdiction (including the EU/UK GDPR and the California CCPA), you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete your documents, annotations, or account data.
- Export your data in a machine-readable format.
- Object to or restrict certain processing.
- Lodge a complaint with a supervisory authority.
To exercise any of these rights, contact us at the address in Section 9. We will respond within the timeframes required by applicable law.
7. Children
Annoteer is designed for use in a workplace context and is not directed at children under 16. We do not knowingly collect personal information from children.
8. Changes to this policy
We may update this policy from time to time. Material changes will be announced in the app and reflected in the “Last updated” date at the top of this page.
9. Contact
Questions about this policy or requests to exercise your rights can be sent to: support@annoteer.app.