Customer Data & Storage
Last updated 2026-08-02
Where your documents actually live, and why that is a deliberate design decision rather than a limitation.
We connect to your storage. We do not sell you storage.
ValiCrew charges one flat price. Holding customer files would make that price depend on how many documents you upload, and it would put your employees' passports and contracts on our infrastructure for no reason other than our convenience.
So the platform does not offer to keep your files. You connect your own Microsoft SharePoint or Google Drive, and uploads go there.
What that means in practice
Your files are in your tenancy. They sit in the SharePoint library or Drive folder you chose, under your own agreement with Microsoft or Google, subject to your own retention and backup rules.
We hold metadata, not documents. Document type, expiry date, reference number and a pointer to the file in your storage. That metadata is what drives expiry reminders and reporting, and it lives in your workspace database in Abu Dhabi.
Downloads are proxied and audited. When someone opens a document, the platform fetches it from your storage and records who accessed what and when. You get an audit trail you would not have if people opened files directly.
Deleting in ValiCrew deletes the file. Removing a document removes the record and makes a best-effort deletion of the stored file. If your storage refuses, the record still goes and the failure is logged rather than hidden.
The access we ask for
Google Drive — the drive.file scope only. This is the narrowest Drive permission that exists:
the application can see and manage only files it created itself, and has no visibility of
anything else in your account. On connecting, it creates a folder named ValiCrew and works inside
it.
Microsoft SharePoint — access limited to the site and document library you pick during setup.
We store no Microsoft tokens at all — the connection is made with your directory and library identifiers. For Google we store one refresh token, encrypted with your workspace's own key, never exposed to the browser, and destroyed the moment you disconnect.
Disconnecting
Disconnect whenever you like. Metadata, expiry tracking and reminders keep working; downloads stop until you reconnect, and they fail with a clear message rather than an error page.
Switching providers affects new uploads only. Existing files stay where they are and remain readable — nothing is migrated behind your back, and nothing is stranded.
Only one storage provider can be connected at a time.
If you never connect anything, we hold nothing
Document records, expiry dates and reminders all work — the platform runs off the dates and reference numbers you type, not off files.
File upload is simply unavailable until a connector is active. This is enforced in the code rather than discouraged in the interface: the upload path refuses outright when there is no connected storage, so there is no state in which a document file of yours ends up on our infrastructure by accident or by fallback. The workspace tells you why instead of failing quietly.
The one exception, and it is not your files
Quarantine. Every upload is scanned before it reaches your storage. A file that fails the scan is held on platform storage for review and never written to your cloud — putting suspected malware into a customer's SharePoint would be an odd way to protect them. That is the only circumstance in which file content sits on our side, and it exists to protect you rather than to serve us.
Contact
Lenouar Artificial Intelligence Developing Services LLC · Al Muroor, Abu Dhabi, United Arab Emirates · Commercial registration CN-6272765