Version: v1.3 Streamlined
Operator: Bobby Built Ventures LLC d/b/a QuillCaddie
Applies to: Users, customers, workspace administrators, and developers using connectors, exports, OAuth integrations, BYOK, customer-managed providers, MCP, API tools, or external AI clients.
Quick summary
Integrations are user/admin controlled. QuillCaddie should not send raw transcripts, source text, AI outputs, files, or other Customer Content to external tools unless a user/admin explicitly authorizes that action. Read-only tools are the default for MCP. BYOK/customer-managed providers shift some responsibility to the customer’s provider account.
1. Integration categories
QuillCaddie may support:
- link-only references that store external URLs;
- export/action connectors that send selected outputs to another tool;
- read-only context connectors that fetch selected external content as context;
- sync/index connectors that keep selected external content updated;
- MCP/API tools for external AI clients or developer workflows; and
- BYOK/customer-managed providers for AI/transcription routing.
2. Launch posture
QuillCaddie should prioritize export/action connectors before broad enterprise sync. Early connectors may include GitHub, Linear, Slack, Google Drive, and Notion. Broad permission-aware enterprise sync should not be promised until built and governed.
3. Authorization
When you connect an integration, you authorize QuillCaddie to access, process, retrieve, create, update, export, or transmit data according to the scopes you grant, workspace settings, and the connector design. You are responsible for having the right to connect that account and use that data.
4. Workspace admin controls
Workspace admins may allow, restrict, approve, disconnect, or monitor integrations where controls are available. Users should not bypass admin restrictions.
5. Least privilege
QuillCaddie should request the minimum scopes reasonably needed for the feature. Some providers may require broad scopes for technical reasons. The UI should explain material permissions where practical.
6. What may be sent externally
QuillCaddie should not send raw transcript text, source text, full AI outputs, files, screenshots, or other Customer Content to third-party services unless a user/admin explicitly triggers or authorizes a connector action, export, context import, sync, MCP/API tool, or provider route.
7. Third-party terms
Third-party services are governed by their own terms, privacy policies, data-retention settings, security practices, model-training settings, and billing. QuillCaddie is not responsible for third-party services after content is sent to them.
8. Revocation and disconnection
Users/admins may disconnect integrations where supported. Disconnection stops future access but may not delete content already exported to or stored by the third-party service. You must manage deletion with that third party.
9. Connector logs
Connector logs should store non-sensitive metadata such as provider, action type, status, timestamp, external URL, and sanitized errors. They should not store raw transcripts, full AI outputs, provider keys, OAuth tokens, secrets, or sensitive provider payloads.
10. MCP and API tools
MCP/API tools allow external clients or AI tools to interact with QuillCaddie. Read-only tools are the default. Write tools, such as creating a capture, creating an issue, or posting to Slack, require explicit enablement and appropriate scopes.
MCP/API calls should be scoped to the authenticated user/workspace, rate-limited where appropriate, and audit logged without sensitive content bodies.
11. External AI clients
If you connect QuillCaddie to external AI clients, those clients may receive data you authorize. Review the external client’s terms, privacy policy, and data-use settings before sending content.
12. Google API Services Limited Use
If you connect Google Drive or another Google API integration, QuillCaddie will use Google user data only to provide or improve user-facing features that are visible in QuillCaddie, such as exporting Markdown/ZIP files to a selected Drive folder or using selected Drive files as context.
QuillCaddie does not use Google user data for advertising, sale, unrelated purposes, or generalized AI/ML model training. QuillCaddie does not allow humans to read Google user data unless you give permission, it is necessary for security/legal reasons, or the law requires it.
13. BYOK and customer-managed providers
BYOK allows users or workspace admins to use their own provider keys or provider accounts where supported. BYOK does not mean QuillCaddie stops processing data; it means processing may be routed through the customer-managed provider according to settings.
Customers are responsible for provider account configuration, provider billing, provider availability, retention/log settings, and provider model-training/model-improvement settings. QuillCaddie is responsible for protecting keys using reasonable secret-storage controls and routing requests according to configured settings.
14. Changes and suspension
QuillCaddie may add, remove, change, suspend, or disable integrations for security, provider, legal, operational, or abuse-prevention reasons.
Contact
Support: support@quillcaddie.com
Privacy requests: privacy@quillcaddie.com
Security reports: security@quillcaddie.com
Legal notices: legal@quillcaddie.com
DMCA notices: dmca@quillcaddie.com
Mail: Bobby Built Ventures LLC d/b/a QuillCaddie, 1500 N Grand St, STE R, Denver, CO 80203