Privacy Policy

Last updated: April 12, 2026

1. Overview

DocuWise (“we”, “our”, “us”) operates the website docu-wise.com and the DocuWise application. This policy explains what personal data we collect, how we use it, and your rights regarding that data. By using DocuWise, you agree to the practices described here.

2. Data We Collect

Account data: When you create an account, we collect your email address and a hashed password (or your Google account identifier if you sign in with Google). We store your subscription plan status and usage counters (number of AI responses used this month).

Documents you upload: Files you upload (PDF, DOCX, TXT, images) are stored in a private, access-controlled storage bucket. Document text is extracted and stored to power AI chat. Raw files are retained until you delete them or close your account.

Chat and generation history: We store the questions you ask and the AI responses, linked to your account, so you can review past conversations. You can delete individual conversations from your account.

Usage and technical data: We collect standard server logs (IP addresses, browser type, pages visited, timestamps) for security and debugging. We do not use third-party analytics cookies on this service.

3. How We Use Your Data

  • To provide the service: processing your documents, generating AI answers, converting files.
  • To enforce usage limits and prevent abuse (rate limiting, quota tracking).
  • To manage your subscription and process payments via our billing provider.
  • To send transactional emails (account confirmation, password reset). We do not send marketing emails without your explicit consent.
  • To improve the service: aggregate, anonymized usage patterns only. We do not use your document content to train AI models.

4. Third-Party Processors

We share your data with the following sub-processors, each bound by their own privacy and security commitments:

ProviderPurposeData shared
SupabaseDatabase, auth, file storageAll account and document data
OpenAIAI language model (chat, generation)Document text, your questions
VercelApplication hostingRequest logs, IP addresses
CreemPayment processingEmail, subscription status
UpstashRate limiting (Redis)Anonymized request counters

Important — OpenAI:Document text you upload is sent to OpenAI’s API to generate answers. OpenAI does not use API-submitted data to train its models by default (as of their current API terms). We recommend not uploading documents containing sensitive personal or confidential information.

5. Data Retention

We retain your data for as long as your account is active. If you delete your account, we delete your documents, chat history, and personal data within 30 days. Billing records may be retained for up to 7 years as required by financial regulations. Server logs are retained for 90 days.

6. Cookies

We use only essential cookies required to maintain your login session (a secure, HTTP-only session cookie set by Supabase Auth). We do not use advertising, tracking, or analytics cookies. No cookie consent banner is required because we only use strictly necessary cookies.

7. Your Rights (GDPR / CCPA)

Depending on your location, you may have the following rights:

  • Access: Request a copy of all data we hold about you.
  • Deletion: Request deletion of your account and all associated data.
  • Portability: Export your documents and chat history from your account settings.
  • Correction: Update your email address from your account settings.
  • Objection: Object to processing of your data for any purpose.

To exercise these rights, email support@docu-wise.com. We will respond within 30 days.

8. Security

All data in transit is encrypted with TLS. Documents are stored in a private Supabase Storage bucket protected by row-level security policies — no other user can access your files. API keys and service credentials are never exposed to the client. We conduct periodic security reviews.

9. Children’s Privacy

DocuWise is not directed at children under 13. We do not knowingly collect data from anyone under 13. If you believe a child has provided us with personal data, contact us at support@docu-wise.com and we will delete it promptly.

10. Changes to This Policy

We may update this policy. Material changes will be communicated via email to registered users at least 14 days before taking effect. The “Last updated” date at the top of this page will always reflect the most recent version.

11. Contact

Questions about this policy? Reach us at support@docu-wise.com.