/ Privacy Policy

The short version: Your documents are encrypted and stored securely. We don't sell your data, train AI on it, or share it with third parties. You can delete everything anytime — and it's actually deleted.

Table of contents

What We Collect

When you use DocuStrata, we collect:

  • Account information: Email address for login (via Google OAuth or email/password)
  • Documents: Files you upload, including PDFs, images, and scanned documents
  • Extracted text: OCR text extracted from your documents for search functionality
  • Usage data: Basic analytics like page views and feature usage (no document contents)

How Your Documents Are Stored

Your documents are stored on Supabase, a SOC 2 Type II compliant infrastructure provider that uses Amazon Web Services (AWS).

  • Encryption at rest: All files are encrypted using AES-256 encryption
  • Encryption in transit: All data transfers use TLS 1.2+ encryption
  • Geographic location: Data is stored in US-based data centers

Important: DocuStrata uses cloud storage, not end-to-end encryption. This means Supabase has administrative access to their infrastructure. We limit access to your documents to operating the service (for example, AI processing) and the narrow cases described in our Access Policy, but we cannot make a "zero-knowledge" claim. This is the same architecture used by Evernote, Notion, Dropbox, and most cloud document services.

What We Don't Do

  • We don't sell your data — ever, to anyone
  • We don't use your documents to train AI — your files are processed by Anthropic and Voyage AI under commercial API terms and are not used to train or improve any AI model
  • We don't scan your content for advertising — no profiling, no targeted ads
  • We don't share with third parties — except infrastructure providers necessary to operate the service

AI Features

DocuStrata reads your documents with AI so that you can ask a question across your whole archive and get a cited answer in seconds.

How reading works: Each document is read once when it enters your library, so it can be found and cited later, and again only when it forms part of the answer to a question you ask. Nothing is read in the background for any other purpose, and no document is used to build a profile of you.

When a document enters your library:

  • Its text is extracted on our servers. Scanned pages and images are transcribed by a vision model at Anthropic so the words on the page become searchable.
  • The text is sent to Anthropic's Claude API, which assigns a document type and a short description.
  • The text is split into passages and sent to Voyage AI, which returns the numerical embeddings that make search and question answering work. We store the embeddings alongside the passages in your library.

When you ask a question:

  • Your question is embedded by Voyage AI to find the relevant passages.
  • Those passages and your question are sent to Anthropic's Claude API, which writes the cited answer.

Both providers process your content under commercial API terms, and neither uses it to train or improve their models. Anthropic deletes API inputs and outputs within 30 days. Keyword search works without any of this.

OCR Processing

Documents you upload are read on our servers. Text-based files (PDF text layers, Word, email, and similar) are extracted in-house with no third party involved. Scanned pages and images are transcribed by a vision model at Anthropic under the commercial terms described above. The desktop migration app runs Tesseract OCR on your own machine, so text extracted there never leaves it.

Cloud Drive Imports

DocuStrata lets you import documents directly from Dropbox, Google Drive, and Microsoft OneDrive. This is optional — you only use it if you choose to connect one of those services.

  • We access only the files you pick. We use each provider's own file picker and the narrowest permission available — Google Drive's per-file drive.file scope, Microsoft Graph read access limited to the items you select, and Dropbox's Chooser. We never browse, index, or read anything in your drive that you didn't explicitly choose.
  • Imports are one-time copies. Each file you select is copied into your DocuStrata library at the moment you import it. We do not set up an ongoing sync and do not access your cloud drive again afterward.
  • Disconnecting doesn't delete your imports. Files already copied into your library remain there even if you later revoke access or disconnect the cloud drive.
  • We don't use cloud files to train AI. Imported documents are treated exactly like any other document in your library and are covered by the "What We Don't Do" and "AI Features" sections above.

DocuStrata's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can revoke DocuStrata's access at any time from your Google, Microsoft, or Dropbox account settings.

Data Retention

  • Your documents: Stored until you delete them
  • Deleted documents: Removed from active storage immediately; residual backup copies are purged within 30 days
  • Account deletion: Your account is deactivated immediately and permanently deleted after 30 days — log back in within that window to restore it. After permanent deletion, your documents, profile, and login identity are removed, and residual backup copies are purged within 30 days

Your Rights

You have the right to:

  • Access your data — download any document you've uploaded
  • Delete your data — remove individual documents or your entire account
  • Export your data — download all documents and extracted text
  • Correct your data — update account information anytime

To exercise these rights, use the in-app features or contact us at support@docustrata.com.

Third-Party Services

DocuStrata uses the following third-party services:

Service Purpose Policy
Supabase Database and file storage View →
Stripe Payment processing View →
Anthropic Reading and answering: document classification, transcription of scanned pages, and cited answers View →
Voyage AI Embeddings that power search and question answering (document passages and your questions) View →
Resend Email delivery: sign-in codes, account and service email (your email address and message content) View →
Vercel Web hosting View →
Google Sign-in and optional Google Drive import View →
Microsoft Optional OneDrive import View →
Dropbox Optional Dropbox import View →

Security

We implement industry-standard security measures:

  • AES-256 encryption for stored files
  • TLS 1.2+ for all data in transit
  • Secure authentication via OAuth 2.0
  • Row-level security ensuring users can only access their own documents
  • Regular security audits of our infrastructure

Children's Privacy

DocuStrata is not intended for use by children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.

Contact Us

If you have questions about this Privacy Policy or our data practices:

Email: support@docustrata.com
Company: DocuStrata, LLC
Address: United States