DocsQA
    How it worksFeaturesPricingBlog
    Get started free
    Back to home
    Legal

    Privacy Policy

    Effective date: July 2, 2026

    1. Introduction

    DocsQA ("we", "our", or "us") operates docsqa.com and the DocsQA Widget-Builder platform — a SaaS service that lets businesses upload documents and deploy AI-powered chat widgets on their websites.

    This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and your rights regarding that data. By using our platform you agree to the practices described here.

    For account, billing, security, and platform operation data, DocsQA generally acts as the data controller. For customer-uploaded documents, widget conversations, and data processed on behalf of a workspace owner, DocsQA generally acts as a processor or service provider for that customer. Business customers can review our Data Processing Addendum.

    2. Data We Collect

    2.1 Account & Identity Data

    When you register or accept a team invitation we collect:

    • Email address
    • First and last name (optional at registration)
    • Password (stored as a bcrypt hash — never in plain text)
    • Role within your organisation (Owner, Admin, Member)
    • Google OAuth profile data if you sign in with Google

    2.2 Organisation (Tenant) Data

    • Organisation name and slug
    • Subscription plan and billing status
    • Allowed widget domains you register

    2.3 Documents You Upload

    When you upload a supported document (PDF, DOCX, TXT, MD, or PPTX) to build a knowledge base, we process the file into text chunks, embeddings, and searchable indexes. Document content is used solely to provide the DocsQA service, including answering questions from your dashboard, playground, demos, and embedded widgets.

    We may retain the original uploaded file while the document or demo remains active so that workspace owners can download/read the source document. Deleted customer documents enter a 72-hour recovery period and are removed from AI retrieval immediately. During that period, authorised workspace members may restore them or permanently delete them sooner. After the recovery period, the source file, extracted content, and embeddings are permanently deleted from active application storage, subject to backups, audit logs, and legal retention duties.

    2.4 Chat & Usage Data

    • Messages sent through your widget or the playground (stored per tenant)
    • Token usage counts (prompt and completion tokens per session)
    • Session identifiers for conversation continuity
    • Widget visitor IDs and conversation IDs generated in the visitor's browser
    • Recent widget chat history stored in the visitor's browser for conversation continuity

    2.5 Payment Data

    When online checkout is enabled, payments may be processed by SSLCommerz or another payment provider. We do not store card numbers or banking credentials. We may store transaction IDs, payment status, amount, and plan purchased for billing history, reconciliation, tax, and dispute-resolution purposes. If your plan is handled manually, we store the plan and billing status needed to operate your workspace.

    2.6 Technical & Log Data

    • IP addresses (used for rate limiting and abuse prevention)
    • Browser and device type (from request headers)
    • Audit logs of significant account actions (document upload, member invite, etc.)
    • Email open events via tracking pixel (for transactional emails only)
    • Authentication cookies used to keep dashboard sessions secure

    2.7 Anonymous Trial Data

    If you use the "Try before signup" feature, we create a temporary session tied to your IP address. Trial documents and chat history are stored for 24 hours and then permanently deleted unless you claim the session by creating an account.

    3. How We Use Your Data

    • To provide, operate, and improve the DocsQA platform
    • To authenticate you and enforce role-based access control
    • To process payments and manage your subscription
    • To send transactional emails (welcome, usage warnings, plan renewal reminders) via Resend
    • To enforce plan limits (document count, token usage, monthly quotas)
    • To detect and prevent abuse, fraud, and security threats
    • To respond to support requests
    • To comply with legal obligations

    We do not use your document content or chat history to train our own AI models. We do not sell your data to third parties.

    4. Data Isolation & Multi-Tenancy

    Every customer account is a separate tenant. Your documents, knowledge bases, chat history, and user data are strictly isolated by tenant ID at the database level. No tenant can access another tenant's data.

    5. Data Sharing

    We share data only with the following categories of sub-processors:

    • OpenAI — AI language model inference (your document content and chat messages are sent to OpenAI for processing)
    • Cohere — document embedding and reranking
    • LlamaParse / LlamaIndex — document parsing and extraction when used for uploaded files
    • Google — OAuth authentication if you choose Google sign-in
    • SSLCommerz or payment providers — payment processing when online checkout is enabled
    • Resend — transactional email delivery
    • Cloud infrastructure providers — hosting, database, object/file storage, Redis, and networking services

    All sub-processors are contractually bound to process data only as instructed and to maintain appropriate security standards. We may update subprocessors as the service evolves, but we remain responsible for selecting providers that support the security and reliability of DocsQA.

    6. Data Retention

    • Account data is retained for the lifetime of your account plus 30 days after deletion
    • Chat history is retained until you delete it or close your account
    • Deleted customer documents and operator-managed demos remain recoverable for 72 hours, then their source files, extracted content, embeddings, histories, and indexes are permanently deleted from active storage
    • Trial session data is deleted after 24 hours if not claimed
    • Payment records are retained for 7 years for legal and tax compliance
    • Audit logs are retained for 12 months

    7. Security

    We implement industry-standard security measures including:

    • TLS encryption in transit for all API and widget traffic
    • Passwords hashed with bcrypt
    • HttpOnly authentication cookies with short-lived access tokens and refresh-token rotation
    • Rate limiting on all public endpoints via Redis
    • Domain allowlist enforcement for widget embedding
    • Role-based access control enforced at both API and database layers

    No system is perfectly secure. If you discover a vulnerability, please report it to [email protected].

    If we become aware of a security incident involving personal data, we will investigate, take appropriate containment steps, and notify affected customers or users where required by applicable law.

    8. Your Rights

    Depending on your jurisdiction, you may have the right to:

    • Access — request a copy of the personal data we hold about you
    • Rectification — correct inaccurate data
    • Erasure — request deletion of your data ("right to be forgotten")
    • Portability — receive your data in a machine-readable format
    • Objection — object to certain processing activities
    • Restriction — request that we limit processing of your data

    These rights may apply under laws such as GDPR, UK GDPR, CCPA/CPRA, or similar regional privacy laws, depending on where you are located and how you use DocsQA. If you are a website visitor using a customer's embedded widget, we may direct your request to the customer that controls that widget or document content.

    To exercise any of these rights, email us at [email protected]. We will respond within 30 days where legally required, subject to identity verification, abuse-prevention needs, backups, and records we must retain for legal, tax, security, or dispute-resolution purposes.

    9. International Processing

    DocsQA and its service providers may process data in countries other than your own. Where required, we use appropriate contractual, technical, and organisational measures to protect data transferred to service providers, such as data processing agreements, transfer safeguards, and provider security commitments.

    If you are located in a jurisdiction with specific cross-border transfer rules, you are responsible for confirming that your use of DocsQA and your uploaded content are lawful for that jurisdiction. Business customers can contact us at [email protected] for data processing and transfer questions.

    10. Cookies and Browser Storage

    We use essential cookies and browser storage for authentication, trials, widget continuity, and service operation. For full details see our Cookie Policy.

    11. Children

    DocsQA is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it promptly.

    12. Changes to This Policy

    We may update this policy from time to time. When we do, we will update the effective date at the top and, for material changes, notify you by email. Continued use of the platform after changes constitutes acceptance of the updated policy.

    13. Contact

    For privacy-related questions or requests, contact us at:

    DocsQA

    [email protected]

    docsqa.com

    © 2026 DocsQA. All rights reserved.

    Privacy PolicyTerms of ServiceCookie PolicyDPA