Privacy
Privacy Policy
DocPlainly Privacy Policy
Consumer service and location
DocPlainly is intended for adults in the United States. We design the service for consumer use, not enterprise, employer, school, healthcare provider, or government use.
What information we process
When you submit a document for explanation, the app processes the document file, extracted text, prompts, and follow-up questions to provide the requested explanation. Documents may contain sensitive personal information, including legal, financial, employment, housing, account, or identification information. We process this information only to provide and protect the service requested by you.
File handling
Uploaded images and PDFs are processed to generate the explanation you requested. DocPlainly does not save the original uploaded file in Secure History. We do not intend to retain uploaded document files on our servers after processing is complete, except where temporary technical processing is strictly necessary to complete the requested analysis, protect the service, troubleshoot a request, or comply with law.
Saved history and cloud storage
Saving is optional. DocPlainly does not automatically save an explanation to history. You choose whether to save an explanation, and where to save it.
Paid subscribers may have these save options:
- Local browser history. Saved explanations stay in your browser on your device until you delete them, clear browser storage, or remove account data from that device. Local history does not sync to other devices.
- Cloud history with a customer-held recovery key. Cloud saved explanations are encrypted before they are stored. You are responsible for keeping the recovery key. If you lose it, DocPlainly cannot recover that cloud history.
- Cloud history with DocPlainly-secured key storage. Cloud saved explanations are encrypted before they are stored, and DocPlainly keeps a protected key wrapper so signed-in devices can unlock cloud history more easily. This option is not customer-only key custody or zero-knowledge storage because authorized backend systems can help unlock the cloud history after account authorization. The key wrapper is designed to move to AWS KMS in the future.
Saved history may include explanation text, summaries, extracted document text, source references, follow-up questions, follow-up answers, generated document titles, reminder-related labels, and metadata needed to operate saved history. The original uploaded file is not stored in saved history or cloud history.
Retention periods
Original uploaded files are not intended to be retained after processing completes, subject to the narrow exceptions in File handling above. To let you move between the upload and result screens, a temporary copy of the current analysis may remain in that browser session for up to 30 minutes; this is not Secure History and is cleared sooner when the session data is removed. Secure History on this device remains until you delete it or browser storage is cleared. Encrypted Secure History remains until you delete it, use a reset/delete option, close/delete your account, or an enabled auto-delete period applies. Document reminders are kept until they are sent, canceled, deleted, or no longer needed for service records. Support/contact records, security records, billing records, and operational logs may be retained for a limited period when needed for security, abuse prevention, troubleshooting, legal or tax compliance, billing, dispute resolution, and service operations. Account deletion removes account data used to operate the account, but information may be preserved or de-identified where retention is required for those limited purposes.
Third-party processing
To generate explanations, document contents may be sent to AI processing providers such as OpenAI. OpenAI's applicable terms, policies, security commitments, service availability, and technical limitations also apply. We do not sell document content or use document content for advertising.
Service providers
We use service providers to operate DocPlainly. These may include hosting and serverless infrastructure providers, database/authentication providers, AI processing providers, payment processors, email delivery providers, and website-certification providers. Examples include Vercel, Supabase, OpenAI, Stripe, Resend, and TrustedSite. These providers process information only as needed to provide, secure, certify, bill for, or support the service.
TrustedSite trustmark
DocPlainly uses TrustedSite code to display and verify website trustmarks. The code may place a short-lived TrustedSite visit value in browser storage and a cookie, retrieve certification settings for the current hostname, and send TrustedSite a limited visit signal needed to operate and measure the trustmark. It is not intended to receive uploaded documents or Secure History.
AI and model training
DocPlainly does not use your uploaded documents, Secure History, or follow-up questions to train DocPlainly-owned AI models. We use customer content to provide the explanation, answer follow-up questions, operate user-requested Secure History and reminders, prevent abuse, troubleshoot, and maintain the service. AI providers may have their own service terms and data-handling commitments.
AI output
AI-generated explanations may be incomplete or incorrect. We process your document to provide a plain-language explanation, but you should compare important details with the original document before acting on the result.
Access controls
We limit access to account and service data to people and systems that need it to operate, secure, troubleshoot, support, bill for, or comply with legal obligations for DocPlainly. Original uploaded files are not intended to be retained after processing. If you keep your own recovery key, DocPlainly cannot recover encrypted Secure History if the key is lost. With DocPlainly-managed access, authorized backend systems can unlock Secure History after appropriate account authorization, so we do not describe that option as customer-only or zero-knowledge.
Security
We use encryption in transit and at rest for server-side data that we maintain, and we use reasonable administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, or destruction.
Age restriction
This app is intended only for adults age 18 and older. We do not knowingly permit children to use the service.
Breach response
If a security incident affects information covered by applicable law, we will investigate and provide notices required under applicable federal or state law. When appropriate, we will describe what happened, what information was involved, what we are doing, and steps affected users can take.
Website analytics
DocPlainly uses limited analytics to understand visits to public website pages. When you arrive through a tagged promotional link, we may record the campaign source, campaign name, optional creative label, public landing page, and date. A campaign label may remain in your browser for up to 30 days and may be associated with your account if you sign in. Our campaign reports do not include uploaded documents, saved explanations, or activity on private account pages.