Legal
Privacy policy
Last updated September 15, 2026. The short version: your documents are yours, they're used only to answer your questions, and you can delete them at any time.
1. Information we collect
Account information
When you create an account we collect your email address and a password. Passwords are stored only as salted one-way hashes — we never see or store them in plain text. We also store your plan and preferences, such as your citation style.
Content you add
This includes files you upload (PDFs, images, text and data files), text you paste, links to YouTube videos or web pages you submit, and the questions you ask. From these we derive extracted text, searchable passages, vector embeddings, AI-generated insights and conversation history.
Technical information
Like most web services, our servers receive standard request data such as IP address, browser type and timestamps, which we use for security and troubleshooting. Your sign-in session is kept in your browser's local storage. We do not use advertising cookies or third-party ad trackers.
2. How we use your information
- To provide the service: processing sources, searching them and answering your questions.
- To generate summaries, key points, topics and suggested questions for your sources.
- To secure your account, prevent abuse and fix problems.
- To contact you about your account or important changes to the service.
We do not sell your data, and we do not use your documents or conversations to train AI models.
3. Service providers
We rely on a small number of processors to run Docmind:
- AI model provider (OpenAI) — to create embeddings, extract text from images, generate insights and write answers. Content is sent through the API, which is not used to train their models by default.
- Cloud infrastructure — for hosting the application, the database (MongoDB), the vector index (Qdrant) and S3-compatible file storage.
- Content sources you point us to— when you add a YouTube or web link, we fetch that video's transcript or that page's content on your behalf.
4. Retention and deletion
Your content is kept for as long as it remains in your account. When you delete a source, we remove the stored file, its searchable passages and embeddings, and its record. You can rename or delete conversations at any time. To delete your entire account and all associated data, contact us.
5. Security
Access to your workspaces requires authentication, and each request is checked against your account. Data is transmitted over HTTPS. No system is perfectly secure, but we work to protect your information using industry-standard practices. Enterprise customers can self-host Docmind to keep all data inside their own infrastructure.
6. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, or to object to certain processing. To exercise any of these rights, get in touchand we'll respond within 30 days.
7. Children
Docmind is not directed to children under 13, and we do not knowingly collect their personal data.
8. Changes to this policy
We may update this policy from time to time. If changes are significant, we'll let you know by email or in the app before they take effect.
9. Contact
Questions about privacy? Contact the Docmind team.