Privacy Policy
Last updated 24 July 2026 · Version 1.0
1. Who we are
Docurensic ("we", "us") operates the forensic document intelligence service at docurensic.com and is based in Canada. We are the controller of the personal information described here. For the documents you submit, you are generally the controller and we act as your processor — we handle them on your instructions to produce your analysis.
Contact: [email protected].
2. What we collect
Account information
Your email address, first and last name, and — if you choose to give them — your company and phone number. We record the date and version of the Terms and Privacy Policy you accepted. Your password is handled by our authentication provider and stored only as a cryptographic hash; we never see it.
Documents and analysis
The files you submit for analysis, and the reports produced from them — findings, risk score, verdict, document type, filename, file size, page count, and a verification hash. Reports may include text and images extracted from the document, and cropped regions of the pages where evidence was found, because that is what makes a finding reviewable.
Whether we keep a copy of the original file is your choice (see section 4).
Usage and diagnostics
Scan counts, API request records, feature usage, error and performance logs, and — where you consent — page views on our public site. We derive an approximate location (country, and coarse coordinates) from your IP address for security and usage statistics. We do not use precise device location.
Sign-in security
To stop automated attacks we record failed sign-in and sign-up attempts with the IP address and a one-way hash of the email address — never the address itself. These records are automatically deleted after 7 days.
Support
The content of support requests you send us, plus the page you were on and the app version, so we can reproduce the problem.
3. Why we use it, and our legal basis
| Purpose | Basis |
|---|---|
| Provide the analysis and the features you use | Performance of our contract with you |
| Create and secure your account | Performance of our contract |
| Prevent abuse, fraud, and automated attacks | Legitimate interests — keeping the Service safe |
| Diagnose faults and improve reliability and detection quality | Legitimate interests — running a working service |
| Analytics on our public website | Your consent (you can decline or withdraw) |
| Product and service emails you ask for | Your consent, or performance of our contract |
| Meet legal obligations | Legal obligation |
We do not use your documents or their contents to train AI models, and we do not sell personal information or share it with other customers. We do not use your data for automated decisions producing legal effects about you — the Service produces analysis for you to act on.
4. How your documents are handled
- Processing. Every upload is processed to produce your analysis. Temporary working copies made during analysis are deleted once it completes.
- Storageless. You can run the Service so that no new copy of your file is created. A slim history record remains — filename, basic scan metadata, verdict, findings, document type, and a verification hash.
- File Vault. If you keep originals, they are encrypted at rest with AES-256-GCM under a key derived for your account. Encryption happens before the bytes reach storage, and the ciphertext is cryptographically bound to your account, so a stored file cannot be decrypted for anyone else.
- Your own storage. If you connect Dropbox or Google Drive, files stay in your storage and are fetched only when needed. We store an index and an access token, and we request read-only access.
- In transit. All traffic uses TLS.
- Deletion. Delete a report or a stored file and it is removed. Reports and stored files delete independently in both directions.
5. Service providers
We use a small number of providers to run the Service. They process data on our instructions and under contract, and none of them are permitted to use your documents to train models.
| Provider | What it does |
|---|---|
| Supabase | Authentication and the application database |
| Railway | Application hosting and file storage |
| Anthropic | The AI reasoning layer that reviews findings |
| Perplexity | Optional open-web corroboration and company lookups |
| Website and in-app analytics (page addresses only, identifiers removed, after consent); domain and URL safety checks, business address lookups, web fonts; Google Drive only if you connect it | |
| Dropbox | Only if you connect a Dropbox folder |
| Twilio | Phone-line verification in the Company Analyzer |
| Email provider | Account, security, and notification email, when configured |
AI prompts are not stored by default. Where you configure an outbound integration yourself — a Slack, Teams, Discord, Telegram, Google Chat, or webhook destination in Smart Workflows — the content you choose to send goes to that destination under its own privacy terms, at your direction.
We may also disclose information if required by law, to enforce our Terms, or to protect the rights and safety of our users — and, in a merger or acquisition, to the acquiring party, subject to this Policy.
6. International transfers
We are based in Canada, and our providers may process data in Canada, the United States, and the European Union. Where personal information leaves your country, we rely on appropriate safeguards — such as standard contractual clauses and provider commitments — to protect it. By using the Service, you understand your information may be processed outside your country of residence and may be accessible to authorities there under applicable law.
7. Cookies, storage, and analytics
We use only the browser storage the site needs to work — your session, your theme choice, your language, and your consent decision. These are essential and set without consent.
Analytics load only after you accept the consent banner, and you can decline or change your mind at any time. This covers both our public website and the signed-in application, so we can see which features are used and where people get stuck.
We use our own first-party page-view counting and Google Analytics. Where Google Analytics is enabled we send it the page address only, with identifiers removed — document and report IDs, file references, and anything you type into a search box are stripped before the address leaves your browser, and we never send it the contents of a document. IP addresses are anonymised. We run no advertising trackers and do not use this data for advertising or to build profiles for other companies.
8. How long we keep things
| Data | Retention |
|---|---|
| Account information | While your account is open |
| Reports and stored files | Until you delete them, or you close your account |
| Failed sign-in / sign-up records | 7 days, then deleted automatically |
| Usage and API request records | Retained for statistics and abuse prevention |
| Support requests | Kept while needed to resolve and support you |
| Website analytics | Aggregate counts, kept in de-identified form |
When you close your account we delete or de-identify the associated personal information, except where we must keep something to meet a legal obligation or resolve a dispute. Backups age out on their own schedule.
9. Your rights
Whatever your location, you can:
- Access the information we hold about you;
- Correct inaccurate account details, in Settings or by asking us;
- Delete your reports, your stored files, or your whole account;
- Export your reports and your stored files;
- Withdraw consent to analytics or optional email at any time;
- Complain to us, and to a privacy regulator.
If the EU or UK GDPR applies to you, you also have the rights to restrict or object to processing, and to data portability. We do not charge for these requests and will respond within the time the applicable law allows. Ask at [email protected].
In Canada, our handling of personal information is subject to PIPEDA and you may complain to the Office of the Privacy Commissioner of Canada. In the EU or UK, you may complain to your local supervisory authority.
10. Security
We encrypt data in transit and encrypt stored documents at rest. Access to your data is scoped to your account and enforced at the database layer. Outbound requests are protected against server-side request forgery, webhooks can be verified with an HMAC signature, uploads are validated before any parser reads them, and sign-in is rate limited. No system is perfectly secure, but if a breach affects your personal information we will notify you and the relevant regulator as required by law.
11. Children
The Service is not intended for anyone under 16, and we do not knowingly collect their personal information. If you believe a child has given us information, write to us and we will delete it.
12. Changes to this Policy
We may update this Policy. When we make a material change we will update the version and date at the top of this page and, for account holders, give notice in the product or by email.
13. Contact
Privacy questions, requests, or complaints: [email protected], or through the in-app Help & support page.