Legal

Privacy Policy

Last updated 24 July 2026 · Version 1.0

The short version. We collect what we need to run the Service and nothing more. Your documents are processed to produce your analysis, encrypted if you keep them, and never used to train AI models. We don't sell your data, we don't run advertising trackers, and analytics — ours and Google Analytics — only load if you say yes, with document and report identifiers stripped from the page addresses we send. You can export or delete what you keep at any time. Questions? [email protected].

1. Who we are

Docurensic ("we", "us") operates the forensic document intelligence service at docurensic.com and is based in Canada. We are the controller of the personal information described here. For the documents you submit, you are generally the controller and we act as your processor — we handle them on your instructions to produce your analysis.

Contact: [email protected].

2. What we collect

Account information

Your email address, first and last name, and — if you choose to give them — your company and phone number. We record the date and version of the Terms and Privacy Policy you accepted. Your password is handled by our authentication provider and stored only as a cryptographic hash; we never see it.

Documents and analysis

The files you submit for analysis, and the reports produced from them — findings, risk score, verdict, document type, filename, file size, page count, and a verification hash. Reports may include text and images extracted from the document, and cropped regions of the pages where evidence was found, because that is what makes a finding reviewable.

Whether we keep a copy of the original file is your choice (see section 4).

Usage and diagnostics

Scan counts, API request records, feature usage, error and performance logs, and — where you consent — page views on our public site. We derive an approximate location (country, and coarse coordinates) from your IP address for security and usage statistics. We do not use precise device location.

Sign-in security

To stop automated attacks we record failed sign-in and sign-up attempts with the IP address and a one-way hash of the email address — never the address itself. These records are automatically deleted after 7 days.

Support

The content of support requests you send us, plus the page you were on and the app version, so we can reproduce the problem.

3. Why we use it, and our legal basis

PurposeBasis
Provide the analysis and the features you usePerformance of our contract with you
Create and secure your accountPerformance of our contract
Prevent abuse, fraud, and automated attacksLegitimate interests — keeping the Service safe
Diagnose faults and improve reliability and detection qualityLegitimate interests — running a working service
Analytics on our public websiteYour consent (you can decline or withdraw)
Product and service emails you ask forYour consent, or performance of our contract
Meet legal obligationsLegal obligation

We do not use your documents or their contents to train AI models, and we do not sell personal information or share it with other customers. We do not use your data for automated decisions producing legal effects about you — the Service produces analysis for you to act on.

4. How your documents are handled

5. Service providers

We use a small number of providers to run the Service. They process data on our instructions and under contract, and none of them are permitted to use your documents to train models.

ProviderWhat it does
SupabaseAuthentication and the application database
RailwayApplication hosting and file storage
AnthropicThe AI reasoning layer that reviews findings
PerplexityOptional open-web corroboration and company lookups
GoogleWebsite and in-app analytics (page addresses only, identifiers removed, after consent); domain and URL safety checks, business address lookups, web fonts; Google Drive only if you connect it
DropboxOnly if you connect a Dropbox folder
TwilioPhone-line verification in the Company Analyzer
Email providerAccount, security, and notification email, when configured

AI prompts are not stored by default. Where you configure an outbound integration yourself — a Slack, Teams, Discord, Telegram, Google Chat, or webhook destination in Smart Workflows — the content you choose to send goes to that destination under its own privacy terms, at your direction.

We may also disclose information if required by law, to enforce our Terms, or to protect the rights and safety of our users — and, in a merger or acquisition, to the acquiring party, subject to this Policy.

6. International transfers

We are based in Canada, and our providers may process data in Canada, the United States, and the European Union. Where personal information leaves your country, we rely on appropriate safeguards — such as standard contractual clauses and provider commitments — to protect it. By using the Service, you understand your information may be processed outside your country of residence and may be accessible to authorities there under applicable law.

7. Cookies, storage, and analytics

We use only the browser storage the site needs to work — your session, your theme choice, your language, and your consent decision. These are essential and set without consent.

Analytics load only after you accept the consent banner, and you can decline or change your mind at any time. This covers both our public website and the signed-in application, so we can see which features are used and where people get stuck.

We use our own first-party page-view counting and Google Analytics. Where Google Analytics is enabled we send it the page address only, with identifiers removed — document and report IDs, file references, and anything you type into a search box are stripped before the address leaves your browser, and we never send it the contents of a document. IP addresses are anonymised. We run no advertising trackers and do not use this data for advertising or to build profiles for other companies.

8. How long we keep things

DataRetention
Account informationWhile your account is open
Reports and stored filesUntil you delete them, or you close your account
Failed sign-in / sign-up records7 days, then deleted automatically
Usage and API request recordsRetained for statistics and abuse prevention
Support requestsKept while needed to resolve and support you
Website analyticsAggregate counts, kept in de-identified form

When you close your account we delete or de-identify the associated personal information, except where we must keep something to meet a legal obligation or resolve a dispute. Backups age out on their own schedule.

9. Your rights

Whatever your location, you can:

If the EU or UK GDPR applies to you, you also have the rights to restrict or object to processing, and to data portability. We do not charge for these requests and will respond within the time the applicable law allows. Ask at [email protected].

In Canada, our handling of personal information is subject to PIPEDA and you may complain to the Office of the Privacy Commissioner of Canada. In the EU or UK, you may complain to your local supervisory authority.

10. Security

We encrypt data in transit and encrypt stored documents at rest. Access to your data is scoped to your account and enforced at the database layer. Outbound requests are protected against server-side request forgery, webhooks can be verified with an HMAC signature, uploads are validated before any parser reads them, and sign-in is rate limited. No system is perfectly secure, but if a breach affects your personal information we will notify you and the relevant regulator as required by law.

11. Children

The Service is not intended for anyone under 16, and we do not knowingly collect their personal information. If you believe a child has given us information, write to us and we will delete it.

12. Changes to this Policy

We may update this Policy. When we make a material change we will update the version and date at the top of this page and, for account holders, give notice in the product or by email.

13. Contact

Privacy questions, requests, or complaints: [email protected], or through the in-app Help & support page.