/ Privacy Policy

The short version: Your documents are encrypted and stored securely. We don't sell your data, train AI on it, or share it with third parties. You can delete everything anytime — and it's actually deleted.

Table of contents

What We Collect

When you use DocuRead, we collect:

  • Account information: Email address for login (via Google OAuth or email/password)
  • Documents: Files you upload, including PDFs, images, and scanned documents
  • Extracted text: OCR text extracted from your documents for search functionality
  • Usage data: Basic analytics like page views and feature usage (no document contents)

How Your Documents Are Stored

Your documents are stored on Supabase, a SOC 2 Type II compliant infrastructure provider that uses Amazon Web Services (AWS).

  • Encryption at rest: All files are encrypted using AES-256 encryption
  • Encryption in transit: All data transfers use TLS 1.2+ encryption
  • Geographic location: Data is stored in US-based data centers

Important: DocuRead uses cloud storage, not end-to-end encryption. This means Supabase has administrative access to their infrastructure. We do not access your documents, but we cannot make a "zero-knowledge" claim. This is the same architecture used by Evernote, Notion, Dropbox, and most cloud document services.

What We Don't Do

  • We don't sell your data — ever, to anyone
  • We don't train AI on your documents — your files are not used to improve any AI models
  • We don't scan your content for advertising — no profiling, no targeted ads
  • We don't share with third parties — except infrastructure providers necessary to operate the service

AI Features

DocuRead's "Ask AI" feature lets you ask questions about your documents and get instant answers — without reading through pages of content yourself.

Privacy advantage: Unlike services that automatically scan all your documents for "smart features," DocuRead's AI only sees a document when you explicitly click "Ask AI" for that specific document. You control when AI accesses your content — it's never automatic.

When you use Ask AI:

  • The text content of that specific document is sent to Anthropic's Claude API
  • This happens only when you click — not in the background
  • Anthropic does not train models on API inputs
  • Your document text is not stored by Anthropic after processing
  • You can use DocuRead's search forever without ever using AI features

This is fundamentally different from competitors who scan everything automatically to build profiles or "improve their AI."

OCR Processing

Text extraction (OCR) is performed using Tesseract, which runs locally on your device during import via our desktop migration app. For documents uploaded directly through the web app, OCR processing occurs on our servers — the extracted text is stored, but processing does not involve any third-party AI services.

Data Retention

  • Your documents: Stored until you delete them
  • Deleted documents: Permanently removed from storage within 30 days
  • Account deletion: All data permanently deleted within 30 days of request

Your Rights

You have the right to:

  • Access your data — download any document you've uploaded
  • Delete your data — remove individual documents or your entire account
  • Export your data — download all documents and extracted text
  • Correct your data — update account information anytime

To exercise these rights, use the in-app features or contact us at privacy@docuread.app.

Third-Party Services

DocuRead uses the following third-party services:

Service Purpose Policy
Supabase Database and file storage View →
Stripe Payment processing View →
Anthropic AI features only View →
Vercel Web hosting View →
Google OAuth authentication only View →

Security

We implement industry-standard security measures:

  • AES-256 encryption for stored files
  • TLS 1.2+ for all data in transit
  • Secure authentication via OAuth 2.0
  • Row-level security ensuring users can only access their own documents
  • Regular security audits of our infrastructure

Children's Privacy

DocuRead is not intended for use by children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.

Contact Us

If you have questions about this Privacy Policy or our data practices:

Email: privacy@docuread.app
Company: Cambridge Holdings, LLC
Address: United States