DocuStore.io

/ Legal

Privacy Policy

Last updated 28 August 2026

This policy covers DocuStore Cloud, the free research preview we host so that researchers can try DocuStore without running their own infrastructure.

It does not cover self-hosted deployments. If you run DocuStore yourself, you are the data controller for whatever your instance holds, and this policy does not apply to you.

01Who is responsible

DocuStore Cloud is operated by the DocuStore team. For any question about this policy, or to exercise any of the rights described in section 8, write to contact@docustore.io.

02What we collect

  • Account details. Your name, email address, and authentication credentials, handled by our identity service.
  • Documents you upload and everything derived from them, including extracted text, page images, chemical structures and their labels, recognised entities, summaries, and vector embeddings.
  • Chat history. Your questions, the answers generated for you, and the citations attached to them.
  • LLM provider credentials. If you connect your own API key, we store it encrypted at rest. Only the last four characters are ever shown back to you, and the plaintext key is never returned to your browser.
  • Usage analytics. Page views, feature usage, time spent in each section, and browser performance metrics, recorded by a self-hosted Umami instance and associated with your user and workspace identifiers.
  • Operational logs. Request metadata, errors, and timing information used to keep the service running.

03Cookies and browser storage

DocuStore Cloud uses no advertising cookies, no third-party trackers, and no cross-site analytics. Our analytics is self-hosted and sets no cookies.

Browser storage is used for the following purposes only:

  • authentication tokens required to keep you signed in
  • short-lived verifiers used during the OAuth flow when you connect an AI provider
  • interface preferences, such as theme, font, font size, remembered workspace, and dismissed notices

04Where your content goes

On DocuStore Cloud you connect your own language model provider, such as OpenRouter or OpenAI. When you chat with a document or run enrichment, excerpts of that document and your questions are sent to the provider you connected. Once your content reaches that provider, their terms and their retention practices govern it, not ours.

Because the key is yours, your relationship with that provider is direct, and you should read their privacy terms before connecting it. Where OpenRouter is used, it forwards your content to whichever model provider you selected.

Embeddings are computed on our own servers. Document content is not sent to any third party in order to be indexed or searched.

We also run a self-hosted Langfuse instance, which records prompts and completions so we can debug the pipeline and manage prompts. This stays on our infrastructure.

We do not sell your data, share it with advertisers, or send it to third-party analytics services.

05Please do not upload sensitive material

DocuStore Cloud is a free research preview, not a secure enclave. Do not upload patient data, personal information about other people, export-controlled material, material you are contractually forbidden to share, or anything whose disclosure would harm you or someone else.

Content you upload is transmitted to third-party language model providers as described above. If your work requires guarantees we cannot make here, self-host DocuStore instead. The software is free and open source, and you can point it at a local model so that nothing leaves your network.

06How long we keep it

Deleting a document or a conversation removes it from the application immediately. You should know, though, that DocuStore is built on an append-only event log: the underlying records may persist in that log and in backups after the item disappears from your view.

If you need your data genuinely erased rather than merely removed from the interface, email us and we will do it by hand. We do not yet have a self-service account deletion button.

Because this is a preview, we may delete preview data at any time, including when the preview ends. Do not treat DocuStore Cloud as a system of record or as your only copy of anything.

07Why we are allowed to process it

For anyone covered by the GDPR or UK GDPR, our lawful bases are: performance of a contract, for everything needed to actually provide the service you asked for; legitimate interests, for security, abuse prevention, and understanding which features people use; and consent where the law requires it, which you may withdraw at any time.

08Your rights

You may ask us to give you a copy of your data, correct it, delete it, export it, or stop a particular use of it. Write to contact@docustore.io and we will respond within 30 days.

If you are in the EU or UK and you think we have handled your data badly, you may also complain to your national data protection authority.

09Security

Traffic is encrypted in transit. LLM provider API keys are encrypted at rest. Documents and conversations are scoped to your workspace, and access is checked on every request.

DocuStore Cloud is a research preview and does not offer the assurances of a commercial platform. Please take this into account when deciding what to upload.

10Where the data lives

Our servers are in the United States. If you are outside the US, using DocuStore Cloud means your data is processed there. Language model providers you connect may process your content in other countries again, according to their own terms.

11Children

DocuStore Cloud is intended for researchers and is not directed at anyone under 16. We do not knowingly collect data from children.

12Changes to this policy

We will update the date at the top when this policy changes and will notify you of any material change. Continuing to use the service after a change means you accept the updated policy.

See also our Terms of Use.