Skip to content

Legal

Privacy policy

We collect the minimum needed to run the product, we do not sell anything, and no model provider we use is permitted to train on your code.

Last updated June 1, 2026

1. Who we are

Docsmith Software, Inc. is a Delaware C-Corporation with its registered office at 412 Bryant Street, Floor 3, San Francisco, CA 94107, United States. For the purposes of the UK and EU General Data Protection Regulation we are the data controller for the personal data described below, and a data processor for the customer content you send us.

2. What we collect

Three categories, and nothing else.

CategoryExamplesSource
Account dataName, email address, hashed password, company name, planYou, at sign-up
Customer contentRepository diffs, documentation pages, drafts, review decisionsYour connected repositories, or the API
Operational dataSync timestamps, model routed to, duration, error codes, IP address of API callsGenerated as the product runs

We do not use advertising trackers, we do not run third-party analytics that follow you between sites, and we do not buy data about you from anyone. The cookie policy lists every cookie the site sets, and there are three.

3. Your source code

This is the part that matters most to the person reviewing this document, so it is separate.

  • Docsmith reads the diff of a change and the text of the documentation pages that change could affect. It does not clone your repository to disk and does not read files the change did not touch.
  • That content is sent to whichever model provider handled the step. Our agreements with every provider we route to exclude training on API traffic, and set zero-day retention where the provider supports it.
  • Which provider handled which step is recorded on the sync, so you can audit after the fact exactly where a piece of code went.
  • Business customers may route model calls to a self-hosted open model through a gateway URL, in which case no code leaves your network boundary at all.

4. Why we process it

Account data is processed to perform our contract with you. Customer content is processed on your instructions, to provide the service. Operational data is processed under our legitimate interest in keeping the service working, billing accurately and preventing abuse. Marketing email is sent only with consent, and every message has a one-click unsubscribe that works.

5. How long we keep it

DataRetention
Account dataFor the life of the account, then 30 days
Diffs and page contentA sync-scoped cache expiring within 24 hours. Configurable to zero on Business
Drafts and review historyAs long as your plan retains history — 30 days on Free, one year on Team, unlimited on Business
Audit logLife of the account (Business)
Invoices and tax recordsSeven years, because we are required to

Deleting your account from Settings removes account data and all customer content within 30 days, including from backups as they roll off. We will confirm in writing when it is done.

6. Sub-processors

These are the third parties that may process customer content or personal data on our behalf. Business customers receive 30 days’ notice before this list changes.

Sub-processorPurposeLocation
Amazon Web ServicesApplication hosting, database, object storageUnited States (us-east-1), EU on request
OpenAIModel inference for routed stepsUnited States
AnthropicModel inference for routed stepsUnited States
StripePayment processing (we never see card numbers)United States
PostmarkTransactional emailUnited States

7. International transfers

Data is processed in the United States by default. Where personal data of people in the UK or EEA is transferred, we rely on the European Commission’s standard contractual clauses together with the UK international data transfer addendum, and we have carried out a transfer risk assessment which is available on request. EU customers on Business can pin processing to eu-central-1.

8. Your rights

If you are in the UK or EEA you have the right to access, correct, delete, restrict, port and object to processing of your personal data. If you are in California you have the rights described in the CCPA, including the right to know and delete, and the right not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined in the CCPA.

Exercise any of these by writing to privacy@docsmithhq.com. We respond within 30 days and do not charge a fee. If you are unhappy with the response you may complain to your supervisory authority; in the UK that is the Information Commissioner’s Office.

9. Security

TLS 1.3 in transit, AES-256 at rest, role-based access internally with production access limited to the engineers who need it and logged when used. The full control list is on the security page. If you believe you have found a vulnerability, write to security@docsmithhq.com — acknowledged within one business day.

10. Children

Docsmith is a business tool and is not directed at anyone under 16. We do not knowingly collect personal data from children. If you believe a child has created an account, tell us and we will delete it.

11. Changes to this policy

When we make a material change we email every account holder at least 14 days before it takes effect, and the date at the top of this page changes. Minor corrections — a typo, a clearer sentence — are made without notice.

12. Contact

Privacy questions go to privacy@docsmithhq.com, or by post to Docsmith Software, Inc., 412 Bryant Street, Floor 3, San Francisco, CA 94107, United States. We have not appointed a data protection officer because we are not required to; privacy enquiries are handled by the CEO.