Legal
Privacy policy
We collect the minimum needed to run the product, we do not sell anything, and no model provider we use is permitted to train on your code.
Last updated June 1, 2026
1. Who we are
Docsmith Software, Inc. is a Delaware C-Corporation with its registered office at 412 Bryant Street, Floor 3, San Francisco, CA 94107, United States. For the purposes of the UK and EU General Data Protection Regulation we are the data controller for the personal data described below, and a data processor for the customer content you send us.
2. What we collect
Three categories, and nothing else.
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, hashed password, company name, plan | You, at sign-up |
| Customer content | Repository diffs, documentation pages, drafts, review decisions | Your connected repositories, or the API |
| Operational data | Sync timestamps, model routed to, duration, error codes, IP address of API calls | Generated as the product runs |
We do not use advertising trackers, we do not run third-party analytics that follow you between sites, and we do not buy data about you from anyone. The cookie policy lists every cookie the site sets, and there are three.
3. Your source code
This is the part that matters most to the person reviewing this document, so it is separate.
- Docsmith reads the diff of a change and the text of the documentation pages that change could affect. It does not clone your repository to disk and does not read files the change did not touch.
- That content is sent to whichever model provider handled the step. Our agreements with every provider we route to exclude training on API traffic, and set zero-day retention where the provider supports it.
- Which provider handled which step is recorded on the sync, so you can audit after the fact exactly where a piece of code went.
- Business customers may route model calls to a self-hosted open model through a gateway URL, in which case no code leaves your network boundary at all.
4. Why we process it
Account data is processed to perform our contract with you. Customer content is processed on your instructions, to provide the service. Operational data is processed under our legitimate interest in keeping the service working, billing accurately and preventing abuse. Marketing email is sent only with consent, and every message has a one-click unsubscribe that works.
5. How long we keep it
| Data | Retention |
|---|---|
| Account data | For the life of the account, then 30 days |
| Diffs and page content | A sync-scoped cache expiring within 24 hours. Configurable to zero on Business |
| Drafts and review history | As long as your plan retains history — 30 days on Free, one year on Team, unlimited on Business |
| Audit log | Life of the account (Business) |
| Invoices and tax records | Seven years, because we are required to |
Deleting your account from Settings removes account data and all customer content within 30 days, including from backups as they roll off. We will confirm in writing when it is done.
6. Sub-processors
These are the third parties that may process customer content or personal data on our behalf. Business customers receive 30 days’ notice before this list changes.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Application hosting, database, object storage | United States (us-east-1), EU on request |
| OpenAI | Model inference for routed steps | United States |
| Anthropic | Model inference for routed steps | United States |
| Stripe | Payment processing (we never see card numbers) | United States |
| Postmark | Transactional email | United States |
7. International transfers
Data is processed in the United States by default. Where personal data of people in the UK or EEA is transferred, we rely on the European Commission’s standard contractual clauses together with the UK international data transfer addendum, and we have carried out a transfer risk assessment which is available on request. EU customers on Business can pin processing to eu-central-1.
8. Your rights
If you are in the UK or EEA you have the right to access, correct, delete, restrict, port and object to processing of your personal data. If you are in California you have the rights described in the CCPA, including the right to know and delete, and the right not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined in the CCPA.
Exercise any of these by writing to privacy@docsmithhq.com. We respond within 30 days and do not charge a fee. If you are unhappy with the response you may complain to your supervisory authority; in the UK that is the Information Commissioner’s Office.
9. Security
TLS 1.3 in transit, AES-256 at rest, role-based access internally with production access limited to the engineers who need it and logged when used. The full control list is on the security page. If you believe you have found a vulnerability, write to security@docsmithhq.com — acknowledged within one business day.
10. Children
Docsmith is a business tool and is not directed at anyone under 16. We do not knowingly collect personal data from children. If you believe a child has created an account, tell us and we will delete it.
11. Changes to this policy
When we make a material change we email every account holder at least 14 days before it takes effect, and the date at the top of this page changes. Minor corrections — a typo, a clearer sentence — are made without notice.
12. Contact
Privacy questions go to privacy@docsmithhq.com, or by post to Docsmith Software, Inc., 412 Bryant Street, Floor 3, San Francisco, CA 94107, United States. We have not appointed a data protection officer because we are not required to; privacy enquiries are handled by the CEO.