Privacy
What happens to your data — and what does not.
This page describes the running system, not an intention. Where something cannot be guaranteed, that is stated here too.
In short
- Without an account your text never leaves the browser — the transform runs locally.
- Unpublished documents are not stored.
- Your content is not used to train AI models.
- No tracking cookies, no reselling, no advertising.
- Deleting your account is a button, not an email request.
Without an account
In the Studio without signing in, your text is structured and typeset inside the browser. No request carries it to our server, your draft is saved only in this browser tab’s session storage so it survives reloading and signing in. This does not store it on our servers. The same is true of the before/after view on the home page.
With an account: what is stored
- Email address and nameSign-in, the confirmation email, and matching a purchase to an account.
- Password as an scrypt hashThe password itself is never stored and cannot be read back. Signing in with Google means there is none at all.
- Published documentsContent, layout, and the style used — only when you press Publish. Delete the document and the share link dies with it.
- Profile & styleIn the account with full access, otherwise only locally in the browser. Uploaded logos and fonts live in file storage and are publicly reachable by their URL — they appear in the document.
- Stripe identifiersCustomer and payment ids, to attach a purchase to your account. We never see card details.
- IP address as a counterOnly for sign-in and sign-up limits, expiring automatically. No access logs containing content.
What is not stored
Text you paste and do not publish is never written to our database — not even during a PDF export: the PDF is produced in memory and handed straight to you. Server logs contain error messages, never document content.
Structuring by Claude
When you are signed in, the pasted text goes to Anthropic once per transform so Claude can recognise headings, sections, lists, and emphasis. What comes back is a structure — your sentences stay yours, word for word.
Under Anthropic's commercial terms, content sent through the API is not used to train their models, and requests are retained for a limited period for abuse detection. docflow itself stores none of this text.
Without an account this never happens: there, the built-in parser structures the text inside the browser.
Share links — the honest limit
A share link is public. The address is random and unguessable, and the page is excluded from search engines — but anyone holding the link sees the document. That is not password protection. For confidential material use the PDF, or delete the document once it has been read.
Who else is involved
The service does not run without these providers. They process data on our behalf, not for their own purposes. Some are based in the US; transfers rely on the standard contractual clauses or certifications of the provider in question.
- VercelHosting, file storage for logos and fonts, page-view measurement.
- Database (Vercel Postgres / Neon)Accounts and published documents.
- UpstashCounters for rate limits, short-lived.
- AnthropicStructuring of pasted text, only with an account.
- StripePayment and invoices.
- ResendConfirmation and welcome emails.
- PlausibleCookieless page-view statistics.
- GoogleOnly if you sign in with Google.
Your rights
Access, rectification, erasure, restriction, portability, and objection under the GDPR. Two of them need no request, they are built in: delete individual documents in your library, or the entire account including documents, logos, and fonts on the account page — immediately and without asking anyone. Profile and style export as JSON there, your documents as Markdown.
Invoice records stay with Stripe for as long as commercial and tax retention periods require — even after an account is deleted. That is a legal duty, not a choice.
You also have the right to lodge a complaint with a data protection supervisory authority.
What does not happen
No sharing or selling of data to third parties for their own purposes. No advertising networks, no profiling, no training on your content. Access to stored documents only where operating the service or fixing a fault makes it unavoidable.
What we do not claim: docflow is a small product with no ISO 27001 or SOC 2 certification, and documents sit unencrypted in the database — protected by access control, not by end-to-end encryption. Everything is transmitted over HTTPS only. If you need a certification or a data processing agreement, talk to us first.