← Legal center

DocVex — Legal

Privacy Policy

DocVex is built privacy-first: your project documents stay on your device, and we collect only what we need to run your account and the collaborative parts of the Service.

Last updated: 18 July 2026

1. Who we are & what this policy covers

Scope of this policy.

This Privacy Policy explains how DocVex ("DocVex", "we") processes personal data when you use the DocVex desktop application, the web application at docvex.ro/app, and the docvex.ro website (together, the "Service"). For your own account data, DocVex acts as the data controller; where we process personal data contained in your team's content on behalf of your organization, we act as a processor under our Data Processing Agreement.

You can reach us about anything in this policy at docvexteam@docvex.ro.

2. Information we collect

Only what the Service needs to function.

Account information

Name, email address, password hash (never the password itself) or Google sign-in identifiers, avatar, and preferences such as your theme and status.

Collaboration data

Data that must be shared with your team to work: project names and descriptions, project membership and roles, invitations (invitee email addresses), team and private chat messages (including reactions, threads, and pins), and in-app notifications.

Legal newsfeed preferences

Your per-article read, pinned, and saved flags for the legal-updates feed.

Connected mailboxes (optional)

If you connect Gmail or Outlook to the Mail feature, we store the OAuth tokens required to sync your mailbox, encrypted at rest. We access your mailbox only to provide the Mail feature you invoked, and never for advertising. Use of data received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

AI usage records

When you use project AI features we record usage metadata — the action, model, and token counts — for quota and usage displays. See Section 5 for what happens to the content itself.

Support & enrollment

Messages you send us, problem reports (which include a screenshot only if you choose to attach one), and waitlist/demo submissions from the website (name, email, firm, message).

Technical data

App version and platform where needed for updates and troubleshooting. We do not run advertising trackers or sell behavioural profiles — see the Cookie Policy.

3. How we use information

Purposes and legal bases.

  • Providing the Service — operating accounts, projects, chat, notifications, mail sync, and AI features you invoke (performance of a contract, Art. 6(1)(b) GDPR).
  • Security — authentication, access control, abuse prevention (contract and legitimate interests, Art. 6(1)(b) and (f)).
  • Communications — transactional emails such as invitations, welcome messages, and support replies (contract); the Legal Newsfeed email briefing only if you opt in (consent, Art. 6(1)(a)).
  • Improving reliability — diagnosing problems from reports you send us (legitimate interests, Art. 6(1)(f)).
  • Legal obligations — where we must retain or disclose information by law (Art. 6(1)(c)).

We do not sell personal data and we do not use your content for advertising.

4. Your project files stay local

The core architectural promise.

Project documents live in a folder on your own device that you choose. DocVex has no cloud file store: your documents are not uploaded to our servers as part of normal operation, and we cannot access them. File metadata used to keep the folder organized (a small sidecar file with filenames and content hashes) also stays inside that folder on your device.

The exceptions are actions you explicitly invoke that require processing — for example asking an AI feature to summarize a document, which transmits the necessary content transiently as described in Section 5.

5. AI features & your content

What is sent, when, and to whom.

AI features — document Q&A, summaries, risk review, drafting, OCR text extraction, audio transcription, document generation, and the legal-feed briefing — are powered by third-party AI providers: Anthropic (Claude models) and, for audio transcription, OpenAI (Whisper).

  • Content is transmitted to an AI provider only when you invoke an AI feature on it — never in the background.
  • We send the minimum needed: the selected document content, image region, audio track, or prompt.
  • We use these providers through their business APIs, which do not use API content to train their models.
  • What we keep afterwards: the results shown to you (some are cached on your device for convenience) and usage metadata (action, model, token counts) — not a server-side copy of your documents.

6. Sharing & sub-processors

Who touches the data, and why.

We share personal data only with the service providers needed to run DocVex, with your team as you direct (project members see the projects and messages you share), or when required by law. Our providers:

ProviderPurposeLocation
SupabaseDatabase, authentication, realtime sync, serverless functions (hosted on AWS)EU (Ireland, eu-west-1)
AnthropicAI document features and legal-feed briefing (Claude)United States
OpenAIAudio transcription (Whisper), only when you use captions/transcriptionUnited States
ResendTransactional email deliveryUnited States / EU
GitHubHosting the website, application downloads, and the update feedUnited States
Google / MicrosoftSign-in with Google; Gmail/Outlook sync — only if you connect themUnited States / EU

The authoritative, maintained list — including how to object to changes — is in the Data Processing Agreement.

7. International transfers

Safeguards for data leaving the EEA.

Our primary infrastructure is in the European Union (Ireland). Where a provider processes data outside the EEA — such as AI processing in the United States — we rely on the European Commission's adequacy decision for the EU–US Data Privacy Framework where the provider is certified, and otherwise on Standard Contractual Clauses with supplementary measures.

8. Data retention

How long data is kept.

  • Account and collaboration data — kept while your account is active. Deleting your account removes your personal account data; messages you posted in shared projects may be retained for the team in anonymized or attributed form according to your organization's instructions.
  • Connected-mailbox tokens — deleted when you disconnect the mailbox or delete your account.
  • Support reports — kept as long as needed to resolve the issue and for a reasonable period after.
  • Enrollment submissions — kept until the request is handled and for a reasonable follow-up period.
  • Project files — on your device, under your control; we hold no copy to retain or delete.

You can erase locally cached app data and delete your account directly from your account settings.

9. Your rights

Access, correction, erasure, and more.

You have the rights the GDPR grants you: access, rectification, erasure, restriction, objection, portability, and the right to withdraw consent where processing is based on consent. The GDPR Compliance page describes each right and how to exercise it; the fastest paths are the in-app account settings (erase data, delete account) and docvexteam@docvex.ro.

10. Security

How data is protected.

We protect personal data with encryption in transit, encryption at rest, row-level security so members access only the projects they belong to, encrypted storage of mailbox tokens, and signed application releases. The full picture — including how to report a vulnerability — is in the Security Policy.

11. Children

DocVex is a professional tool.

The Service is not directed at children and may not be used by anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.

12. Changes & contact

Staying informed.

We will update this policy as the Service evolves and will announce material changes in the app or by email before they take effect. The "Last updated" date above reflects the current version.

Questions, requests, or complaints: docvexteam@docvex.ro. You also have the right to lodge a complaint with your supervisory authority — in Romania, the ANSPDCP (dataprotection.ro).

The operating legal entity's registered details will be added to this page upon incorporation. This document has not yet been reviewed by counsel and does not constitute legal advice.