DocVex — Legal
DocVex is built privacy-first: your project documents stay on your device, and we collect only what we need to run your account and the collaborative parts of the Service.
Last updated: 18 July 2026
Scope of this policy.
This Privacy Policy explains how DocVex ("DocVex", "we") processes personal data when you use the DocVex desktop application, the web application at docvex.ro/app, and the docvex.ro website (together, the "Service"). For your own account data, DocVex acts as the data controller; where we process personal data contained in your team's content on behalf of your organization, we act as a processor under our Data Processing Agreement.
You can reach us about anything in this policy at docvexteam@docvex.ro.
Only what the Service needs to function.
Name, email address, password hash (never the password itself) or Google sign-in identifiers, avatar, and preferences such as your theme and status.
Data that must be shared with your team to work: project names and descriptions, project membership and roles, invitations (invitee email addresses), team and private chat messages (including reactions, threads, and pins), and in-app notifications.
Your per-article read, pinned, and saved flags for the legal-updates feed.
If you connect Gmail or Outlook to the Mail feature, we store the OAuth tokens required to sync your mailbox, encrypted at rest. We access your mailbox only to provide the Mail feature you invoked, and never for advertising. Use of data received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
When you use project AI features we record usage metadata — the action, model, and token counts — for quota and usage displays. See Section 5 for what happens to the content itself.
Messages you send us, problem reports (which include a screenshot only if you choose to attach one), and waitlist/demo submissions from the website (name, email, firm, message).
App version and platform where needed for updates and troubleshooting. We do not run advertising trackers or sell behavioural profiles — see the Cookie Policy.
Purposes and legal bases.
We do not sell personal data and we do not use your content for advertising.
The core architectural promise.
Project documents live in a folder on your own device that you choose. DocVex has no cloud file store: your documents are not uploaded to our servers as part of normal operation, and we cannot access them. File metadata used to keep the folder organized (a small sidecar file with filenames and content hashes) also stays inside that folder on your device.
The exceptions are actions you explicitly invoke that require processing — for example asking an AI feature to summarize a document, which transmits the necessary content transiently as described in Section 5.
What is sent, when, and to whom.
AI features — document Q&A, summaries, risk review, drafting, OCR text extraction, audio transcription, document generation, and the legal-feed briefing — are powered by third-party AI providers: Anthropic (Claude models) and, for audio transcription, OpenAI (Whisper).
Who touches the data, and why.
We share personal data only with the service providers needed to run DocVex, with your team as you direct (project members see the projects and messages you share), or when required by law. Our providers:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, realtime sync, serverless functions (hosted on AWS) | EU (Ireland, eu-west-1) |
| Anthropic | AI document features and legal-feed briefing (Claude) | United States |
| OpenAI | Audio transcription (Whisper), only when you use captions/transcription | United States |
| Resend | Transactional email delivery | United States / EU |
| GitHub | Hosting the website, application downloads, and the update feed | United States |
| Google / Microsoft | Sign-in with Google; Gmail/Outlook sync — only if you connect them | United States / EU |
The authoritative, maintained list — including how to object to changes — is in the Data Processing Agreement.
Safeguards for data leaving the EEA.
Our primary infrastructure is in the European Union (Ireland). Where a provider processes data outside the EEA — such as AI processing in the United States — we rely on the European Commission's adequacy decision for the EU–US Data Privacy Framework where the provider is certified, and otherwise on Standard Contractual Clauses with supplementary measures.
How long data is kept.
You can erase locally cached app data and delete your account directly from your account settings.
Access, correction, erasure, and more.
You have the rights the GDPR grants you: access, rectification, erasure, restriction, objection, portability, and the right to withdraw consent where processing is based on consent. The GDPR Compliance page describes each right and how to exercise it; the fastest paths are the in-app account settings (erase data, delete account) and docvexteam@docvex.ro.
How data is protected.
We protect personal data with encryption in transit, encryption at rest, row-level security so members access only the projects they belong to, encrypted storage of mailbox tokens, and signed application releases. The full picture — including how to report a vulnerability — is in the Security Policy.
DocVex is a professional tool.
The Service is not directed at children and may not be used by anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.
Staying informed.
We will update this policy as the Service evolves and will announce material changes in the app or by email before they take effect. The "Last updated" date above reflects the current version.
Questions, requests, or complaints: docvexteam@docvex.ro. You also have the right to lodge a complaint with your supervisory authority — in Romania, the ANSPDCP (dataprotection.ro).
The operating legal entity's registered details will be added to this page upon incorporation. This document has not yet been reviewed by counsel and does not constitute legal advice.