Privacy Policy

Last updated: March 23, 2026

DocuChat ("we," "our," or "us") operates the DocuChat platform at docuchat-drab.vercel.app. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

1. Information We Collect

Account Information

When you create an account, we collect your email address and password. Your password is securely hashed and never stored in plain text.

Website Data

When you create a chatbot, you provide website URLs for us to crawl. We store the crawled content (text extracted from your web pages) to train your AI chatbot. This content is used solely for generating chatbot responses.

Chat Conversations

We store chat conversations between your website visitors and your chatbot. This includes the messages sent by visitors and the AI-generated responses. This data is used to provide the chat service and power your analytics dashboard.

Usage Data

We automatically collect certain information when you use our service, including message counts, chatbot usage statistics, and general interaction patterns to improve our service.

2. How We Use Your Information

  • To provide, maintain, and improve the DocuChat service
  • To train and operate your AI chatbots using your website content
  • To process your transactions and manage your subscription
  • To send you service-related communications (account verification, billing, support)
  • To provide analytics about your chatbot performance
  • To detect and prevent fraud or abuse of our service

3. Third-Party Services

We use the following third-party services to operate DocuChat:

  • Supabase — Database hosting, authentication, and file storage. Your account data, chatbot configurations, and chat conversations are stored on Supabase infrastructure. See their privacy policy.
  • OpenAI — We send your crawled website content and chat messages to OpenAI's API to generate chatbot responses. OpenAI processes this data according to their privacy policy. As of our API agreement, OpenAI does not use data submitted via the API to train their models.
  • LemonSqueezy — Payment processing for subscriptions. We do not store your credit card information directly; it is handled by LemonSqueezy. See their privacy policy.
  • Vercel — Application hosting. See their privacy policy.

4. Cookies

We use essential cookies and local storage to maintain your authentication session and remember your preferences. We do not use tracking cookies or third-party advertising cookies.

5. Data Retention

We retain your account data and chatbot content for as long as your account is active. Chat conversation logs are retained for the duration of your subscription. When you delete a chatbot, its associated training data and conversations are permanently removed within 30 days. When you delete your account, all associated data is permanently deleted within 30 days.

6. Your Rights (GDPR)

If you are located in the European Economic Area (EEA), you have certain data protection rights under the General Data Protection Regulation (GDPR):

  • Right to Access — You can request a copy of your personal data.
  • Right to Rectification — You can request correction of inaccurate data.
  • Right to Erasure — You can request deletion of your personal data.
  • Right to Restrict Processing — You can request limitation of processing.
  • Right to Data Portability — You can request your data in a portable format.
  • Right to Object — You can object to processing of your personal data.

To exercise any of these rights, please contact us at docat0209@gmail.com. We will respond to your request within 30 days.

7. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including encryption in transit (TLS/SSL), secure password hashing, and access controls. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

8. Children's Privacy

DocuChat is not intended for use by children under the age of 16. We do not knowingly collect personal information from children under 16. If we learn that we have collected data from a child under 16, we will delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the service after changes constitutes acceptance of the updated policy.

10. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

Email: docat0209@gmail.com