Cookiedoc

Privacy Policy

Last updated: August 28, 2026

1. What we process

This includes your registered email, display name, your explicitly selected preferred site, login and security records, point ledger, recharge orders, conversation content and the files you upload. We record the necessary model usage and billing snapshots for metering, reconciliation, support and security auditing.

2. How files and conversations are processed

To complete the analysis, files and conversations are sent to the configured model relay service, which in turn accesses the upstream model. Do not upload materials you are not entitled to process. In production, the operator is responsible for configuring separate relays, databases and credentials.

3. Optional analytics

We use self-hosted Umami for anonymous traffic trends and load Google Analytics 4 only after you explicitly allow analytics. We send sanitized events for public pages, registration, uploads, completed answers and checkout starts. We do not send filenames, file contents, prompts, answers, voice content, email addresses, or internal document and conversation IDs to these analytics tools. Rejecting analytics does not limit product functionality, and you can change your choice through Analytics settings on this privacy page.

4. Third-party services

Login may use Google; consented traffic analytics uses Google Analytics 4; payments use Stripe; transactional email uses Resend; model analysis uses the operator-configured relay routes; production backups use the configured S3-compatible service. Different environments should use separate databases, credentials and third-party test/production configurations.

5. Retention and deletion

Account, order and ledger information is retained for as long as needed for reconciliation, anti-fraud and legal obligations. Conversations and uploaded files are retained per product settings; you can delete conversations from the workspace. Production backups are retained for at least 30 days per operational policy, and copies inside backups may be deleted after the backup cycle ends. To request deletion or export of your data, contact the support email in the footer.

6. Deletion, source lock and physical erasure

Once you delete a file, it becomes inaccessible immediately. To prevent accidental deletion, a newly uploaded original is not deleted during the protected period (7-day source lock, per operational configuration); the protected period only defines when deletion becomes possible, not that the file disappears on its own. The original remains in protected secure storage for recovery and compliance purposes; it is not accessible to you or others, does not disappear over time, and is not physically erased automatically. Physical erasure is performed only after an explicit operations or legal process approves it. Local caches, temporary copies and backup object mappings are invalidated along the deletion path; source documents and derived chunks share the same deletion semantics.Account deletion: after deletion the account can no longer sign in; conversations and files follow the deletion semantics above; unused points are handled per the points and refund rules; order and ledger records are retained as required for reconciliation and legal obligations.Cancelling subscriptions: no further renewal charges occur after cancellation; purchased entitlements, where applicable, continue until the end of the current term as described on the product page.

7. Security

We use host-only cookies, access control, one-time cross-domain SSO, server-side API keys and rate limiting to protect the service. Internet transmission and third-party processing still carry objective risks — please redact sensitive information before uploading.

Privacy Policy · Cookiedoc