This Privacy Policy explains how DocAI: PDF Summarizer & Chat ("we", "us", or "our") collects, uses, and protects your information when you use our mobile application (the "App"). By using the App, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
1.1 Personal Information
When you create an account, we collect:
- Full name
- Email address
- Password (stored using industry-standard bcrypt hashing — we never store your plain-text password)
1.2 Document and File Data
To provide our core AI services, we process files you actively upload:
- PDFs, DOCX, and TXT files
- Files are temporarily processed to generate summaries, key points, and to power the AI chat interface
- Documents are stored on encrypted cloud infrastructure linked strictly to your account
1.3 Usage and Diagnostic Data
We automatically collect the following to improve the App:
- Device type and operating system version
- App crash reports and error logs
- Feature interaction data (e.g., which features are used, login frequency, selected language)
2. How We Use Your Information
- To deliver the Service: Analyse your documents, run the AI Q&A feature, and return accurate summaries and key points.
- To improve the App: Aggregate usage trends help us identify bugs, prioritise features, and optimise performance.
- Customer support: To send password reset emails and respond to your support inquiries.
- Security: To detect and prevent fraudulent activity or abuse of the Service.
3. Data Processing & AI
- By uploading documents, you consent to their text content being sent to our third-party AI provider (Groq / LLaMA) solely to generate responses for you.
- We do not use your personal documents to train proprietary AI models.
- Our AI provider contractually states they do not use API-submitted data for training their models.
- Document text is converted into mathematical embeddings (vector representations) stored exclusively in your account's private database partition.
4. Permissions We Request
The App requests only the permissions strictly necessary for its stated functionality:
5. Security
We take data security seriously and employ multiple layers of protection:
- All data in transit is encrypted using TLS 1.2+
- Passwords are hashed with bcrypt — never stored in plain text
- Row-Level Security (RLS) ensures users can only access their own data
- API keys are stored in server-side environment variables, never in the app binary
- Infrastructure is hosted on Supabase (AWS us-east-1) with SOC 2 Type II compliance
6. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Ask us to correct inaccurate or incomplete data.
- Erasure: Request deletion of your account and all associated documents and chat history.
- Portability: Receive your data in a structured, machine-readable format.
- Opt-out: Unsubscribe from any marketing communications at any time.
To request account deletion, go to Settings → Sign Out and then email us at the address below. We will process valid requests within 30 days.
7. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Updating the "Effective Date" at the top of this document
- Sending an in-app notification on next launch
- Emailing registered users for significant changes
Continued use of the App after changes are posted constitutes your acceptance of the revised policy.
8. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please reach out:
Email us at: info@appxwind.com
Website: www.appxwind.com