Privacy Policy
Last updated: July 30, 2026
This Privacy Policy explains what information DocZea ("DocZea," "we," "us") collects when you use our document intelligence service (the "Service"), how we use it, and the choices you have. It applies to doczea.com and the DocZea web application.
DocZea is an independently run service, not yet formally incorporated, based in the Philippines.
1. Information We Collect
Account information. Your email address and password (stored as a salted hash, never in plain text) when you sign up.
Document content. The receipts, invoices, and other documents you upload, and the structured data our AI extracts from them — merchant name, dates, amounts, tax figures, line items, and a plain-language summary. This is very likely to include personal and financial information, since that is the nature of a receipt or invoice.
Usage and billing data.How many documents you upload each month (to enforce your plan's quota), which plan you are on, and — if you subscribe — billing status and payment history from our payment processor (we do not ourselves store your card details; see §3).
Team and workspace data. If you invite teammates, their email address, the role you assign them, and a record of approval/rejection decisions on shared documents.
2. How We Use Information
- To provide the Service — storing your documents, running AI extraction, and making the results searchable.
- To enforce plan quotas and process subscription payments.
- To send transactional email — signup confirmation, team invites, and (if you enable them) webhook and billing notifications. We do not send marketing email beyond what you explicitly opt into.
- To detect and prevent abuse of the Service, including automated access via the developer API.
- To respond to support requests.
We do not sell your personal information, and we do not use your uploaded documents to train AI models.
3. Who We Share Information With
Operating DocZea means some of your data necessarily passes through a small number of specialist providers, each handling a specific part of the Service:
- Supabase — our database and authentication provider. Stores your account, documents' metadata, and extracted data.
- Cloudflare R2 — object storage for the original files you upload.
- OpenAI — receives the content of a document (as an image or PDF) once, at upload, to perform AI extraction.
- Anthropic — receives relevant document data when you use the AI chat feature, to answer your questions about your own documents.
- Creem — our payment processor. Handles your payment details directly; we never receive or store your full card number.
- Resend — sends transactional email (confirmations, invites) on our behalf.
- Vercel — hosts the application and its standard web server logs.
Each of these providers is contractually restricted to using your data only to provide their service to us, not for their own purposes. We do not share your data with any other third party except where required by law.
4. Data Retention
We retain your account and document data for as long as your account is active. If you delete a document, it is removed from active storage. If you delete your organization entirely, every workspace, document, category, tag, API key, and webhook belonging to it is permanently deleted, and any active subscription is canceled — see §6 below for how to do this yourself.
5. Data Security
Access to your data is enforced at the database level, not only in application code, using row-level security tied to your workspace membership — the same rules apply whether a request comes from our web app, our API, or (in future) a mobile client. Original document files are stored in a private object storage bucket and served only through short-lived signed links, never a public URL. API keys and invite tokens are stored as one-way hashes; a leak of our database alone would not expose usable credentials.
6. Your Rights and Choices
Access and correction. You can view and edit your account and document data at any time from within the Service.
Deletion. You can permanently delete your organization and all of its data yourself, at any time, from Settings → Danger Zone. This cancels any active subscription and removes your data — it is not a soft delete, and cannot be undone. If you would like your account (rather than just an organization) removed, or have any other request regarding your personal data, contact us at hello@doczea.com. Full step-by-step instructions, including what happens if you cannot sign in, are on our Delete Your Account page.
Depending on where you live, you may have additional rights under laws such as the GDPR (EEA/UK) or applicable data protection law in your country — including the right to request a copy of your data or to object to certain processing. Contact us and we will respond within a reasonable time.
7. International Data Transfers
Our service providers operate infrastructure in multiple countries. Where your data is transferred internationally, we rely on the safeguards those providers offer (such as Standard Contractual Clauses, where applicable) to protect it in transit and at rest.
8. Children's Privacy
DocZea is a business tool and is not directed at, or intended for use by, anyone under 18. We do not knowingly collect information from children.
9. Changes to This Policy
We may update this policy as the Service changes. If we make a material change, we will update the date at the top of this page and, where appropriate, notify you by email.
10. Contact Us
Questions about this policy or your data can be sent to hello@doczea.com.