Last updated: 2026-08-24
Privacy Policy
Roles
For account and billing data, Docsfra acts as data controller. For the content of documents you upload, we act as data processor on your instructions — you remain the controller of that content.
Data we process
- Account data: name, work email, authentication records.
- Usage and billing data: API request metadata, credit consumption, ledger entries.
- Document content: processed solely to provide the service you request — parsing, representation, search and answers. We do not use your documents to train models.
- Marketing site analytics: docsfra.com uses Google Analytics (GA4) with cookies to measure traffic.
Where processing happens
Document parsing runs on Docsfra's own GPU infrastructure by default; page images are not sent to third-party AI providers. When you enable AI modules, only extracted text reaches the model lane you configured — including your own key or endpoint if you use BYOK.
Subprocessors
- Infrastructure/hosting provider (compute and storage).
- Backblaze B2 (encrypted offsite backups).
- Google Analytics (marketing site only, not the API or console data plane).
- OpenRouter or your configured model provider — only when you enable model-backed modules, and only extracted text.
Retention and deletion
Raw uploaded media is subject to scheduled retention sweeps with recorded deletion timestamps. Derived artifacts persist while your tenant is active. You can request deletion of your data; enterprise agreements can define custom retention windows.
Your rights
Under KVKK (Türkiye) and, where applicable, GDPR, you may request access, correction, deletion, restriction and portability of your personal data, and object to processing. Write to privacy@docsfra.com; we respond within the statutory period.
Contact
Privacy questions and requests: privacy@docsfra.com.
This policy is an informational template pending counsel review; the signed data-processing agreement prevails for enterprise customers.
