Privacy Policy

Last updated: February 18, 2026

The short version: We don't store your documents, we don't store patient data, and we don't train AI on your content. DocDraft is a stateless tool — what you generate stays with you.

1. Information We Collect

Account information: Email address, name (if provided via Google sign-in), and authentication credentials. This is required to provide the Service.

Subscription information: Payment processing is handled entirely by Stripe. We do not store credit card numbers or billing details on our servers.

Usage metrics: We track document generation counts per account for plan limit enforcement. We do not store the content of generated documents.

2. Information We Do NOT Collect

3. How We Use Information

4. AI Processing

Clinical input is sent to third-party AI providers (Anthropic/Claude) for document generation. This input is de-identified — patient names, DOBs, and identifiers are added client-side after generation, never sent to AI. AI providers do not train on API inputs per their data policies.

5. Data Security

All data is encrypted in transit (TLS/SSL). Account data is stored in Google Cloud Firestore, which provides encryption at rest. We follow security best practices appropriate for the data we handle.

6. Data Retention

Account information is retained while your account is active. Generated documents are never retained. You may request account deletion at any time by contacting us.

7. Third-Party Services

8. Your Rights

You may request access to, correction of, or deletion of your account data at any time. Contact us at support@docdraft.org.

9. Changes

We may update this policy. Material changes will be communicated via email or in-app notice.

10. Contact

Questions about privacy? Email support@docdraft.org.