Privacy Policy
Last updated: July 2026
1. Who we are
DocAlcove ("we", "us", "our") provides a service that turns your documents into AI-powered chatbots for your website. If you have questions about this policy, contact us at hello@docalcoveai.com.
2. What data we collect
- Account information: When you sign in with Google, we receive your email address and name (via Supabase OAuth).
- Uploaded documents: Files you upload (PDF, DOCX, TXT) are stored in Supabase Storage and processed into embeddings via Cloudflare Workers AI.
- Chat messages: Visitor messages and bot responses are stored per-visitor UUID. No personally identifiable information is collected from visitors.
- Usage data: Aggregate page views and session data via Umami analytics (cookieless, no personal data).
3. How we use your data
We use your data solely to power the DocAlcove service:
We do not sell your data. We do not serve ads.
4. Sub-processors
We use the following third-party services to operate DocAlcove:
- Supabase – database, authentication, file storage (US-hosted on AWS)
- Cloudflare – AI embeddings and chat inference
- Paddle – payment processing (not active during beta)
- Umami – cookieless analytics (Umami Cloud during beta)
5. Data retention
- Account data: retained until you delete your account
- Uploaded documents: deleted when the document or bot is removed, or upon account deletion
- Chat logs: retained for 90 days for abuse review, then permanently deleted
- Analytics: aggregate only, retained indefinitely
6. Your rights
You have the right to access, rectify, or delete your personal data at any time. You can delete your account from the dashboard settings. For any other request, email us at hello@docalcoveai.com.
7. Lawful basis
We process your data under Article 6.1(b) GDPR (contract performance – to provide the service) and Article 6.1(f) (legitimate interest – analytics to improve the service).
8. Changes
We may update this policy from time to time. Material changes will be communicated via email.