← Back to DocFila
DocFila Privacy Policy
Last updated: September 27, 2026 • Effective Date: January 5, 2026
1. Introduction
DocFila, a NotaNovice UG Company ("DocFila", "we", "our", or "us"), a company registered in Germany (HRB 13806, Amtsgericht Hagen), is committed to protecting your privacy and ensuring you have a positive experience using our services.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application, web application, and related services (collectively, the "Services"). Please read this policy carefully.
By using our Services, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, do not use our Services.
2. Data Controller
For the purposes of the General Data Protection Regulation (GDPR), the data controller is:
DocFila, a NotaNovice UG Company
58256 Ennepetal
Germany
Email: privacy@docfila.com
Data Protection Officer: dpo@docfila.com
3. Information We Collect
We collect several types of information:
A. Information You Provide Directly:
- Account Information: Email address, name, password (hashed), profile photo
- Profile Data: Address, phone number, date of birth (optional)
- Documents: Files you upload, scan, create, or process
- Communications: Messages you send to us for support
- Payment Information: Processed securely by our payment providers
B. Information Collected Automatically:
- Device Information: Device type, operating system, unique device identifiers
- Usage Data: Features used, actions taken, time spent, crash reports
- Log Data: IP address, browser type, pages visited, access times
- Location Data: General location based on IP (not precise GPS)
C. Information from Third Parties:
- Social Login: If you sign in via Google/Apple, we receive basic profile info
- Analytics Providers: Aggregated usage statistics
4. How We Use Your Information
A. Service Provision:
- Create and manage your account
- Process, store, and organize your documents
- Enable AI-powered features (analysis, translation, generation)
- Process payments and manage subscriptions
B. Service Improvement:
- Analyze usage patterns to improve features
- Debug issues and fix errors
- Develop new features based on user needs
C. Communication:
- Send important service notifications
- Respond to your support requests
- Send marketing communications (with your consent)
D. Security:
- Detect and prevent fraud
- Enforce our terms of service
- Protect our users and services
5. Legal Basis for Processing (GDPR)
Under GDPR, we process your data based on:
- Contract Performance: Processing necessary to provide our Services
- Legitimate Interests: Analytics, security, and service improvement
- Consent: Marketing communications and optional cookies
- Legal Obligation: Tax records, fraud prevention, legal requests
6. AI Processing & Document Analysis
DocFila's AI setting has three modes: On, Local only and Off. It is On unless you change it (Settings > AI Settings). While it is On:
- When you use an AI feature, the document content it needs is sent through DocFila's servers (Google Cloud Functions, us-central1) to Google's Gemini API for processing
- Each time you save a document, its text (up to roughly the first 9,000 characters) is sent automatically to Google Vertex AI to build the search index for your library. This happens without a separate request from you
- A few features also send limited content automatically: the daily digest on Home sends the titles and expiry dates of documents that have expired or are about to, and a count of your documents by type; on some plans, capture processing and search may send the recognised text or your search query to a Google model when on-device processing is not confident enough
- DocFila's AI functions do not store your prompts or the model's responses. Results a feature exists to produce (for example a summary, extracted fields, or a Studio conversation) are saved to your account
- We do NOT use your documents to train AI models
- How long Google keeps this content, and how it may use it, is governed by Google's terms for the services we use; you can ask us for the applicable terms
- In Local only or Off mode, no document content is sent to any AI service
- Text recognition for Latin, Chinese, Japanese, Korean and Devanagari scripts is done on your device. When you are signed in and a scanned page is in a script your device cannot read (for example Arabic or Cyrillic), the page image is sent to Google's Gemini API to read it
AI features include: Document explanation, translation, reply generation, form filling assistance, document creation, and search across your documents. See AI data handling for what each AI feature sends.
7. Data Storage & Security
Your data is protected using:
- Firebase Authentication: Secure, industry-standard login
- Firebase Cloud Storage: Encrypted document storage
- Firebase Firestore: Encrypted metadata storage
- TLS: Encryption in transit for all connections to DocFila (the protocol version is negotiated between your device and Google's servers)
- AES-256: Encryption at rest for stored data
- Field-level encryption: the text extracted from your documents is encrypted again with per-account keys before it is stored
- Automated security checks before each release (database and storage security-rule tests, secret scanning). No independent penetration test has been performed yet
Data is stored in secure data centers located in the European Union and United States. We implement appropriate technical and organizational measures to protect your data against unauthorized access, alteration, or destruction.
8. Data Sharing & Third Parties
We do NOT sell your personal information. We may share data with:
A. Service Providers:
- Google Cloud/Firebase: Infrastructure, storage and authentication
- Google (Gemini API and Vertex AI): AI processing and search indexing of document content while the AI setting is On
- Google Firebase Crashlytics and Google Analytics for Firebase: Crash reports and usage statistics, only if you allow them
- Resend, and Twilio SendGrid as a fallback: Email delivery, including attachments you send
- Infobip: SMS delivery (appointment reminders and review requests)
- RevenueCat: Subscription management
- Stripe: Payment processing
- GitHub: Bug reports you choose to send (redacted technical details only)
The current list, with what each receives, is kept in our Trust Center.
B. Legal Requirements:
- When required by law or legal process
- To protect our rights, privacy, safety, or property
- In connection with a merger, acquisition, or sale of assets
What each of these providers may do with the data it receives is governed by its own terms.
9. International Data Transfers
Your information may be transferred to and processed in countries outside the EEA. When we transfer data internationally, we ensure adequate protection through:
- The EU-US Data Privacy Framework, where the recipient is certified under it
- Standard Contractual Clauses approved by the European Commission
You can request a copy of the safeguards we use by contacting our DPO.
10. Data Retention
We retain your data for as long as necessary to provide our Services:
- Active Account: Data retained while your account is active
- Account Deletion: Documents permanently deleted within 30 days
- Backups: no managed backups of your data are configured at present; this section will state how long backups are kept before any are introduced
- Legal Requirements: Some data retained for up to 7 years for tax/legal purposes
- Anonymized Analytics: May be retained indefinitely
You can request deletion of your account at any time in Settings.
11. Your Rights (GDPR)
Under GDPR, you have the following rights:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time
- Right to Lodge a Complaint: File a complaint with a supervisory authority
To exercise these rights, contact us at privacy@docfila.com or use the in-app data management features in Settings > Privacy.
12. Your Rights (CCPA — California Residents)
California residents have additional rights under the CCPA:
- Right to Know: What personal information we collect and how we use it
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: Opt out of the "sale" of personal information
- Right to Non-Discrimination: No discrimination for exercising rights
We do not sell personal information as defined by the CCPA.
13. Children's Privacy
DocFila is not intended for children under 13 (or 16 in certain jurisdictions). We do not knowingly collect personal information from children.
If you are a parent or guardian and believe we have collected information from a child, please contact us immediately at privacy@docfila.com. We will delete such information promptly.
14. Cookies & Tracking
We use cookies and similar technologies for analytics and to improve your experience. You can manage your cookie preferences at any time through our cookie consent banner or in Settings.
15. Marketing Communications
With your consent, we may send marketing communications about new features, special offers, and tips for getting the most out of DocFila.
You can opt out at any time by:
- Clicking "Unsubscribe" in any email
- Updating preferences in Settings > Notifications
- Contacting us at privacy@docfila.com
16. Changes to This Policy
We may update this Privacy Policy periodically. Changes will be indicated by updating the "Last updated" date, in-app notification for material changes, and email notification for significant changes.
Continued use of our Services after changes constitutes acceptance of the updated policy.
17. Contact Us
If you have questions about this Privacy Policy or your data, contact us:
General Inquiries:
Email: privacy@docfila.com
Data Protection Officer:
Email: dpo@docfila.com
Postal Address:
DocFila, a NotaNovice UG Company
Attn: Privacy Team
58256 Ennepetal
Germany
German Supervisory Authority:
Landesbeauftragte für Datenschutz und Informationsfreiheit NRW
www.ldi.nrw.de