Legal
Privacy Policy
Last updated: 29 August 2026
This policy describes how the Doxelo mobile application and related services (“Doxelo”, “we”, “us”) handle personal data. Doxelo converts, translates and extracts documents you choose to upload. Contact: info@mdevelopment.ro.
The short version
- Your documents are never used to train models.
- Files live in a private bucket. Access is by short-lived signed URLs, not a public link.
- Library documents belong to your account and stay until you delete them.
- You can delete a document or the entire account from inside the app.
- We do not run ads and we do not ask for App Tracking Transparency, because we do not track you across apps.
Who this applies to
People who create a Doxelo account (on iOS, via Sign in with Apple) and upload files for conversion, translation or extraction.
Data we process
Account
When you sign in with Apple we store Apple’s stable user identifier. If you share an email address (including Apple’s Hide My Email relay), we store that address. We may store a display name if Apple provides one, a language preference, a credits balance, and your chosen retention setting for temporary processing files.
Documents you upload
Original files, derived assets (for example extracted images), the internal reconstructed document model, quality reports, version history, and exported files (Word, Excel, PDF, CSV, HTML, JSON). These are user content used only to provide the service you requested.
Jobs and billing
Processing job status, page counts, parser mode (Standard or High Accuracy), error codes, and credit or subscription state mirrored from the App Store via RevenueCat. We do not store your full card number. Apple processes the payment.
Diagnostics
Crash reports may include app version, device class, and error codes. Filenames, document text, OCR text and storage URLs are stripped. If you use Report a Problem, the default payload is diagnostics only. Access to a page or document requires your separate, explicit permission.
What we do not collect
Precise location, contacts, advertising identifiers for tracking, or analytics events that contain document text. Product analytics, if enabled, use event names and technical counts (for example page count and processing mode), never the contents of a file.
Why we process it
To create and secure your account, convert and export documents, restore your library on a new device, charge credits or a subscription you buy, prevent abuse, and fix failures. The legal bases we rely on are performance of a contract (providing the app you asked for) and, where required, legitimate interests in keeping the service secure and reliable. Where a local law requires consent for a specific processing activity, we will ask for it.
Where files go
Uploads are sent directly to object storage with a short-lived upload URL. The API does not accept file bytes in the request body. Storage keys are namespaced by account id. Every download checks that the signed-in account owns the document. The storage bucket and the database are encrypted at rest.
Parsing runs on our servers. Translation, when you request it, is sent to our translation provider (DeepL by default) as text blocks from the reconstructed document, not as a public posting of your file. Purchase receipts are verified with RevenueCat and Apple. Crash reports, if configured, go to Sentry without document content.
Retention
Library documents (the original, the reconstructed result, versions and exports) remain until you delete them or delete your account. They are not deleted merely because a temporary processing cache expired.
Temporary processing artifacts (worker scratch space used during conversion) are discarded when the job finishes. In the app you can choose how long related processing data should be eligible for cleanup: 24 hours, 7 days, or keep until you delete.
Session refresh tokens expire or are revoked on sign-out. Billing records required for tax or accounting may be kept in anonymised form without document content.
Your choices
- Delete a document in the Library. That removes the original, assets, reconstruction and exports.
- Delete your account in Settings. That removes your documents, sessions and account record.
- Restore Purchases to reconcile App Store entitlements on a new device.
- Email info@mdevelopment.ro to ask for a copy or correction of account data we hold.
If you are in the EEA, UK or a similar jurisdiction you may also have the right to object, restrict processing, or lodge a complaint with a supervisory authority. Using Doxelo is voluntary; you can stop by deleting the app and the account.
Children
Doxelo is not directed at children under 13 (or the equivalent minimum age in your country). We do not knowingly collect personal data from children.
International transfers
Servers and subprocessors may be located outside your country. We use providers that offer appropriate safeguards for the service they perform (account, storage, translation, crash reporting, payments).
Changes
If this policy changes in a material way, we will update the date above and, where required, notify you in the app. Continued use after the update means the new policy applies to later processing.
Contact
Privacy questions: info@mdevelopment.ro
Support: doxelo.app/support