Privacy Policy
Last updated: July 27, 2026
The short version
- Files you process with our tools are deleted from our storage automatically within 24 hours. We do not keep a library of them.
- Five of our image converters never upload anything: they run inside your browser and the file never leaves your device.
- Documents you save to the vault stay until you delete them. They are visible only to your account.
- We do not sell your data, we do not advertise, and no provider we use is allowed to train AI models on your documents.
- This website runs no analytics. See the Cookie Policy for the exact list of what we put in your browser.
1. Who we are
DocFather is a product of IT Nest Limited, a private company limited by shares registered in the Hong Kong SAR. We are the data controller for the personal data described here.
IT Nest Limited, Office 3906, 39/F, The Center, 99 Queen's Road Central, Central, Hong Kong (BRN 77297048)
Contact: support@docfather.com
This policy covers docfather.com, the DocFather iOS app and the @DocFatherBot Telegram bot. Where the three behave differently, it says so. Please write to us at the address above rather than to the registered office: support email reaches a person, post does not.
2. Files you process with tools
Five image converters do not involve us at all. JPG to PNG, PNG to JPG, JPG to WEBP, WEBP to JPG and HEIC to JPG convert inside your browser. No file, and no copy of one, is ever sent anywhere.
Every other tool needs a server. Your browser uploads the file straight into our Cloudflare R2 storage over an encrypted connection, the job runs, and the result is written back to the same storage for you to download. Both the file you sent and the result are deleted automatically by a storage rule 24 hours after upload. The link you download the result with stops working after 6 hours, and the link your browser uploads with stops working after 15 minutes.
We keep a record that the job happened, described in section 5. We do not keep the file.
Some operations need a specialist provider, and only for the length of the job:
- CloudConvert for file format conversion and compression
- Anthropic for AI features: summaries, chat, analysis, extraction and document generation
- DeepL for document translation
- Mistral AI for reading text out of scans and photos
We send them only what the operation you asked for requires. All four are used through paid business APIs whose terms do not permit training models on the content we send.
3. Vault documents
The vault is storage, so it works differently. When you save a document we keep three things: the original file in Cloudflare R2, the text we extracted from it, and a short set of metadata fields such as document type, title and dates. The text and the metadata are stored in our Cloudflare D1 database so that search can answer questions about your documents.
Being precise about encryption. Cloudflare encrypts our storage and database at rest, and everything travels over an encrypted connection. We do not add a second layer of our own on top, and we hold no per-document key that would stop us reading a file. Anyone who tells you their vault is "end-to-end encrypted" is describing something we do not do. We would rather say so than let the word do work it has not earned.
The vault uses AI providers too. When you save a document, a scan or photo goes to Mistral AI so its text can be read, and the beginning of the extracted text goes to Anthropic so the type, title and dates can be filled in. When you search your vault, document titles, metadata and the relevant passages go to Anthropic to produce the answer. This is how the vault answers questions rather than just listing file names, and it is worth knowing before you store a passport or a contract in it.
Vault documents stay until you delete them or delete your account. Deleting a document removes the file and its extracted text together.
4. Account data
On the website and in the iOS app, sign-in is handled by Google Firebase Authentication, using Google, an email address and password, or a one-time sign-in link. From it we receive and store your account identifier, email address and display name. In the Telegram bot there is no Firebase and no email: bot users are identified by their Telegram account id, username and first name.
Alongside that we store your language, credit balance and subscription state. Your account record is created the first time an authenticated request arrives, which can be a plain visit to the account page rather than a deliberate sign-up.
If you request a sign-in link by email, we pass your address to Resend to deliver the message, and we store your address plus a one-way hash of the link for 15 minutes so the link can be used once and then expires. That request is protected by Cloudflare Turnstile.
Signed-in users can save up to ten signature images for reuse. These are stored under your account until you delete them. No automatic rule removes them, because their whole purpose is to still be there next time.
5. Records of what you do
We keep an operational record for each operation you run: which tool it was, when, how many pages, how much it cost us and how many credits it cost you, how long it took, and whether it failed. Alongside it we keep your credit transactions, purchases, subscription grants and promo code use. These records are how billing, refunds and support work, and they are kept per user rather than only in aggregate.
They record that an operation happened and how big it was. They do not contain your document contents.
IP addresses. We rate limit the free tools and the sign-in link by IP address, which means your IP is held in a short-lived key for about an hour. This is anti-abuse, not measurement.
Errors. When something fails, the error is forwarded to a private Telegram group so we notice it. Those alerts can include the name of the file that failed, and file names are often descriptive. They do not include the file itself.
6. Analytics and your browser
This website runs no analytics. There is no Google Analytics, no advertising pixel, no session recorder and no heatmap. It also sets no cookies at all. What it does keep in your browser is the handful of values needed to keep you signed in, listed one by one in the Cookie Policy.
The iOS app is different. It uses TelemetryDeck to count which features are used, and it sends us a report when it crashes or hits an error. That report includes the device model, operating system version, app version and a device identifier. TelemetryDeck builds no advertising profile and uses no advertising identifier. Neither happens on this website.
7. Payments
Payments are processed by Stripe on the web, Apple for in-app purchases, and Telegram for Stars. We never see or store card numbers. To set up a checkout or subscription we send Stripe your email address and our internal account identifiers so the payment can be matched to your balance, and they send back the confirmation and purchase details.
8. Who else processes your data
The full list, with what each one is for and what reaches it:
| Provider | What for | What reaches them |
|---|---|---|
| Cloudflare | Hosting, file storage (R2), database (D1), bot protection (Turnstile) | Every file you process or save, every account and ledger record, and the IP address of every request |
| Google Firebase | Sign-in and, in the iOS app, push notifications | Email address, display name, sign-in method, device push token |
| CloudConvert | File format conversion and compression | The file you are converting, fetched from our storage for the duration of the job |
| Anthropic | All AI features: summaries, chat, analysis, extraction, document generation, vault metadata and vault search | The text of the document you are working on, or the part of it the feature needs |
| Mistral AI | Reading text out of scans and photos (OCR) | The scanned pages or images that need recognising |
| DeepL | Document translation | The document being translated |
| Stripe | Card payments and subscription management on the web | Your email address and our internal account identifiers, plus whatever you type into Stripe directly |
| Apple | In-app purchases and subscriptions in the iOS app | Purchase and subscription events. Apple does not tell us who you are |
| Resend | Sending sign-in links and other transactional email | Your email address and the contents of that email |
| Telegram | The @DocFatherBot product surface, Stars payments, and internal error alerts | For bot users, your Telegram account details and the documents you send the bot. For all users, error reports that can include a file name |
| TelemetryDeck | Usage analytics in the iOS app only, never on this website | App events and device type, with no advertising identifier and no advertising profile |
9. How long we keep things
- Files you process: deleted automatically 24 hours after upload.
- Download links: 6 hours. Upload links: 15 minutes.
- Job records: 24 hours. For the chat and question tools these include the answer that was produced.
- Sign-in link: 15 minutes, stored as a one-way hash.
- IP address for rate limiting: about one hour.
- Vault documents and saved signatures: until you delete them.
- Account, credits and operational records: until you delete your account, after which we keep only what tax and accounting rules require us to keep.
10. Your rights
If you are in the EU, the UK or another place with comparable law, you have the right to get a copy of your data, correct it, delete it, receive it in a portable form, object to or restrict how we use it, and complain to your data protection authority.
Some of this you can do yourself, immediately: delete individual vault documents from the vault page or the app, and delete saved signatures from the signing tool.
For the rest, including deleting your account and exporting your data, write to support@docfather.com from the email address on the account. We handle these by hand rather than with a button, so please allow us up to 30 days, which is the legal maximum rather than our target. Deleting your account removes your account record, vault documents, saved signatures, credit history and operational records.
11. Where your data goes
IT Nest Limited is established in the Hong Kong SAR, and the providers in section 8 run in the United States and the European Union. So if you are in the EU or the UK, your data is processed outside it.
The European Commission has not issued an adequacy decision for Hong Kong. Where EU or UK law requires a safeguard for a transfer, it is provided by the Standard Contractual Clauses contained in the data processing terms of the providers listed above, which we accept as part of using their services.
12. Children
DocFather is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has created an account, write to us and we will remove it.
13. Changes
If we materially change this policy we will update this page and the date at the top. Significant changes affecting vault storage will be announced by email.