Privacy Policy
Last updated: September 24, 2026
The short version
- Files you process with our tools are deleted from our storage automatically within 24 hours. We do not keep a library of them.
- Five of our image converters never upload anything: they run inside your browser and the file never leaves your device.
- Documents you save to the vault stay until you delete them. They are visible only to your account.
- We do not sell your data, we do not advertise, and no provider we use is allowed to train AI models on your documents.
- We measure how DocFather is used without cookies and without storing anything in your browser for it. If your browser sends Global Privacy Control or Do Not Track, this website does not load our product analytics at all. Section 6 has the details, and the Cookie Policy lists everything we keep in your browser.
1. Who we are
DocFather is a product of IT Nest Limited, a private company limited by shares registered in the Hong Kong SAR. We are the data controller for the personal data described here.
IT Nest Limited, Office 3906, 39/F, The Center, 99 Queen's Road Central, Central, Hong Kong (BRN 77297048)
Contact: support@docfather.com
This policy covers docfather.com, the DocFather iOS app and the @DocFatherBot Telegram bot. Where the three behave differently, it says so. Please write to us at the address above rather than to the registered office: support email reaches a person, post does not.
2. Files you process with tools
Five image converters do not involve us at all. JPG to PNG, PNG to JPG, JPG to WEBP, WEBP to JPG and HEIC to JPG convert inside your browser. No file, and no copy of one, is ever sent anywhere.
Every other tool needs a server. Your browser uploads the file straight into our Cloudflare R2 storage over an encrypted connection, the job runs, and the result is written back to the same storage for you to download. Both the file you sent and the result are deleted automatically by a storage rule 24 hours after upload. The link you download the result with stops working after 6 hours, and the link your browser uploads with stops working after 15 minutes.
We keep a record that the job happened, described in section 5. We do not keep the file.
Some operations need a specialist provider, and only for the length of the job:
- CloudConvert for file format conversion and compression
- Anthropic for AI features: summaries, chat, analysis, extraction and document generation
- DeepL for document translation
- Mistral AI for reading text out of scans and photos
We send them only what the operation you asked for requires. All four are used through paid business APIs whose terms do not permit training models on the content we send.
3. Vault documents
The vault is storage, so it works differently. When you save a document we keep three things: the original file in Cloudflare R2, the text we extracted from it, and a short set of metadata fields such as document type, title and dates. The text and the metadata are stored in our Cloudflare D1 database so that search can answer questions about your documents.
Being precise about encryption. Cloudflare encrypts our storage and database at rest, and everything travels over an encrypted connection. We do not add a second layer of our own on top, and we hold no per-document key that would stop us reading a file. Anyone who tells you their vault is "end-to-end encrypted" is describing something we do not do. We would rather say so than let the word do work it has not earned.
The vault uses AI providers too. When you add a document, a scan or photo goes to Mistral AI so its text can be read, and the beginning of the extracted text goes to Anthropic so the type, title and dates can be filled in. When you search your vault, document titles, metadata and the relevant passages go to Anthropic to produce the answer. This is how the vault answers questions rather than just listing file names, and it is worth knowing before you store a passport or a contract in it.
In the iOS app, nothing is kept until you choose to keep it. A document you add is uploaded, read and analysed first, and you see what was found before anything is saved or charged. If you choose Don’t save, the file, its text and its metadata are deleted at once. If you leave without choosing, the unsaved document is deleted automatically after 24 hours.
Vault documents stay until you delete them or delete your account. Deleting a document removes the file and its extracted text together.
4. Account data
Sign-in is handled by Google Firebase Authentication. On the website you can use Google, an email address and password, or a one-time code sent to your email. In the iOS app you can use Sign in with Apple, Google or an emailed code. From these we receive and store your account identifier, email address and display name. With Sign in with Apple, Apple may give us a private relay address instead of your real one, and shares your name only if you allow it. In the Telegram bot there is no Firebase and no email: bot users are identified by their Telegram account id, username and first name.
Alongside that we store your language, credit balance and subscription state. Your account record is created the first time an authenticated request arrives, which can be a plain visit to the account page rather than a deliberate sign-up.
Using the app without signing in. The iOS app works before you sign in. To hold your credits and purchases it creates an account for the device: the app generates a random identifier and keeps it in the device keychain, and we store only a one-way hash of it. That account has no name and no email address. If you sign in later, it is merged into your account, credits and purchases included.
If you sign in with a code sent by email, we pass your address to Resend to deliver it, and for 10 minutes we keep a one-way hash of your address and of the code, so the code works once and then expires. On the website that request is protected by Cloudflare Turnstile. So that nobody can flood an inbox, we limit how many codes can be requested per address and per sender: for a little over two hours we keep a count under a one-way hash of your address, and another under a one-way hash of your IP address together with, in the iOS app, an identifier of the app installation. In the app, our server can also give the app a random sender id, kept for up to a year, for the same purpose.
Signed-in users can save up to ten signature images for reuse. These are stored under your account until you delete them. No automatic rule removes them, because their whole purpose is to still be there next time.
5. Records of what you do
We keep an operational record for each operation you run: which tool it was, when, how many pages, how much it cost us and how many credits it cost you, how long it took, and whether it failed. Alongside it we keep your credit transactions, purchases, subscription grants and promo code use. These records are how billing, refunds and support work, and they are kept per user rather than only in aggregate.
They record that an operation happened and how big it was. They do not contain your document contents.
IP addresses. We rate limit the free tools, the search box and sign-in by IP address, which means your IP is held in a short-lived key for about an hour. This is anti-abuse, not measurement.
Errors. When something fails on our server, in the app or in a page of this website, the error is forwarded to a private Telegram group so we notice it. Alerts from the server and the app can include the name of the file that failed, and file names are often descriptive; reports from the website arrive with file names removed. None of them include the file itself.
6. Analytics, search and your browser
Product analytics. We use PostHog to understand how DocFather is used: which pages are opened, which tools are started, whether a job finished or failed, how a visit arrived (a search engine, an AI assistant, a campaign link), and what people type into the search box on the home page. It never receives a file, a file name, the text of a document, what you write in an AI tool, or an answer we generate. In search phrases, email addresses and long numbers are replaced before anything is sent.
It is set up so that it cannot follow you around. It writes no cookie and stores nothing in your browser, so each page load starts as a new, unconnected visitor. Requests go through our own domain to PostHog’s servers in the EU (Frankfurt), and PostHog is set to discard your IP address rather than store it. Automatic click capture, session recording and heatmaps are all off. If you are signed in, events are linked to your random account id, never to your name or email, so that the steps of one visit count as one person. Our server records a few events under the same id that a browser cannot report reliably, such as a completed purchase or a failed job, including for Telegram bot users.
Page statistics. Cloudflare, which serves this website, also counts page views and measures how fast pages load (Cloudflare Web Analytics). It sets no cookie, stores nothing in your browser and keeps no profile of you; we see totals such as visits per page, browser, country and load times.
Switching it off. If your browser sends Global Privacy Control or Do Not Track, this website does not load PostHog at all. In the iOS app, turn off Analytics on the Account screen. You can also object by writing to us, and we will delete the analytics history linked to your account.
The search box. “What do you need to do?”, on the home page and in the app, first matches what you type inside your browser or phone. Only when nothing matches and you press Enter (Search in the app) is the phrase sent to our server, which asks Anthropic which of our tools fits. We keep the suggestion for 30 days so the same phrase is answered at once next time. It is stored under a one-way fingerprint of the phrase rather than the phrase itself, although the suggestion can paraphrase what you asked. On the website, a phrase nobody has asked before goes through Cloudflare Turnstile first. Searching is free. Please do not type into it anything you would not want an AI provider to read.
The iOS app uses TelemetryDeck rather than PostHog. It counts which features are used, including whether a search found something, but never records what you typed. The app also sends us a report when it crashes or hits an error, with the device model, operating system version, app version and a device identifier. TelemetryDeck builds no advertising profile, uses no advertising identifier and is not used on this website.
What stays in your browser. This website sets no cookies. It keeps only the handful of values needed to keep you signed in and to remember that you closed the notice, listed one by one in the Cookie Policy.
7. Payments
Payments are processed by Stripe on the web, Apple for in-app purchases, and Telegram for Stars. We never see or store card numbers. To set up a checkout or subscription we send Stripe your email address and our internal account identifiers so the payment can be matched to your balance, and they send back the confirmation and purchase details.
8. Who else processes your data
The full list, with what each one is for and what reaches it:
| Provider | What for | What reaches them |
|---|---|---|
| Cloudflare | Hosting, file storage (R2), database (D1), bot protection (Turnstile) and page statistics (Web Analytics) | Every file you process or save, every account and ledger record, the IP address of every request, and page views with load times |
| Google Firebase | Sign-in and, in the iOS app, push notifications | Email address, display name, sign-in method, device push token |
| CloudConvert | File format conversion and compression | The file you are converting, fetched from our storage for the duration of the job |
| Anthropic | All AI features: summaries, chat, analysis, extraction, document generation, vault metadata and vault search, plus suggesting a tool when the search box finds nothing | The text of the document you are working on, or the part of it the feature needs, and search phrases that found no match |
| Mistral AI | Reading text out of scans and photos (OCR) | The scanned pages or images that need recognising |
| DeepL | Document translation | The document being translated |
| Stripe | Card payments and subscription management on the web | Your email address and our internal account identifiers, plus whatever you type into Stripe directly |
| Apple | In-app purchases, subscriptions and Sign in with Apple in the iOS app | Purchase and subscription events. With Sign in with Apple, your email or a private relay address, and your name if you choose to share it |
| Resend | Sending sign-in codes and other transactional email | Your email address and the contents of that email |
| Telegram | The @DocFatherBot product surface, Stars payments, and internal error alerts | For bot users, your Telegram account details and the documents you send the bot. For all users, error reports that can include a file name |
| PostHog | Product analytics on this website, and events our server records such as purchases and failed jobs | Pages opened, tools used, how a visit arrived, search phrases typed on this website with emails and long numbers removed, and your account id if you are signed in (for bot-only users, their Telegram id). No IP address, no files, no document text |
| TelemetryDeck | Usage analytics in the iOS app only, never on this website | App events and device type, with no advertising identifier and no advertising profile |
9. How long we keep things
- Files you process: deleted automatically 24 hours after upload.
- Download links: 6 hours. Upload links: 15 minutes.
- Job records: 24 hours. For the chat and question tools these include the answer that was produced.
- Documents added in the app but not saved: deleted at once when you choose Don’t save, otherwise after 24 hours.
- Sign-in code: 10 minutes. Sign-in link: 15 minutes. Both are stored as a one-way hash.
- IP address for rate limiting: about one hour; the sign-in code limits keep their one-way hashes for a little over two hours.
- Search suggestions: 30 days, under a one-way fingerprint of the phrase.
- Analytics events: up to 7 years, the retention period of our PostHog plan. Once your account is deleted, the events tied to its id no longer lead to anyone, and on request we erase them too.
- Vault documents and saved signatures: until you delete them.
- Account, credits and operational records: until you delete your account, after which we keep only what tax and accounting rules require us to keep.
10. Why we may use your data, and your rights
EU and UK data protection law asks us to name a legal basis for each use of your data. Ours are:
- Providing the service you asked for (performance of a contract): running files through the tools, your account and credits, the vault, payments, sign-in emails and the search box.
- Legitimate interests: protecting the service from abuse with rate limits and bot checks, finding and fixing errors, and understanding how DocFather is used so we can improve it. You can object to any of these at any time.
- Legal obligation: the payment and accounting records that tax law requires us to keep.
- Consent: push notifications in the iOS app, which you allow or refuse when the app asks and can switch off in your phone’s settings at any time.
If you are in the EU, the UK or another place with comparable law, you have the right to get a copy of your data, correct it, delete it, receive it in a portable form, object to or restrict how we use it, and complain to your data protection authority. Where we rely on consent, you can withdraw it at any time. For analytics, the quickest ways to object are in section 6.
Some of this you can do yourself, immediately: delete individual vault documents from the vault page or the app, delete saved signatures from the signing tool, and delete your whole account in the iOS app under Account, Settings, Delete account, which takes effect at once.
For the rest, including deleting your account from the website and exporting your data, write to support@docfather.com from the email address on the account. We handle these by hand, so please allow us up to 30 days, which is the legal maximum rather than our target. Deleting your account removes your account record, vault documents, saved signatures, credit history and operational records. We keep a one-line note that an account was deleted and when.
We do not sell or share personal information in the sense California law gives those words, and we honour Global Privacy Control. We make no decisions about you by automated means that have legal or similarly significant effects, and we do no profiling.
11. Where your data goes
IT Nest Limited is established in the Hong Kong SAR, and the providers in section 8 run in the United States and the European Union. So if you are in the EU or the UK, your data is processed outside it.
The European Commission has not issued an adequacy decision for Hong Kong. Where EU or UK law requires a safeguard for a transfer, it is provided by the Standard Contractual Clauses contained in the data processing terms of the providers listed above, which we accept as part of using their services.
12. Children
DocFather is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has created an account, write to us and we will remove it.
13. Changes
If we materially change this policy we will update this page and the date at the top. Significant changes affecting vault storage will be announced by email.