Legal

Privacy Policy

Your privacy matters. This policy explains what data we collect, why we collect it, and how we protect it — in plain language.

Last updated: July 16, 2026

Our commitment to you

DocumintQ is built on a foundation of trust. We process millions of sensitive documents for legal, financial, and enterprise teams. We take our responsibility seriously: your files are yours, your data is never sold, and we maintain SOC 2 Type II certification to back it up.

1. Information We Collect

Account Information

When you register for DocumintQ, we collect your name, email address, company name (optional), and a hashed password. We never store plaintext passwords.

Files You Upload

PDF files and documents you upload for processing are stored temporarily on our servers using AES-256 encryption. Files are used solely to deliver the requested operation (merge, split, convert, sign, etc.) and are automatically purged from our servers within 24 hours of processing, unless you explicitly save them to your DocumintQ workspace.

Usage Data

We collect information about how you interact with our platform — including the tools used, credit consumption, session timestamps, browser type, IP address, and device type. This data is used to improve our service and ensure platform stability.

Payment Information

Credit card and billing details are handled exclusively by our PCI-DSS compliant payment processor. DocumintQ does not store raw card numbers or CVV codes on our servers.

2. How We Use Your Information

  • To provide, operate, and maintain the DocumintQ platform and its 70+ PDF tools.
  • To process your file operations and deliver results accurately.
  • To manage your account, credit balance, and subscription.
  • To send transactional emails (receipts, password resets, usage alerts).
  • To detect and prevent fraud, abuse, or unauthorized access.
  • To improve our AI-powered features such as Smart OCR and Auto-Tagging.
  • To comply with legal obligations and respond to lawful requests.
  • To send product updates and promotional content — you may opt out at any time.

3. Email Provider Integrations (Gmail & Outlook)

Data We Access

If you choose to connect a Gmail or Microsoft Outlook/Office 365 account to DocumintQ's Workflow Automation feature (the "Email Received" trigger), we request read-only access to that inbox — via the Gmail API (gmail.readonly scope) for Google accounts, or the Microsoft Graph API (Mail.Read scope) for Outlook/Microsoft 365 accounts. Through this access, we read email metadata (sender, subject, timestamp) and attachments from messages matching filters you configure yourself (e.g. sender address, domain, subject keywords, or presence of an attachment). We do not access, read, or store emails that do not match your configured trigger rules, and we do not browse your inbox beyond what is needed to evaluate those rules.

How We Use This Data

Attachments extracted from matching emails, regardless of provider, are used solely to perform the workflow actions you have configured — such as OCR processing, PDF conversion, structured field extraction, or saving the document to your DocumintQ workspace. This data is used only to provide the specific features you set up and is never used for advertising, profiling, or any purpose unrelated to your configured workflow.

Data Sharing

Email data accessed through Gmail or Outlook integrations is never sold, rented, or transferred to third parties for advertising or marketing purposes. It may only be shared with infrastructure subprocessors (such as our cloud hosting and OCR processing providers) strictly as needed to deliver the workflow you configured, and all such subprocessors are bound by data processing agreements limiting their use of the data. This data is never used to develop, improve, or train AI/ML models beyond generating your requested output.

Data Protection

OAuth tokens and refresh tokens used to access your Gmail or Outlook account are encrypted at rest using AWS KMS / AWS Secrets Manager and are never stored as plaintext. Extracted attachments are encrypted using the same AES-256 standard described in Section 4 (File Processing & Storage), and all data in transit is protected using TLS 1.3.

Data Retention & Deletion

Extracted attachments follow the same retention rules as any other file in your workspace (see Section 9). You may disconnect your Gmail or Outlook account at any time from your DocumintQ account settings — this immediately revokes our access token and stops all further email monitoring. Disconnecting does not automatically delete documents already extracted and saved to your workspace; those can be deleted separately from your dashboard at any time.

Limited Use Compliance (Google APIs)

DocumintQ's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Microsoft Graph Data Handling

DocumintQ's use of data obtained through the Microsoft Graph API is limited to the features described above and is handled in accordance with Microsoft's applicable data protection requirements for third-party applications.

4. File Processing & Storage

Temporary Processing

Files uploaded for one-time operations (merge, compress, convert, etc.) are processed in isolated, encrypted environments. They are not read by human staff, not used to train AI models, and not shared with third parties. Files are deleted automatically within 24 hours.

Workspace Storage

Files saved to your DocumintQ workspace are stored with AES-256 encryption at rest and TLS 1.3 in transit. You retain full ownership of your files. You can delete them at any time from your dashboard, and deletion is permanent and irreversible.

Team & Collaboration Features

When you share files or folders with team members, those users gain access only to the specific assets you share. Audit trails record all access and modification events for compliance purposes.

5. Data Security

DocumintQ maintains a comprehensive information security program that includes AES-256 file encryption, TLS 1.3 for all data in transit, SOC 2 Type II compliance, regular third-party penetration testing, role-based access controls (RBAC), multi-factor authentication (MFA) support, and continuous anomaly detection. Despite these measures, no system is completely immune to risk. We encourage you to use a strong, unique password and enable MFA on your account.

6. GDPR & Your Rights

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR):

  • Right of Access — request a copy of the personal data we hold about you.
  • Right to Rectification — request correction of inaccurate or incomplete data.
  • Right to Erasure (“Right to be Forgotten”) — request deletion of your personal data, subject to legal retention obligations.
  • Right to Restriction — request that we limit the processing of your data.
  • Right to Data Portability — receive your data in a structured, machine-readable format.
  • Right to Object — object to processing based on legitimate interests or direct marketing.
  • Right to Withdraw Consent — where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, contact us at privacy@documintq.com. We will respond within 30 days.

7. Cookies & Tracking Technologies

Essential Cookies

Required for authentication, session management, and basic platform functionality. These cannot be disabled without breaking the service.

Analytics Cookies

We use privacy-respecting analytics tools to understand usage patterns and improve the platform. No personally identifiable information is shared with analytics providers.

Preference Cookies

Store your settings such as language preference and dashboard layout.

Managing Cookies

You can control non-essential cookies through our Cookie Preferences panel or your browser settings. Disabling essential cookies will impair platform functionality.

8. Third-Party Services

DocumintQ integrates with carefully vetted third-party services to deliver its features, including payment processors, cloud infrastructure providers, email delivery services, and — where you choose to enable it — the Gmail API and Microsoft Graph API for email-based workflow automation. All third-party processors are bound by data processing agreements (DPAs) and are prohibited from using your data for any purpose beyond delivering the contracted service. We do not sell, rent, or broker your personal data. Our access to and use of Google user data via the Gmail API adheres to the Google API Services User Data Policy, including the Limited Use requirements.

9. Data Retention

  • Temporarily uploaded files: deleted within 24 hours of processing.
  • Workspace files: retained until you delete them or close your account.
  • Gmail/Outlook-extracted attachments: retained under the same workspace file rules above until deleted by you.
  • Account data: retained for the duration of your account, plus up to 90 days after closure for backup/audit purposes.
  • Billing records: retained for 7 years to comply with financial regulations.
  • Usage logs: retained for 12 months for security and abuse prevention.

10. Children's Privacy

DocumintQ is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact privacy@documintq.com and we will promptly delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date at the top of this page and, for material changes, notify you via email or an in-app notice. Your continued use of DocumintQ after such changes constitutes acceptance of the updated policy.

12. Contact Us

For privacy-related questions, data requests, or to report a concern:

Email: privacy@documintq.com

Company: Acumen Technologies

Address: Available upon request

Have questions about this policy? Contact our privacy team