Privacy Policy
Last updated: July 2026
DocButterfly ("we", "us", or "our") operates the DocButterfly platform and API services. This policy explains what information we collect, how we use it, and your rights.
1. Information We Collect
Account information: When you register, we collect your email address and a hashed password. You may optionally provide a phone number.
API usage data: Each API call is logged with a timestamp, endpoint name, token cost, processing duration, response status, and your IP address. This data powers your usage dashboard and our billing system.
Document content: Documents you submit to the API are processed in memory and are not retained once the response is returned, with three exceptions. (a) Template samples — if you save a document as a template sample, that document and a thumbnail of it are stored so the template can be previewed and reused. (b) Training samples — documents you explicitly mark as consented or synthetic training samples are stored so we can build extraction models scoped to your own account. (c) Output cache — the result of a document-composition operation, including the generated document, is cached against your account so an identical repeat request is not billed twice. We also store the templates, workflows and brand assets you create in the portal. Stored items are retained until deleted — see Section 5.
Billing information: The service is currently in pre-launch beta and we do not process payments or collect payment details. When paid plans launch we will name our payment processor in this policy before any payment data is collected.
Communications: If you contact us, we retain that correspondence to assist you.
2. How We Use Your Information
- To authenticate you and secure your account
- To track token usage and generate invoices
- To display your usage history in the portal
- To investigate abuse or errors if they occur
- To send transactional emails (password reset, billing receipts) — no marketing emails without your consent
3. Data Storage & Security
All data is stored in Microsoft Azure (Central US region). We use Azure Database for PostgreSQL for account records, Azure Table Storage for API client and usage state, and Azure Blob Storage for stored documents. Data is encrypted at rest and in transit (TLS 1.2+).
API keys are verified against a salted scrypt authenticator. By default we also keep a copy of your key encrypted with AES-256-GCM so you can retrieve it from the portal if you lose it. You can switch your account to hash-only storage, after which the key cannot be recovered and can only be regenerated.
4. Third-Party Services
| Service | Purpose | Data Shared |
|---|---|---|
| Microsoft Azure | Infrastructure hosting | All application data |
| Azure OpenAI | AI features (Document AI, AI assistant) | Document content you submit to AI endpoints, and messages you type into our AI assistant |
| Azure Document Intelligence | Document extraction and OCR | Documents submitted to Document AI operations, and consented training samples |
| Azure Communication Services | Transactional email | Recipient address and message content |
| Microsoft Graph | Email sending and calendar event creation, on your instruction | Message content, recipients, extracted dates |
| DocuSign | E-signature requests | The document to be signed and signer details |
We do not sell your data to any third party.
5. Data Retention
API usage logs are currently retained indefinitely. We are implementing a 12-month retention window; until it is in place you may request deletion of your usage history by contacting us (see Section 7).
Documents stored as template samples, training samples or cached outputs are retained until you delete them, or until you ask us to remove them.
Account data is retained while your account is active. We do not yet offer self-service account deletion; to have your account and associated data removed, email privacy@docbutterfly.com and we will action it manually within 30 days.
6. Cookies
We use only essential cookies required for authentication and security. No tracking, advertising, or analytics cookies are used. See our Cookie Policy for details.
7. Your Rights
Depending on your location, you may have the right to:
- Access a copy of the personal data we hold about you
- Correct inaccurate data
- Request deletion of your account and associated data. Deletion is currently handled manually — email privacy@docbutterfly.com. Note that deleting a template in the portal removes the template and its preview copy; training samples you uploaded for that template must be deleted individually, or ask us to remove them for you.
- Object to or restrict certain processing
- Data portability (receive your data in a machine-readable format)
To exercise any of these rights, contact us at privacy@docbutterfly.com. We will respond within 30 days.
8. GDPR (EU/UK Users)
Our lawful basis for processing your data is contractual necessity (to provide the service you signed up for) and legitimate interest (security, fraud prevention, usage tracking). Where we rely on consent, you may withdraw it at any time.
9. Changes to This Policy
We may update this policy as the service evolves. Material changes will be communicated via email. Continued use of the service after changes constitutes acceptance.
10. Contact
DocButterfly
Email: privacy@docbutterfly.com