Privacy Policy
Last updated: July 15, 2026
1. Introduction
Docline ("we," "our," or "us") operates www.docline.app, a document intelligence platform for legal and accounting professionals. Docline lets you capture public webpages, import URLs, upload PDFs, generate editable PDFs, and use artificial intelligence to detect important dates and deadlines. You review every detected date and may optionally save dates in Docline or synchronize selected dates with Google Calendar. This Privacy Policy explains what information we collect, how we use it, how Google user data is handled, and your rights. By using Docline, you agree to this Policy.
2. Information We Collect
We collect only the information needed to operate Docline. Categories include:
- Account information: When you register, we collect your email address, display name, and authentication credentials through Clerk, our identity provider. We also store your language preference and account identifiers needed to associate your data with your account.
- Uploaded files and captured content: When you upload a PDF, paste HTML, enter a URL, or use our bookmarklet to capture a public webpage, we process that content to extract text and detect dates. Source files and full page HTML are processed transiently and are not permanently stored after analysis completes.
- Generated PDFs: When you generate a consolidated or editable PDF, the output is produced for your download or immediate use. Docline does not maintain a permanent archive of generated PDF files on our servers after delivery.
- Detected dates and saved deadlines: After AI analysis, you manually review detected dates. If you choose to save a date, we store structured records including the date, deadline type, notes, source quote, page number, and associated document title or source URL.
- Payment and subscription information: Paid plans are processed by Paddle. We store subscription status, plan tier, billing period dates, and Paddle customer identifiers. We do not store full payment card numbers.
- Usage metrics: We track PDF generations, document analyses, and saved events per billing period to enforce plan limits and prevent abuse.
- Google Calendar data: Only if you explicitly connect Google Calendar, we store encrypted OAuth access and refresh tokens. When you request synchronization, we access calendar event data from your primary Google Calendar as described in Section 3.
- Analytics: Docline does not use third-party advertising or behavioral analytics platforms (such as Google Analytics or Meta Pixel). We collect limited operational and usage metrics described above solely to run the Service, enforce plan limits, and maintain security.
- Cookies: We use a single functional cookie to remember your language preference (English or Spanish). This cookie is not used for advertising or cross-site tracking. Authentication session cookies are managed by Clerk.
3. Google Calendar Integration
Google Calendar synchronization is entirely optional. Docline does not require a Google account to analyze documents or save deadlines inside Docline. Calendar access is requested only when you click to connect Google Calendar or choose to sync an approved date.
OAuth scope requested:
https://www.googleapis.com/auth/calendar.events
This is the only Google OAuth scope Docline requests. It permits Docline to create, read, update, and delete events on your primary Google Calendar—solely to provide the synchronization features you explicitly request. With this scope, Docline may access:
- Event titles, descriptions, start times, end times, and Google-assigned event IDs on your primary calendar.
- OAuth access and refresh tokens issued by Google to authenticate API requests on your behalf.
- A time-bounded list of events when you view the in-app calendar, so you can see which deadlines are already synchronized.
- No other Google data: Docline does not access Gmail, Google Drive, Google Contacts, your Google profile photo, or any other Google API.
You authorize this access through Google’s OAuth consent screen. You may revoke access at any time by disconnecting Google Calendar in Docline or by removing Docline at https://myaccount.google.com/permissions.
4. AI Processing
Docline uses DeepSeek, a third-party large language model provider, to analyze content you provide. AI processing is used exclusively to detect important dates, extract deadlines, and assist in generating editable PDFs from your submitted materials.
Content sent to DeepSeek
DeepSeek receives only user-provided content submitted for analysis: text extracted from uploaded PDFs, HTML you paste, content fetched from public webpages or URLs you supply, and related prompts needed to perform date extraction or PDF generation.
Data that DeepSeek never receives
- Google Calendar events or event metadata retrieved from Google APIs.
- Google OAuth access tokens, refresh tokens, or authorization codes.
- Google user profile information (name, email from Google, or Google account identifiers).
- Any other data obtained through Google APIs.
How AI fits into the workflow
The AI pipeline ends when detected dates are returned to you. You manually review every date. Only after your review may you save a date in Docline or create a Google Calendar event. Google Calendar data is completely isolated from the AI pipeline: it is never analyzed, summarized, classified, transmitted to DeepSeek, or used by any AI model.
Docline does not use Google user data to train, fine-tune, or improve AI models. User-provided content sent to DeepSeek is used only to deliver the analysis you requested in that session.
5. Google User Data
Google user data obtained through Google APIs is used exclusively to provide features you explicitly request—primarily creating, listing, updating, and deleting calendar events for deadlines you approve.
Google user data is never:
- Sold to any party.
- Shared with advertisers or used for interest-based advertising.
- Transferred to data brokers.
- Used to train, improve, or develop generalized artificial intelligence or machine learning models.
- Transferred to third-party AI providers (including DeepSeek) for any purpose.
- Used for creditworthiness determinations, lending decisions, or insurance underwriting.
We do not use Google user data for purposes unrelated to the calendar synchronization functionality visible in Docline’s user interface.
6. Google API Services User Data Policy Compliance
The use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Docline’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Google Calendar data is used only to provide calendar synchronization requested by the authenticated user.
- We use Google user data only to provide or improve user-facing features that are prominent in Docline’s interface (the calendar and deadline sync workflow).
- We do not transfer Google user data to third parties except as necessary to operate the Service (e.g., secure hosting), to comply with applicable law, or with your explicit direction—and never for advertising.
- Human access to Google user data is limited to what is necessary for security, compliance, or support with your consent.
- We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
7. Security
We implement technical and organizational measures designed to protect your information, including Google user data:
- HTTPS/TLS: All connections between your browser and Docline are encrypted using HTTPS.
- OAuth security: Google Calendar access uses the industry-standard OAuth 2.0 authorization code flow. Docline requests only the minimum scope required (calendar.events).
- Secure token storage: Google OAuth access and refresh tokens are encrypted at rest using AES-256-GCM before being stored in our database.
- Database protection: Application data is stored in a PostgreSQL database hosted on Supabase with access controls and encryption at rest.
- Access controls: Server-side API routes verify your authenticated session via Clerk before processing requests or calling Google APIs. Only the account owner can connect, disconnect, or sync calendar events.
- Infrastructure: Docline is hosted on Vercel. Production system access is restricted to authorized operators.
No method of transmission or storage is completely secure. If you believe your account has been compromised, contact us immediately.
8. Data Retention
We retain data only as long as necessary to provide the Service or as required by law:
- Account and subscription data: Retained while your account is active.
- Uploaded source content: Not retained permanently after AI processing completes.
- Generated PDFs: Not retained on our servers after delivery to you.
- Saved deadlines: Retained until you delete them or delete your account.
- Google OAuth tokens: Retained only while your Google Calendar connection is active. Deleted when you disconnect or delete your account.
- Google Calendar event listings: Fetched on demand for display; not maintained as a permanent secondary copy of your calendar.
How to delete your data
You may delete your Docline account and associated data at any time at /delete-account or by emailing us from your registered address. Account deletion revokes Google OAuth tokens with Google where possible, permanently deletes stored tokens from our database, and removes your deadlines, bookmarks, usage records, and authentication account. /delete-account
How to disconnect Google
Disconnect Google Calendar from the Calendar tab in your dashboard without deleting your Docline account. This revokes Docline’s tokens with Google and deletes stored credentials from our systems. You may also revoke access at https://myaccount.google.com/permissions. Events previously created in your Google Calendar remain there unless you delete them separately.
9. Third-Party Services
Docline uses the following third-party service providers. Each receives only the data necessary for its function:
- Google Calendar API — Receives OAuth tokens and calendar event payloads (titles, descriptions, times) when you request synchronization. Does not receive your uploaded documents or AI analysis input.
- DeepSeek — Receives text extracted from user-provided PDFs, HTML, and webpage content for date detection and PDF generation. Does not receive Google Calendar data, OAuth tokens, or Google profile information.
- Clerk — Receives email, name, and authentication credentials for account sign-up, sign-in, and session management.
- Supabase (PostgreSQL) — Stores account-linked application data: saved deadlines, bookmarks, encrypted Google OAuth tokens, subscription and usage records.
- Vercel — Hosts the Docline application and serverless API functions. Processes requests transiently during operation.
- Paddle — Processes subscription payments. Receives billing information you provide at checkout. Docline receives subscription status and customer IDs only.
Each provider maintains its own privacy policy. We encourage you to review them. We do not sell personal information to third parties.
10. Your Rights
Depending on where you live, you may have the following rights regarding your personal information:
Rights for users in the European Economic Area, United Kingdom, and Switzerland (GDPR)
You may have the right to access, rectify, erase, restrict processing, object to processing, and data portability. Our lawful bases for processing include performance of our contract with you, your consent (for optional Google Calendar connection), and our legitimate interests in operating and securing the Service. You may lodge a complaint with your local data protection authority. To exercise your rights, visit /delete-account, disconnect Google from your dashboard, or contact us.
Rights for California residents (CCPA/CPRA)
California residents have the right to know what personal information we collect, request deletion, correct inaccurate information, and opt out of the sale or sharing of personal information. Docline does not sell or share personal information for cross-context behavioral advertising. We do not use Google user data for advertising. To submit a request, contact us at the email below. We will verify your identity before processing requests.
Regardless of jurisdiction, you may download or delete your data by deleting your account, disconnecting Google Calendar, or contacting us for assistance.
11. Contact
For privacy questions, data access or deletion requests, Google user data inquiries, or Google OAuth verification questions, contact our privacy team at francoferreyr4@gmail.com.
12. Google Compliance Confirmation
Docline confirms the following with respect to Google user data:
- ✔ Google Calendar information never enters the AI pipeline.
- ✔ AI analyzes only user-provided content (webpages, HTML, URLs, and uploaded documents).
- ✔ Google Calendar information is never used to train AI models.
- ✔ Google Calendar information is never shared with AI providers.
- ✔ Google Calendar information is never sold.
- ✔ Google Calendar information is processed only to provide functionality explicitly requested by the user (calendar event synchronization).
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date. Material changes may be communicated via email or in-app notice. Continued use of Docline after changes constitutes acceptance of the updated Policy.