Privacy Policy

Last updated: July 30, 2026

1. Controller

The controller for data processing under the GDPR is:
Enock Aimé Jodelle Yonkeu Nyabeo, Bettenstrasse 90, 4123 Allschwil, Switzerland
Email: support@docriva.com

We have not appointed a data protection officer, as the legal requirements for doing so are not met.

2. Representative in the European Union

As we are based in Switzerland and therefore outside the EU, while our service is also directed at people in the EU, we have designated a representative in the Union under Art. 27 GDPR:

Cedric Ngonthe
Schulstr. 8a
58095 Hagen
Germany

For any data protection matter you may contact either our representative or us directly at support@docriva.com.

3. What data do we process?

Account data: email address and password (stored only as a cryptographic hash, via Supabase Auth). If you sign in with Google or Apple, additionally the email address and, where applicable, the name provided by them.

Documents: documents you upload or scan (PDFs, photos), stored in Supabase Storage.

Analysis results: extracted text, classification, summary, reply drafts and answers to the questions you ask about a document.

Metadata: document title, category, tags, deadlines, folder assignment, calendar entries.

Usage data: the number of documents analysed in the current month (to check your plan quota) and your subscription status.

Payment data for your subscription: for paid plans, our payment provider processes the payment details. We ourselves never receive card details, only the payment status and the term of your subscription.

Payment details contained in your documents: If the analysis finds payment information in a document – such as IBAN, BIC, recipient name, payment reference, amount, due date or the method of payment (bank transfer, direct debit, already paid) – we store it as part of the analysis results; the same applies to a phone number or email address contained in the document. It serves display purposes only: Docriva does not initiate payments and passes this information neither to a bank nor to a payment provider. Tapping a recognised phone number or email address merely opens your device’s phone or email app; whether you actually place the call or send the message is your decision there. Such details often concern a third party – the sender of an invoice, for instance – and are subject to the same safeguards and deletion periods as the rest of a document’s content.

Error data: in the event of technical faults, error messages and technical context (e.g. device type, app version) are sent to our error monitoring. Personal data such as IP address, cookies or user identifiers are deliberately not transmitted.

Beta signup: if you sign up as a tester we process your email address plus the optional details you provide about your name, device, platform and intended use. The legal basis is your consent under Art. 6(1)(a) GDPR, which you can withdraw at any time by writing to support@docriva.com. To distribute the test build we pass your email address to Google Play or Apple TestFlight. We delete these details once the test phase ends.

4. Special categories of personal data

Docriva lets you store any kind of document – including particularly sensitive ones such as doctor's letters, medical findings or prescriptions (health data within the meaning of Art. 9 GDPR).

We process such data solely because you upload it and thereby explicitly instruct us to process it. The legal basis is your explicit consent under Art. 9(2)(a) GDPR, which you give by uploading such a document and can withdraw at any time by deleting the document or your account.

Please note: for these documents too, the recognised text is sent to our providers for text recognition and AI analysis (see sections 6 and 8). If you do not want this, please do not upload such documents.

5. Purposes and legal bases

  • Providing the service (account, storage, analysis, deadline management, synchronisation) – Art. 6(1)(b) GDPR (performance of the user agreement).
  • Sign-in with Google or Apple – Art. 6(1)(b) GDPR; using these sign-in options is voluntary.
  • Handling subscriptions and payments – Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR for statutory tax and commercial retention duties.
  • Security and abuse prevention (including quota checks and blocking in cases of misuse) – Art. 6(1)(f) GDPR; our legitimate interest lies in stable, abuse-free operation.
  • Error monitoring to keep the service stable – Art. 6(1)(f) GDPR; legitimate interest in fixing faults.
  • Documents with sensitive content – additionally Art. 9(2)(a) GDPR (see section 4).

6. How is data processed?

  • Text recognition (OCR): photos and PDF pages are sent to the Google Cloud Vision API for text recognition, via its European endpoint – processing therefore takes place in the EU. Only the extracted text is then stored.
  • AI analysis: the extracted text (max. 40,000 characters per request) is sent for analysis to the API of Mistral AI, a French company. Processing takes place within the European Economic Area. The use of your data to train AI models is switched off in our Mistral account.
  • Storage: all data is held at Supabase (database + storage), protected by Row Level Security.
  • Synchronisation: in the web app your documents always reside in the cloud and can be accessed from any device you sign in on. In the mobile app, documents are initially stored only locally on the device; an encrypted cloud backup – and thus synchronisation with the web app – only takes place on the Premium and Pro plans.
  • Deadline reminders: reminders are scheduled as local notifications directly on your device. No data is transmitted to a push service for this.
  • Where processing happens: text recognition, AI analysis, database, file storage and our server functions are located in the EU or the European Economic Area. The contents of your documents are processed and stored there only.

7. Data security

  • Encrypted transmission: all data is transmitted via TLS/HTTPS.
  • Encryption on the server: Supabase encrypts stored data at rest (AES-256).
  • Encrypted cloud backup: document contents from the mobile app are additionally encrypted with AES-256-GCM before upload. The key used is managed server-side per user. This is therefore not end-to-end encryption: if our server environment were fully compromised, decryption would be technically possible.
  • Access control: Row Level Security ensures that no other user can access your data.
  • Administrative access: for support, billing and abuse prevention there is an administrative access path through which account and subscription data as well as the file storage can be accessed to a limited extent. Such access is logged.
  • API keys: all provider keys are held server-side only and are not visible to users.

8. Recipients / processors

  • Supabase (auth, database, storage, server functions) – hosted in the EU region Frankfurt
  • Google Cloud Vision (OCR) – for text recognition from photos and PDFs, via the service's European endpoint
  • Google (sign-in) – optional registration and login with a Google account. Google learns that you are signing in to Docriva; we receive your email address and name.
  • Apple (sign-in) – optional registration and login with an Apple ID. If you choose “Hide My Email”, we only receive an anonymised relay address.
  • Mistral AI (AI analysis) – for document analysis. A French company; processing takes place within the European Economic Area. Training use is switched off in our account.
  • RevenueCat (In-App Purchases) – for subscription management in the mobile app
  • Stripe (payment processing) – for web app subscriptions. Payment takes place on a Stripe-hosted page; card details never reach our servers.
  • Vercel (hosting) – for the web application and the website; the server functions run in the Frankfurt region
  • Cloudflare (DNS) – name resolution for the docriva.com domain
  • Sentry (error monitoring) – to diagnose crashes and technical errors in the web and mobile apps. We use Sentry's EU region and have disabled the transmission of personal data.
  • Resend (email delivery) – for service emails such as the confirmation of a cancellation. Sending runs through the EU region (Ireland).

We have data processing agreements under Art. 28 GDPR in place with every provider listed above that processes personal data on our behalf. Under those agreements they are bound to process the data solely on our instructions and for the purposes described here, not to use it for their own purposes – in particular not to train AI models – and to maintain a level of protection equivalent to the one described in this policy.

9. Transfers to third countries

The processing of your documents takes place entirely within the EU or the European Economic Area: Supabase (database, file storage, server functions) in Frankfurt, text recognition via the European endpoint of Google Cloud Vision, AI analysis at Mistral AI in France, hosting of the web application at Vercel in Frankfurt, and Sentry and Resend in their EU regions.

Some of the providers listed in section 8 are based in the USA – Google and Apple (sign-in), Stripe (payment processing), RevenueCat (in-app purchases) and Cloudflare (DNS). None of them receives the contents of your documents; what they process is account, subscription and connection data. Google (text recognition) as well as Microsoft and Google as infrastructure providers to Mistral AI are US companies too – but they operate the services we use in European data centres.

Such transfers take place on the basis of the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR and – where the provider is certified accordingly – on the basis of the EU-US Data Privacy Framework under Art. 45 GDPR. Despite these safeguards, access to transferred data by authorities in the third country cannot be entirely excluded.

10. Retention periods

  • Account, documents, analyses and metadata: until you delete them or your account. Deleting your account removes them irreversibly.
  • Text sent for analysis: our providers process it to answer the respective request; according to their statements it is not stored permanently for their own purposes.
  • Invoicing and payment data: up to ten years due to commercial and tax retention obligations (Art. 958f Swiss Code of Obligations).
  • Error data: in line with our monitoring provider's standard retention of typically 90 days.
  • Logs of administrative access: for as long as required for traceability and abuse prevention.

11. Availability across platforms

Docriva is available as a web app and as a mobile app (Android and iOS). The extent to which data is synchronised between platforms depends on your plan (see section 6).

12. No automated decision-making

The AI analysis serves only to prepare your documents for you. There is no automated decision within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you. Results may be incorrect and must be checked by you.

13. Minors

Docriva is aimed at adults. Under our Terms of Service, use is permitted from the age of 18, or for minors with the consent of a parent or guardian. If we become aware that an account was created without the required consent, we will delete it.

14. Your rights

  • Access (Art. 15 GDPR): you may request information about the data we store about you at any time. Settings → “Download my data” gives you that information immediately and directly.
  • Rectification (Art. 16 GDPR): you may have inaccurate data corrected; many details can be changed directly in the app.
  • Erasure (Art. 17 GDPR): you can delete your account and all data at any time in the settings. Without the app and without logging in, use our account deletion form.
  • Restriction of processing (Art. 18 GDPR).
  • Data portability (Art. 20 GDPR): Settings → “Download my data” gives you everything stored about your account, including your document files, as a ZIP archive – on every plan, free of charge.
  • Objection (Art. 21 GDPR): you may object to processing that we base on a legitimate interest.
  • Withdrawal of consent (Art. 7(3) GDPR): you can withdraw consent at any time with effect for the future.
  • Complaint to a supervisory authority (Art. 77 GDPR): you may lodge a complaint with the data protection authority responsible for your place of residence or for us.

An email to support@docriva.com is enough to exercise your rights.

15. Is providing data required?

An email address is required to create an account; without it we cannot provide the service. Uploading documents is voluntary – but without documents Docriva cannot fulfil its core function.

16. Contact

For privacy questions: support@docriva.com