Legal · Privacy Policy

Company / Privacy · FIG.P

Privacy Policy

How Docframe handles account data, repository access, uploads, and generated documentation. Last updated August 1, 2026.

Terms of Service →

1. Overview

This Privacy Policy explains how Docframe, Inc. (“Docframe,” “we,” “us”) collects, uses, and shares information when you use docframe.ai, docs.docframe.ai, our APIs, CLI, and related services (the “Service”).

We build a documentation engine for codebases. We aim to collect only what we need to operate accounts, generate and host docs, improve the product, and meet legal obligations.

2. Information we collect

Account data: GitHub identity (such as username, avatar, and email if provided by GitHub), OAuth tokens scoped to repositories you authorize, and plan/billing identifiers from our payment processor.

Customer Content: repository metadata and file contents you authorize us to read for generation; uploaded PDF, DOCX, or HTML zip files; generated documentation (docs.json / site content); and chat edit prompts you submit.

Usage data: product interactions, job statuses, approximate device/browser information, IP address, and diagnostic logs needed to operate and secure the Service.

Communications: messages you send to hello@, support@, or other Docframe addresses.

3. How we use information

Provide the Service: authenticate you, analyze authorized sources, generate and store documentation manifests, render published sites, process exports, and meter AI credits.

Secure and maintain the Service: detect abuse, debug failures, and monitor reliability.

Communicate with you: transactional email, security notices, and (with consent where required) product updates.

Improve the product: aggregated and de-identified analytics about feature usage. We do not sell personal information.

4. AI processing

When you use AI generation or editing features, relevant snippets of Customer Content and your prompts may be sent to subprocessors that provide large language model inference.

We configure providers not to use your content to train their models where the provider offers that control. You should avoid submitting secrets in chat prompts.

5. How we share information

Service providers: hosting, databases, analytics, email, payment processing, and AI inference providers under contractual obligations.

Public publish: if you publish documentation, the published pages and assets are available to anyone with the link (or more broadly if indexed).

Legal: when required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset sale with appropriate safeguards.

6. Retention

We retain account and project data while your account is active and as needed to provide the Service. You may delete projects in-product; residual backups may persist for a limited period.

Published sites remain available until you unpublish or delete them, or your account is closed subject to plan limits.

Logs and security records are retained for operational periods appropriate to investigating incidents.

7. Security

We use industry-standard measures appropriate to the nature of the data, including transport encryption (TLS), access controls, and least-privilege practices for production systems.

No method of transmission or storage is perfectly secure. Report suspected vulnerabilities to security@docframe.ai.

8. Your rights

Depending on your location, you may have rights to access, correct, delete, or export personal data, or to object to or restrict certain processing.

To exercise rights, contact privacy@docframe.ai. You may also revoke GitHub OAuth access from your GitHub settings.

If you are in the EEA/UK, Docframe is the controller for personal data described here unless otherwise stated. You may lodge a complaint with a supervisory authority.

9. International transfers

We may process data in the United States and other countries where we or our subprocessors operate. Where required, we use appropriate transfer mechanisms such as Standard Contractual Clauses.

10. Children

The Service is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided data, contact us and we will delete it.

11. Cookies and similar technologies

We use necessary cookies and local storage for authentication sessions and preferences (such as theme). We may use privacy-respecting analytics. You can control cookies through your browser settings.

12. Changes

We may update this Privacy Policy periodically. We will post the updated policy on this page with a new effective date. Material changes may be communicated by email or in-product notice.

13. Contact

Privacy questions: privacy@docframe.ai. General contact: hello@docframe.ai or our Contact page.

© 2026 Docframe, Inc. All rights reserved.