Privacy Policy

Last updated: 2026-08-18

This Privacy Policy describes how CheckMyDoc (“we,” “our,” or “us”) collects, uses, and shares personal data when you visit our website, sign up for an account, or use our contract-review service. We've tried to write this in plain English. Where we use a defined term (like “Personal Data”), we mean the same thing the relevant law means.

1. Who is the controller

CheckMyDoc is the controller of personal data we collect about visitors to our website and account holders. For documents that team accounts upload for review, the customer team is the controller and CheckMyDoc is the processor — that relationship is governed by our Data Processing Addendum.

2. What we collect

From visitors

  • IP address, user agent, referrer, and pages viewed — for security, abuse prevention, and aggregate analytics.
  • Cookies described in § 7 below, including a session cookie set by Auth.js if you sign in.

From account holders

  • Name and email address you provide at signup.
  • Authentication metadata (last sign-in time, provider used, OAuth account ID for Google sign-in).
  • Team membership and role — owner, admin, or member — for any team you join or create.
  • Billing information handled by Flitt, our payment processor. We store the order and subscription identifiers Flitt returns, the plan, and the subscription status. Card details are submitted from your browser directly to Flitt — we never receive or store card numbers.

From documents you upload

  • The contracts you upload, plus any extracted text we generate while processing them.
  • Filename, MIME type, byte size, and the team / user who uploaded it.
  • Findings, redline suggestions, and risk scores produced by our AI pipeline, stored alongside the source document.
  • Audit-log entries recording every read, write, role change, and deletion, with the actor, IP address, user agent, and timestamp.

3. How we use it

  • To provide the service — classify, review, and store the documents you upload.
  • To send transactional email about your account, your reviews, and changes to the service. We do not send marketing email by default.
  • To authenticate you, prevent abuse, and keep audit logs for security investigations.
  • To improve the product in aggregate — including measuring usage patterns, monitoring error rates, and tracking conversion funnels via PostHog. We do not feed your contracts back into AI model training, and we do not sell or share your data with third parties for marketing.

4. Legal bases (for EEA / UK residents)

  • Contract— we process your account information and the documents you submit because we need to in order to deliver the service you signed up for.
  • Legitimate interests— security logs, fraud prevention, and aggregate product analytics. You can object via privacy@checkmydoc.co.
  • Consent— non-essential cookies and any future marketing communications. You can withdraw consent at any time.
  • Legal obligation— financial records and tax-related billing data we're required to retain.

5. Sub-processors and sharing

We rely on a small list of sub-processors to deliver the service. The current list is published at checkmydoc.co/security and reproduced in our DPA. We do not sell personal data. We may disclose data when required by law, in response to valid legal process, or to protect the rights and safety of our users and the public.

6. International transfers

Our application and database are hosted in the European Union (Railway, EU West), and documents stay on that infrastructure up to the point of AI analysis.

Some sub-processors do process data outside the EU — notably the AI model provider (United States), and our transactional email, error-monitoring, and analytics tools. For those transfers we rely on the European Commission's 2021 Standard Contractual Clauses and conduct a Transfer Impact Assessment. If you access the service from outside the EU, your data is still processed on the EU infrastructure described above.

7. Cookies

  • Strictly necessary— the Auth.js session cookie that keeps you signed in.
  • Analytics and marketing— PostHog cookies to understand how the product is used, and tags delivered through Google Tag Manager. Google Tag Manager loads on every page but operates under Google Consent Mode: analytics and advertising storage stay denied until you accept the cookie banner, and are set to denied again if you decline. You can disable these in your browser without losing functionality.
  • Error monitoring— Sentry sets cookies and stores breadcrumbs to help us diagnose crashes.

8. How we store and secure it

Documents are stored in Cloudflare R2 with AES-256 encryption at rest. Our database is Postgres on Railway with encrypted volumes. All traffic between the browser, our servers, and our sub-processors uses TLS 1.2 or higher. Access to the production environment is restricted to a small number of engineers and recorded in audit logs.

9. How long we keep it

  • Documents and reviews: retained for the life of your team account, plus a 30-day purge window after a hard-delete request or account closure.
  • Audit logs: retained for 24 months from creation.
  • Billing records: retained for 7 years to satisfy financial and tax-record obligations.
  • Marketing email opt-outs: retained indefinitely so we know never to contact you again.

10. Your rights

Depending on where you live, you have the right to access, correct, port, or delete personal data we hold about you, and to object to or restrict certain processing. You also have the right to lodge a complaint with your local supervisory authority. To exercise any of these rights, email privacy@checkmydoc.cofrom the address on file and we'll respond within 30 days.

For California residents: you have the right to know what we collect, the right to delete, and the right not to be discriminated against for exercising those rights. We do not sell or share personal data as those terms are defined under the CCPA.

11. Children

CheckMyDoc is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Changes

We may update this policy as the service evolves. When we make material changes, we'll update the “Last updated” date at the top and, for changes that affect your rights, send a notification email to account holders.

13. Contact

Email privacy@checkmydoc.cowith privacy questions, data-subject requests, or anything that's confusing here. For general support, email hello@checkmydoc.co.