Privacy policy
This policy explains what Dr. AI collects, why, who can see it, and what you can ask us to do about it. It is written to be read, not to be survived.
Last updated 1 Aug 2026
1.The short version
We collect what we need to run an order and nothing we do not. Your documents are encrypted before storage and are readable only by the reviewer assigned to your order and, if you open a dispute, by an administrator.
Your name, email address and phone number are never shown to the other party in an order. Documents entering the shared workspace have author metadata removed first. You can ask for a copy of your data, or its deletion, at any time.
2.What we collect
- Account details: your name, email address, an optional phone number, country, time zone, and a password stored only as an Argon2id hash.
- Order content: the documents you upload, your instructions, the reports produced, and the workspace messages exchanged.
- Reviewer records: for reviewer accounts, the professional profile, evidence of licensed software access, and payout account details (encrypted at rest).
- Financial records: deposits, order payments, payouts, invoices, and the ledger entries behind your wallet balance.
- Technical records: IP address, browser user-agent, session activity, and an audit trail of actions that affect money, files or access.
3.Why we process it
- To perform the contract: creating and matching orders, delivering reports, and handling payment.
- To meet legal obligations: keeping financial and tax records for the period required by law.
- For legitimate interests: preventing fraud and abuse, enforcing our acceptable-use rules, resolving disputes, and keeping the service secure and available.
- With your consent, where you have opted in: product announcements and other non-essential email.
4.How your documents are handled
Every uploaded file is scanned, then encrypted with AES-256-GCM before it reaches storage. The initialisation vector and authentication tag are stored on the file record, separately from the payload, and integrity is verified on every read. Keys come from application configuration and are never written alongside the files.
When a reviewer accepts your order, we create a workspace copy with author, company, custom-property and tracked-change identity fields removed. The reviewer only ever sees that copy. Your original remains available to you.
We do not submit your document to any similarity repository. Reviewers are required, as a condition of approval, to run checks in a mode that does not add your work to a repository.
5.Anonymity between clients and reviewers
Inside an order, you and your reviewer are identified only by workspace handles such as "Client C-4821". The database queries that render the workspace do not select name, email or phone, so there is no path by which one side can be shown to the other.
Workspace messages are filtered before they are stored: email addresses, phone numbers, messaging-app handles, external links and off-platform payment requests are replaced. The unfiltered text is never written to the database.
7.How long we keep things
- Order documents and reports: for the life of your account, so you can return to them. Delete an order's files at any time from the order page.
- Unattached uploads: deletable immediately, and removed automatically if never attached to an order.
- Financial records and invoices: retained for the statutory period, even after account closure.
- Audit and security logs: 24 months.
- Session records: until expiry or revocation, then pruned.
8.Your rights
Wherever you are, we apply the same set of rights: access, correction, deletion, export, restriction, objection, and withdrawal of consent for optional processing. Use the contact form and choose "Privacy or data request", or manage most of it directly in your account settings.
We respond within 30 days. If we cannot fulfil a request in full — for example because we must keep a financial record — we will tell you which part we are keeping and why.
9.Security measures
- Passwords hashed with Argon2id; no reversible storage of credentials.
- Optional TOTP two-factor authentication, required for administrators and for withdrawals.
- Server-side sessions that can be revoked individually or all at once, with a sliding idle expiry and a hard maximum lifetime.
- Rate limiting on authentication, uploads, messaging and withdrawals.
- Malware scanning on every upload, with macro-enabled documents rejected outright.
- Encryption at rest for documents, TOTP secrets, payout account details and licence references.
- An append-only audit log covering every action that touches money, files or access.
10.International transfers
Our reviewers and infrastructure are international, so your data may be processed outside your country. Where that happens we rely on appropriate safeguards, including standard contractual clauses with our processors.
11.Age
Dr. AI is not intended for anyone under 16. If we learn that an account belongs to someone under 16 we close it and delete the associated data.
12.Changes to this policy
We will post any change here and update the date above. For changes that materially affect how we handle your documents or personal data, we will notify account holders directly before the change takes effect.
This document describes the platform's data-handling design. Before operating Dr. AI commercially, have it reviewed by a qualified legal adviser for your jurisdiction and adjust the retention periods, lawful bases and contact details to match your actual arrangements.