Privacy Policy

Last updated: August 11, 2026

Your trust matters. This policy explains what we collect, why, and the choices you have. In short: we collect what we need to run DocSemantic, we don’t sell your data, and you can ask us to delete it.

01. Scope of this policy

This Privacy Policy explains how AUSPRO PTY LTD (“DocSemantic,” “we,” or “us”) collects, uses, shares, and protects information when you use our service, CLI, APIs, and website (the “Service”). It applies to information about account holders and visitors. Our processing of data you send us on behalf of your organization is also governed by your Terms of Service.

02. Information we collect

We collect the following categories of information:

  • Account information — your name, email address, hashed password, team role, and subscription tier.
  • Service content you submit — API specifications, live traffic samples, drift history, and configuration you send to us so the Service can detect drift.
  • Integration data — tokens and identifiers for services you connect, such as GitHub, Slack, Datadog, or Sentry.
  • Billing information — subscription status and billing metadata. Card details are collected and stored by Stripe, not by us.
  • Usage and device data — log data, IP address, approximate location, and analytics about how the Service is used.

Please do not send us traffic samples or specifications that contain sensitive personal data unless expressly agreed in writing. You control what data you transmit to the Service.

03. How we use information

We use information to:

  • Provide, operate, and secure the Service, including drift detection, alerts, and auto-fix pull requests.
  • Authenticate you, manage your workspace, and enforce plan entitlements and rate limits.
  • Process payments and manage subscriptions.
  • Send transactional messages such as alerts, invites, and account notices.
  • Monitor, debug, and improve the Service and develop new features.
  • Comply with legal obligations and enforce our Terms.

04. AI processing

Some features generate explanations or suggested fixes using AI models. When you use those features, the relevant specification or drift context may be processed by our AI provider(s) to produce output. We do not use your Customer Data to train third-party foundation models, and we configure providers to process data only to return results to you.

06. How we share information

We do not sell your personal information. We share information only with service providers (“subprocessors”) that process data on our behalf, with third-party services you choose to connect, and where required to comply with law or protect our rights. We may also transfer information in connection with a merger, acquisition, or sale of assets, subject to this policy.

07. Subprocessors

We rely on the following providers to operate the Service:

ProviderPurpose
NeonDatabase hosting (account data, specs, drift history)
VercelApplication hosting, edge delivery, and analytics
UpstashRate limiting and ephemeral operational state
StripeSubscription billing and payment processing
ResendTransactional and notification email delivery

We update this list as our infrastructure evolves. Where required, subprocessors are bound by data-processing agreements consistent with applicable law.

08. Data retention

We retain account information for as long as your account is active and as needed to provide the Service. Drift-history retention depends on your plan. We may retain limited information as necessary to comply with legal obligations, resolve disputes, and enforce our agreements, after which it is deleted or anonymized. You can request deletion of your account and associated data as described below.

09. Security

We use administrative, technical, and organizational measures to protect information, including encryption in transit, hashed passwords, scoped API keys, and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

10. Your rights

Depending on where you live (for example under GDPR or the CCPA/CPRA), you may have rights to access, correct, delete, or port your personal data, to object to or restrict certain processing, and to opt out of the “sale” or “sharing” of personal information (we do not sell or share it for cross-context behavioral advertising).

To exercise these rights, use our contact form and choose the privacy topic. We will respond as required by applicable law. You may also have the right to lodge a complaint with your local data protection authority.

11. Cookies

We use strictly necessary cookies to keep you signed in and to secure the Service, and limited analytics to understand usage. You can control cookies through your browser settings; disabling necessary cookies may prevent you from signing in.

12. International transfers

We and our subprocessors may process information in countries other than yours. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers of personal data.

13. Children

The Service is intended for use by developers and organizations and is not directed to children under 16. We do not knowingly collect personal data from children.

14. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice.

15. Contact

For privacy questions or requests, use our contact form. The data controller is AUSPRO PTY LTD (ABN 41 687 962 607), Melbourne, VIC, Australia.