Privacy Policy
Last updated: August 11, 2026
Your trust matters. This policy explains what we collect, why, and the choices you have. In short: we collect what we need to run DocSemantic, we don’t sell your data, and you can ask us to delete it.
01. Scope of this policy
This Privacy Policy explains how AUSPRO PTY LTD (“DocSemantic,” “we,” or “us”) collects, uses, shares, and protects information when you use our service, CLI, APIs, and website (the “Service”). It applies to information about account holders and visitors. Our processing of data you send us on behalf of your organization is also governed by your Terms of Service.
02. Information we collect
We collect the following categories of information:
- Account information — your name, email address, hashed password, team role, and subscription tier.
- Service content you submit — API specifications, live traffic samples, drift history, and configuration you send to us so the Service can detect drift.
- Integration data — tokens and identifiers for services you connect, such as GitHub, Slack, Datadog, or Sentry.
- Billing information — subscription status and billing metadata. Card details are collected and stored by Stripe, not by us.
- Usage and device data — log data, IP address, approximate location, and analytics about how the Service is used.
Please do not send us traffic samples or specifications that contain sensitive personal data unless expressly agreed in writing. You control what data you transmit to the Service.
03. How we use information
We use information to:
- Provide, operate, and secure the Service, including drift detection, alerts, and auto-fix pull requests.
- Authenticate you, manage your workspace, and enforce plan entitlements and rate limits.
- Process payments and manage subscriptions.
- Send transactional messages such as alerts, invites, and account notices.
- Monitor, debug, and improve the Service and develop new features.
- Comply with legal obligations and enforce our Terms.
04. AI processing
Some features generate explanations or suggested fixes using AI models. When you use those features, the relevant specification or drift context may be processed by our AI provider(s) to produce output. We do not use your Customer Data to train third-party foundation models, and we configure providers to process data only to return results to you.
05. Legal bases (EEA/UK)
If you are in the EEA or UK, we process personal data on the following bases: performance of a contract (to provide the Service), our legitimate interests (to secure and improve the Service), consent (where required, e.g. certain cookies), and compliance with legal obligations.
07. Subprocessors
We rely on the following providers to operate the Service:
| Provider | Purpose |
|---|---|
| Neon | Database hosting (account data, specs, drift history) |
| Vercel | Application hosting, edge delivery, and analytics |
| Upstash | Rate limiting and ephemeral operational state |
| Stripe | Subscription billing and payment processing |
| Resend | Transactional and notification email delivery |
We update this list as our infrastructure evolves. Where required, subprocessors are bound by data-processing agreements consistent with applicable law.
08. Data retention
We retain account information for as long as your account is active and as needed to provide the Service. Drift-history retention depends on your plan. We may retain limited information as necessary to comply with legal obligations, resolve disputes, and enforce our agreements, after which it is deleted or anonymized. You can request deletion of your account and associated data as described below.
09. Security
We use administrative, technical, and organizational measures to protect information, including encryption in transit, hashed passwords, scoped API keys, and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
10. Your rights
Depending on where you live (for example under GDPR or the CCPA/CPRA), you may have rights to access, correct, delete, or port your personal data, to object to or restrict certain processing, and to opt out of the “sale” or “sharing” of personal information (we do not sell or share it for cross-context behavioral advertising).
To exercise these rights, use our contact form and choose the privacy topic. We will respond as required by applicable law. You may also have the right to lodge a complaint with your local data protection authority.
12. International transfers
We and our subprocessors may process information in countries other than yours. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers of personal data.
13. Children
The Service is intended for use by developers and organizations and is not directed to children under 16. We do not knowingly collect personal data from children.
14. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice.
15. Contact
For privacy questions or requests, use our contact form. The data controller is AUSPRO PTY LTD (ABN 41 687 962 607), Melbourne, VIC, Australia.