Privacy Policy
DocWallet Labs is built on a simple belief: your documents are yours. This policy explains what we collect, what we structurally cannot see, and the rights you hold over your data.
Effective date: 2026-07-07
1. Introduction
This Privacy Policy describes how DocWallet Labs (“DocWallet Labs,” “we,” “us,” or “our”) collects, uses, and protects information when you use the DocWallet mobile application (the “App”) and the informational website at docwalletlabs.com (the “Site”). Together, the App and the Site are the “Services.”
By creating an account or using the Services, you agree to the practices described in this Policy. If you do not agree, please discontinue use of the Services. We may update this Policy from time to time; when we do, we will revise the effective date above and, for material changes, notify you through the App or by email.
2. Information We Collect
We collect only what is necessary to operate the Services:
Account data. When you register, we collect your email address and a salted, one-way hash derived from your authentication credential. We do not store your passphrase in any recoverable form.
Device and usage metadata. We collect standard technical data such as your device model, operating system version, App version, IP address (for fraud prevention and rate-limiting), and coarse-grained usage signals (e.g., feature interactions, crash reports). This data is never linked to the content of your documents.
Subscription and billing data. Payment processing is handled entirely by our payment processor (Apple App Store / Google Play). We receive only a transaction confirmation and subscription status; we never see or store your payment card details.
Document content — what we do not collect.All documents, images, and metadata you store are encrypted on your device before they are transmitted to our servers. Our servers receive and store only ciphertext. We have no technical ability to access, read, or process the contents of your documents. See Section 4 for a full explanation of our zero-knowledge architecture.
3. How We Use Information
We use the information we collect for the following purposes:
- Service operation. To create and maintain your account, sync your encrypted vault across devices, manage family and single-document sharing tokens, and process subscription status.
- Security and abuse prevention. To detect and prevent unauthorized access, enforce rate limits, investigate potential violations of our Terms of Service, and maintain the integrity of the platform.
- Expiry notifications. To send push notifications or emails when a document expiry date you have entered is approaching. These notifications reference only document-slot labels (e.g., “Passport”) and dates — never the document content itself.
- Service communications. To send transactional emails (account confirmations, subscription receipts, security alerts). We do not send marketing email without your explicit consent.
- Product improvement. To diagnose crashes, understand aggregate feature usage, and improve reliability. All analytics are aggregated and de-identified; no individual document contents are ever involved.
4. Zero-Knowledge Architecture
DocWallet is built on a zero-knowledge model. This is not a marketing claim — it is a structural property of the system.
When you set up your vault, a master encryption key is generated on your device and wrapped by a key derived from your passphrase using a memory-hard key-derivation function. The wrapped key is stored on our servers solely so your vault can be restored when you sign in on a new device — but it can only be unwrapped on-device using a passphrase that we never receive.
Every document you store is encrypted on-device with your master key before any data leaves your phone. The ciphertext is what our servers store and sync. Neither DocWallet Labs employees, contractors, nor any third-party infrastructure provider can decrypt your documents, because none of them ever possesses your plaintext key.
Encrypted family sharing and single-document sharing work the same way: shared access is mediated by a per-share encryption layer negotiated between devices. Even if our servers were compromised, the attacker would obtain only ciphertext.
This architecture means that we cannot honor a demand (including a lawful government demand) to produce plaintext document contents — there is simply nothing to produce. We can only provide account metadata (email address, subscription status, ciphertext blobs, timestamps) if legally compelled.
5. Data Sharing & Third Parties
We do not sell, rent, or trade your personal information to anyone, ever.
We share limited data only with the following categories of service providers, each of whom is bound by data processing agreements:
- Cloud infrastructure. We use third-party cloud providers for hosting, object storage (encrypted ciphertext only), and managed database services. These providers never access your plaintext document contents.
- Push notification providers. Apple APNs and Google FCM are used to deliver expiry and sharing notifications to your device. Only a device token and a notification payload (never document content) are transmitted.
- Error monitoring. Crash reports and error traces may be processed by an error-monitoring provider. These reports are sanitized to exclude any user-identifiable document data before transmission.
- Legal compliance. We may disclose account metadata (not document content — see Section 4) if required by a valid legal process, court order, or to protect the rights and safety of DocWallet Labs or others. We will notify affected users when legally permitted to do so.
6. Data Retention & Deletion
We retain your account data and encrypted vault for as long as your account is active. If you delete your account, we will delete your account record, encrypted vault, and associated metadata within 30 days, except where retention is required by applicable law or legitimate fraud-prevention obligations.
You can initiate account deletion at any time from within the App settings. Because your documents are encrypted, deletion of your account means the ciphertext stored on our servers becomes permanently inaccessible.
Aggregate, de-identified analytics data (with no link to any individual account) may be retained indefinitely for product analytics purposes.
7. Security
Security is the core purpose of DocWallet, not an afterthought. In addition to the zero-knowledge encryption described in Section 4, we maintain the following safeguards:
- All data in transit is protected by TLS 1.2 or higher.
- All data at rest is encrypted at the storage layer by our cloud provider, in addition to the end-to-end encryption we apply.
- Access to production systems is restricted to a minimal set of authorized personnel and gated by multi-factor authentication.
- We perform periodic security reviews of our codebase and infrastructure.
No system is perfectly secure. If you believe you have discovered a security vulnerability, please disclose it responsibly tosupport@docwalletlabs.com.
8. Children's Privacy
DocWallet is not directed to children under the age of 13. We do not knowingly collect personal information from anyone under 13. If you believe we have inadvertently collected data from a child under 13, please contact us immediately atsupport@docwalletlabs.comand we will promptly delete that information.
Certain sensitive document categories (e.g., financial and employment records) are intended for users aged 18 and older. We reserve the right to terminate accounts found to be in violation of these age restrictions.
9. International Data Transfers
DocWallet Labs is headquartered in the United States. If you access the Services from outside the United States, your account metadata (email address, subscription status, encrypted vault ciphertext) may be transferred to and processed in the United States or other countries where our service providers operate.
For users in the European Economic Area (EEA), the United Kingdom, or Switzerland, such transfers are carried out in accordance with applicable data protection law — including, where required, by relying on Standard Contractual Clauses (SCCs) approved by the European Commission. Because document content is end-to-end encrypted and we cannot decrypt it, the practical privacy risk of any such transfer is limited to account metadata only.
10. Your Rights
Depending on your jurisdiction, you may have the following rights with respect to your personal data:
- Access. You may request a copy of the personal data we hold about you (account metadata, usage logs).
- Rectification. You may correct inaccurate personal data directly in the App or by contacting us.
- Erasure / Right to be forgotten. You may request deletion of your account and associated data (see Section 6).
- Portability. You may export your encrypted vault from within the App at any time. We will also provide account metadata in a machine-readable format upon request.
- Objection and restriction. You may object to or request restriction of certain processing activities.
- Withdrawal of consent. Where processing is based on your consent (e.g., optional analytics), you may withdraw that consent at any time without affecting the lawfulness of prior processing.
- CCPA / California residents. California residents have the right to know what personal information we collect, the right to delete it, and the right to opt out of its sale. We do not sell personal information, so there is nothing to opt out of. To exercise any other right, contact us atsupport@docwalletlabs.com.
To exercise any of these rights, emailsupport@docwalletlabs.com. We will respond within 30 days (or the period required by applicable law). We may need to verify your identity before fulfilling a request.
11. Cookies & Analytics
The informational website at docwalletlabs.com uses only essential first-party cookies required for basic site functionality (e.g., session continuity). We do not use third-party advertising cookies or tracking pixels.
The App does not use browser cookies. Aggregate, de-identified analytics data may be collected through the App to understand feature usage patterns and improve reliability. This data does not include document contents and cannot be linked back to your identity.
If we ever add non-essential analytics to the Site, we will obtain your consent through a cookie-consent mechanism before activating them.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes — changes that meaningfully affect your rights or our data practices — we will provide notice by updating the effective date at the top of this page, by posting a notice in the App, or by emailing the address associated with your account.
Your continued use of the Services after the effective date of an updated Policy constitutes acceptance of the changes. If you do not agree to a material change, you may delete your account before the change takes effect.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or how DocWallet Labs handles your data, please contact our Privacy team:
DocWallet LabsEmail:support@docwalletlabs.com
Website:docwalletlabs.com
For users in the EEA, you also have the right to lodge a complaint with your local data protection authority if you believe our processing of your personal data violates applicable law.