DocWallet
Legal

Privacy Policy

DocWallet Labs is built on a simple belief: your documents are yours. This policy explains what we collect, what we structurally cannot see, and the rights you hold over your data.

Effective date: 2026-07-07

1. Introduction

This Privacy Policy describes how DocWallet Labs (“DocWallet Labs,” “we,” “us,” or “our”) collects, uses, and protects information when you use the DocWallet mobile application (the “App”) and the informational website at docwalletlabs.com (the “Site”). Together, the App and the Site are the “Services.”

By creating an account or using the Services, you agree to the practices described in this Policy. If you do not agree, please discontinue use of the Services. We may update this Policy from time to time; when we do, we will revise the effective date above and, for material changes, notify you through the App or by email.

2. Information We Collect

We collect only what is necessary to operate the Services:

Account data. When you register, we collect your email address and a salted, one-way hash derived from your authentication credential. We do not store your passphrase in any recoverable form.

Device and usage metadata. We collect standard technical data such as your device model, operating system version, App version, IP address (for fraud prevention and rate-limiting), and coarse-grained usage signals (e.g., feature interactions, crash reports). This data is never linked to the content of your documents.

Subscription and billing data. Payment processing is handled entirely by our payment processor (Apple App Store / Google Play). We receive only a transaction confirmation and subscription status; we never see or store your payment card details.

Document content — what we do not collect.All documents, images, and metadata you store are encrypted on your device before they are transmitted to our servers. Our servers receive and store only ciphertext. We have no technical ability to access, read, or process the contents of your documents. See Section 4 for a full explanation of our zero-knowledge architecture.

3. How We Use Information

We use the information we collect for the following purposes:

4. Zero-Knowledge Architecture

DocWallet is built on a zero-knowledge model. This is not a marketing claim — it is a structural property of the system.

When you set up your vault, a master encryption key is generated on your device and wrapped by a key derived from your passphrase using a memory-hard key-derivation function. The wrapped key is stored on our servers solely so your vault can be restored when you sign in on a new device — but it can only be unwrapped on-device using a passphrase that we never receive.

Every document you store is encrypted on-device with your master key before any data leaves your phone. The ciphertext is what our servers store and sync. Neither DocWallet Labs employees, contractors, nor any third-party infrastructure provider can decrypt your documents, because none of them ever possesses your plaintext key.

Encrypted family sharing and single-document sharing work the same way: shared access is mediated by a per-share encryption layer negotiated between devices. Even if our servers were compromised, the attacker would obtain only ciphertext.

This architecture means that we cannot honor a demand (including a lawful government demand) to produce plaintext document contents — there is simply nothing to produce. We can only provide account metadata (email address, subscription status, ciphertext blobs, timestamps) if legally compelled.

5. Data Sharing & Third Parties

We do not sell, rent, or trade your personal information to anyone, ever.

We share limited data only with the following categories of service providers, each of whom is bound by data processing agreements:

6. Data Retention & Deletion

We retain your account data and encrypted vault for as long as your account is active. If you delete your account, we will delete your account record, encrypted vault, and associated metadata within 30 days, except where retention is required by applicable law or legitimate fraud-prevention obligations.

You can initiate account deletion at any time from within the App settings. Because your documents are encrypted, deletion of your account means the ciphertext stored on our servers becomes permanently inaccessible.

Aggregate, de-identified analytics data (with no link to any individual account) may be retained indefinitely for product analytics purposes.

7. Security

Security is the core purpose of DocWallet, not an afterthought. In addition to the zero-knowledge encryption described in Section 4, we maintain the following safeguards:

No system is perfectly secure. If you believe you have discovered a security vulnerability, please disclose it responsibly tosupport@docwalletlabs.com.

8. Children's Privacy

DocWallet is not directed to children under the age of 13. We do not knowingly collect personal information from anyone under 13. If you believe we have inadvertently collected data from a child under 13, please contact us immediately atsupport@docwalletlabs.comand we will promptly delete that information.

Certain sensitive document categories (e.g., financial and employment records) are intended for users aged 18 and older. We reserve the right to terminate accounts found to be in violation of these age restrictions.

9. International Data Transfers

DocWallet Labs is headquartered in the United States. If you access the Services from outside the United States, your account metadata (email address, subscription status, encrypted vault ciphertext) may be transferred to and processed in the United States or other countries where our service providers operate.

For users in the European Economic Area (EEA), the United Kingdom, or Switzerland, such transfers are carried out in accordance with applicable data protection law — including, where required, by relying on Standard Contractual Clauses (SCCs) approved by the European Commission. Because document content is end-to-end encrypted and we cannot decrypt it, the practical privacy risk of any such transfer is limited to account metadata only.

10. Your Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal data:

To exercise any of these rights, emailsupport@docwalletlabs.com. We will respond within 30 days (or the period required by applicable law). We may need to verify your identity before fulfilling a request.

11. Cookies & Analytics

The informational website at docwalletlabs.com uses only essential first-party cookies required for basic site functionality (e.g., session continuity). We do not use third-party advertising cookies or tracking pixels.

The App does not use browser cookies. Aggregate, de-identified analytics data may be collected through the App to understand feature usage patterns and improve reliability. This data does not include document contents and cannot be linked back to your identity.

If we ever add non-essential analytics to the Site, we will obtain your consent through a cookie-consent mechanism before activating them.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes — changes that meaningfully affect your rights or our data practices — we will provide notice by updating the effective date at the top of this page, by posting a notice in the App, or by emailing the address associated with your account.

Your continued use of the Services after the effective date of an updated Policy constitutes acceptance of the changes. If you do not agree to a material change, you may delete your account before the change takes effect.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or how DocWallet Labs handles your data, please contact our Privacy team:

DocWallet Labs
Email:support@docwalletlabs.com
Website:docwalletlabs.com

For users in the EEA, you also have the right to lodge a complaint with your local data protection authority if you believe our processing of your personal data violates applicable law.