Legal

Privacy Policy

Last updated: March 1, 2026 · Effective: March 1, 2026

DocsCanary (“we”, “us”, or “our”) operates docscanary.com. This policy explains what data we collect, why we collect it, and how we protect it. If you have questions, contact us at privacy@docscanary.com.

1. Information We Collect

Account information. When you create an account, we collect your email address, name, and organization name. This is used to authenticate you and manage your subscription.

Repository and documentation URLs. When you connect a repository or run an audit, we collect the URLs you provide (e.g., github.com/your-org/your-repo and docs.your-product.com). We use these to perform the analysis you request.

Audit results and drift data. We store the output of documentation health checks — page status (In Sync, Drifting, Out of Sync), severity scores, and AI-generated suggestions. This is the core data that powers your dashboard.

Payment information. We use Stripe to process payments. We never see or store your full credit card number. Stripe is PCI-DSS compliant and handles all payment data directly.

Usage and analytics data. We collect anonymized usage data (page views, feature usage, session length) via Google Analytics to understand how the product is used and improve it. This data is aggregated and not personally identifiable.

Communications. If you contact us via email or a support form, we retain that correspondence to respond to your inquiry.

2. What We Do NOT Collect or Store

We never store your source code. DocsCanary processes code diffs and commit metadata in memory to understand what changed semantically. Raw source code, file contents, and full diffs are discarded immediately after analysis. Only the semantic result (what the change means for your docs) is retained.

We do not sell your data. We do not share your data with third parties for advertising purposes. We do not train AI models on your code or documentation content.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the DocsCanary service
  • Process transactions and manage your subscription
  • Send you product updates, alerts, and billing communications
  • Respond to support requests
  • Improve the accuracy of our drift detection and AI suggestions
  • Comply with legal obligations and enforce our Terms of Service

We will not use your data for any purpose materially different from those described here without your consent.

4. Third-Party Services

DocsCanary uses the following sub-processors to deliver the service. Each is bound by their own privacy policies and data processing agreements:

  • Stripe — payment processing (stripe.com)
  • Postmark — transactional email delivery (postmarkapp.com)
  • Anthropic Claude — AI analysis for drift detection and fix suggestions. Commit diffs are sent to Claude for semantic analysis and are not retained by Anthropic for training purposes under our API agreement.
  • Google Analytics — anonymized usage analytics (analytics.google.com)
  • Supabase / PostgreSQL — database hosting for account data and audit results

5. Cookies

We use cookies and similar tracking technologies to maintain your session, remember your preferences, and collect analytics data.

Essential cookies are required for the service to function (authentication, CSRF protection).

Analytics cookies (Google Analytics) help us understand how the product is used. These can be blocked by browser extensions without affecting product functionality.

You can disable non-essential cookies in your browser settings at any time.

6. Data Retention

We retain your account data and audit results for as long as your account is active. If you cancel your subscription, your data is retained for 90 days to allow you to reactivate or export, then deleted.

Free audit results (run without an account) are retained for 30 days, then automatically purged.

You may request deletion of your account and all associated data at any time by emailing privacy@docscanary.com. We will process the request within 30 days.

7. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your account and associated data
  • Export your data in a portable format
  • Object to certain processing activities

EU and UK residents have additional rights under GDPR / UK GDPR. To exercise any of these rights, email privacy@docscanary.com.

8. Security

We use industry-standard measures to protect your data: encryption in transit (TLS), encryption at rest, access controls, and regular security reviews. No system is 100% secure, but we take security seriously. See our Security page for details on our code access tiers and data handling practices.

9. Children's Privacy

DocsCanary is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a minor has provided us personal data, contact us and we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email (if you have an account) and by updating the “Last updated” date at the top. Continued use of the service after changes constitutes acceptance of the updated policy.

11. Contact

Questions or concerns about this policy? Contact us:

Privacy Policy