Privacy
What happens to a file you open here, what we store about you, and how to get any of it back or deleted. Written to be read, not to be survived.
Last updated
The short version
When you use the tools, your documents are not sent to us. Every tool that takes a file does its work inside your browser — the file is read, changed and saved without ever leaving the device you are sitting at.
That is not a promise about how carefully we handle your documents. It is a statement that we never receive them. We could not hand one over, look inside one, or lose one in a breach, because we never had it.
The one exception is a document you choose to send to other people for signature. It has to reach them, so an encrypted copy is stored with us until the request is finished. Section 2 explains how it is protected, and why the copy we hold cannot be opened without a key we do not keep.
What we do store is the small amount an account needs: who you are, what you paid for, and how much of your daily allowance you have used.
Your files stay on your device
Merging, splitting, converting, compressing, OCR, signing, redaction — all of it runs in your browser, and no tool sends your document anywhere. The site security policy also limits which addresses the page can reach at all: this site and the few services named in the cookie policy. You can watch the traffic yourself in any browser's network panel while a tool runs.
This also means the tools keep working with the network switched off, and that a file you never uploaded cannot be leaked by us later.
One tool is different and says so on its own page: the web-page-to-PDF converter takes an address, not a file, and fetches that page from our side. It never receives a document from you.
You can also bring a file from Google Drive, Dropbox or OneDrive. That provider's own window asks for your permission first. Google Drive grants access only to the files you pick (the permission Google calls drive.file), Dropbox hands over a link to the one file you choose, and OneDrive grants read-only access so its picker can show your files. The file you choose is downloaded into the page and handled like a file from your device: it is not sent to us. The access the provider grants is short-lived, is not stored with us, and is gone when you close the tab.
Signature requests are the exception, and a deliberate one. When you send a document for signature, it is encrypted before it leaves the page, and only the encrypted copy is stored with us. The key that opens it is placed inside the signing links. The key passes through our server only while those links are created or sent again, to be handed to our email provider for delivery, and it is never stored. The copy we keep therefore cannot be opened from our storage on its own — not by us, and not by anyone who reaches that storage. Signers open the document with their own link, and the signed version is encrypted the same way before it comes back.
What we store when you have an account
Your email address, and — if you signed in with Google, Apple, Microsoft or GitHub — the basic profile that provider shares: an account identifier, your name and, where the provider has them, a username and a link to your profile picture. We never receive your password.
Alongside that: which version of these terms you accepted and when, which plan you are on and when it renews, how many credits you have left, a counter of how many tools you have run in the current period, and, if you are on a team, which team you belong to.
Payments are handled by Stripe as the seller of record. Your card never reaches us; we keep only a reference that links your account to your subscription.
If someone invites you to a team, their invitation holds your email address until you accept it or it expires.
If you send a signature request, we also store the request itself: its title, your message and the name you give, each signer's name and email address, where their fields sit on the page, and a record of each step — when the request was sent, opened, signed or declined, with the browser's user agent and a salted fingerprint of the network address it came from. The document itself is stored only in encrypted form.
What we store without an account
If you rate the site or a tool, we keep the score, anything you typed, which tool it was about, your language, and two identifiers: a random one stored in your browser and a short technical fingerprint. Neither contains your name or your email.
We are telling you about them anyway, because under European law an identifier that can single out a browser counts as personal data even when it carries no name. They exist for one reason — to stop the same visitor voting a hundred times — and for nothing else.
Our infrastructure provider also keeps ordinary connection records for a short period: which page was requested, when, and from roughly where. Those are used to keep the service up and to spot abuse.
Why we are allowed to store it
Account details, plan records, credits and usage counters: because you asked us for the service and we cannot provide it without them.
Payment records: the same reason, plus the tax and accounting law that applies to any business that takes money.
Ratings, usage counters and connection records: our own legitimate interest in keeping the service working, honest and free of abuse, and in understanding which tools people reach for and how well those tools do the job, so that we can make them better. That understanding comes from counts and scores, never from a profile of you. You can object to this — see your rights below — and we will stop unless we have a compelling reason not to.
We do not sell personal data, we do not share it for advertising, and we do not build profiles of you.
How long we keep it
Account data: until you close the account. Closing it removes your plan record, usage counters, credits and team memberships along with it, and the removal is immediate rather than scheduled.
Signature requests: the encrypted documents are deleted 30 days after a request is completed, declined or expires, and when you cancel it; a request that is never sent is deleted after a day. The record of the request — who was asked to sign and when each step happened — stays in your account until you delete the request or close the account.
Payment records: kept for as long as tax and accounting rules require, which is typically several years. Stripe, as the seller of record, holds the primary copy.
Usage counters: reset every day or every month depending on which allowance they track.
Ratings: kept while the site shows an overall score, because that score is made of them.
Connection records: a short period, measured in days.
Who else is involved
We use a small number of outside services, each for one job and each acting on our instructions only:
Hosting and delivery — serves the site, keeps the connection records described above and counts anonymous page views.
Accounts, sign-in and storage — stores your email address, the identity your sign-in provider returns, and the encrypted documents of signature requests.
Payments — takes the payment as seller of record and holds the billing details we never see.
Email delivery — sends the messages your account generates, such as a sign-in link, a receipt or a signature request with its signing link.
Tools never send a document to any of them. A document sent for signature is stored only in encrypted form, and the signing links that open it pass through email delivery the way a sign-in link does. The current list of providers is available on request; write to the address below.
If you use DocuGrip on behalf of a company and need a data processing agreement, ask and we will send one.
Cookies and measurement
We use cookies that the site needs in order to work — keeping you signed in, remembering your language and your display settings. There are no advertising cookies and no third-party trackers following you to other sites.
To count visits we use Cloudflare Web Analytics. It sets no cookie and stores nothing on your device. For each page view it records the page, the referring site, the browser type, the country and page load timing, without identifying you or following you across sites. Cloudflare does this on our behalf, as part of hosting and delivery.
We also keep a few anonymous daily counts of steps on the site, such as how many times a tool was opened, started and finished, how often the pricing page was viewed and a checkout was started. Each count is one number per day, per step and per tool. It holds no identifier, no IP address and no cookie, so nothing in it can be tied to you, and nothing is counted at all when your browser sends a Global Privacy Control signal.
Most of what the site remembers is not a cookie at all: it sits in your own browser storage and never reaches us. Your account settings page lists every one of those and lets you erase them. If your daily limit stops a job, the files you picked are kept in that storage so you can finish within 30 minutes after upgrading or logging in. They are removed as soon as you are back; if you do not come back in time, they are removed the next time you open DocuGrip, and you can erase them yourself from your settings at any time.
Your rights, and how to use them
You can ask for a copy of what we hold, correct it, have it deleted, ask us to restrict or stop a particular use, or take your data elsewhere. Where we rely on legitimate interest, you can object.
Two of these do not need to involve us at all: your account page can export everything we hold about you as a file, and can close the account and delete it. Both work immediately.
For anything else, write to privacy@docugrip.com. We answer within thirty days and we will not ask you for a form or a lawyer.
If you live in California or another US state with a consumer privacy law, you have the same rights: to know what we hold, to have it corrected or deleted, and to take a copy with you. We do not sell or share personal information as those laws define it, we hold no sensitive personal information, and using a right will never change the price or quality of the service. A browser Global Privacy Control signal is treated as a valid opt-out — there is nothing further for it to switch off. Someone you authorise can make a request for you; we will ask them to show that authorisation.
If you are in the European Union or the United Kingdom and you are not satisfied with how we handled your request, you can complain to your national data protection authority.
Children, changes, and who we are
This service is not aimed at children under 13 and we do not knowingly collect their data.
If this policy changes in a way that affects you, we will say so on this page and move the date below.
DocuGrip is operated by Simulator Arts LLC, which is the data controller for everything described here. For any privacy or data protection question, including the requests above, write to privacy@docugrip.com — that address reaches a person, not a queue.