Doqlo Privacy Policy
Last updated: 2026-07-25
This Privacy Policy explains how Doqlo (“Doqlo”, “we”, “us”, or “our”) collects, uses, and protects information when you use our websites, applications, and services (collectively, the “Service”).
Contact: For privacy questions or requests, submit them via the Support page on our website.
If you do not agree with this Privacy Policy, do not use the Service.
1. Privacy-First Summary
Doqlo is designed to minimize data collection and long-term document retention.
- We do not provide or maintain long-term cloud storage of your PDF files as an account document library.
- We do not store your signatures as a retained dataset or signature library.
- Many interactive editing actions are performed in your browser.
- Certain features require your Document Data to be temporarily transmitted to and processed on our servers. This may include document conversion, form creation or modification, merging or composition, validation, export generation, and download delivery.
- We process Document Data only as reasonably necessary to provide and operate the Service, including for the limited operational purposes described in this Policy. We do not retain Document Data as a long-term stored dataset.
- Short-lived working files, technical buffers, intermediate files, and temporary retrieval artifacts may be created as part of processing and delivery. Where implemented, temporary retrieval artifacts are access-limited and automatically deleted under our retention controls.
- Documents or other files that you voluntarily submit through Support are handled as Support Communications and may be retained with the related support record.
This summary is provided for convenience. The rest of this Policy controls.
2. Definitions
- “Account Data” means information associated with your account (e.g., email, authentication identifiers, subscription status).
- “Document Data” means PDFs and related files or data that you submit, create, edit, process, or generate through the Service. This may include document contents, form fields and field values, signatures, annotations, overlays, images, structured data such as CSV data, and intermediate, converted, or generated document outputs.
- “Usage Data” means service operation signals (e.g., export counters, timestamps, security signals, and diagnostic events) used for plan enforcement, security, and reliability.
- “Service Providers” means vendors we use to operate the Service (e.g., authentication and payment processors, infrastructure providers).
3. Information We Collect
3.1 Account Data (Sign-In)
If you sign in using a third-party provider such as Google or Microsoft, we receive basic account information such as:
- Name (as provided by the sign-in provider)
- Email address
- Auth provider identity metadata necessary to sign you in
The exact fields we receive depend on your provider account settings and the sign-in method. We use this information to authenticate you and manage your account.
3.2 Usage Data
We collect limited usage information necessary to operate the Service, including:
- Export counts and other plan usage counters
- Subscription status and plan tier
- Basic service telemetry used to keep the Service reliable and secure (e.g., error logs, rate limiting and anti-abuse signals)
This may include technical data such as IP address, device/browser information, and timestamps as part of security and reliability logging.
We do not store document contents or file names as a retained usage or analytics dataset.
3.3 Support Communications
If you submit a support request, we may collect the information you provide (e.g., email, message content, and any attachments you choose to include) to respond and maintain support records.
Documents or other files that you voluntarily submit through Support are handled as Support Communications rather than ordinary temporary Document Data processing and may be retained with the related support record. Please avoid sending sensitive personal information or confidential documents unless it is necessary for your support request.
3.4 Sensitive Information in Documents
We do not request sensitive personal information for account creation or for purposes unrelated to providing the Service. However, Document Data that you choose to process through the Service may contain sensitive personal information, such as financial information, government identifiers, health information, or information about other individuals.
You are responsible for ensuring that you have the rights, permissions, and lawful authority necessary to submit and process such information through the Service. We process this information only as described in this Policy and as necessary to provide and operate the Service.
4. How We Use Information
We use information to:
- Provide and operate the Service and the features you request
- Process, convert, generate, validate, or deliver documents where a requested feature requires server-side processing
- Authenticate users and manage accounts
- Enforce plan limits and prevent abuse
- Process payments and manage subscriptions
- Maintain security, prevent fraud, diagnose technical issues, and maintain or improve the reliability and quality of document processing
- Communicate with you about the Service (e.g., billing notices, support responses)
- Comply with legal obligations
5. Document Processing and File Handling
5.1 Browser-Based Processing and Local Storage
Many interactive document-editing actions, such as placing signatures, dates, text, and other overlays, are performed in your browser.
Some features may use browser storage on your device to preserve drafts, preferences, or session state. Information stored locally on your device is controlled through the Service’s available controls and your browser or device storage settings.
5.2 Server-Side Document Processing
When reasonably necessary to provide and operate the Service, including for the limited operational purposes described in this Section, Document Data may be temporarily transmitted to and processed on our servers.
Server-side processing may include activities such as:
- Converting a document into a compatible or flattened format
- Creating, detecting, adding, or modifying form fields
- Combining, composing, validating, or generating documents
- Filling documents from structured data
- Generating exports
- Preparing processed files for download or delivery
We process Document Data only as reasonably necessary to provide and operate the Service, secure the Service, and comply with applicable legal obligations.
We do not routinely access or review Document Data. Limited authorized access may occur where reasonably necessary to provide support, diagnose or resolve technical issues, verify processing quality, maintain or improve document-processing functionality, investigate security incidents or abuse, or comply with law. Any such access is limited to the purpose that made it necessary.
We do not maintain Document Data as a long-term account-based document repository or document library.
5.3 Temporary Processing and Delivery Artifacts
Temporary working copies, intermediate files, technical buffers, or other transient artifacts may be created during processing.
These artifacts may be retained for a limited period to complete processing and delivery and for related operational purposes such as troubleshooting, quality verification, security, and service reliability. Where implemented, converted, generated, or exported files may also be held temporarily so that you can retrieve them, including through a time-limited or access-limited download link. These artifacts are deleted under our operational retention controls and are not maintained as a long-term document repository.
Operational logs may be retained for purposes such as security, fraud prevention, rate limiting, reliability, and debugging. These logs are intended to contain technical metadata rather than document contents.
5.4 No Sale, Advertising Use, or AI Training
We do not sell Document Data.
We do not use Document Data for targeted advertising, user profiling, or advertising measurement.
We do not use Document Data to train artificial intelligence or machine-learning models.
6. Payments
Payments are processed by Stripe. We do not store your full payment card details. Stripe may collect and process billing information in accordance with Stripe’s privacy policy.
We may receive limited payment-related information from Stripe (for example, billing status, Stripe customer/subscription identifiers, and the last four digits and brand of a card) to manage subscriptions and support billing.
Billing descriptor: Charges may appear on your statement as “doqlo.com” (or a similar descriptor).
7. Cookies and Similar Technologies
We use cookies and similar technologies (such as local storage or browser storage) to operate the Service. These technologies help us provide core functionality, keep the Service secure, and remember certain preferences.
7.1 What we use them for
We may use cookies or browser storage for purposes such as:
- Essential functionality (e.g., maintaining sign-in sessions, routing requests, and enabling core features)
- Security and abuse prevention (e.g., protecting against fraud, rate limiting, and detecting automated misuse)
- Preferences and UI state (e.g., remembering basic settings or interface choices)
- Local drafts or session state (e.g., preserving work or progress on your device where a feature supports it)
- Reliability and debugging (e.g., short-lived identifiers or flags used to diagnose errors and improve stability)
Some of these technologies are required for the Service to function. If you disable them, sign-in and other core features may not work.
7.2 Advertising and cross-site tracking
Doqlo does not use cookies for targeted advertising, and we do not use our own cookies to track you across other companies’ websites.
If we introduce analytics or advertising-related technologies in the future, we will update this Privacy Policy and, where required, provide appropriate notice and choices.
7.3 Third-party cookies (sign-in providers, embedded video, payments, infrastructure)
When you choose to sign in with a third-party provider such as Google or Microsoft, that provider may set cookies on its own domains (for example, Google domains such as google.com or accounts.google.com, or Microsoft domains such as login.microsoftonline.com). If you view an embedded YouTube video on our site, Google or YouTube may set cookies or similar storage on their own domains in connection with that media player. If you use Stripe-powered checkout or payment pages, Stripe may set cookies on its own domains. These third-party cookies are controlled by the respective providers and are governed by their policies, not ours.
7.4 Your choices
You can control cookies through your browser settings and tools. You can also delete existing cookies at any time. Note that blocking essential cookies or clearing browser storage may prevent parts of the Service from functioning properly or may remove locally stored drafts, preferences, or session state.
8. Data Retention
We retain information only for as long as reasonably necessary for the purposes described in this Policy.
- Account Data: Retained while your account is active and as necessary for billing, compliance, fraud prevention, dispute resolution, and legal obligations.
- Usage Data: Retained as necessary for plan enforcement, security, fraud prevention, service reliability, and debugging.
- Document Data processed on our servers: Retained only for as long as reasonably necessary to complete requested processing and related short-term operational purposes, such as delivery, troubleshooting, quality verification, security, and service reliability. Temporary working files, intermediate files, and retrieval artifacts are deleted under our operational retention controls and are not retained as a long-term document repository.
- Local browser data: Drafts or session information stored locally on your device may remain until deleted through available product controls, cleared through your browser or device settings, or removed automatically by the Service or browser.
- Support Communications: Retained as reasonably necessary to respond to requests, maintain support records, resolve disputes, and improve support operations. This may include documents or attachments that you voluntarily submit to Support.
- Operational logs: May be retained for security, fraud prevention, rate limiting, reliability, debugging, and legal compliance. Operational logs are intended to record technical and service metadata rather than document contents.
If you request account deletion, we will delete or de-identify Account Data subject to legal, accounting, tax, security, or fraud-prevention requirements.
9. Sharing and Disclosure
We may share information:
- With Service Providers (e.g., Stripe, authentication providers, hosting/infrastructure providers) to operate the Service
- If required by law, legal process, or government request
- To protect the rights, safety, and security of Doqlo, our users, or the public
- In connection with a corporate transaction (e.g., merger, acquisition), subject to appropriate protections
Document Data may be temporarily processed by hosting, infrastructure, storage, delivery, or other technical Service Providers only as necessary to provide the features you request. We require Service Providers handling personal information on our behalf to use it only for authorized service purposes and to apply appropriate safeguards.
We do not share Document Data for advertising.
10. Security
We implement reasonable technical and organizational measures designed to protect Account Data, Document Data during processing, and the integrity of our systems. No method of transmission or storage is 100% secure.
Because we do not retain Document Data as a long-term stored dataset, exposure risk is reduced by design, even though limited short-lived working files, processing buffers, intermediate files, or temporary download artifacts may exist in the ordinary operation of the Service.
11. International Processing and Transfers
Account Data, Usage Data, Support Communications, and Document Data may be processed in countries other than your own, depending on where our infrastructure and Service Providers operate.
When information is processed in another jurisdiction, it may be subject to the laws of that jurisdiction and may be accessible to courts, law-enforcement agencies, or other authorities through lawful processes.
We use contractual, technical, and organizational measures intended to provide appropriate protection when information is processed by Service Providers.
12. Your Choices and Rights
Depending on your location, you may have rights to:
- Access and correct your Account Data
- Request deletion of your Account Data
- Object to or restrict certain processing
To make a request, submit it via the Support page on our website. We may verify your identity before fulfilling requests.
13. Children’s Privacy
The Service is not directed to children under 13 (or the age required by local law). We do not knowingly collect personal information from children.
14. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date indicates when the Policy was last revised.
If a change is material, we may provide additional notice (for example, through the Service or by email if associated with your account). Where required by law, we will obtain consent before using or disclosing personal information for a materially new purpose.
Your continued use of the Service after an updated Policy becomes effective means that the updated Policy will apply to your subsequent use of the Service. If you do not agree with an updated Policy, you should stop using the Service.
15. Support
For privacy questions or requests, submit them via the Support page on our website.