Privacy Policy
Effective 17 August 2026 · Last updated 17 September 2026
In plain language. DocVerifyPro runs entirely inside your web browser. When you open a document with this service, that document is read and processed by your own device. It is never transmitted to us, and we never receive, see, store or process it. There is no upload step, because there is no server to upload to.
This is not a retention promise. It is an architectural fact: we cannot disclose, lose, sell or be compelled to produce a document we never received.
The only personal information we handle is the billing information you provide if you buy a plan, and that is handled by Stripe.
1. Who we are
DocVerifyPro ("we", "us") operates the web application available at the address from which you accessed this policy.
Data controller: DocVerifyPro, operated as a sole proprietorship registered in Puerto Rico, United States.
Privacy contact: privacy@docsupra.com
Postal correspondence. DocVerifyPro operates as a sole proprietorship without a public business address. Requests requiring postal correspondence — including data subject access requests under GDPR or CCPA — should be initiated by email to the address above, and a correspondence address will be supplied directly to the requester.
2. How document processing works
DocVerifyPro is a client-side application. All image analysis, correction and file generation is performed by JavaScript executing in your browser, using your device's own processor and memory.
- Documents you select are read into your browser's memory using the standard
FileReaderinterface. - Image correction — illumination flattening, glare reduction, perspective correction, contrast
processing — is performed on an HTML
<canvas>element in your browser. - Output files (PDF, JPEG, PNG, TIFF) are generated in your browser and saved directly by your browser to the location you choose.
Verify this yourself. Open your browser's developer tools, select the Network tab, and process a document. No request carrying document data will appear. The studio also includes a built-in live network audit that counts every outbound request. Or simply disconnect from the internet — the application keeps working.
2.1 What this means
- We do not store your documents, because we never receive them.
- We do not log your documents, because we never receive them.
- We do not use your documents to train artificial intelligence or machine learning models, because we never receive them.
- We cannot provide your documents to any third party, law enforcement body or litigant, because we never receive them.
- Closing the browser tab discards all processing data. There is no cache to purge and no retention period to wait out.
2.2 Metadata removal
Where you enable the metadata stripping option, camera EXIF data — including GPS coordinates, device serial numbers and timestamps — is discarded during processing and is not written to the output file. This also occurs on your device.
3. Information we do collect
3.1 Payment information
If you purchase a plan, checkout is handled by Stripe, Inc. We do not collect, receive, transmit or store your card number, CVC or expiry date at any point. Stripe collects this directly.
From Stripe we receive: your email address, the plan purchased, the transaction amount and date, the payment status, and the country associated with the payment method. We use this solely to provide the plan you paid for, to issue receipts, and to meet tax and accounting record-keeping obligations.
Legal basis (GDPR): performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for retention of financial records.
Retention: financial records are retained for the period required by applicable tax law, commonly seven years. Your email address is retained for the life of your subscription plus that statutory period.
3.2 Values stored on your device
These values are stored in your browser, by the application itself, so it recognises you and your plan when you come back. None of them is sent anywhere except the licence token, and only to the licence service:
dv_licence_token— a signed licence token issued after purchase, so the application recognises your plan on return visits.dv_quien— the email on your Stripe receipt, shown in your account panel. It never leaves your device.dv_equipo— a random number that identifies this device for plans sold per seat. It is not a fingerprint and says nothing about you.dvp_nombre,dvp_entrada,dvp.org— the name and organisation you typed in the welcome screen, and that you have already seen it.dv_pago_pendiente— the id of a checkout that has not finished yet, so a payment that settles later still unlocks your plan. Removed once it does.dvp-pago(IndexedDB) — only while you pay: the document you were fixing waits on this device so it is back when Stripe returns you. Deleted on return, and after two hours at the latest.dv_trial_runs— a counter recording how many documents this browser has processed.
All of them live on your device. Clearing your browser storage removes them.
3.3 Licence server
Subscription checks are handled by a licence service we operate on Cloudflare Workers. When you begin checkout, return from Stripe, or download a file, your browser contacts this service.
What it receives: your licence token (or nothing at all, if you have no licence yet), the plan name, and the network request itself.
What it never receives: your documents. No image data, no extracted text, no file contents are transmitted at any point. The service has no upload endpoint.
Anonymous abuse counting. To count downloads against a plan without requiring an account, the service stores a SHA-256 hash of your IP address combined with a salt that rotates every day. The result expires after 48 hours, cannot be reversed to your IP, and cannot be correlated across days. It is a rate-limit token, not an identifier, and it is not linked to any other data.
Legal basis (GDPR): performance of a contract (Art. 6(1)(b)) for licence validation; legitimate interests (Art. 6(1)(f)) for abuse prevention on requests made without a licence.
3.4 Website analytics
One cookie-free page counter, nothing else. We count page views with Cloudflare Web
Analytics, which records the page, the referring site, the country and the browser type, sets no cookie,
and does not identify you or follow you to other sites. This site loads no tag manager, no advertising
pixel and no other tracker. You can confirm this in your browser's Network tab: the only measurement
request goes to cloudflareinsights.com.
We set no cookies. The only values kept on your device are the ones listed in section
3.2, placed by the application itself (in localStorage, and in IndexedDB only while you pay)
so that it works and remembers your plan — not to follow you. One of them, dv_equipo,
is a random number for this device, used only to count the seats or devices a plan includes; it is not
a fingerprint and is not used for analytics or advertising. Because nothing is stored for analytics,
advertising or tracking, no consent banner is required, and you will not see one.
Server logs. The site is hosted on Cloudflare Workers. Like every web host, Cloudflare processes the connection data needed to deliver a page and to protect the site from attack — your IP address, the time of the request, the page requested and your browser's user-agent string. We do not build reports from these logs, do not export them, and do not combine them with anything else. Cloudflare retains them under its own retention schedule.
Legal basis (GDPR): legitimate interests (Art. 6(1)(f)) — delivering the site and preventing abuse.
If we ever add analytics, this section will be rewritten before the change goes live, and the “last updated” date at the top of this page will change. We will not add anything that sets a cookie or tracks you across other sites.
3.6 The payment form
The one third-party script this site can load is Stripe.js, and it loads
only if you open the payment panel — never on an ordinary visit, and never while you
are working on a document. You can confirm this in your browser’s Network tab: browse, upload and
process as much as you like and no request to js.stripe.com appears until you press the
subscribe button.
When you do open it, the card fields are rendered by Stripe inside their own frame. Your card number, expiry and CVC go directly from your browser to Stripe. They do not pass through this site, and they do not pass through our licence service — which is why we never hold them and could not disclose them to anyone. Stripe acts as an independent data controller for payment data under its own privacy policy, and as our processor for the billing details described in section 3.1.
Your documents are not part of this. Opening the payment panel does not upload, transmit or expose any document you have processed. Document handling is unchanged by anything in this section.
3.5 Support correspondence
If you email us, we hold that correspondence in order to answer you. Please do not attach documents to support emails. We do not need them and do not want to receive them. If you send one, we will delete it and ask you not to send another.
4. What we never do
- We never sell personal information. We have never sold personal information.
- We never share personal information with advertisers or data brokers.
- We never use your documents for model training.
- We do not build advertising profiles or engage in cross-context behavioural advertising as defined by the CPRA.
5. Sub-processors
| Sub-processor | Purpose | Data received |
|---|---|---|
| Stripe, Inc. | Payment processing | Billing details, email |
| Stripe, Inc. (Stripe.js) | Payment form, loaded only when you open it | Card details, entered directly into Stripe's own frame |
| Cloudflare, Inc. | Hosting, CDN, the licence service, cookie-free page counting, inbound email routing | Server-log connection data (IP, time, page, user-agent); for abuse counting, a daily-salted hash of the IP; licence token; email sent to our addresses |
| Cloudflare, Inc. (Workers AI) | Drafting first replies to support email and answering the on-site assistant | The text of your message or question — never a document |
| Google LLC (Gmail) | The support inbox: email to our addresses is forwarded there | The email you send us |
| Resend, Inc. | Operator alert emails when the licence service errors; sign-in links and invitations for Team and Studio members | For alerts: the route and error message of a server fault — never a document, token or customer email. For sign-in emails: the recipient address and the one-time link |
Support email is kept in our support system for 90 days, then deleted automatically; the copy in the support inbox is kept as correspondence.
No sub-processor receives document content, because no sub-processor is sent document content. Standard Contractual Clauses govern transfers of personal data outside the European Economic Area and the United Kingdom where such transfers occur.
6. Your rights
6.1 Under GDPR (EEA and UK)
You have the right to access, rectify, erase, restrict processing of, and port your personal data, and to object to processing based on legitimate interests. You may withdraw consent at any time where processing is based on consent.
In practice, the personal data we hold about you is limited to your billing record. Requests concerning documents are not applicable, as we hold none.
You may lodge a complaint with your national supervisory authority.
6.2 Under CCPA/CPRA (California)
California residents have the right to know what personal information is collected, to request deletion, to request correction, to opt out of sale or sharing, and to limit the use of sensitive personal information. You will not be discriminated against for exercising these rights.
We do not sell or share personal information as those terms are defined by the CPRA, so no opt-out mechanism is required. We do not collect sensitive personal information as defined by the CPRA.
6.3 Making a request
Email the privacy contact address in Section 1. We will verify your identity by reference to the email address associated with your payment record and respond within 30 days (GDPR) or 45 days (CCPA/CPRA), extendable where permitted by law.
7. Security
Our website is served exclusively over HTTPS using TLS. Payment processing is carried out by Stripe, which maintains PCI DSS Level 1 certification as a service provider.
Because document processing occurs on your device, the security of your documents during processing depends on the security of your own device and browser. We recommend keeping your browser updated and not using shared or public computers for sensitive documents.
8. Children
This service is not directed at children under 16 and we do not knowingly collect personal information from them.
9. Changes to this policy
We will post any changes on this page and update the "last updated" date. Where changes are material we will provide notice by email to active subscribers before the changes take effect.
10. Not legal or immigration advice
DocVerifyPro is document imaging software. Format and file-size presets are provided as a convenience and reflect published requirements as of the date shown against each preset. Requirements set by government agencies, employers and institutions change without notice. You are responsible for confirming current requirements with the receiving body before submission. Nothing in this service constitutes legal, immigration, tax or financial advice, and we make no representation that any document processed with this service will be accepted by any recipient. DocVerifyPro does not verify the authenticity of any document.
Made and copyrighted © 2026 by Soelys Muñoz. DocVerifyPro™ is her trademark. All rights reserved. How to recognise the real site.