DOCSUPRA › Privacy Review
Everything your reviewer will ask, answered before they ask it.
The short answer. Document content is never transmitted and never stored by us. Correction runs on an HTML canvas in the visitor’s own browser. The only data we hold is a billing record created by Stripe when someone pays.
Trust center: the security questionnaire answers, sub-processor list, DPA, SLA and enterprise agreement live there. This page is the narrative behind them. This page is written for the person who has to sign off on the tool, not for the person who wants to use it. It states architecture, not assurances — and every claim on it is one you can check without asking us.
What happens to a document, step by step
| Step | Where it happens | What leaves the machine |
|---|---|---|
| File is opened | Browser, from local disk | Nothing |
| Geometry, lighting, legibility | HTML canvas, on the device’s own processor | Nothing |
| EXIF, GPS and device serials removed | Same, before anything is written | Nothing |
| Export to the target specification | Same | Nothing |
| File saved | The user’s own download folder | Nothing |
| Payment | Stripe, directly | Card data goes to Stripe, never to us |
How to verify it rather than believe it
The studio ships a live network monitor that instruments every outbound request the page makes. Three checks, about two minutes:
| Check | Expected result |
|---|---|
| Process a real document with the monitor open | The upload counter stays at zero |
| Open your browser’s own Network tab and repeat | No request carries the file |
| Disconnect from the network entirely and process again | It keeps working |
That third one is the decisive test. Software that needs a server cannot pass it.
What we hold, and for how long
| Data | Held? | Where |
|---|---|---|
| Document content | No. There is no endpoint that receives it. | — |
| Document metadata | No. Discarded on the device during processing. | — |
| Account or password | No. There are no accounts. | — |
| Billing record | Yes, the minimum for a licence | Stripe, plus a licence key |
| Abuse counter | A salted daily hash of the IP, expiring in 48 hours | Not a persistent identifier |
What we do not claim
We do not sell a compliance certification and we do not assert one. No SOC 2 or ISO 27001 audit has been performed; the day one exists it will be named here with its auditor. We make no finding about whether a document is genuine — this is imaging software, and no software determines authenticity from a photograph. What a zero-transmission architecture means under your own regulatory obligations is your counsel’s determination, not ours.
The questions that usually come next
Do we need a data processing agreement?
That is your counsel’s call. What we can tell you factually is that we do not receive document content, so there is no document processing for such an agreement to govern. The billing record is handled by Stripe under their own terms.
What happens if you are breached?
The document material is not there to be taken. A breach of our infrastructure would expose the billing records that Stripe already holds — not a single client file, because none was ever received.
Can the software be used offline?
Yes, once loaded, and this is the honest demonstration of everything above. Load the page, disconnect, and keep working.
What it costs
Prices are in USD and exclude any tax that applies in your country; Stripe calculates it and shows it before you pay.
See every plan →More for teams
Made and copyrighted © 2026 by Soelys Muñoz. DocVerifyPro™ is her trademark. All rights reserved. How to recognise the real site.