Data Policy
What actually happens to your data.
The strongest way to protect sensitive data is to never be able to read it in the first place. That principle shapes how doconvoy is built. Here's what we hold, what we can't, and where it lives.
What we collect, and what we don't
We never hold the plaintext of your secrets or submissions, and we don't use advertising or cross-site tracking.
Account data
Your email and name, sign-in sessions, and billing contact. This is what lets you log in and run a workspace.
Content you share or collect
Encrypted in your browser before it reaches us. We hold the scrambled result and can't read it.
Access metadata
Timestamps and view counts for your audit trail. Inside the app, device, location, and IP are off unless you turn them on.
What protects your data
End-to-end encryption
Content is encrypted on your device before it reaches us. We store only ciphertext and don't hold the keys, so there's nothing readable for us to lose, leak, or hand over.
Erasure that actually erases
We erase by destroying keys (crypto-shredding): immediately for a person, and across an entire workspace when it's deleted. No chasing copies through backups.
Data minimisation & clean deletion
We keep as little as possible, and we handle email addresses so they're easy to erase. An address is encrypted and kept in a separate store, and the rest of the app refers to it by a stand-in token. Destroy the key and the email is gone everywhere at once.
A complete, exportable audit trail
Every share, access, and key change is recorded in an immutable log you can export. It's evidence you can show, and the basis for access and portability requests.
Where your data lives
Application data is hosted with AWS in the EU, so personal data stays in a known region rather than wherever a vendor happens to put it. A self-hosted option for stricter residency needs is on our roadmap, not available today.
A short list of providers process data on our behalf — AWS for hosting, storage and email, and Stripe for payments. Our marketing site uses cookieless analytics. The full list, with what each one handles, is on our sub-processors page.
How it maps to the rules
A plain look at where our design meets common data-protection principles, and where the responsibility stays with you.
| Principle | What doconvoy does | Built in? |
|---|---|---|
| Data minimisation (Art. 5) | We store ciphertext only, and tokenise identifying details. | By design |
| Storage limitation (Art. 5) | Expiry is mandatory (default 3 months, max 1 year); no “never expires”. | By default |
| Integrity & confidentiality (Art. 5) | Client-side end-to-end encryption; keys never reach our servers. | By design |
| Right to erasure (Art. 17) | Crypto-shredding — per item, per person (immediate), or per workspace. | Supported |
| Access & portability (Art. 15 / 20) | List who accessed what, and export data for a subject request. | Supported |
| Lawful basis for collecting the data | We give you the tools; the lawful basis for your collection is yours to hold. | Your call |
Read the detail
Ready to collect and share sensitive data without handing it to a third party to read?
Start sharing securely