Effective date: [COMPLETAR: date]
Controller: [COMPLETAR: name or legal entity], located at [COMPLETAR: address and country].
Privacy contact: [email protected]
Website: docpana.com
DocPana is an app for formatting academic papers (APA-UPEL, APA 7, MLA, ICONTEC and other style guides), filling in Word templates, converting between Word and PDF, and editing documents from your phone. This policy explains what data we keep, why, who we share it with, how long we keep it and how you can delete it.
1. Summary
- We keep what's needed for you to have an account and download your documents again: your name, your email, your formatting settings, your templates and the documents you generate.
- Documents in your history are deleted automatically after 90 days. Templates are kept until you delete them.
- Your text is sent to an AI provider (DeepSeek) in only two cases: when you turn on AI proofreading in the corrector, and whenever you upload a template so we can find its fields. Formatting, converting and editing happen on our server without AI.
- If you write to us from the app or rate a correction, we keep your message or your rating; we only receive your document if you deliberately check the box to attach it, and it's deleted after 30 days.
- We don't sell your data or use it for advertising. Today the app shows no ads and takes no payments.
- You can delete your account and all its data from the app (Profile → Delete account) or at https://docpana.com/en/eliminar-cuenta.
2. What data we keep and why
2.1 Your account
| Data | Where it comes from | Why |
|---|---|---|
| Name | You type it when signing up, or Google gives it to us if you sign in with Google | To show it in your profile |
| Email address | You type it when signing up, or Google gives it to us | To identify your account and sign you in |
| Password | You type it when signing up | To sign you in. We don't store your password: only an irreversible hash (salted PBKDF2-SHA256) |
| Profile photo | Only if you sign in with Google | To show it in your profile (we store the link Google gives us, not the image) |
| Your Google account identifier | Only if you sign in with Google | To recognize you next time you sign in with Google |
| App language (Spanish or English) | You choose it in Profile → Language | To use the same language on all your phones |
| Plan (Free, Basic or Pro), start date and, if it's a temporary plan (for example, Pro during a tester program), its end date | Set by the service | To apply your plan's credits and limits, and to move you back to Free when the temporary plan ends |
| Account creation date | Automatic | Account management |
| Country at sign-up (just two letters, e.g. «VE») | When the account is created: the approximate country Cloudflare infers from your connection, if our server sits behind Cloudflare; otherwise, the region set in your phone's language (the «VE» in «Spanish (Venezuela)»), which the app sends once when you sign up. We don't store your IP address or your location: the app doesn't ask for location permission | Internal aggregate statistics (how many accounts and corrections there are per country). Not used for anything else. Accounts created before 2026-10-03 don't have it |
2.2 Your formatting settings
The style guide you choose, the measurements you adjust (margins, font, line spacing…), your named personal formats, the style guides you modified, which guides you hide in the selector, and any instructions you write for the AI. We use them to give your documents the format you set up.
2.3 Your documents
What you upload to correct, convert or edit is processed in our server's memory and is not kept. If it has to be written to disk to convert it (LibreOffice or the PDF converter), it goes into a temporary folder that is deleted when done. When you upload a file that must be converted first (a .doc, .odt or .rtf), the conversion is kept on our server for up to 10 minutes so it isn't repeated when you correct it; it is deleted when used or when that time passes, and it is not included in backups.
History. The document we deliver to you (corrected, converted, exported from the editor or generated from a template) is kept in your history with its name, type, size and date, so you can download it again. We keep at most your last 50 documents and 150 MB, and each document is deleted automatically after 90 days (or sooner, if you delete it or delete your account).
Templates. When you upload a Word file as a template we keep the file, the name you give it and the fields we find (with their label, the sample text and a little of the surrounding text, so we know where each value goes). Templates don't expire: they are files you save on purpose to reuse, and they're deleted when you delete them or delete your account.
Antivirus and active content. Every file you upload is scanned by an antivirus that runs on our own server: the file is not sent to any external service to be scanned. If a threat is found, the file is rejected and our logs keep the name of the threat and your account number, not the file name or its contents. In addition, documents with macros are rejected, and anything that runs or loads by itself when the document is opened (controls, templates and images linked from the internet) is removed from the document we return to you; text, formatting, embedded images and ordinary links are kept.
Please note that documents and templates may contain personal data about you or other people (names, ID numbers, addresses). We only process them to provide the service you request.
2.4 Credits and usage
Credit balance (your plan's credits, the week's, the welcome credits and purchased ones) and their expiry dates.
Credit transactions: every time you earn or spend credits (with the reason and, where relevant, the document name), so you can see your spending history and so we can refund your credits if something fails.
Usage counters: how many AI corrections, template analyses, conversions and operations you do per day, to apply your plan's limits and prevent abuse. They only store the operation type and time, and old ones are deleted automatically.
Days you use the app: the date you last used it and which days you opened the app while signed in (just the day, not the time or what you did). We use them to know how many people keep using DocPana and, in tester programs before releasing a version, how many days each tester used it. The days are deleted after 90 days, and everything is deleted when you delete your account.
Correction log: for each correction that finishes (successfully, with an error or cancelled) we store the style guide, how many words and pages it had, whether AI was requested and used, the error code if there was one, how long it waited in the queue and how long it took, and your plan, your sign-up country and the app language at that moment. Never the file name or anything of its content. It's used for the service's internal statistics (which style guides are used, how many corrections fail, at what times there's more work). When you delete your account it becomes anonymous, no longer linked to you.
AI consumption: for each call to the AI provider we store the task type, the model, how many tokens were used and the estimated cost. We don't store the text sent. This is how we control our costs.
Promo codes: if you redeem a code (Profile → «I have a code»), we store which code you redeemed, when, and what you got (credits or days of the Pro plan), plus an irreversible fingerprint of your email (the same one as in section 7) so each code can only be used once per person. Our team sees in the admin panel who redeemed each code and their later use of the app (days you opened it, corrections made), to know which campaigns work. If the code says so, your account gets a tag with the campaign name (section 2.8). When you delete your account, the redemption becomes anonymous: the link to your account is removed and only the fingerprint remains, so the code can't be redeemed again by deleting the account and creating another one.
2.5 Technical logs
Our server keeps technical logs to detect and fix failures and to keep the service secure: the time, the IP address you connect from, the path requested and the result, and internal messages that identify your account by a number — never by your email, your name, your file names or the text of your documents. Logs rotate and are overwritten automatically: the application's take up at most about 100 MB per service, and the web server's are deleted after [COMPLETAR: 14] days.
To stop password-guessing and mass account creation, the server counts attempts per IP address and per email for a few minutes. That count is stored on the server without the IP address or the email in readable form (only an irreversible fingerprint), is deleted when it expires, and is not included in backups. If many rejected attempts keep coming from one IP address, we may block it temporarily (from minutes to a few hours).
The website and your country. To show you your country's style guide first (APA-UPEL in Venezuela, ICONTEC in Colombia, APA 7 in the rest of Latin America and in English-speaking countries…), the website asks our server for the approximate country that Cloudflare infers from your IP address. We don't store it or write it to the logs, and the website uses no cookies: that country, and the one you pick yourself under “Not your country? Change”, stay only in that browser tab (sessionStorage) and are deleted when you close it. If there's no answer, the website goes by your browser's language.
2.6 What's stored on your phone
The app stores on your phone your session (in the system's secure storage), the language you chose, whether you've seen the tutorial, and the documents you download (in the app's cache, until you share them or save them wherever you like). The app doesn't ask for location, contacts, camera or microphone permissions, and includes no analytics or tracking tools. To choose the language and the order of the style guides it uses your phone's language and region settings, which are not sent to the server, except the language you choose in Profile (saved to your account) and the phone's region, which is sent once when you create the account for your sign-up country (section 2.1). It also stores which team notices you closed (just their number), so they aren't shown to you again, and whether you accepted notifications (section 2.10). The only permission it may ask for is notifications, and only if you agree to receive them.
2.7 App integrity check (once enabled)
It is not enabled today. Once enabled, to prevent abuse (mass-created accounts, modified copies of the app) the app will ask Google Play for an integrity token when you sign up [COMPLETAR when enabling: and for which other actions, depending on the server configuration]. To issue it, Google receives signals from your device and from the installed app, which it handles under its own policy ([COMPLETAR: link to Google's privacy policy]). We receive only a verdict from Google: whether the app is the one we published on Google Play and whether the device passes its checks. The check is accompanied by a random identifier of the app installation, which is neither the advertising ID nor an identifier of your phone. We don't store identifiers of your device [COMPLETAR/REVISAR when enabling, depending on the implementation: confirm that neither the installation identifier nor the verdict is kept beyond the request].
2.8 Our team's notes and tags
When you write to us for help, or to prevent abuse, our team may add internal notes to your account (for example, what you asked and how it was solved) and tags (for example "tester", the university you come from, or a possible-abuse flag). You don't see them in the app: only our team sees them in the administration panel, and they're used to support you and protect the service. They're deleted when you delete your account.
What the team does with your account from the panel (giving you credits, changing your plan, suspending it, writing a note or adding a tag) is kept in an audit log, with who did it, when and why. That log is kept even if you delete your account, because it's the record of what each team member did (to settle complaints and detect abuse), but it then identifies your account only by a number: it doesn't keep your email, your name or the text of the notes.
2.9 Support and «Did it come out right?»
- Support requests (Profile → «Help and support»). If you write to us from the app we keep the type of problem, your message, our replies and the rest of the conversation, so we can help you and you can see the replies in «My requests». With the request the app automatically sends some technical data: the app version, your phone model and its Android version, the app language, your plan and the number of your last correction (not its content). It helps us find the problem without having to ask you. Requests are kept while you have the account and are deleted when you delete it (they're not anonymised).
- Screenshot (optional). If you attach an image to the request, we check it's a PNG, JPEG or WebP image and, before saving it, we remove its metadata (where it was taken, phone model, date). Only our team sees it in the panel, with no public link, and every time someone opens it it's recorded in the audit log. It's deleted after 30 days (the request stays).
- «Did it come out right?». When a correction finishes (or from your history) you can tell us 👍 or 👎, check what went wrong and leave a comment. We keep your answer together with the style used, the page count, whether AI was used and a summary of the change report without the text of your document (only how many changes there were in each section). It's used to measure and improve the corrector's quality. One rating per correction: if you change it, it replaces the previous one. Ratings are kept while you have the account and deleted when you delete it.
- Your document, only if you attach it. When you give 👎 you can check «Attach my document so the team can review it», which starts unchecked. Only if you check it do we copy the corrected document from your history (and the original, if we still had it) so our team can see the problem, and we record the date you gave your consent. Only our team sees it, every download is recorded in the audit log and it's deleted after 30 days, or earlier if you change your rating without checking the box or delete your account. Without the box, our team can't see your document.
2.10 Notifications (if you turn them on)
The app can send you a notification when a correction you left running in the background finishes, when our team replies to a support request and, occasionally, with a notice from the team (at most one a day). They start turned off: the app asks you after your first correction and only asks for the phone's permission if you agree; you can turn them on or off at any time in Profile → Notifications (or in the phone's settings).
If you turn them on we store your phone's notification token: an identifier issued by the system (Google's Firebase Cloud Messaging on Android, Apple Push Notification service on iPhone) through Expo so we can send messages to that installation of the app. We store it together with the platform (Android or iOS), the app's random installation identifier (the one in section 2.7, which doesn't identify your phone), the app language and the date. It's not the advertising identifier and can't be used to track you outside DocPana: only to deliver these notifications.
Notifications are delivered by Expo (Expo, a 650 Industries, Inc. company; [COMPLETAR: link to its privacy policy]), which passes them to Google or Apple to reach your phone. They receive the token and the notification text («Your document is ready», «We replied to your support request» or the team's notice) with the internal number of the correction, request or notice, to open the right screen when you tap it. They never include your file name, the text of your document or the text of your messages.
The token is deleted when you sign out on that phone, turn notifications off, sign out on all devices or delete your account, and stops being used if Google or Apple tell us the app is no longer installed.
3. Artificial intelligence: what text is sent to DeepSeek
We use the AI service of DeepSeek ([COMPLETAR: provider's legal entity according to its current terms, e.g. Hangzhou DeepSeek Artificial Intelligence Co., Ltd.]), which processes data outside Venezuela ([COMPLETAR: country, according to DeepSeek's terms; currently the People's Republic of China]). DeepSeek acts as a provider that processes the text on our behalf: it reviews it and sends the result back to us. We don't send it your name, your email or any identifier of your account.
Corrector. Only if you turn on AI proofreading (it's off by default), we send:
- the body text of the chapters you tick;
- the title-page lines of those chapters, only to add accents;
- bibliography entries that have no structure, to separate author, year and title;
- any instructions you wrote for the AI and a summary of the chosen style guide.
Direct quotations are set aside before the paragraph is sent. Headings are not sent. If you don't turn on AI, the corrector sends nothing to DeepSeek: our server applies the formatting.
Templates. When you upload a template, its text is always analyzed with AI (DeepSeek) to find the fillable fields and name them: we send the paragraphs and cells of the file (at most 400 blocks, starting with the title page). The app tells you this before you pick the file. If the AI is unavailable, the template is analyzed without it, using only the visible markers (underscores, braces, empty cells).
Filling in a template, converting between Word and PDF and editing don't use AI.
How DeepSeek uses the data it receives is governed by its own terms: [COMPLETAR: link to DeepSeek's current privacy policy and API terms, and what they say about retention and use for training].
4. Sign in with Google
If you choose "Continue with Google", Google sends us a signed token with your name, your email address (and whether Google has verified it), your profile photo and your Google account identifier. We use them only to create your DocPana account, link it to an account you already had with the same email, and identify you when you sign in. We don't ask for access to your Google Drive, your Gmail or any other data in your Google account. When you delete your DocPana account we delete this data (except the anti-abuse fingerprint in section 7).
5. Ads and payments (once enabled)
Today DocPana shows no ads and doesn't sell plans or credits. Once enabled:
- Rewarded ads (Google AdMob). You'll only see one if you choose to watch it to earn a credit. Google AdMob will collect data from your device (such as the advertising ID, IP address and ad interaction data) under its own policy ([COMPLETAR: link to Google's advertising policy]). We'll only receive from Google the signed confirmation that you watched the ad, with your account number and a transaction identifier, to give you the credit exactly once. [COMPLETAR when enabling: whether personalized ads are requested, and consent where required.]
- Purchases with Google Play. Plans and packs will be paid through Google Play Billing. Google processes the payment; we never see or store your card details. We'll receive the product purchased, its status and the purchase receipt to give you the plan or the credits.
We'll update this policy before enabling either of them.
6. Who we share your data with
We don't sell your data or hand it over for advertising. Only these providers are involved, each for its own purpose:
| Provider | Purpose | What it receives |
|---|---|---|
| DeepSeek | AI proofreading (if you turn it on) and template analysis | The text described in section 3, without your account details |
| Google (sign-in) | Verifying your identity if you sign in with Google | You exchange it with Google; we only download Google's public keys to check the token |
| [COMPLETAR: hosting provider, e.g. Oracle Cloud Infrastructure, region] | Hosting the server and database | All the data described, encrypted in transit |
| Google AdMob and Google Play (once enabled) | Rewarded ads and payments | What's described in section 5 |
| Expo (650 Industries, Inc.), and through it Google (Firebase Cloud Messaging) and Apple (APNs) | Delivering notifications, if you turn them on | Your phone's notification token and the text of each notification, with nothing from your documents (section 2.10) |
| Google Play (app integrity, once enabled) | Checking that the app is genuine and preventing abuse | Signals from your device and the app, collected by Google; we only receive its verdict (section 2.7) |
| [COMPLETAR: only if enabled] Cloudflare, Inc. | Protecting the service against attacks and delivering the website and the API | All traffic between your phone or browser and our server goes through its network: it sees your IP address and the technical data of each request, and the content (including the files you upload) passes through its servers, encrypted from your device to Cloudflare and from Cloudflare to our server. It processes it on our behalf, under its own terms ([COMPLETAR: link to Cloudflare's privacy policy]) |
We may also disclose data if a law or a competent authority requires it.
7. How long we keep your data
| Data | How long |
|---|---|
| Account, settings, templates, credit balance and transactions | As long as you have the account. Deleted when you delete it |
| History documents | 90 days at most (or less if you delete them or go over 50 documents or 150 MB) |
| Files you upload for processing | Only while they're processed (prior conversions, up to 10 minutes) |
| Usage counters | For the length of the limit period (minutes, a day) |
| Days you opened the app (date only) | 90 days; deleted when you delete your account |
| Promo code redemptions | As long as you have the account; when you delete it they become anonymous (no link to your account, with the irreversible email fingerprint) |
| Internal notes and tags our team adds to your account | As long as you have the account. Deleted when you delete it |
| Support requests (messages, replies and technical data) | As long as you have the account. Deleted when you delete it |
| Screenshot attached to a request | 30 days; then the image is deleted and the request stays |
| «Did it come out right?» ratings (with the style, page count and change-report summary without text) | As long as you have the account. Deleted when you delete it |
| Document you attach to a rating (only if you check the box) | 30 days, or earlier if you change the rating without the box or delete your account |
| Audit log of what our team does with your account (including when it opened a screenshot or downloaded your attached document) | Kept; once you delete your account it only identifies it by a number, without your email, your name or the text of the notes or your messages |
| AI consumption log (no text) | Kept for our accounting; when you delete your account it becomes anonymous, no longer linked to you |
| Correction log (style guide, words, AI, times; no name or content) | Kept for the service's statistics; when you delete your account it becomes anonymous, no longer linked to you |
| Your phone's notification token (if you turn them on) | Until you sign out on that phone, turn them off or delete your account |
| Technical logs | Rotate automatically by size; the web server's, [COMPLETAR: 14] days |
| Temporary IP address blocks after rejected attempts | From minutes to a few hours |
| Backups | We make encrypted backups of the database: daily ones (without the history) are kept for 14 days and weekly ones (with the history) for up to 28 days. Anything you delete — a document or your account — may remain inside an encrypted backup for up to 28 days and disappears when that backup expires. They're only used to restore the service after a failure |
| Anti-abuse fingerprint | See below |
Anti-abuse fingerprint. When you delete your account we keep an irreversible fingerprint of your (normalized) email and, if you signed in with Google, of your Google account identifier: an HMAC-SHA256 code computed with a secret server key. It doesn't store your email and can't be used to recover it; it's only used to recognize, if that same identity signs up again, that it already received the welcome credits, so they can't be obtained over and over by deleting and recreating accounts. It's kept with no time limit [COMPLETAR: or the period you decide] because deleting it would defeat its purpose. It's not used for anything else.
8. How to delete your account and your data
- In the app: Profile → Delete account. We ask for your password (or to confirm again with Google) so nobody can delete it with your unlocked phone. Your account, settings, formats, templates, history, credit balance and transactions are deleted immediately, and your sessions stop working.
- Without the app: at https://docpana.com/en/eliminar-cuenta, or by emailing us at [email protected] from your account's email address.
- The internal notes and tags our team may have added to your account are deleted too, as are your support requests (with their screenshots), your ratings (with any documents you attached), the days you opened the app and your phones' notification tokens.
- All that remains afterwards is the anti-abuse fingerprint in section 7 (also in promo code redemptions, which become anonymous), the AI consumption and correction logs with no link to your account, our team's audit log with your account identified only by a number (section 2.8) and, for up to 28 days, the encrypted backups.
You can also delete individual documents from your history and your templates at any time.
9. Security
- All communication between the app and the server is encrypted (HTTPS/TLS).
- Passwords are stored as an irreversible hash (PBKDF2-SHA256 with 480,000 iterations), never in plain text.
- Your session is a signed token that expires after 30 days; you can sign out on all your devices from Profile.
- The database isn't reachable from the internet, and backups are encrypted with a key that isn't on the server.
- We limit sign-in and sign-up attempts.
- The files you upload are scanned by an antivirus on our own server, and we never run macros or other active content from documents.
- Our team's access to the administration panel requires a password and a second factor (a code from an authenticator app), and every action is logged. This changes nothing in your user account.
- The server only accepts encrypted connections, receives security updates automatically and is monitored to alert us to failures and access attempts.
No system is infallible. If we detect a breach affecting your data, we'll notify you [COMPLETAR: timeframe and channel, according to applicable law].
If you find a security issue, email us at [email protected] (also listed in /.well-known/security.txt). We'll reply, and we ask you not to make it public until we've fixed it.
10. Your rights
You can ask us at any time to access your data, correct it, delete it, object to its processing or get a copy of it, by emailing [email protected] from your account's email address. We'll reply within [COMPLETAR: e.g. 30 days]. From the app you can change your language and settings, delete documents and templates, and delete your account yourself; to correct your name or email, write to us.
In Venezuela, the Constitution recognizes everyone's right to access information about them held in records, to know how it's used and to request its correction or destruction (Article 28). If you live in another country, you may have additional rights under your local law; you can also complain to your country's data protection authority. [COMPLETAR/REVISAR with a lawyer: applicable law and competent authority.]
11. Children
DocPana is meant for high school and university students and for tutoring schools. It is not directed at children under 13 [COMPLETAR/REVISAR: minimum age for the countries where it's published] and we don't knowingly collect data from children under that age. If you're under 18 [COMPLETAR/REVISAR: applicable age of majority], you need permission from your parent or guardian to use the app. If you believe a minor gave us data without that permission, write to us and we'll delete their account.
12. International transfers
Our server is located in [COMPLETAR: country or region of the hosting provider] and DeepSeek processes the text we send it outside Venezuela (section 3). [COMPLETAR: only if Cloudflare is enabled] Traffic also goes through Cloudflare's network, which has servers in many countries and serves it from the one closest to you. By using DocPana, your data is processed in those countries, whose data protection laws may differ from yours.
13. Changes to this policy
If we change this policy we'll tell you in the app or by email before the change takes effect, and update the date above. If the change affects how we use your data, we'll ask for your consent where the law requires it.
14. Contact
[COMPLETAR: name or legal entity of the controller]
[COMPLETAR: address and country]
Privacy and your data: [email protected]
Help with the app: [email protected]
Security: [email protected]