Skip to content

Privacy Policy

Effective date: Oct 7, 2026
Last updated: Oct 7, 2026

This policy explains how Docdrift handles personal data: what we collect, why, who we share it with, how long we keep it and what rights you have. It covers docdrift.io, the Docdrift app, its GitHub Apps, its MCP server and agent hooks, and its connector for AI assistants (the "Service").

1. Who we are

Docdrift is operated by Un martes a las 10 am, S.A. de C.V. ("we", "us"), Calle Perseo 1304, Col. Concepción La Cruz, C.P. 72836, San Andrés Cholula, Puebla, Mexico.

  • Privacy contact, and the person in charge of personal data requests: [email protected].

2. Two roles: your account and your workspace's content

  • Account Data. We decide how to use the data we need to run your account, bill you, keep the Service secure and run our website. For this data we're the controller (the responsable, under Mexican law), and this policy applies.
  • Customer Data. What you and your team connect to Docdrift or write in it, and what Docdrift derives from it, belongs to the customer who owns the workspace. For personal data in it (for example, the names of people who opened pull requests), we act on the customer's behalf as a processor, under our Data Processing Agreement. If you're one of those people, contact the workspace's customer first; we'll help them answer you.
  • We never store your source code. Docdrift reads code in memory while it analyzes a change and deletes it when the job ends. We keep only what we derive from it, as our Security page lists.

3. What we collect

CategoryWhat it includesWhere it comes from
Account and profileName, email address, verified email addresses of your GitHub account, GitHub username and ID, avatar, time zone and view preferenceYou, and GitHub if you sign in with it
Workspace and teamWorkspace name, your role and project access, invitations you send (with the invitee's email), your answers during onboarding (such as how many people change your code and whether you read code), and the history of actions in the workspace (audit log)You and your team
Sign-in and securityOne-time sign-in codes (stored only as a hash), session records with your browser's user agent and a hash of your IP address, and signals from our bot protection at sign-upYour browser and Cloudflare Turnstile
BillingBilling name, email, address, tax ID, plan, invoices and payments. Stripe collects your card details; we never see full card numbersYou, through Stripe
Usage recordsUnits used per period, records of analyses and AI calls (tasks, times, token counts and costs, never content), calls to our MCP server and connector (tool, project, result, never content), emails sent to you and their delivery status, and daily counts of product activity that don't identify youThe Service
Connected accountsThe email of the Notion or Google account you connect and the tokens for that connection (encrypted)Notion and Google, when you connect them
AI assistant connectionsWhich assistant you connected (Claude or ChatGPT), when, and its tokens (stored only as hashes)You
Docdrift VerifiedIf you approve publishing a repository as its admin: your GitHub identity and when you approved. If you report a public page: your reason, your text and, if you give it, your emailYou
SupportWhat you write to us and our repliesYou
Website visitsTechnical data that Cloudflare processes to deliver and protect our website, such as IP address and user agent. We don't use analytics or advertising cookies (see our Cookie Policy)Your browser

We don't ask for special categories of personal data, such as health data, and we ask you not to put them in Docdrift.

PurposeDataLegal basis (GDPR)
Create and run your account and workspace, and provide the features you useAccount, workspace, connected accounts, assistant connectionsPerforming our contract with you
Sign you in, keep the Service secure, prevent fraud and abuse (including repeated free trials and fake sign-ups)Sign-in and security, usage records, website visitsOur legitimate interest in a secure Service, and yours
Bill you, issue receipts and keep tax recordsBillingPerforming our contract; complying with tax law
Send emails about your account, your workspace and the Service (not marketing)Account, workspacePerforming our contract
Answer support requestsSupportPerforming our contract; our legitimate interest in helping users
Review reports about Verified pages and keep publishing consentDocdrift VerifiedOur legitimate interest in keeping public pages truthful; the Owner's contract
Measure and improve the Service with counts that don't identify peopleUsage recordsOur legitimate interest in improving Docdrift
Comply with the law and defend legal claimsAny, as neededComplying with legal obligations; our legitimate interest
  • You can turn off optional emails in Settings; emails required to run your account can't be turned off.
  • We don't send marketing emails. If we ever do, we'll ask for your consent where the law requires it and let you opt out in every email.
  • Where we rely on legitimate interests, you can object (section 9).
  • Under Mexican law, all these purposes are necessary for our relationship with you. We don't use your data for secondary purposes.

5. AI processing

  • Docdrift uses AI models on Google Cloud Vertex AI, in the European Union, to analyze your product. Vertex AI is configured with zero data retention: its data caching is turned off for Docdrift, checked at every deployment, and Google doesn't use the data to train models.
  • We don't use your data, or Customer Data, to train AI models.
  • Docdrift doesn't make decisions about people that have legal or similarly significant effects on them.

6. Who we share it with

  • Our subprocessors, only to run the Service: Google Cloud, Hetzner, Cloudflare, Backblaze, Resend and Stripe. The full list, with what each does and where, is on our Subprocessors page. Stripe also uses some payment data as an independent controller, for fraud prevention and its legal obligations, under its own privacy policy.
  • Services you connect, such as GitHub, Notion, Google and your AI assistant, receive what Docdrift writes or returns to them at your request, under your agreement with them.
  • Your team. Members of a workspace see each other's names and what each did in it. The Owner sees the workspace's activity log on the Team plan.
  • The public, only if the Owner publishes a Docdrift Verified page. The page never shows code, file paths, symbol names or names of private repositories.
  • Authorities, when the law requires it. We review each request and share only what's required.
  • A buyer, if Docdrift or its business is sold or merged. We'll tell you before your data becomes subject to a different privacy policy.

We don't sell personal data, we don't share it for cross-context behavioral advertising, and we don't let third parties track you on our website.

7. International transfers

We're based in Mexico. Our servers and database are in Germany, our file storage for exports and backups is in the European Union and AI analysis runs in the European Union, but some providers, such as Cloudflare, Resend and Stripe, process data in the United States and other countries. When we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, including Mexico, we use the European Commission's Standard Contractual Clauses and, for the United Kingdom, its International Data Transfer Addendum, or rely on the provider's certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions. You can ask us for a copy of these safeguards at [email protected].

Under Mexican law, sending data to providers that process it for us isn't a transfer. The only transfer we make is to Stripe, for fraud prevention and its own legal obligations; it's necessary for the payment contract, so it doesn't need your consent.

8. How long we keep it

  • Account and profile: while your account exists. When you delete your account, we remove your name, avatar and tokens and replace your email with a hash within 24 hours. In workspaces you belonged to, your past actions stay attributed to "Former member".
  • Customer Data: while the workspace uses it. When a repository is disconnected, data derived from its code, and text our AI wrote about it, is deleted within 1 hour; what the team wrote or imported stays in a trash for 30 days, unless the Owner empties it sooner. Deleting a workspace moves it to the trash for the same period.
  • Backups: deleted data leaves our backups within 84 days.
  • Security and activity records: audit log, 1 year; server logs, which never contain file paths or file contents, 30 days; notifications, email delivery records and MCP call records, 90 days; records of analyses and AI calls, 180 days; daily activity counts that don't identify people, 400 days. Sign-in codes are deleted after 24 hours and export files 24 hours after they're ready.
  • Emails we sent: our email provider keeps them for 30 days.
  • Billing records: for as long as tax law requires. In Mexico, generally 5 years.
  • Terms you accepted: which version of our terms you accepted and when, for 10 years, as Mexican commercial law requires, even after you delete your account.

9. Your rights

Depending on where you live, you have some or all of these rights. We honor them for everyone, whatever the law requires where you live.

  • Access your data and get a copy, including in a portable format.
  • Correct it. You can change most of it yourself in Settings.
  • Delete it. You can delete your account in Settings.
  • Object to processing based on our legitimate interests, and restrict processing in some cases.
  • Withdraw consent, where we rely on it, without affecting what we did before.
  • Complain to a data protection authority (section 12).

Mexico (ARCO rights). You can exercise your rights of access, rectification, cancellation and opposition, revoke your consent and limit the use or disclosure of your data by emailing [email protected] with your name, the email of your account, the right you want to exercise and what it concerns, and a document proving your identity or, if someone acts for you, their authority. We answer within 20 days and, if your request is granted, we carry it out within 15 days after our answer. We answer by email. Section 17 is this policy in Spanish for people in Mexico.

California and other U.S. states. You have the right to know what personal information we collect, use and disclose, to delete and correct it, and to opt out of its sale or sharing, which we don't do. Because we don't sell or share personal information, there's nothing to opt out of; if your browser sends an opt-out preference signal, such as Global Privacy Control, we treat it as an opt-out request anyway. We don't use sensitive personal information to infer characteristics about you, and we don't use automated decision-making technology to make significant decisions about you. We won't discriminate against you for exercising your rights. An authorized agent can make a request for you with your signed permission. If we deny your request, you can appeal by replying to our answer; we'll respond within the time your state's law sets.

How to make a request. Email [email protected] from your account's email, or tell us how to reach you. We may ask you to confirm your identity. We answer within one month under the GDPR and within 45 days under the CCPA, and tell you if we need more time as the law allows. If your request is about Customer Data, we'll pass it to the customer that owns the workspace.

10. Security

We protect personal data with the measures described on our Security page: workspace isolation checked in the application and the database, encryption in transit, encrypted credentials, hashed tokens, least-privilege access and an audit log. No system is perfectly secure; if a breach affects your data, we'll tell you and the authorities as the law requires.

11. Children

Docdrift isn't meant for anyone under 18, and we don't knowingly collect their data. If you think a child gave us personal data, email [email protected] and we'll delete it.

12. Complaints

Contact us first at [email protected]. You can also complain to:

  • in the European Union, the data protection authority of the country where you live or work;
  • in the United Kingdom, the Information Commissioner's Office (ico.org.uk);
  • in Mexico, the Secretaría Anticorrupción y Buen Gobierno;
  • in California, the California Privacy Protection Agency (cppa.ca.gov).

13. Notice for California residents

In the last 12 months we collected these categories of personal information, from the sources and for the purposes in sections 3 and 4:

  • Identifiers: name, email address, GitHub username and ID, IP address (our database keeps only a hash of it).
  • Customer records: billing name, address and tax ID.
  • Commercial information: your plan, purchases and invoices.
  • Internet or other electronic network activity: usage records and security logs.
  • Inferences: the workspace profile we set from your onboarding answers, used only to adapt the product.

We disclosed each category for a business purpose to the service providers in section 6. We didn't sell or share any of it, and we don't knowingly sell or share the personal information of anyone under 16. We keep each category for the periods in section 8.

14. Cookies

We use only strictly necessary cookies. See our Cookie Policy.

15. Google user data

How we access, use, store and share data from Google APIs is explained in our Google API disclosure.

16. Changes to this policy

If we change this policy in a way that matters, we'll email the Owner of each workspace and show a notice in the app before the change takes effect. The date at the top shows the latest version.

17. Aviso de privacidad integral (México)

Esta sección es el aviso de privacidad integral para titulares en México, conforme a la Ley Federal de Protección de Datos Personales en Posesión de los Particulares. Para ellos, esta versión en español prevalece sobre el resto de la política.

  • Responsable: Un martes a las 10 am, S.A. de C.V., con domicilio en Calle Perseo 1304, Col. Concepción La Cruz, C.P. 72836, San Andrés Cholula, Puebla, México. Departamento de datos personales: [email protected].
  • Datos que tratamos: los de la sección 3: identificación y contacto (nombre, correo, usuario de GitHub), datos de tu workspace y tu equipo, datos de acceso y seguridad, datos de facturación (nombre, domicilio y RFC o identificación fiscal; los datos de tu tarjeta los recaba Stripe, no nosotros), registros de uso, cuentas conectadas y lo que escribes a soporte. No tratamos datos personales sensibles.
  • Finalidades: crear y operar tu cuenta y tu workspace y darte las funciones que usas; iniciar sesión y proteger el servicio contra fraude y abuso; cobrarte y cumplir obligaciones fiscales; enviarte correos sobre tu cuenta y el servicio; atender soporte; revisar denuncias de páginas de Docdrift Verified; medir el servicio con conteos que no te identifican; y cumplir la ley. Todas son necesarias para la relación contigo; no usamos tus datos para finalidades secundarias ni para mercadotecnia.
  • Encargados y transferencias: nuestros proveedores (sección 6 y la lista de subprocesadores) tratan datos por nuestra cuenta, lo que no es una transferencia. La única transferencia es a Stripe, para prevenir fraudes y cumplir sus obligaciones legales; es necesaria para el contrato de pago y no requiere tu consentimiento.
  • Cómo limitar el uso o la divulgación: desactiva los correos opcionales en Settings o escribe a [email protected].
  • Derechos ARCO y revocación del consentimiento: escribe a [email protected] con tu nombre, el correo de tu cuenta, el derecho que quieres ejercer y sobre qué datos, y un documento que acredite tu identidad o, si actúa alguien por ti, su representación. Respondemos en un máximo de 20 días y, si procede, lo hacemos efectivo en los 15 días siguientes. Te respondemos por correo.
  • Tecnologías de rastreo: solo usamos cookies estrictamente necesarias para iniciar sesión y proteger el servicio; no usamos cookies de analítica ni de publicidad. Detalle en la política de cookies.
  • Cambios a este aviso: te avisamos por correo y en la app antes de que un cambio importante entre en vigor, y publicamos la versión vigente en docdrift.io/privacy.
  • Autoridad: si consideras que se vulneró tu derecho a la protección de datos, puedes acudir a la Secretaría Anticorrupción y Buen Gobierno.