Docca

As of September 1, 2026

Security

Docca staff cannot see your documents, and no document is ever used to train AI.

How we protect data

Encrypted at rest and in transit

Documents, images and uploaded files are stored encrypted with AES-256, the standard banks and governments use. All traffic runs over HTTPS. The address issued when you open a document works for that one file only and expires quickly.

Our staff cannot see your documents

Docca staff cannot see customer documents.

Never used to train AI

Docca does not run its own AI models. When you ask ChatGPT, Claude or another service to write a document, Docca only stores and displays what the AI agent writes. The data policy of the AI that creates the document is governed by the terms between you and that service.

Security measures

Encryption everywhere

Every document, image and file in Docca is stored encrypted with AES-256, the algorithm used by banks and governments, including the US government. Every upload and edit travels over HTTPS.

  • Storage: AES-256 encrypted on Cloudflare R2
  • Transit: HTTPS everywhere
  • Passwords: stored only as one-way hashes
  • Document URLs: scoped to one file and short-lived

Strict access control

Docca staff cannot see customer documents.

Each email gets at most ten login attempts every 15 minutes. That stops anyone from guessing passwords one by one.

You can see every signed-in device. Sign out a lost laptop on its own, or all devices at once. Changing your password signs you out everywhere. Sessions end on their own after a week without use.

  • AI connection keys: work only in the workspace chosen when issued

No AI model training

Docca does not run its own AI models. When you ask ChatGPT, Claude or another service to write a document, Docca only receives, stores and displays what the AI agent writes.

Network security

Share links and document addresses never show up in search engines. Only people you invite or send the link to can open them.

  • Documents open in an isolated sandbox · outbound requests from documents are blocked
  • Images in a document load only for people who can view that document
  • Share links and document URLs: blocked from search indexing

Audit log & monitoring

Every action is recorded: who, when and what. You can review logins, document views and edits, share setting changes, and team members invited or removed.

  • Each entry shows who, when, which channel (web / AI connection / share link), and which IP and browser
  • Kept for 1 year; the Free plan shows the last 30 days
  • Admins can browse it in the app and download it as CSV

Granular permissions

Control access per folder and per document within a workspace.

  • 5 levels: None · View · Comment · Edit · Full
  • Documents inherit their folder's permissions
  • New members get View access by default
  • Share links: off by default, can expire or be revoked

Data handling and deletion

DataWhereHow longDeletion
Document content · images · filesCloudflare R2 (encrypted)Until you delete itOriginal files deleted 30 days after moving to Trash
Account · workspaceAWS Seoul regionUntil you close your accountDeleted as soon as you close your account
Activity logAWS Seoul region1 yearDeleted automatically after that
Billing informationPaddle-Card numbers aren't stored in Docca

Where your data is processed

AWS

Servers · database · email delivery

Seoul region

Cloudflare

Document content and file storage (R2)

Outside Korea (US) · encrypted

Paddle

Paid plan billing (email · billing details)

Outside Korea (UK)

What we collect, how long we keep it and overseas transfers are described in our Privacy Policy.

FAQ

Can Docca staff see my documents?
No.
Do you train AI on my documents?
No. Docca does not run its own AI models. You connect the AI that creates your documents yourself, and its data policy is governed by the terms between you and that service.
Where is my data stored?
Servers and the database are in the AWS Seoul region. Document content and files are stored encrypted in Cloudflare R2. R2 is outside Korea, as our Privacy Policy states.
Is a deleted document really deleted?
Yes. 30 days after a document goes to Trash, the original file is deleted too. When you close your account, your account and your workspaces’ documents are deleted right away.
Who can open a share link?
Only the people you send it to. Links are off by default. When you turn one on, you can set an expiry or revoke it at any time. Links never appear in search engines.
How do I send a security questionnaire?
Send it as is to support@indinity.co. We will answer each item and reply.

Contact

Send security questionnaires, data processing agreements and vulnerability reports to this address. We confirm receipt of vulnerability reports within three business days.

support@indinity.co

Evaluating Docca for your team? Pick a time for a product walkthrough on the Team inquiries page.