As of September 1, 2026
Docca staff cannot see your documents, and no document is ever used to train AI.
Documents, images and uploaded files are stored encrypted with AES-256, the standard banks and governments use. All traffic runs over HTTPS. The address issued when you open a document works for that one file only and expires quickly.
Docca staff cannot see customer documents.
Docca does not run its own AI models. When you ask ChatGPT, Claude or another service to write a document, Docca only stores and displays what the AI agent writes. The data policy of the AI that creates the document is governed by the terms between you and that service.
Every document, image and file in Docca is stored encrypted with AES-256, the algorithm used by banks and governments, including the US government. Every upload and edit travels over HTTPS.
Docca staff cannot see customer documents.
Each email gets at most ten login attempts every 15 minutes. That stops anyone from guessing passwords one by one.
You can see every signed-in device. Sign out a lost laptop on its own, or all devices at once. Changing your password signs you out everywhere. Sessions end on their own after a week without use.
Docca does not run its own AI models. When you ask ChatGPT, Claude or another service to write a document, Docca only receives, stores and displays what the AI agent writes.
Share links and document addresses never show up in search engines. Only people you invite or send the link to can open them.
Every action is recorded: who, when and what. You can review logins, document views and edits, share setting changes, and team members invited or removed.
Control access per folder and per document within a workspace.
| Data | Where | How long | Deletion |
|---|---|---|---|
| Document content · images · files | Cloudflare R2 (encrypted) | Until you delete it | Original files deleted 30 days after moving to Trash |
| Account · workspace | AWS Seoul region | Until you close your account | Deleted as soon as you close your account |
| Activity log | AWS Seoul region | 1 year | Deleted automatically after that |
| Billing information | Paddle | - | Card numbers aren't stored in Docca |
Servers · database · email delivery
Seoul region
Document content and file storage (R2)
Outside Korea (US) · encrypted
Paid plan billing (email · billing details)
Outside Korea (UK)
What we collect, how long we keep it and overseas transfers are described in our Privacy Policy.
Send security questionnaires, data processing agreements and vulnerability reports to this address. We confirm receipt of vulnerability reports within three business days.
support@indinity.coEvaluating Docca for your team? Pick a time for a product walkthrough on the Team inquiries page.