Security & Data Deletion
DocuScan is built privacy-first. Most tools never send your file anywhere — they run entirely in your browser. This page explains how we protect the small amount of data that does touch our servers, and how to have it removed.
Processing happens on your device
Scanning, conversion, compression, OCR, signing, watermarking and password protection all run locally in your browser. Your documents are not uploaded to our servers to perform these tasks.
Share links are short-lived
If you choose to create a share link, the PDF is stored temporarily and automatically deleted after 1 hour. A scheduled cleanup job also actively purges anything expired. We never index, publish, or read your files.
Abuse protection
Every API endpoint is rate-limited per client to prevent scripted abuse, and uploads are validated server-side (type and size) — a spoofed file type or oversized payload is rejected before it is stored.
In transit & at rest
The production app is served over HTTPS. When share-link storage is enabled, files live in a private bucket (never publicly listable) and are served only through our app, behind expiry checks. Hardening on the roadmap before public launch: signed download URLs, encryption at rest, and upload virus scanning.
What we store about you
No accounts yet, so we collect no name, email, or password. We keep a small anonymous cookie counter to enforce daily free limits. If you opt in to analytics, we record privacy-friendly, aggregated usage events — no ad tracking and no selling of data. You can decline analytics at any time.
Requesting data deletion
Because guest files auto-delete within an hour and we hold no account data, there is usually nothing to remove. If you submitted feedback with an email, or want any record associated with you deleted, email privacy@docuscan.app from the address in question. We will confirm and complete deletion within 30 days. To clear locally-stored preferences (consent, dismissed prompts), clear this site's data in your browser settings.
Found a vulnerability? Please report it responsibly to security@docuscan.app and give us a reasonable window to fix it before disclosure. This page will be expanded into a full policy before public launch.