Privacy Policy
Last updated: July 10, 2026
Doctorine B.V. ("Doctorine", "we", "us") provides a developer-documentation and API-portal platform for businesses and their teams. This Privacy Policy explains how we collect, use, share, and protect personal data when you use doctorine.xyz, app.doctorine.xyz, Doctorine-hosted documentation portals, and related services.
Our roles
Doctorine is the controller for account, billing, product usage, website, support, security, and business-contact data. For documentation, API specifications, project content, private-portal reader records, and other customer content processed inside a workspace, the customer is the controller and Doctorine acts as processor under our Data Processing Agreement.
Data we collect
- Account and identity data. Name, email address, organization name, workspace membership, role, authentication identifiers, and login security events.
- Customer content. Documentation, Markdown/MDX, OpenAPI specifications, project metadata, branches, releases, import status, publishing settings, custom-domain settings, and related version history.
- Reader and portal data. Public page requests, private portal access checks, search queries, documentation analytics, Try-It metadata, and reader identifiers when a customer enables private access or developer-account features.
- Billing and tax data. Customer name, billing email, billing address, tax identification number, subscription, invoices, payment status, and limited payment-method details supplied by Stripe. We do not store full card numbers.
- Support and communications. Messages, attachments, feedback, procurement details, and records needed to respond to requests.
- Security and operations data. IP address, device and browser information, request metadata, audit logs, abuse signals, error diagnostics, and service telemetry needed to operate and protect Doctorine.
- Optional acquisition analytics. If you consent, Google Analytics receives page views, referrer and campaign information, coarse device/browser metadata, and a first-party analytics identifier across doctorine.xyz and app.doctorine.xyz. We do not send account content, user IDs, or enable advertising signals.
Sources of data
We receive data directly from you, from your organization, from customer configuration and imported content, from connected services that you authorize, and from providers such as WorkOS for authentication and Stripe for payments, billing, tax, invoices, and the Customer Portal.
How we use data
- Provide, secure, maintain, and improve the service.
- Authenticate users, enforce workspace roles, and protect tenant boundaries.
- Build, preview, publish, roll back, and serve documentation portals.
- Process subscriptions, invoices, payment methods, tax IDs, and tax calculations.
- Detect abuse, prevent fraud, investigate incidents, and meet security obligations.
- Provide support, send service notices, and handle legal or procurement requests.
- Comply with accounting, tax, sanctions, export-control, and legal obligations.
Lawful bases
We process personal data under the GDPR and UK GDPR where applicable based on contract performance, legitimate interests in operating and securing a B2B SaaS platform, legal obligations such as tax and accounting rules, and consent where required for optional communications or non-essential cookies.
EU residency and international transfers
Doctorine is designed for EU data residency by construction. Primary application storage, database processing, object storage, and the core control plane are provisioned in the European Union where our architecture permits it. Public documentation may be cached and served from Cloudflare's global edge when a customer chooses to publish it publicly. WorkOS authentication, Stripe payments and tax, and some support/security providers may process data outside the EEA. For those transfers we rely on appropriate safeguards such as Data Processing Agreements, Standard Contractual Clauses, the EU-US Data Privacy Framework where applicable, and technical controls that minimize the data sent to each provider.
Subprocessors
We use subprocessors only where needed to provide, secure, bill, and support the service. Our current trust and subprocessor information is published at /trust/subprocessors/. Key providers include Cloudflare for edge, security, storage, and workers; Neon for EU Postgres; WorkOS for authentication; and Stripe for payments, billing, tax, invoices, and the Customer Portal. Google Analytics is a consent-controlled US/global carve-out used only for Doctorine's own website-to-dashboard acquisition journey, not customer documentation portal analytics.
Retention
We retain account and workspace data while the account is active and for a reasonable period after termination to support export, audit, dispute resolution, and reactivation. Customer content is retained until deleted by the customer or under the relevant agreement. Operational logs are kept for security and reliability needs and then deleted or anonymized. Billing, invoice, tax, and accounting records are retained for the period required by applicable law, which may be seven years or longer depending on the record and jurisdiction.
Deletion and export
Workspace administrators can request export or deletion of customer content. Verified erasure requests are handled through our deletion process, including deletion from primary systems and cryptographic erasure where encryption-key destruction is the appropriate control. Some records may be retained where required for tax, accounting, security, legal claims, or abuse prevention.
Cookies and similar technologies
We use essential cookies and similar technologies for authentication, session security, fraud prevention, load balancing, and service operation. With your explicit permission, we also use a first-party Google Analytics cookie for up to 180 days to measure the journey between doctorine.xyz and app.doctorine.xyz. Analytics is off by default; declining makes no Google Analytics request, and you can withdraw consent at any time through the "Analytics preferences" control. Advertising storage, advertising user data, personalization signals, and Google Signals remain disabled. We do not sell personal data or use Doctorine to run third-party advertising profiles.
Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or port your personal data. You may also have the right to withdraw consent and to lodge a complaint with a supervisory authority. In the Netherlands, the relevant supervisory authority is the Autoriteit Persoonsgegevens. To exercise rights, contact privacy@doctorine.xyz. If your data is controlled by a Doctorine customer, we may direct your request to that customer or assist them as processor.
US state privacy notices
We do not sell personal data and do not share personal data for cross-context behavioral advertising. We collect the categories listed above for the business purposes described in this policy. Where a US state privacy law applies, you may request access, correction, deletion, portability, or an opt-out of sale or sharing by contacting us. We do not use sensitive personal information to infer characteristics.
Children
Doctorine is a business service and is not directed to children. We do not knowingly collect personal data from children under 16.
Security
We use technical and organizational controls designed for tenant isolation, least-privilege access, encryption in transit and at rest, auditability, private-docs access gates, abuse controls, and incident response. No service can be perfectly secure, but we design Doctorine so customer workspaces, releases, objects, logs, search, and billing state are separated by tenant boundaries.
Changes
We may update this policy as Doctorine, our providers, or legal obligations change. Material changes will be posted here with a new effective date.
Contact
Privacy requests: privacy@doctorine.xyz. Legal and procurement requests: legal@doctorine.xyz.