Docmiro
🇩🇪 Deutsch

Privacy Policy

About this page: This is an English translation of our German Datenschutzerklärung for convenience; in case of any discrepancy, the German version is authoritative. It describes the actual, current scope of Docmiro during its testing/development phase (Android and iOS app, not yet published on the Play Store or App Store) and was drafted with AI assistance based on the GDPR; it will be reviewed further before public release in the app stores.

1. Controller

Lars Loris
Westring 30
76437 Rastatt
Germany
Email: contact@docmiro.com

2. Overview: what data is processed where

Docmiro deliberately follows a "local-first" principle: in the current "Light" feature set, your documents (photos/files) never leave your device. Server-side, we only process your account data and the text already recognized on your device for AI analysis — never the document or image itself.

3. Registration and user account

When you register, we collect your email address and a password of your choosing (stored by us only as a cryptographic hash, never in plain text). You may optionally provide a display name. If you enable two-factor authentication (TOTP), we store the required secret encrypted. The legal basis is performance of the usage contract (Art. 6(1)(b) GDPR). For abuse prevention, we log security-relevant events (e.g. login attempts, IP address, timestamp) for a limited period (Art. 6(1)(f) GDPR, legitimate interest in account security). For each sign-in we also store a session/device entry (internal ID, device name or app/browser identifier, time of last activity) so that sign-ins can be managed and revoked. We do not read any device identifier of your device (e.g. an advertising ID); the app does not perform usage analytics or advertising tracking.

4. Documents, text recognition and AI analysis

When you photograph or import a document, text recognition (OCR) runs entirely on your device (Android: ML Kit, iOS: Apple Vision, both offline). The image/file itself is never transmitted to our servers and stays in your device's private, app-only storage.

Only the text already recognized on your device is — if you trigger an AI analysis — sent to our server and from there, for structured extraction (e.g. counterparty, deadlines, cost), to Anthropic PBC (San Francisco, USA), the provider of the "Claude" AI model. Our server does not permanently store this text; it only forwards it for processing and logs a slim usage/cost record (model used, token count, success/failure) without the actual text content.

As Anthropic is based in the US, this involves a transfer of data to a third country. We base this on the EU Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) with Anthropic, supplemented by Anthropic's participation in the EU-US Data Privacy Framework where applicable. The legal basis for the processing is performance of the usage contract (Art. 6(1)(b) GDPR), as the AI analysis is a core feature you actively request.

AI-suggested values are only stored as a contract/deadline in your account after your explicit confirmation (locally on-device, or server-side only to the extent required for subscription/cost checks, see point 2).

5. Payment data

Paid tiers are processed exclusively via Google Play Billing. We never collect, process or store payment data (e.g. card details) ourselves — this remains entirely with Google. We only receive confirmation of a successful purchase from Google (purchase token, booked tier, expiry date) to activate your tier. Google's own privacy policy applies in addition. The iOS app currently offers no paid purchases; should purchases be offered via the Apple App Store in the future, payment data will likewise remain with Apple.

6. Email delivery

For registration confirmation, password reset and any notifications, we send emails via a mail server we operate ourselves (no third-party email marketing provider involved). This processes your email address and the respective message content. Legal basis is performance of the contract (Art. 6(1)(b) GDPR).

7. Push notifications

Local reminders (e.g. for notice periods) are scheduled entirely on-device (Android WorkManager or local iOS notifications) and never leave your device.

8. Waitlist signup

If you sign up for the waitlist using the form on this website, we collect your first name, last name and email address, as well as — for abuse prevention — your IP address and the time of signup. We use this data to notify you by email when Docmiro becomes available on the Play Store or App Store. We also send you a confirmation email when you sign up and when you unsubscribe. The legal basis is your voluntarily given consent (Art. 6(1)(a) GDPR). You may request deletion of your entry at any time yourself via the unsubscribe form on this page (just your email address is enough), or informally by emailing the address above; at the latest after the launch in the app stores and the notification, the waitlist data will be deleted, unless further consent exists (e.g. a user account in the app).

9. Server log files

When you visit this website and when the app accesses our servers, the server automatically collects and stores technically necessary information in server log files: IP address, date and time of the request, address requested, client used. This data is used solely for technical security purposes (including abuse detection and securing the admin area, Art. 6(1)(f) GDPR) and is not combined with other data sources.

10. Cookies

This website does not use any cookies that would require consent. The app does not use cookies.

11. Retention and deletion

We store account-related data for the duration of your usage contract. After account deletion, your personal data is deleted or anonymized unless statutory retention obligations require otherwise (e.g. commercial/tax retention periods for payment records). You may request account deletion at any time via the app or informally by emailing the address above.

12. Your rights

You have the right at any time to request access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR) regarding your personal data stored with us, as well as a right to object (Art. 21 GDPR) and a right to lodge a complaint with the competent supervisory authority. Where processing is based on your consent (e.g. the waitlist, see point 8), you may withdraw that consent at any time with effect for the future. Contact details in point 1.

13. Changes to this policy

Once Docmiro provides further functionality requiring additional data processing (e.g. the planned cloud sync extension, further analytics or AI providers), this privacy policy will be expanded and updated accordingly before each respective feature is released.