Dr. Redact
Legal Document
Privacy Policy
Effective Date: July 2, 2026
Last Updated: July 2, 2026
Privacy Officer: privacy@drredact.com
Plain-English Summary: We process your documents to provide redaction services. We never sell your data, never use your document content to train AI, and permanently delete your files according to your plan's retention period. This policy explains exactly what we collect, how we use it, and your rights.

Privacy Policy

drredact.com · Effective July 2, 2026

Dr. Redact ("we," "us," or "our") is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our document redaction platform at drredact.com and related mobile applications (the "Service"). Please read this policy carefully. If you disagree with its terms, please discontinue use of the Service.

1 Information We Collect

1.1 Information You Provide Directly

Data TypeExamplesPurpose
Account InformationName, email address, organization name, job titleAccount creation, authentication, communication
Payment InformationBilling address, payment method (processed by Stripe — we do not store card numbers)Payment processing, fraud prevention
DocumentsPDFs, images, Word files you upload for redactionProviding the redaction service
Support CommunicationsEmails, chat messages sent to our support teamCustomer support, service improvement
BAA InformationOrganization name, authorized signer name, titleHIPAA compliance, executed agreement records

1.2 Information Collected Automatically

Data TypeExamplesPurpose
Usage DataPages processed, plans purchased, features used, processing timestampsBilling accuracy, service improvement, abuse prevention
Device InformationIP address, browser type, operating system, device typeSecurity monitoring, fraud prevention
Log DataServer access logs, error logs, API call recordsSecurity, debugging, compliance audit trails
CookiesSession cookies, authentication tokens, preference cookiesKeeping you logged in, remembering preferences

1.3 Information We Do NOT Collect

  • We do not read, analyze, or index the content of your documents for any purpose other than performing the requested redaction
  • We do not use document content to train AI models — yours or anyone else's
  • We do not build advertising profiles from your document content
  • We do not sell any personal data to third parties

2 How We Use Your Information

We use the information we collect for the following purposes:

  • To provide the Service: Processing documents, generating redaction certificates, storing files during the retention period, and delivering results
  • To manage your account: Authentication, billing, plan management, and team access control
  • To communicate with you: Transactional emails (receipts, deletion notices, support responses), and service announcements
  • To ensure security: Detecting fraud, unauthorized access, abuse of the Service, and security threats
  • To improve the Service: Analyzing aggregate, anonymized usage patterns to improve accuracy, performance, and features
  • To comply with legal obligations: Maintaining records required by applicable law, responding to lawful government requests, and fulfilling HIPAA obligations

3 How We Handle Your Documents

3.1 Processing

Documents you upload are transmitted over TLS 1.3 encrypted connections to our processing servers. During processing, documents are temporarily held in encrypted memory to enable AI pattern detection and redaction. Processed documents are stored in AES-256 encrypted cloud storage (Amazon Web Services S3) until the retention period ends.

3.2 Access Controls

Your documents are accessible only to:

  • You and authorized members of your account team
  • Dr. Redact's automated processing systems (AI engine, storage systems)
  • Dr. Redact's security and compliance personnel when required to investigate a reported security incident or comply with a legal obligation

No Dr. Redact employee has routine access to your document content. Access to raw document data by staff requires documented authorization and audit logging.

3.3 Retention and Deletion

Your uploaded original is destroyed as soon as you process the document: the redacted output replaces it in storage, and no copy of the unredacted file is kept. Only the redacted output and its audit certificate remain for the balance of your retention period.

Documents are automatically and permanently deleted when your plan's retention period expires. Deletion is irreversible. We send advance notification emails before deletion (7 days and 1 day prior). Upon account termination, documents are retained for 30 days or the remainder of your plan's standard retention period, whichever is shorter, to allow final downloads, then permanently deleted.

3.4 No AI Training

We expressly commit that document content uploaded to Dr. Redact is never used to train, fine-tune, or evaluate any artificial intelligence model, whether operated by Dr. Redact or any third party.

4 Third-Party Services and Data Sharing

We use the following third-party service providers who may receive limited data necessary for their service function:

ProviderPurposeData SharedTheir Privacy Policy
StripePayment processingBilling information, transaction recordsstripe.com/privacy
ClerkAuthentication & user managementEmail, account credentialsclerk.com/privacy
Amazon Web ServicesCloud infrastructure & document storageEncrypted documents, metadataaws.amazon.com/privacy
AnthropicAI-assisted detection of sensitive information within documentsDocument content (processed to detect sensitive information; not used to train models)anthropic.com/legal/privacy
ResendTransactional email deliveryEmail address, message contentresend.com/legal/privacy-policy

We do not share your personal information with any other third parties except:

  • When required by law, court order, or lawful government request
  • To protect the rights, property, or safety of Dr. Redact, our users, or the public
  • In connection with a merger, acquisition, or sale of assets (with advance notice to you)
  • With your explicit written consent

5 HIPAA Privacy Practices

5.1 Business Associate Status

When you use Dr. Redact to process documents containing Protected Health Information ("PHI") as defined under the Health Insurance Portability and Accountability Act ("HIPAA"), Dr. Redact acts as a Business Associate on your behalf. Our processing of PHI is governed by the applicable Business Associate Agreement ("BAA") entered into between you and Dr. Redact.

5.2 PHI Safeguards

For accounts with an active BAA, we implement HIPAA-required administrative, physical, and technical safeguards including:

  • AES-256 encryption for PHI at rest
  • TLS 1.3 encryption for PHI in transit
  • Role-based access controls limiting PHI access
  • Audit logging of all PHI access events
  • A Business Associate Agreement is in place with Amazon Web Services; Dr. Redact is in the process of establishing a HIPAA Business Associate Agreement with its AI subprocessor, Anthropic. Until that agreement is executed, the Service must not be used to submit Protected Health Information (PHI) on any plan.
  • Breach notification procedures as required by 45 C.F.R. §164.400–414

5.3 Breach Notification

In the event of a breach of unsecured PHI, we will notify affected Covered Entities without unreasonable delay and no later than 60 calendar days after discovery of the breach, as required by the HIPAA Breach Notification Rule.

6 GDPR — Rights of EU/EEA Residents

If you are located in the European Union or European Economic Area, the General Data Protection Regulation ("GDPR") provides you with additional rights. Our lawful basis for processing your personal data is:

  • Contract performance: Processing necessary to deliver the Service you've subscribed to
  • Legitimate interests: Security monitoring, fraud prevention, service improvement
  • Legal obligation: Compliance with applicable law
  • Consent: Marketing communications (where applicable)
Right of Access
Request a copy of the personal data we hold about you
Right to Rectification
Request correction of inaccurate personal data
Right to Erasure
Request deletion of your personal data ("right to be forgotten")
Right to Portability
Receive your personal data in a structured, machine-readable format
Right to Object
Object to processing based on legitimate interests
Right to Restrict
Request restriction of processing in certain circumstances

To exercise any of these rights, contact privacy@drredact.com. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.

7 CCPA — Rights of California Residents

If you are a California resident, the California Consumer Privacy Act ("CCPA") provides you additional rights:

  • Right to Know: The categories and specific pieces of personal information we collect, the purposes for which we use it, and the categories of third parties with whom we share it
  • Right to Delete: Request deletion of personal information we have collected from you
  • Right to Opt-Out: We do not sell personal information. This right is not applicable, but we provide it as a disclosure
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights

To exercise CCPA rights, contact privacy@drredact.com. We will respond within 45 days.

8 Cookies and Tracking

We use the following types of cookies:

  • Essential cookies: Required for authentication and core Service functionality. Cannot be disabled.
  • Preference cookies: Remember your settings and preferences (e.g., dark/light mode). Can be cleared in your browser.
  • Analytics cookies: Aggregate, anonymized usage statistics to improve the Service. You may opt out via your cookie preferences.

We do not use advertising cookies or cross-site tracking. You may control cookies through your browser settings. Disabling essential cookies will prevent you from logging in to the Service.

9 Security Measures

We implement industry-standard security measures including:

  • AES-256 encryption for all documents at rest
  • TLS 1.3 for all data in transit
  • Multi-factor authentication support for all accounts
  • Regular security audits and penetration testing
  • Access logging and anomaly detection
  • SOC 2 Type II compliance (planned Year 2)

No method of electronic transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. If you believe your account has been compromised, contact security@drredact.com immediately.

10 Contact and Changes

Privacy Officer

Privacy Officer, Dr. Redact LLC
Dr. Redact LLC
4539 N 22nd St, STE N, Phoenix, Arizona 85016
Email: privacy@drredact.com

Policy Updates

We may update this Privacy Policy periodically. We will notify you of material changes by email to the address on file and by updating the "Last Updated" date above. We encourage you to review this policy periodically. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.