Privacy policy, 20 July 2026

Local memory stays local unless you encrypt and sync it.

Kytona Limited operates docmancer.dev and the optional Docmancer Cloud service. The MIT-licensed local package has no default telemetry and does not send memory to us. This policy describes website and cloud processing.

01

Data we process

  • Account identity, contact, authentication, membership, and device metadata
  • Subscription, invoice, support, consent, and service-usage metadata
  • IP address, user agent, request timing, ciphertext size, cursor, and transfer volume
  • Website page paths and a pseudonymous account identifier for signed-in product analytics
  • Client-encrypted memory revisions, wrapped workspace keys, signatures, and opaque references

02

Data we do not receive in plaintext

Cloud memory text, tags, graph relations, project identifiers, tombstone state, query text, and local paths are encrypted on the client. Local web actions never pass through the hosted service. Device private keys are not sent. Secret detection runs on the client and reports only optional risk counts and hashed location references.

03

Website analytics

When analytics is enabled, the website uses PostHog to record page views through explicit events. Query strings, form contents, email addresses, autocaptured interactions, persistent analytics cookies, and session recordings are disabled. Signed-in sessions can be associated with a pseudonymous account identifier. This analytics applies to docmancer.dev, not to the local Docmancer package or the contents of local memory.

04

Purposes and lawful bases

We process data to perform the service contract, secure accounts and infrastructure, provide support, understand and improve the website and hosted product, comply with law, and pursue legitimate interests in reliability and abuse prevention. Optional marketing and beta-report submission rely on consent where required.

05

Sharing and retention

We use the providers listed on the subprocessors page, including PostHog for website analytics, and do not sell personal data. Account, billing, analytics, security, and support records follow documented legal and operational retention. Hosted ciphertext is exportable and deletable, while backup copies expire on the backup schedule.

06

Your rights

Depending on your location, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent. Contact privacy@kytona.com. You may also complain to the UK Information Commissioner or your local authority.

07

International transfers and security

Where providers process data outside the UK or EEA, we use an applicable adequacy decision or contractual safeguards. Security controls include client-side encryption, tenant isolation, access control, redacted logs, dependency monitoring, backups, and incident response.