Legal

Privacy Policy

Last updated: July 29, 2026

1. Information We Collect

When you use the Service (including the public PolyDocs MCP endpoint at polydocs.arcflameinteractive.com/mcp), we may collect:

  • Account Information: Name, email address, and billing details when you purchase a license.
  • API Keys: Application Tokens are stored as SHA-256 hashes in SQLite for quota tracking and rate limiting.
  • IP Addresses: Logged in access logs for security monitoring and rate limiting. Rotated weekly, retained for 30 days.
  • Usage Data: API call timestamps, endpoint access logs, monthly call counts, and aggregate usage metrics for service optimisation. Individual records purged after 90 days.
  • Generated File Paths: Output file references are tracked for lifecycle management. Local filesystem paths are rejected in remote mode.
  • Support Communications: Emails and messages sent to our support team for troubleshooting.

2. What We Do NOT Collect

We do not read, store, or log the actual content of documents generated through the Service. Document content is processed exclusively in memory during generation and is never written to long-term storage. We do not train AI models on your prompts, documents, or usage patterns. Generated files are written to a temporary output directory and auto-deleted after 24 hours of inactivity.

3. How We Use Your Information

We use collected information solely to:

  • Provide, maintain, and improve the Service.
  • Process payments and manage license tokens.
  • Communicate with you about service updates, billing, and support.
  • Detect and prevent abuse or unauthorised access.

4. Data Sharing

We do not sell your personal information. We may share data with trusted third-party processors (payment gateways, Cloudflare for access control) who are contractually bound to protect your data. We may disclose information if required by law.

5. Data Security

All API traffic is encrypted via TLS 1.3. Access to the Service is gated through Application Tokens. Our infrastructure uses industry-standard security practices. However, no system is 100% secure — we recommend you do not transmit sensitive information through generated documents.

6. Lawful Basis (GDPR)

If you are located in the European Economic Area (EEA), our lawful basis for processing your personal data is:

  • Contractual Necessity: Processing required to provide the Service under our Terms of Service.
  • Legitimate Interests: Usage analytics, security monitoring, and service improvement — balanced against your rights and interests.
  • Consent: Where required, we will obtain your consent before processing your data for specific purposes.

7. International Data Transfers

Your data may be processed on servers located outside the EEA, including in India and the United States. We ensure appropriate safeguards are in place through Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms as required by applicable law.

8. Data Retention

The table below summarises what data we store, how, and for how long:

What Stored? Retention
Document content Processed in memory only Not stored long-term
Generated files Output directory Auto-deleted after 24h of inactivity
API keys SHA-256 hashed In SQLite for quota tracking
IP addresses Access logs Rotated weekly, 30 day retention
File paths Sanitised — local paths rejected N/A (rejected in remote mode)
Usage data Monthly counts Individual records purged after 90 days

Billing information is retained as required by tax regulations. You may request deletion of your account data by contacting us.

9. Your Rights (Including GDPR)

You have the following rights regarding your personal data:

  • Right to Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure (Right to be Forgotten): Request deletion of your personal data, subject to legal retention obligations.
  • Right to Restrict Processing: Request limitation of how we use your data.
  • Right to Data Portability: Request a machine-readable copy of your data to transfer to another provider.
  • Right to Object: Object to processing based on legitimate interests or direct marketing.

To exercise any of these rights, email [email protected]. We will respond within 30 days. If you are in the EEA, you also have the right to lodge a complaint with your local data protection supervisory authority.

10. Changes to This Policy

We may update this Privacy Policy. Material changes will be notified via email or a notice on our website. Continued use after changes constitutes acceptance.

11. Contact & Data Protection Officer

For privacy-related inquiries or to contact our Data Protection Officer: [email protected].