Privacy Policy
Effective 30 September 2026 · Applies to the AllDoc website and Android beta
We keep document processing separate from advertising and support. This version sends no files to a third-party conversion API and loads no Google advertising cookies.
Who operates AllDoc
Mohit Nagar, Founder & Lead Developer, operates AllDoc from Sonipat, Haryana, India – 131027. For privacy questions, use support@alldoc.online or choose “Privacy request” on the contact form. If a domain email fails to deliver, use the contact form while mailbox delivery is being verified.
Zero permanent file retention
AllDoc does not deliberately save uploaded documents, document passwords, or generated files to disk, a database, or a document backup. This is a zero permanent file-retention design, not a claim that processing happens without temporary copies. Files are processed in server memory. The published frontend is hosted on Netlify. Document operations run on the operator’s Raspberry Pi, reached over HTTPS through Cloudflare Tunnel. Netlify serves the public pages; document uploads go directly to the Pi API through Cloudflare, not a paid conversion service. Cloudflare terminates the public TLS connection and transports requests through an encrypted tunnel to the Pi. Its LibreOffice worker writes temporary files only to a RAM-backed container filesystem and removes each job’s files before returning the result; its RAM-only Office profile is discarded when the worker is recycled. This is not browser-only processing.
- Conversion, compression, lock and unlock input is held for the request and released after processing. Passwords are used only to encrypt a new copy or decrypt the supplied file; the application does not log or persist them.
- OCR, translation and advanced export jobs run asynchronously. Job records expire within 15 minutes; generated downloads have a separate five-minute limit. OCR image intermediates use a private RAM-backed folder and are removed after each operation. A cleanup task runs every ten minutes to remove abandoned temporary files older than ten minutes; a crash can therefore leave a temporary RAM copy for up to about twenty minutes. Server shutdown discards that RAM filesystem.
- PDF editor source files remain in memory for up to 30 minutes from upload. “Clear workspace” deletes those server copies earlier. Closing a tab does not guarantee immediate server deletion.
- Generated downloads remain in memory for up to five minutes, or until you remove the result/clear the relevant workspace. Memory limits can expire files earlier.
- Stopping the server discards its in-memory workspace and downloads. Files you download to your device remain under your control.
These are application-level safeguards. They do not promise forensic secure erasure of operating-system memory, swap, crash dumps, or device backups. Application access logs omit document contents and passwords. Infrastructure providers may process IP addresses, request metadata, security logs and diagnostic information under their own policies. These are separate from AllDoc’s temporary document buffers.
OCR and translation
When you explicitly select OCR or translation, AllDoc reads document text on its own Pi using Tesseract and translates it locally using IndicTrans2 models. Document text is not submitted to Google Translate, Hugging Face inference, or a paid translation API. Hugging Face is used only to obtain model files during setup. Scans are limited to five pages; translation accepts up to 12,000 characters. Machine translation and OCR can contain mistakes. Translated PDF, Word and text exports create a new text layout. Downloaded copies remain on your device until you remove them.
Installing AllDoc
The installable web app stores only its icon, styles and offline information page for startup. The service worker does not cache uploaded documents, API responses, download links, contact submissions or passwords. Installation does not enable offline document processing: these tools need the AllDoc server to be reachable.
Android upload confirmation
Choosing a document does not upload it automatically. Before online conversion, OCR, translation, advanced document processing or an Office preview, AllDoc shows “Upload document”. Expand “Read more · Privacy & policy” to review processing details or open this policy. Selecting “Upload & convert” sends the chosen file over HTTPS to AllDoc for the requested operation; “Cancel” leaves it on your device. Only upload documents you are authorized to process. After retrieving a converted file, the app requests removal of the temporary server download. If removal cannot complete, the normal five-minute expiry still applies. Files saved in your app library remain until you delete them or uninstall.
PDF-to-Word and PDF-to-Excel extract existing text or tables; they do not perform OCR on scanned pages. Supported Word and Excel previews also use the online conversion service. Scanning and reading an existing PDF do not require a conversion upload.
Hosting, essential sessions and Android scanning
Netlify serves public pages and Cloudflare connects the Pi API. These providers may process connection metadata, such as IP addresses and request times, for delivery, security and service operation. Their infrastructure may operate outside India. Read Netlify’s privacy policy and Cloudflare’s privacy policy. Document contents are not submitted to Netlify by the document tools.
The Pi API uses an essential, secure, HttpOnly session cookie named __Host-alldoc with a 24-hour lifetime to scope your temporary files. A request token protects changes from cross-site requests. A keyed digest of the connection address is held temporarily in memory for abuse limits; it is not an advertising identifier. Blocking essential cookies prevents conversion and editing. Cross-site third-party embeds are not supported.
On Android, scanning and PDF reading run on-device. Scans and downloaded results remain in the app’s private library until you delete them or uninstall. Copies you export or share are controlled by you and the receiving app. Google Play services supplies the ML Kit scanner and may download components, updates and compatibility information. Google receives scanner performance and utilization metrics; ML Kit does not send the input document images or resulting scans to Google for processing. See Google ML Kit privacy information. Only an online document operation you confirm uploads a file to the configured AllDoc HTTPS service. The Android beta does not initialize advertising or request advertising identifiers.
Contact messages have a separate purpose
If you submit the contact form, we store your name, reply email, topic, message, submission time and a random receipt number in the operator’s local support inbox. We use them to respond, troubleshoot and handle privacy requests. Do not put passwords, financial records or document contents in the form; file attachments are not accepted. Contact records are automatically removed after 30 days while the server is running, or at the next start if it was offline. The operator can delete a receipt earlier.
The form saves a message to this server’s inbox; it does not send an automatic email. Emails you send directly to the listed email addresses are handled by the email provider and may have different retention in those mailboxes. Any continuing correspondence is outside the web form’s automatic deletion window.
Cookies, advertising and the Double-Click DART cookie notice
Advertising is disabled in this build. We do not currently load AdSense, analytics, third-party fonts, or advertising identifiers. A privacy-choice preference may be saved in your browser’s local storage if you ask AllDoc to keep advertising disabled. That preference is not a tracking identifier.
The phrase “Double-Click DART cookie” is a historical name associated with Google/DoubleClick advertising. Modern Google advertising uses cookies and other identifiers, including cookies associated with Google and doubleclick.net domains; this notice does not mean a cookie literally named DART is currently installed by AllDoc.
If Google AdSense is enabled in a future release, Google and other third-party advertising vendors may use cookies to serve ads based on visits to this and other websites. Advertising cookies can support personalized ads and measurement; even non-personalized ads may use cookies for purposes such as frequency capping and fraud prevention. Google ad code will remain disabled until the site has valid publisher settings and the required consent integration.
You can manage Google personalized advertising in My Ad Center, learn how Google uses information from partner sites, and review participating vendors’ opt-outs at YourAdChoices. Browser settings can restrict cookies. These choices may not stop every advertisement or every non-advertising use of data.
Choice, consent and regional readiness
Where applicable, we will obtain the consent required before optional advertising technologies run and provide a way to withdraw it. Personalized AdSense advertising in the EEA, UK and Switzerland requires Google’s specified certified consent-management arrangements. AllDoc’s simple privacy-preference panel is not a Google-certified CMP. Public advertising remains a separate launch requirement.
We do not sell personal information or share it for cross-context behavioral advertising in the current ad-free build. A supported Global Privacy Control signal keeps advertising disabled. A future advertising release must explain any changed data uses and provide applicable opt-out mechanisms before those uses begin.
Your privacy rights
Depending on your location and the laws that apply, you may have rights to access, correct or delete personal information, receive a portable copy, restrict or object to processing, withdraw consent, or complain to a supervisory authority. California residents may have applicable rights to know, delete, correct, opt out of sale/sharing, limit certain uses of sensitive information and receive non-discriminatory treatment. GDPR/CCPA readiness features and this notice are not a legal certification, nor a claim that every provision applies to this service.
Contact us with the relevant receipt number and the minimum information needed to identify your request. We may need proportionate verification before disclosing records. Uploaded documents cannot normally be retrieved once their short memory window expires. We aim to address requests within applicable statutory periods, which may differ from our ordinary support response target.
Security, children and changes
The application avoids logging document contents and passwords and uses HTTPS for public connections, private sessions, request-size and rate limits, bounded document processing, and an Office worker without network access. These controls reduce risk but cannot eliminate vulnerabilities or denial-of-service attacks. No service can guarantee absolute security. The service is not directed to children under 13; do not submit children’s personal information through the contact form. Material changes to processing, hosting or advertising will be reflected in this policy and its effective date before activation.