Privacy & Terms
Last updated: 1 September 2026
DocStash ("we", "our") is a tool for uploading, versioning, and sharing documents, including from AI assistants via the Model Context Protocol (MCP). This page covers both our Privacy Policy and Terms of Service. Jump to Privacy · Jump to Terms.
For our MCP security model, see the Security page.
Privacy Policy
What we collect
Everything DocStash collects, and why.
| What | Why we collect it | What it is, exactly |
|---|---|---|
| Your documents | To store them and serve them back to you | File contents, names, version history, descriptions |
| Account | To identify you | Name, email, Google account ID |
| Sessions | So you can revoke devices | Browser user-agent, IP at login |
| Connected AI agents | So you can revoke integrations | Agent client name, authorizing device |
| Server logs | Security and debugging | Request IP addresses (rotated) |
| Usage analytics | To improve the product | Pages visited, features used, performance signals |
When you connect an AI agent, it acts only as you, on your own account. We never receive the agent's conversation with you, only the tool inputs it sends us, such as the content of a document you asked it to create.
Your documents
You own the documents you create or upload. We store them only to run the service. We do not read, analyze, index, sell, or train AI models on them, and our staff do not access their contents except to debug an issue you report (with your consent), to investigate abuse, or where legally required.
How we use it
Only to run and improve DocStash and to keep it secure. We do not sell your personal information or run advertising trackers.
Communications
We may send you product updates, tips, and occasional marketing emails. You can opt out of marketing emails at any time using the unsubscribe link in any of them. We will still send essential account and security messages, which are needed to operate your account.
Aggregated data
We may create aggregated, de-identified, or anonymized data from how DocStash is used, and use or share it for our business purposes, including to analyze and improve the service. This data is never derived from the contents, names, or descriptions of your documents, and cannot reasonably be used to identify you.
Cookies
We set one essential cookie, __Host-ds_session, which is httpOnly, Secure, and strictly necessary to keep you signed in. We don't use analytics, advertising, or third-party tracking cookies.
Third parties
DocStash processes and stores data in the United States. It runs on these sub-processors.
- Supabase handles authentication and file storage (AWS us-east-1, USA). See supabase.com/privacy.
- Google Cloud Run hosts the API and MCP services (GCP us-east1, USA). See Google Cloud privacy notice.
- Vercel hosts our web surfaces (the marketing site, the product app, and the public viewer) in the US region on a global edge CDN. See vercel.com/legal/privacy-policy.
- Google OAuth verifies your identity when you sign in (Google global infrastructure). Google shares only your name, email, and a provider-issued identifier.
- PostHog powers anonymous, cookieless usage analytics on our marketing site only (US region). See posthog.com/privacy.
AI tool integrations
When you connect an AI assistant (Claude, ChatGPT, Cursor, etc.) via MCP and ask it to read or write a document, the document content passes through that assistant's servers under its own privacy policy. We do not control how those providers process, store, or train on that content, please review the relevant provider's terms before sharing sensitive documents.
Public documents
Documents are private to you (or your org) by default. If you explicitly flip a document to "public", either from the web UI or via the manage_sharing MCP tool, its URL becomes reachable on the open internet by anyone with the link. Public documents are not indexed or advertised by us, but they are not authenticated either. You can revoke public access at any time.
Retention & deletion
We keep your account and documents for as long as you use DocStash. Deleting a document moves it to a trash bin you can restore from, and we don't auto-empty trash, so it stays recoverable until it is permanently deleted. An organization admin can permanently delete a trashed document from the app, which removes the file and its contents and can't be undone. To delete your entire account, email us at the address below and we'll remove your data within 30 days.
We may retain certain information for as long as necessary to provide the service and for legitimate business purposes, such as security and abuse prevention, audit and usage records, resolving disputes, enforcing our terms, and complying with legal obligations. Aggregated data is handled as described above.
Your rights
If you're in a jurisdiction with a data-protection law (GDPR, CCPA, and similar) you have the right to access, correct, export, or delete your personal data. Email us and we'll handle it.
Terms of Service
Using DocStash
By creating an account or using DocStash you agree to these terms. If you don't agree, please don't use the service. You must be old enough to form a binding contract in your jurisdiction.
Your account
You're responsible for keeping your sign-in credentials safe and for any activity that happens under your account, including activity by AI agents you authorize via MCP. Revoke tokens from settings if a device or agent is compromised.
Your content
You retain ownership of the documents you upload. You grant us a limited license to store, transmit, and display them solely as needed to provide the service. If you mark a document as public, you're authorizing us to serve it without authentication to anyone with the link.
Don't upload content that's illegal, infringes someone else's rights, contains malware, or that you don't have the right to share. We may remove content that violates these rules or applicable law.
Acceptable use
- Don't attempt to break, overload, or abuse the service.
- Don't use DocStash to host phishing, malware, or content that's illegal where you live or where we operate.
- Don't probe for vulnerabilities without first contacting us. Responsible reports are welcome.
- Don't upload, create, or share sexually explicit or pornographic content, or content that sexualizes minors in any way. Child sexual abuse material (CSAM) is met with zero tolerance. It is removed, the account is terminated, and it is reported to the National Center for Missing & Exploited Children (NCMEC) and relevant authorities.
- Don't upload or host content that is hateful, harassing, that promotes violence, or that infringes someone else's rights.
Content moderation & reporting
Publicly shared documents and uploaded images are subject to automated and manual content review. We may remove any content, disable a link, or suspend an account that violates these terms, with or without notice, to keep the platform and its users safe.
See something that breaks these rules? Report it to hello@docstash.ai and we’ll act on it.
Service availability
DocStash is provided "as is" and "as available", with no warranties of any kind. We don't guarantee uptime or that the service will be free of bugs. Your documents are stored on managed infrastructure with encryption at rest and automated backups.
Limitation of liability
To the maximum extent allowed by law, DocStash and its operators are not liable for any indirect, incidental, or consequential damages arising out of your use of the service. Our total liability is limited to what you paid us in the preceding twelve months (which, for free accounts, is zero).
Termination
You can stop using the service and delete your account at any time. We may suspend or terminate accounts that violate these terms or that pose a security or legal risk.
Ownership of the software
The DocStash software, design, and trademarks are proprietary, all rights reserved. No license to copy, modify, redistribute, or reverse-engineer the software is granted by use of the service. Enterprise customers under a separate signed agreement may receive additional rights as set out in that agreement.
Governing law
These terms are governed by the laws of India, without regard to its conflict-of-laws rules. Any dispute arising out of or relating to these terms or your use of DocStash is subject to the exclusive jurisdiction of the courts of India.
Changes
We may update these terms over time. Material changes will be reflected in the "Last updated" date at the top of this page. Continued use after a change means you accept the updated terms.
Contact
Questions about these terms or our privacy practices? hello@docstash.ai.