DocStash

Privacy & Terms

Last updated: 1 September 2026

DocStash ("we", "our") is a tool for uploading, versioning, and sharing documents, including from AI assistants via the Model Context Protocol (MCP). This page covers both our Privacy Policy and Terms of Service. Jump to Privacy · Jump to Terms.

For our MCP security model, see the Security page.

Privacy Policy

What we collect

Everything DocStash collects, and why.

WhatWhy we collect itWhat it is, exactly
Your documentsTo store them and serve them back to youFile contents, names, version history, descriptions
AccountTo identify youName, email, Google account ID
SessionsSo you can revoke devicesBrowser user-agent, IP at login
Connected AI agentsSo you can revoke integrationsAgent client name, authorizing device
Server logsSecurity and debuggingRequest IP addresses (rotated)
Usage analyticsTo improve the productPages visited, features used, performance signals

When you connect an AI agent, it acts only as you, on your own account. We never receive the agent's conversation with you, only the tool inputs it sends us, such as the content of a document you asked it to create.

Your documents

You own the documents you create or upload. We store them only to run the service. We do not read, analyze, index, sell, or train AI models on them, and our staff do not access their contents except to debug an issue you report (with your consent), to investigate abuse, or where legally required.

How we use it

Only to run and improve DocStash and to keep it secure. We do not sell your personal information or run advertising trackers.

Communications

We may send you product updates, tips, and occasional marketing emails. You can opt out of marketing emails at any time using the unsubscribe link in any of them. We will still send essential account and security messages, which are needed to operate your account.

Aggregated data

We may create aggregated, de-identified, or anonymized data from how DocStash is used, and use or share it for our business purposes, including to analyze and improve the service. This data is never derived from the contents, names, or descriptions of your documents, and cannot reasonably be used to identify you.

Cookies

We set one essential cookie, __Host-ds_session, which is httpOnly, Secure, and strictly necessary to keep you signed in. We don't use analytics, advertising, or third-party tracking cookies.

Third parties

DocStash processes and stores data in the United States. It runs on these sub-processors.

  • Supabase handles authentication and file storage (AWS us-east-1, USA). See supabase.com/privacy.
  • Google Cloud Run hosts the API and MCP services (GCP us-east1, USA). See Google Cloud privacy notice.
  • Vercel hosts our web surfaces (the marketing site, the product app, and the public viewer) in the US region on a global edge CDN. See vercel.com/legal/privacy-policy.
  • Google OAuth verifies your identity when you sign in (Google global infrastructure). Google shares only your name, email, and a provider-issued identifier.
  • PostHog powers anonymous, cookieless usage analytics on our marketing site only (US region). See posthog.com/privacy.

AI tool integrations

When you connect an AI assistant (Claude, ChatGPT, Cursor, etc.) via MCP and ask it to read or write a document, the document content passes through that assistant's servers under its own privacy policy. We do not control how those providers process, store, or train on that content, please review the relevant provider's terms before sharing sensitive documents.

Public documents

Documents are private to you (or your org) by default. If you explicitly flip a document to "public", either from the web UI or via the manage_sharing MCP tool, its URL becomes reachable on the open internet by anyone with the link. Public documents are not indexed or advertised by us, but they are not authenticated either. You can revoke public access at any time.

Retention & deletion

We keep your account and documents for as long as you use DocStash. Deleting a document moves it to a trash bin you can restore from, and we don't auto-empty trash, so it stays recoverable until it is permanently deleted. An organization admin can permanently delete a trashed document from the app, which removes the file and its contents and can't be undone. To delete your entire account, email us at the address below and we'll remove your data within 30 days.

We may retain certain information for as long as necessary to provide the service and for legitimate business purposes, such as security and abuse prevention, audit and usage records, resolving disputes, enforcing our terms, and complying with legal obligations. Aggregated data is handled as described above.

Your rights

If you're in a jurisdiction with a data-protection law (GDPR, CCPA, and similar) you have the right to access, correct, export, or delete your personal data. Email us and we'll handle it.

Terms of Service

Using DocStash

By creating an account or using DocStash you agree to these terms. If you don't agree, please don't use the service. You must be old enough to form a binding contract in your jurisdiction.

Your account

You're responsible for keeping your sign-in credentials safe and for any activity that happens under your account, including activity by AI agents you authorize via MCP. Revoke tokens from settings if a device or agent is compromised.

Your content

You retain ownership of the documents you upload. You grant us a limited license to store, transmit, and display them solely as needed to provide the service. If you mark a document as public, you're authorizing us to serve it without authentication to anyone with the link.

Don't upload content that's illegal, infringes someone else's rights, contains malware, or that you don't have the right to share. We may remove content that violates these rules or applicable law.

Acceptable use

  • Don't attempt to break, overload, or abuse the service.
  • Don't use DocStash to host phishing, malware, or content that's illegal where you live or where we operate.
  • Don't probe for vulnerabilities without first contacting us. Responsible reports are welcome.
  • Don't upload, create, or share sexually explicit or pornographic content, or content that sexualizes minors in any way. Child sexual abuse material (CSAM) is met with zero tolerance. It is removed, the account is terminated, and it is reported to the National Center for Missing & Exploited Children (NCMEC) and relevant authorities.
  • Don't upload or host content that is hateful, harassing, that promotes violence, or that infringes someone else's rights.

Content moderation & reporting

Publicly shared documents and uploaded images are subject to automated and manual content review. We may remove any content, disable a link, or suspend an account that violates these terms, with or without notice, to keep the platform and its users safe.

See something that breaks these rules? Report it to hello@docstash.ai and we’ll act on it.

Service availability

DocStash is provided "as is" and "as available", with no warranties of any kind. We don't guarantee uptime or that the service will be free of bugs. Your documents are stored on managed infrastructure with encryption at rest and automated backups.

Limitation of liability

To the maximum extent allowed by law, DocStash and its operators are not liable for any indirect, incidental, or consequential damages arising out of your use of the service. Our total liability is limited to what you paid us in the preceding twelve months (which, for free accounts, is zero).

Termination

You can stop using the service and delete your account at any time. We may suspend or terminate accounts that violate these terms or that pose a security or legal risk.

Ownership of the software

The DocStash software, design, and trademarks are proprietary, all rights reserved. No license to copy, modify, redistribute, or reverse-engineer the software is granted by use of the service. Enterprise customers under a separate signed agreement may receive additional rights as set out in that agreement.

Governing law

These terms are governed by the laws of India, without regard to its conflict-of-laws rules. Any dispute arising out of or relating to these terms or your use of DocStash is subject to the exclusive jurisdiction of the courts of India.

Changes

We may update these terms over time. Material changes will be reflected in the "Last updated" date at the top of this page. Continued use after a change means you accept the updated terms.

Contact

Questions about these terms or our privacy practices? hello@docstash.ai.