Version 1.3 · Last updated 2026-08-21
Zerodoc is a private document extraction API and the trading name of Rocsoft Ltd, a limited company incorporated in the Isle of Man (“Zerodoc”, “we”), which acts as the data controller for the account data described below. For documents you submit for processing, we act as a data processor on your behalf.
We do not use advertising or third-party tracking cookies. We set exactly one cookie, and only if you choose to sign in with Google or GitHub: a short-lived security token that protects the sign-in against cross-site request forgery. It lasts ten minutes, is cleared as soon as sign-in completes, and identifies nothing about you. Your browser’s local storage is used only to operate the site: your sign-in session token, your post-login redirect, a display name you optionally set, how you first found us (referrer/UTM, recorded once at sign-up), and an optional onboarding answer. Signing out clears your session token; you can clear the rest at any time via your browser.
We measure site traffic without storing anything on your device for that purpose, and without advertising trackers of any kind. Our own first-party measurement records which pages were viewed, which links were clicked, how long a page was open, and your country and device type, against a pseudonymous identifier our servers derive from your IP address and browser type; these records are deleted after 90 days. We additionally use PostHog, an analytics service running on its EU (Frankfurt) infrastructure, configured cookielessly — it stores nothing on your device either. On our public marketing pages (never inside the signed-in app) PostHog may also record an anonymised replay of how a page was used, with every input field and all on-page text masked before it leaves your browser. For signed-in users, we record product usage events (for example “first extraction completed”) keyed to a pseudonymous account identifier — never your email address, and never anything from your documents; these are deleted when your account is deleted. All of this is done on the basis of our legitimate interests in understanding and improving the service.
To protect the service from abuse, we also keep short-lived rate-limit counters derived from your IP address through a daily-rotating salted hash — the stored value cannot be reversed to your IP, expires automatically within 48 hours, and is used for nothing except counting requests. The free demo’s allowance (3 extractions per IP address) is counted the same way but against a keyed hash that stays stable, so the allowance does not reset daily; it cannot be reversed to your IP without our secret key, expires 90 days after your last demo run, and counts nothing except demo runs.
We do not store the documents you submit, nor the text or fields extracted from them. Documents are processed in memory and discarded immediately after the API response. There is no document retention, archival, or training on your content.
Account and usage data are used solely to operate the service: authenticate you, enforce plan quotas and rate limits, bill subscriptions, and send transactional sign-in emails. We do not sell personal data or use your content to train models.
We process account and usage data to perform our contract with you (providing the API) and on the basis of our legitimate interests in operating and securing the service.
Document processing takes place in the EU. Where a sub-processor processes personal data outside the UK/EEA, we rely on appropriate safeguards such as Standard Contractual Clauses and the provider’s data-localization options.
Documents and extracted content are never retained. Account data is kept for the life of your account; usage metadata is kept as needed for billing and then aggregated or deleted. Site-traffic records are deleted after 90 days. You can request deletion of your account data at any time.
Subject to applicable law, you have rights to access, correct, delete, and port your personal data, and to object to or restrict certain processing. To exercise these, contact us at privacy@zerodoc.io.
Our Data Processing Agreement is incorporated into our Terms of Service and applies automatically to all customers.
We may update this policy; material changes will be notified via the dashboard or email. Questions: privacy@zerodoc.io.