Privacy Policy
Racdoc Technologies Inc. · Last updated: 23 July 2026
Some highlighted items are placeholders to be finalised before this page goes fully live (dates, address, and a few details under technical review).
RacDoc — Privacy Policy
Racdoc Technologies Inc.
Effective date: 23 July 2026 · Last updated: 23 July 2026
1. Who We Are
This Privacy Policy explains how Racdoc Technologies Inc. ("RacDoc," "we," "us"), a company based in Burnaby, British Columbia, Canada, collects, uses, and protects your information when you use the RacDoc app and services (the "Service"). RacDoc is the data controller responsible for your information.
2. Our Privacy Commitment
RacDoc is a private document vault. Your documents are encrypted on your own device before they are uploaded, so we store only unreadable data. The key that unlocks them stays on your device and is never sent to us — so we cannot open your vault, and neither can anyone working for us.
RacDoc can also scan a document to detect details like its type and expiry date. The scan only suggests these details — you review and confirm them before anything is saved to your vault. Section 5 explains how that works. We never sell, rent, or trade your data.
3. Information We Collect
3.1 Account information.
When you sign up we collect your email address and a securely hashed version of your password. If you sign in with Google or Apple, we receive your email address and a unique sign-in identifier (and, from Google, optionally your name).
3.2 Technical information.
To run and secure the Service we process basic technical data such as device type and operating system, your IP address (used for authentication and security), and crash/diagnostic logs. These logs never contain the contents of your documents.
3.3 Your documents and folders.
You upload documents into encrypted folders. Your files, your file names, and your folder names are all encrypted on your device before they reach us — so we store them only in unreadable form.
3.4 Document details (metadata).
When our AI scanner reads a document, it produces a small set of details — such as document type (e.g. "Passport"), expiry date, and suggested tags. These details are encrypted on your device with your own key before they are stored, so they are held by us only in unreadable form.
4. How Your Documents Are Protected
4.1 Encrypted on your device.
Everything is encrypted on your device before it leaves your hands. Your key stays with you — we never receive it, so we cannot read your vault.
4.2 Zero-knowledge storage.
Because only you hold your keys, neither RacDoc nor our service providers can read your stored documents, file names, folder names, or document details. Our systems hold only encrypted data and the access-control records needed to run your account.
4.3 What our backend can and cannot see.
Our backend is not given your plaintext files, plaintext file keys, plaintext file names, or plaintext folder names. When you use AI scanning (Section 5), your document is read to extract its details, and the results are encrypted on your device before they are stored.
4.4 The limited operational information we can see.
5. AI Document Scanning
When you scan a document, RacDoc reads it to suggest details such as its type and expiry date. You then review, edit, and confirm those details — nothing is saved to your vault until you approve it. Here is how that processing works and what happens to your document.
5.1 What happens.
When a document is scanned, your app sends it over an encrypted connection to our secure scanning function, which passes it to our AI processing provider for classification and extraction. The provider returns the detected details (type, expiry date, suggested tags). Your app then encrypts those details with your key before they are stored.
5.2 Processed inside a secure enclave.
Your document is processed inside a secure hardware enclave — read by the AI to extract its details, never readable by us. The enclave is an isolated environment where the content cannot be viewed by any person.
5.3 Not stored by the provider.
Your document is processed inside the enclave and is not retained or logged by the AI provider once processing completes.
5.4 Where this processing happens.
This AI processing currently takes place in a secure enclave located in the United States. The provider cannot read or keep your document, but this does mean your document is briefly transferred to a US-based enclave at the moment of scanning. We are working to move this processing to Canada as the Service grows.
5.5 Limited technical metadata.
The AI provider cannot see what your document contains, but it does receive limited technical information needed to route the request — such as connection timing and request size.
5.6 No other AI services.
We do not send your documents to any other outside AI service (such as general cloud document-AI tools). AI scanning happens only through the secure enclave described here.
5.7 You are in control.
The scan only pre-fills a form for you. You can change any detail, and nothing is stored until you confirm. Scanning is optional — if it is unavailable or you skip it, you can always enter a document's details yourself.
6. How We Use Your Information
We use your information only to provide and secure the Service: to operate your account, store and sync your encrypted documents, run scanning when you request it, send you the reminders and notices described below, provide support, and keep the Service safe. We do not use your information for advertising or profiling.
7. Sharing and Secure Links
7.1 Sharing with another person.
When you share a file with another RacDoc user, sharing is done using end-to-end key exchange (X25519 with HKDF-SHA256), so the file is re-encrypted for that recipient. Only encrypted file keys and encrypted content are exposed in the process.
7.2 Secure share links.
When you create a share link, the shared content is encrypted, and a recipient can open it only with the unique link — and the optional password, if you set one — during the window you choose (1, 7, or 30 days).
7.3 Expiry and revocation.
When a share expires or you revoke it, the link can no longer be used to open the content. Any copy a recipient already downloaded to their own device is outside our control and remains their responsibility.
7.4 About share links.
A share link, by its nature, can be opened by anyone who has the link — and the password, if you set one — while it is active. Share links only with people you trust. If someone reports a share link to us for abuse and provides the link (and password, if set), we may be able to view what that specific link points to, in order to act on the report.
8. Service Providers
We use a small number of trusted providers to run the Service. They only ever hold encrypted data, except that the AI provider processes a document in readable form transiently inside the secure enclave (Section 5), where it is not stored.
- AWS S3 — stores your encrypted document files (encrypted blobs only) in Canada.
- Supabase (Auth, Postgres, Storage, Edge Functions) — stores encrypted account records, encrypted document details, and access-control data in Canada; runs the secure functions that issue short-lived upload/download links and the scanning request. Secrets are held in Supabase Vault in Canada.
- AI Secure Enclave Processor — performs the secure-enclave AI scanning in Section 5 (US-based).
- Resend — sends our transactional and reminder emails (Section 10).
- Firebase Cloud Messaging — delivers mobile push notifications.
- Apple App Store / Google Play — app distribution and sign-in.
We put data-processing terms in place with these providers where available for our plan.
9. Where Your Data Is Stored & International Transfers
Storage.
Your encrypted account data and documents are stored on infrastructure located in Canada. Because everything is encrypted under your key, it remains unreadable wherever it is stored.
Processing.
As explained in Section 5, the AI scanning step currently takes place in a secure enclave in the United States. This is a brief, transient transfer of your document for processing only — the provider cannot read or keep it. We are working to move this to Canada.
International users.
If you are located outside Canada — including in the EU/EEA, the UK, or the US — your encrypted information is transferred to and stored in Canada, which benefits from a European Commission adequacy decision for data transfers.
10. Legal Requests and Data Disclosure
If we receive a valid legal request from a competent authority, we will disclose only the limited information we actually hold, and only to the extent legally required. We will challenge requests that are improper, overbroad, or unlawful.
Because your documents and their details are encrypted with a key that only you hold, and because our AI scanning provider does not retain your document after processing, we cannot produce readable copies of your documents in response to a legal request — we do not have them. We can only ever disclose the limited account and operational information described in this policy.
11. Email and Push Notifications
We send you service messages — such as email verification, expiry reminders, and important notices — through Resend (email) and Firebase Cloud Messaging (push).
Our reminders tell you only that an item in your vault is expiring and ask you to open RacDoc to review it — with no document details in the email or push message itself, so that even if your notifications were seen by someone else, your document information is not exposed.
12. Data Retention and Deletion
12.1 Trash.
When you delete a document it is held in Trash for 30 days, during which you can restore it. After 30 days it is permanently deleted.
12.2 Account deletion.
When you delete your account, your profile, keys, document details, and encrypted documents are removed from our production systems, subject to the same 30-day recovery window before permanent deletion.
12.3 Backups.
We keep encrypted backups for disaster recovery for up to 7 days, after which they are purged. Backups are encrypted and are not used to restore individual deleted accounts.
12.4 Inactive accounts.
Accounts inactive for 24 consecutive months may be flagged for deletion after advance email warnings.
13. Recovery Methods and Biometrics
13.1 Recovery phrase.
If you choose a recovery phrase, it is generated on your device (BIP-39), and key recovery is protected using Argon2id. Your recovery phrase is known only to you — we never see or store it.
13.2 Cloud backup option.
If you choose cloud backup recovery, the backup is encrypted on your device with your backup password before it leaves your device, so we cannot read it.
13.3 Biometrics.
Face ID and fingerprint unlock are handled entirely by your device's operating system. Your biometric data never reaches our servers — the app only receives a yes/no from your device.
14. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, export, or restrict processing of your personal information, and to withdraw consent. Because your documents are encrypted under your own key, some of this you can already do yourself in the app (view, export, delete). To make a formal request, contact privacy@racdoc.com; we respond within the time required by applicable law (generally within 30 days).
15. Children's Privacy
RacDoc is intended only for adults. You must be at least 18 years old to use the Service. We do not direct the Service to anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has created an account or provided us with personal information, contact us at privacy@racdoc.com and we will close the account and delete the information. Where a minor's documents need to be kept in RacDoc, they should be managed by a responsible adult through that adult's own account.
16. We Do Not Sell Your Data
We do not sell, rent, or trade your personal information or your documents. We do not run advertising, we do not profile you for marketing, and we do not monetise your data. Our business is the Service itself — not your information.
17. Our Approach to Privacy Law
RacDoc is a Canadian company, and we operate under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation. Where other privacy laws apply to you — such as the General Data Protection Regulation in the EU/EEA, the UK GDPR, or state privacy laws in the United States — we honour the rights those laws give you.
Rather than applying different standards in different places, we build RacDoc so the same protections apply to everyone: your documents are encrypted so we cannot read them, we do not sell or share your data, we do not advertise to you or profile you, and you can access, export, or delete your information at any time.
18. Changes to This Policy
We may update this policy from time to time. If we make a material change, we will notify you through the Service or by email. The "last updated" date above shows the latest version.
19. Contact Us
Questions or requests: privacy@racdoc.com — Racdoc Technologies Inc., British Columbia, Canada.