Privacy Policy

Effective July 7, 2026 Updated August 25, 2026 Version 1.4 — DocketVox

Privacy at a Glance

(for busy legal professionals)

DocketVox is built with privacy by design at its core:

🔒 Minimal Data We collect only the minimum data needed to authenticate you and send emails on your behalf.
🧠 Never Stored (Note Content) Note body text and audio for regular dictation are never stored on our servers. Exception: Encrypted Secure Send stores encrypted (AES-256-GCM) content server-side with 2FA-gated decryption.
🚫 No Tracking No third-party analytics, no data sales, no advertising tracking.
🖥️ Self-Hosted Self-hosted on a single U.S. VPS with strong encryption.
✅ Your Rights We support your access, correction, and deletion rights by request, with quick response times. Account data export/portability is on our roadmap and not yet available.

This approach minimizes risk and supports your professional confidentiality obligations. Read the full policy below for details.

DocketVox ("we," "us," or "our") provides a secure dictation-to-email productivity tool for legal professionals. This Privacy Policy explains how we collect, use, disclose, and protect your personal data. It is designed to be transparent and compliant with applicable laws, including U.S. state privacy laws (such as Rhode Island's Data Transparency and Privacy Protection Act where applicable), CCPA/CPRA, and GDPR principles where relevant.

This policy should be read alongside our Terms & Conditions.

1. Information We Collect

We follow strict data minimization — we collect only what is necessary to provide, secure, and improve the Service.

1.1 Information You Provide Through OAuth

When signing in via Google or Microsoft, we receive:

We store this to recognize returning users. We never receive or store passwords.

1.2 Email Send Permissions

We request only the minimum scopes needed to sign you in and send email on your behalf:

We do not request read access to inboxes, contacts, calendars, or other mail data.

1.3 Information You Voluntarily Provide

1.4 Information Collected Automatically

2. What We Do NOT Collect

Privacy is foundational. We deliberately do not collect, store, or process:

This design significantly reduces privacy risk for legal professionals handling sensitive matters.

3. How We Use Your Information

We use data only for:

5. Data Storage, Security & Retention

5.1 Storage

Data resides on a single virtual private server in the United States, using SQLite databases on our own server; sensitive fields (such as OAuth tokens and other server-side secrets) are encrypted at rest before storage — the exact algorithm depends on the field class (see §5.2). We do not use third-party cloud databases or analytics processors.

5.2 Encryption & Security

5.3 Retention

6. Data Sharing & Disclosure

We do not sell, rent, or share your personal data for advertising or marketing.

Limited sharing only occurs:

We also use a small number of essential service providers: Stripe (payment processing for subscriptions), Cloudflare (bot protection on the public demo), Hugging Face and jsDelivr (delivery of the on-device speech model and library), Google Fonts (typography on our public pages), and our hosting provider. None of these receive your note content, audio, or vault keys. We use no advertising, analytics, or data-brokerage services.

7. Data Breach Notification

We maintain procedures to detect, investigate, and respond to incidents.

In a confirmed breach affecting your personal data:

You remain responsible for your account credentials and email provider security. We are not liable for breaches stemming from compromised user credentials or third-party email provider issues.

8. Your Rights & Choices

Depending on your location and applicable law (including RIDTPPA where thresholds are met, CCPA/CPRA, etc.), you may have these rights:

How to exercise rights: Email support@DocketVox.com. We respond within required timeframes (typically 30 days, extendable where allowed). Identity verification may be required.

9. Cookies & Local Storage

We use only essential or functional browser storage — no tracking or advertising cookies.

9.1 Cookie / Storage Table

9.2 Third-Party

Google/Microsoft may set cookies during OAuth (governed by their policies).

9.3 Management

No consent banner needed currently (all storage is strictly necessary/functional). Manage via browser settings. Disabling essentials may break functionality. We will add a consent banner if non-essential cookies are introduced.

10. International Data Transfers

Data is stored in the United States. If you are outside the U.S., your data may be transferred there.

Our integrations with Google and Microsoft operate under their standard data-processing terms, which include European Commission-approved Standard Contractual Clauses (SCCs) where required. If we enter into other cross-border data-transfer arrangements, we will put appropriate safeguards (such as SCCs) in place.

11. Children's Privacy

The Service is for legal professionals and not directed at anyone under 18. We do not knowingly collect data from minors and will promptly delete any such information discovered.

12. Changes to This Policy

We may update this policy periodically. Material changes will be notified via your account email and/or in-app notice. The "Last Updated" date and version number will reflect revisions. Continued use after changes constitutes acceptance.

13. Contact Us

For questions, data requests, or concerns:

Email: support@DocketVox.com
Response time: We aim to respond within 5 business days.

↑ Back to top