Effective July 7, 2026Updated August 25, 2026Version 1.4 — DocketVox
Privacy at a Glance
(for busy legal professionals)
DocketVox is built with privacy by design at its core:
🔒 Minimal Data
We collect only the minimum data needed to authenticate you and send emails on your behalf.
🧠 Never Stored (Note Content)
Note body text and audio for regular dictation are never stored on our servers.
Exception: Encrypted Secure Send stores encrypted (AES-256-GCM) content server-side with 2FA-gated decryption.
🚫 No Tracking
No third-party analytics, no data sales, no advertising tracking.
🖥️ Self-Hosted
Self-hosted on a single U.S. VPS with strong encryption.
✅ Your Rights
We support your access, correction, and deletion rights by request, with quick response times.
Account data export/portability is on our roadmap and not yet available.
This approach minimizes risk and supports your professional confidentiality obligations. Read the full policy below for details.
DocketVox ("we," "us," or "our") provides a secure dictation-to-email productivity tool for legal professionals. This Privacy Policy explains how we collect, use, disclose, and protect your personal data. It is designed to be transparent and compliant with applicable laws, including U.S. state privacy laws (such as Rhode Island's Data Transparency and Privacy Protection Act where applicable), CCPA/CPRA, and GDPR principles where relevant.
We follow strict data minimization — we collect only what is necessary to provide, secure, and improve the Service.
1.1 Information You Provide Through OAuth
When signing in via Google or Microsoft, we receive:
Email address
Name
Profile picture URL (if provided)
Unique identifier (Google sub or Microsoft oid)
We store this to recognize returning users. We never receive or store passwords.
1.2 Email Send Permissions
We request only the minimum scopes needed to sign you in and send email on your behalf:
Google: basic profile only (openid, email address, name). We request no Gmail scopes — we never read from or send through your Gmail. Outbound mail is sent from DocketVox’s own system account over authenticated SMTP.
Microsoft:User.Read (your name and email address) and Mail.Send (send-only, via Microsoft Graph).
We do not request read access to inboxes, contacts, calendars, or other mail data.
1.3 Information You Voluntarily Provide
Recovery email (for PIN reset — optional)
Client/matter references (in email subjects — optional)
Custom note type labels and preferences (theme, timestamp format, etc.)
Vault recovery key (12-word backup phrase for the encrypted vault — optional)
WebAuthn passkeys (Face ID / Touch ID / Windows Hello — stored by your device's platform authenticator, never on our servers)
Reminder settings (titles, deadlines, recurrence)
Support communications
1.4 Information Collected Automatically
Audit logs: Metadata only (event type, success/failure, timestamp, user email). No note content or audio.
Session tokens: A random opaque token in a secure HttpOnly cookie (30-day expiry).
Technical data: Browser type, device info, and IP address (for security, rate limiting, and troubleshooting). Server logs are used for security and operations only and are not used for advertising or profiling.
2. What We Do NOT Collect
Privacy is foundational. We deliberately do not collect, store, or process:
Note body text or email content (regular dictation) — relayed through DocketVox's servers to your email recipient and never stored, cached, or retained. (Outbound sending is described in §1.2.) Encrypted Secure Send is an exception: content is stored encrypted (AES-256-GCM) on our servers with 2FA-gated decryption.
Voice recordings/audio — never stored by us and never leave your device. Speech-to-text runs entirely on-device via a local Whisper model (transformers.js, WASM; WebGPU acceleration is planned but not yet live). Your audio is transcribed in your browser and is not transmitted to us or to any third-party speech service.
Browsing history, behavior tracking, or device fingerprints (beyond rotated server logs).
Data for advertising, retargeting, or commercial brokerage.
This design significantly reduces privacy risk for legal professionals handling sensitive matters.
3. How We Use Your Information
We use data only for:
Authenticating and managing your account
Sending emails on your behalf (core functionality)
Optional PIN protection and recovery
Delivering configured reminders
Security, fraud prevention, troubleshooting, and audit logging
Service improvement (aggregated/anonymized only)
Account notices, updates, and support (with consent where required)
Complying with legal obligations
4. Legal Basis for Processing (Where Applicable)
For users in the EEA, UK, or jurisdictions requiring it:
Contract performance — Necessary to deliver the Service per our Terms.
Legitimate interests — Security, fraud prevention, improvement, and logging (balanced against your rights).
Consent — For non-essential elements (we obtain it where required and allow withdrawal).
Legal obligation — To comply with laws and valid requests.
5. Data Storage, Security & Retention
5.1 Storage
Data resides on a single virtual private server in the United States, using SQLite databases on our own server; sensitive fields (such as OAuth tokens and other server-side secrets) are encrypted at rest before storage — the exact algorithm depends on the field class (see §5.2). We do not use third-party cloud databases or analytics processors.
5.2 Encryption & Security
In transit: HTTPS (TLS 1.2+).
At rest: PINs (salted & hashed with Argon2id); client-side drafts (AES-256-GCM); encrypted vault blobs and Secure Send content (AES-256-GCM, keys wrapped via ECDH or an Argon2id key-encryption key); WebAuthn PRF key material (held in the browser only, cleared after use); OAuth tokens and other sensitive server-side fields (Fernet / AES-128-CBC with HMAC-SHA256).
Additional measures: Read-only container filesystem at runtime.
5.3 Retention
Account data/preferences: Until deletion requested (fulfilled within 30 days).
Audit logs: Metadata only, retained for security monitoring. Automated 90-day pruning is planned but not yet implemented.
Tokens (PIN reset, Secure Send decrypt links): Deleted after use or expiry. PIN reset tokens expire after 30 minutes; Secure Send links expire 3 days after sending by default (7 or 30 days if chosen by the sender); verification codes expire after 15 minutes.
6. Data Sharing & Disclosure
We do not sell, rent, or share your personal data for advertising or marketing.
Limited sharing only occurs:
With Google/Microsoft (solely per your OAuth authorization for auth/email sending).
With essential service providers (e.g., hosting) under strict contracts.
As required by law (valid legal process) — we notify you when possible.
In a business transfer (with prior notice).
We also use a small number of essential service providers: Stripe (payment processing for subscriptions), Cloudflare (bot protection on the public demo), Hugging Face and jsDelivr (delivery of the on-device speech model and library), Google Fonts (typography on our public pages), and our hosting provider. None of these receive your note content, audio, or vault keys. We use no advertising, analytics, or data-brokerage services.
7. Data Breach Notification
We maintain procedures to detect, investigate, and respond to incidents.
In a confirmed breach affecting your personal data:
We notify you without undue delay via your account email.
We provide details on the incident's nature/scope and mitigation steps.
We cooperate with you and authorities as required by law (e.g., 72-hour timelines where applicable).
You remain responsible for your account credentials and email provider security. We are not liable for breaches stemming from compromised user credentials or third-party email provider issues.
8. Your Rights & Choices
Depending on your location and applicable law (including RIDTPPA where thresholds are met, CCPA/CPRA, etc.), you may have these rights:
Access — View account info in Settings.
Correction — Contact us to correct account/identity data (some preferences, e.g., theme and note types, can be updated in Settings).
Deletion — Request account/data deletion by emailing support@DocketVox.com (processed within 30 days; anonymized security logs may remain).
Portability — Account data export is on our roadmap but is not yet available. We will update this policy when it ships.
Opt-out of sale/sharing — We do not sell data. We will update this policy and provide mechanisms if that changes.
Withdraw consent — Where based on consent (e.g., certain communications).
Non-discrimination — No adverse treatment for exercising rights.
Complain — Contact us or your supervisory authority (e.g., state AG, FTC, or EEA/UK DPA).
How to exercise rights: Email support@DocketVox.com. We respond within required timeframes (typically 30 days, extendable where allowed). Identity verification may be required.
9. Cookies & Local Storage
We use only essential or functional browser storage — no tracking or advertising cookies.
Google/Microsoft may set cookies during OAuth (governed by their policies).
9.3 Management
No consent banner needed currently (all storage is strictly necessary/functional). Manage via browser settings. Disabling essentials may break functionality. We will add a consent banner if non-essential cookies are introduced.
10. International Data Transfers
Data is stored in the United States. If you are outside the U.S., your data may be transferred there.
Our integrations with Google and Microsoft operate under their standard data-processing terms, which include European Commission-approved Standard Contractual Clauses (SCCs) where required. If we enter into other cross-border data-transfer arrangements, we will put appropriate safeguards (such as SCCs) in place.
11. Children's Privacy
The Service is for legal professionals and not directed at anyone under 18. We do not knowingly collect data from minors and will promptly delete any such information discovered.
12. Changes to This Policy
We may update this policy periodically. Material changes will be notified via your account email and/or in-app notice. The "Last Updated" date and version number will reflect revisions. Continued use after changes constitutes acceptance.
13. Contact Us
For questions, data requests, or concerns:
Email:support@DocketVox.com Response time: We aim to respond within 5 business days.