1. Introduction
DocuQueue ("we", "us", "our") is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights. By using our service, you agree to the collection and use of information as described here.
2. Information We Collect
Account Information
- Email address (required for account creation)
- Password (stored as a hash, never in plaintext)
Payment Information
- Payment method details are processed by our payment provider (Dodo Payments)
- We do not store credit card numbers, UPI IDs, or bank details on our servers
- We retain billing records (transaction IDs, amounts, dates) for accounting purposes
Usage Data
- API request logs (endpoints called, timestamps, response codes)
- URLs submitted for PDF conversion (processed temporarily, not stored)
- PDF output (cached in Redis for up to 1 hour for download, then deleted)
Technical Data
- IP address (logged for rate limiting and abuse prevention)
- User-Agent header (logged for API abuse detection)
OAuth & AI Agent Data
When you connect DocuQueue to an AI client (such as Claude, ChatGPT, or Cursor) via MCP:
- OAuth tokens: Access and refresh tokens issued to authenticate your AI client. Tokens are stored encrypted and retained until you disconnect or they expire.
- Tool call logs: For each MCP tool invocation, we log the tool name, timestamp, and outcome (success/error). We do not log request parameters or response payloads.
- Session data: A session identifier to correlate requests from the same AI client session.
3. MCP & AI Agent Access
DocuQueue supports the Model Context Protocol (MCP), allowing AI assistants to access your documents through tool-based interactions.
Your AI Client Is Your Agent
When you authorize an AI client (such as Claude by Anthropic) to access DocuQueue, that client acts as your agent. We treat tool calls from your authenticated AI client the same as direct API calls from you. The AI client receives document data as part of the conversation and processes it under its own terms and privacy policy.
Pass-Through Architecture
DocuQueue's MCP server is a thin gateway. It forwards your AI client's authorized requests to our API and returns the responses. We do not store document content, template data, or tool responses beyond the time needed to process the request.
What We Do NOT Collect
- Document content or generated PDFs (processed and discarded)
- Template designs or data you submit via AI clients
- Conversation history or prompts from your AI client
- Personal information beyond your account email
Third-Party AI Client Disclaimer
Your AI client provider (Anthropic, OpenAI, etc.) processes prompts and tool results under their own privacy policies. DocuQueue does not control how third-party AI clients handle, store, or use data once it leaves our server. Please review the privacy policy of your chosen AI client.
Token Retention & Revocation
- OAuth access tokens expire after 30 minutes
- Refresh tokens expire after 7 days or when you disconnect
- You can revoke access at any time by disconnecting the AI client from your DocuQueue account
- Upon revocation, all stored tokens are immediately deleted
No AI Training
We do not use your document content, template data, or tool interactions to train AI models. Your data is used solely to provide the DocuQueue service.
4. How We Use Your Data
- Service delivery: To process your conversion requests and serve PDFs
- Authentication: To verify your identity and API key
- Billing: To manage subscriptions and process payments
- Rate limiting: To enforce plan-based rate limits and credit allocations
- Abuse prevention: To detect and prevent unauthorized use
- Communication: To send service updates, billing notifications, and support responses
- MCP tool calls: To process AI client requests and return document data
5. Data Retention
| Data Type |
Retention Period |
| Account details |
Until account deletion |
| API request logs |
30 days |
| Submitted URLs |
Not stored (processed and discarded) |
| Generated PDFs |
1 hour (Redis cache), then deleted |
| Billing records |
7 years (Indian tax law requirement) |
| IP logs |
30 days |
| OAuth access tokens |
30 minutes (then expired) |
| OAuth refresh tokens |
7 days or until disconnection |
| MCP tool call logs |
30 days |
6. Data Sharing
We do not sell, rent, or trade your personal information. Data is shared only with:
- Payment processor: Dodo Payments, for payment processing only
- Infrastructure providers: Railway (hosting), for service delivery
- AI client providers: Tool responses are returned to your authenticated AI client (e.g., Anthropic for Claude) under their own privacy policies
- Law enforcement: When required by Indian law or valid legal process
7. Data Security
We implement industry-standard security measures:
- All data in transit is encrypted via TLS
- API keys are stored as irreversible hashes
- OAuth tokens are encrypted at rest
- Database access is restricted and authenticated
- Regular security reviews of infrastructure and code
No system is 100% secure. If you discover a vulnerability, please report it responsibly to security@docuqueue.com.
8. Your Rights
You have the right to:
- Access your personal data we hold
- Correct inaccurate data in your account
- Delete your account and associated data
- Export your usage data in a portable format
- Revoke AI client access at any time via your account settings
- Opt out of non-essential communications
To exercise these rights, email arun@docuqueue.com.
9. GDPR Compliance
While DocuQueue is based in India and primarily serves Indian users, we respect the principles of the EU General Data Protection Regulation (GDPR):
- We collect only data necessary for service delivery
- We do not use your data for advertising or profiling
- You can request data deletion at any time
- We do not transfer data outside India except as required for infrastructure (hosting)
If you are an EU resident and wish to exercise GDPR rights, contact us at arun@docuqueue.com.
10. Cookies
Our API does not use cookies. Our documentation site may use essential cookies for session management only.
11. Children's Privacy
The service is not directed at individuals under 18. We do not knowingly collect data from minors.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email or a notice on our website. The "Last updated" date at the top reflects the most recent revision.
13. Contact
For privacy-related inquiries, contact us at arun@docuqueue.com.