This Privacy Policy explains how okdoc (“we”, “us”), operator of okdocai.com, collects, uses and protects personal information when you use the Service. We act as the data controller for account data, and as a processor for the documents you send through the Service.
Account data: your name, email and organization details. Document data: the documents you create or upload, recipient names, emails and phone numbers, and signature images. Payment data: processed by our payment providers; we receive confirmation and limited metadata, not full card numbers. Usage data: logs and analytics needed to run and improve the Service.
Signer engagement data: when a document is sent for signature, we collect the audit-trail metadata needed for legal validity (timestamps, IP addresses, device and user-agent) and behavioral engagement data about how the document was viewed: opens and view count, dwell time, time spent per page, scroll depth, click heatmap, and device class. This engagement data is shared with the sender who created the document, so they can see whether and how their document was read.
We use information to provide the Service, generate and deliver documents, send signing and reminder emails, process payments, maintain the audit trail and legal validity of signatures, give the sender engagement insight into their documents, prevent abuse, and comply with legal obligations.
AI processing: to power document generation, contract analysis, automatic field mapping on uploaded PDFs, recipient-triggered translation and follow-up drafting, we send the relevant document content and prompts to OpenAI's API. OpenAI processes this content under OpenAI's API terms. We do not configure zero-retention or redaction, and we do not represent that the content is never seen or stored by OpenAI.
Where applicable law requires it, we rely on the performance of our contract with you, your consent, our legitimate interests in operating and securing the Service, and compliance with legal obligations.
We share data with service providers that help us run the Service: Supabase (database, storage and authentication), Vercel (hosting and logs), OpenAI (AI generation, contract analysis, PDF field mapping, translation and follow-up drafting), Resend (email delivery), Green API (WhatsApp message delivery, including signer phone numbers, where you enable it), Sumit (billing, invoicing and Sign&Pay), Stripe and PayPal (Sign&Pay, when your organization connects its own account), and Google Analytics 4 and Microsoft Clarity (usage analytics on our marketing site and inside the signed-in app only; not loaded on signing pages). Document engagement data is also shared with the sender of each document. A full, current list is published at okdocai.com/subprocessors. We do not sell your personal information.
Sender advertising pixels: a sender may enable their own advertising pixels (such as Meta, TikTok or Google) for documents they send. These pixels load on the signing page only after the recipient consents. okdoc does not place its own advertising pixels on signing pages.
We retain signed documents and their audit records while your account is active and for a defined period afterward (up to 7 years) to preserve their legal validity, unless you request earlier deletion. Behavioral engagement analytics are kept for a shorter defined window (up to 24 months). On request, and on closure of your account, we delete or anonymize personal data, subject to any retention required by law. These periods reflect our current retention practice and may be adjusted as we refine our data-lifecycle controls.
We use encryption in transit (TLS/HSTS), tenant isolation, encryption of connected payment-provider secrets at rest, access controls and reputable infrastructure providers to protect your data. Signed documents are sealed with a cryptographic fingerprint. More detail is at okdocai.com/security. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Subject to applicable law, you may access, correct, export or delete your personal data, and object to or restrict certain processing. To exercise these rights, contact privacy@okdocai.com. Signers may request information about a document they were asked to sign.
For visitors and signers in the United States, this is a plain-language summary of the categories of personal information we collect and why. Identifiers (name, email, phone, IP address): to create accounts, deliver documents and maintain the audit trail. Commercial and transaction information (billing details, payment confirmations): to process payments and issue invoices. Internet and device activity (opens, dwell, per-page time, scroll depth, click heatmap, device and browser data): to power signing, provide the sender with engagement insight, and run analytics. Document content you or a sender provides: to deliver the signing service and the AI features described above. We may share these categories with the sender of a document and with the subprocessors listed above. We do not sell personal information.
Our providers may process data outside your country, including in the EU and the US. Where required, we rely on appropriate safeguards for such transfers.
We use essential cookies needed to sign in and operate the Service, and limited analytics on our marketing site and inside the signed-in app (Google Analytics 4 and Microsoft Clarity); these are not loaded on signing pages. A sender may enable their own advertising pixels on documents they send; those pixels load on the signing page only after the recipient consents.
The Service is not directed to children under 18, and we do not knowingly collect their personal data.
You can connect okdoc to AI assistants (such as Claude or ChatGPT) through the Model Context Protocol (MCP). A connection is created only after you explicitly authorize it — by signing in with OAuth or by generating an API key in your dashboard — and it is scoped to your organization only: a connected assistant can access and act on your organization's documents, templates, contacts, business profile, automations and statistics, and can never access data of any other okdoc organization. Read-only API keys limit the assistant to viewing data without making changes.
Your conversations with the assistant are processed by that assistant's provider under its own privacy policy; okdoc only receives the specific tool requests the assistant makes on your behalf and handles them like any other API activity. You can revoke a connection at any time by deleting the API key or disconnecting the connector in Settings, which immediately stops all further access.
For privacy questions or requests, contact privacy@okdocai.com. We may update this Policy; material changes will be notified through the Service.