Privacy Policy

Effective Date: August 29, 2026

1. Introduction

Welcome to EnDocs AI ("we," "our," or "us"), a service provided by Creative Encode Technologies Pvt. Ltd. We respect your privacy and are committed to protecting your personal data and confidential documents. This Privacy Policy explains how we collect, use, process, and safeguard your information when you use our website and AI-powered document tools (the "Service").

2. Scope & Definitions

  • Personal Data: Any information that relates to an identified or identifiable individual.
  • User ("you"): The individual accessing or using the Service.
  • Uploaded Files: The documents (e.g., PDFs) you upload to the Service for processing.
  • Guest Session: A temporary, account-less usage period on our Service.

3. Information We Collect

We collect information in the following categories:

  • Information You Provide: Uploaded files, generated files, and chat queries submitted to our AI assistant.
  • Technical Information: IP addresses, browser type, device information, operating system, and approximate location.
  • Usage Information: Session identifiers, referring URLs, timestamps, page views, and interaction metrics.

4. How We Use Information

Data CategoryPurpose of Processing
Uploaded PDFsPerform requested document operations (e.g., convert, compress)
PDF MetadataAllow AI assistant to plan and orchestrate operations
Chat HistoryMaintain the context of your ongoing Guest Session
Session IDsMaintain guest session state and link your temporary files
IP/Device InfoSecurity, abuse prevention, rate-limiting, and diagnostics
AnalyticsUnderstand usage patterns to improve the Service

5. PDF Files and Document Processing

Privacy is core to EnDocs AI. We explicitly separate our AI assistant orchestration from automated document processing:

  • AI Assistant: Our AI assistant does not receive your PDF files or their full contents for general-purpose analysis. It receives only necessary file metadata to plan your request.
  • Document Processing: Your PDF files are processed by our backend systems only when required to provide the requested functionality (e.g., PDF-to-Word conversions). This is a secure, programmatic step necessary to fulfill your actions.

6. AI Features and AI Providers

When utilizing AI models (e.g., via APIs to external LLM providers), we send only the necessary context (such as your chat queries and file metadata) required to fulfill your request.

No AI Training on Your Data: We configure our external AI provider integrations (such as OpenAI) via their enterprise APIs to strictly prohibit them from using your chat inputs or metadata to train their machine learning models.

7. Guest Sessions and Account Information

No user account registration is required for core features. You use EnDocs AI via temporary Guest Sessions. While no account is needed, this does not mean usage is entirely untraceable; as outlined above, we still collect technical information (such as IP addresses and session IDs) necessary to deliver and secure the Service.

8. Cookies and Analytics

We use cookies, local storage, and similar tracking technologies to operate the Service, maintain your Guest Session, and analyze traffic. We may collect technical and usage information (such as IP address, browser type, device information, and interaction data). Where appropriate, we may aggregate or anonymize this information for analytics and service improvement. You can instruct your browser to refuse cookies, but some parts of the Service may not function properly.

9. Data Retention and Deletion

We prioritize a minimal-retention architecture. Uploaded files and generated files are automatically scheduled for deletion from our active service storage after the applicable session expires, typically within 60 minutes.

Data CategoryStandard Retention Period
Uploaded / Generated PDFs~60 minutes (tied to active session)
Chat History & Metadata~60 minutes (tied to active session)
Session IdentifiersDeleted upon session expiry/closure
Security & Error LogsUp to 30 days for diagnostics & abuse prevention
Aggregated AnalyticsRetained indefinitely in an anonymized format

* Note: Some limited technical, security, or legally required records may be retained for longer periods where strictly necessary (e.g., in secure backups).

10. Data Sharing and Service Providers

We do not sell your Personal Data. We may share information with trusted third-party service providers who assist us in operating our infrastructure. These providers process information on our behalf and are bound by appropriate confidentiality agreements. Categories of providers include:

  • Cloud Hosting Infrastructure
  • AI API Providers
  • Analytics Services
  • Security and DDoS Protection Networks

11. International Data Transfers

Our infrastructure and third-party service providers may be located in regions outside of your home country (including servers located outside of India). When we transfer Personal Data internationally, we utilize appropriate safeguards to ensure that your data remains protected in accordance with applicable laws.

12. Data Security

We use reasonable technical and organizational measures designed to protect information against unauthorized access, alteration, disclosure, loss, or destruction. These measures include TLS encryption for data in transit, encryption at rest for stored files, access controls, and active security monitoring. However, no internet transmission or electronic storage system is 100% secure, and we cannot guarantee absolute security.

13. Your Privacy Rights

Depending on your jurisdiction (including frameworks such as the Indian DPDP Act), you may have specific rights regarding your Personal Data, such as the right to:

  • Request access to your Personal Data.
  • Request correction of inaccurate data.
  • Request deletion of your data (subject to our automated deletion systems).
  • Withdraw consent, where applicable.
  • Raise a privacy grievance or complaint.

To exercise any of these rights, please contact our Support team using the details provided below.

14. Children's Privacy

EnDocs AI is not intended for individuals under the age of 18. We do not knowingly collect personal data from children in violation of applicable law. If we learn that we have collected personal data from a minor without verified parental consent, we will take immediate steps to delete that information.

15. Data Breach and Security Incidents

If we become aware of a security incident involving Personal Data, we will take reasonable steps to investigate, contain, and remediate the issue, and we will provide notifications as required by applicable law.

16. Business Transfers

If Creative Encode Technologies Pvt. Ltd. is involved in a merger, acquisition, restructuring, corporate reorganization, or sale of assets, your Personal Data and session information may be transferred as part of that transaction, subject to standard confidentiality obligations.

17. Changes to This Privacy Policy

We reserve the right to modify this Privacy Policy at any time. Changes will be posted on this page with a revised "Effective Date". Material changes may also be communicated directly through the Service where appropriate.

18. Contact Us

If you have any questions, concerns, or grievances regarding this Privacy Policy or our data practices, please contact us at:

Creative Encode Technologies Pvt. Ltd.

Support & Privacy Email: support@endocsai.com