Privacy Policy
Last updated on August 27, 2026

Documentation.AI is a product of Keevs Health Inc. This Privacy Policy explains how Keevs Health Inc. (“Keevs Health,” “we,” “us,” or “our”) collects, uses, and shares information about you when you use the Documentation.AI websites, apps, and related services (collectively, the “Services”).
This Policy is a notice describing our privacy practices; it is not a contract. Your use of the Services is governed by our Terms and Conditions and, for business customers, any written agreement between us.
1) Who we are & scope
Documentation.AI provides AI‑powered tools to create, manage, and collaborate on technical documentation. Keevs Health Inc., a Delaware corporation headquartered at 2925 Manor Bridge Drive, Alpharetta, GA 30004, USA, is the legal entity that operates Documentation.AI and is responsible for the processing described in this Policy. This Policy applies to information we collect through our websites, the Documentation.AI app, APIs, SDKs, and customer support channels, and to information about prospective customers and visitors to our marketing website.
2) Our roles: controller & processor
The Services involve two kinds of personal information, and our role differs between them:
- Where we are the controller: for account, billing, marketing, website telemetry, and security logs, Keevs Health Inc. decides how and why the information is processed, and this Policy governs.
- Where we are the processor: for content you or your organization upload or generate in a workspace, we process it on the customer’s behalf and under the customer’s instructions. If you use the Services through an organization, that organization controls the workspace, and its agreement with us and its own privacy policy govern that content.
- Customer responsibilities (you): you are responsible for having a lawful basis and notices for any personal data you input about others, honoring deletion and retention requirements you impose internally, and configuring integrations and permissions appropriately. You must not upload special category data or highly sensitive personal data unless our contract explicitly permits it.
- DPA & subprocessors: a Data Processing Addendum (DPA) is available by emailing [email protected]. We publish our current list of subprocessors and provide at least 30 days’ prior notice before adding or replacing one, except for emergency replacements, which we notify promptly thereafter.
3) Documentation sites published by our customers
Our customers use the Services to publish documentation sites for their own users. If you visit or interact with a documentation site published by one of our customers (including its search or AI assistant), the customer who publishes that site is the controller of the information collected there, and their privacy policy governs. We process that information only as the customer’s processor, to operate the site on their behalf. Please direct requests about information collected on a customer’s documentation site to that customer; we will assist them in responding as our agreement with them requires.
4) Information we collect
We collect the following categories of information:
A. Account & contact information
- Name, email address, password (hashed), company/organization, role, and preferences.
- If you sign in with a third‑party provider (e.g., Google, GitHub), we receive basic profile info according to your settings with that provider.
B. Workspace content you choose to provide
- Documentation, source text or code snippets, files, images, prompts, model inputs/outputs, comments, tags, and project metadata you upload or create in the Services.
- If you enable integrations (e.g., repositories, knowledge bases, ticketing, chat), we access only the data necessary to perform the integration as configured by you.
C. Payment information
- If you purchase a paid plan, billing name, email, and payment method details are processed by our payment processor (Stripe). We do not store full credit/debit card numbers on our systems; the processor’s use of your information is governed by its own privacy policy and its contract with us.
D. Device & usage data (collected automatically)
- IP address, device identifiers, browser type, operating system, timestamps, pages viewed, referral URLs, crash/diagnostic logs, and product interaction events.
E. Cookies & similar technologies
- We use essential cookies and limited analytics to remember your settings, keep you signed in, understand usage, and improve the Services. You can control cookies via your browser settings; essential cookies are required for core functionality.
F. Communications & support
- Messages you send to us (including email, chat, and support tickets), plus related metadata.
5) How we use information
We use information to:
- Provide, operate, and secure the Services;
- Generate documentation and AI‑assisted outputs you request;
- Personalize features and recommend content;
- Process transactions and send transactional communications;
- Provide customer support and troubleshoot issues;
- Monitor, prevent, and detect fraud, abuse, and security incidents;
- Analyze usage to improve performance, features, and user experience;
- Comply with applicable laws and enforce our agreements.
Where a legal basis is required, we rely on performance of our contract with you, our legitimate interests (such as securing and improving the Services), your consent where required, and compliance with legal obligations.
We may de‑identify or aggregate information for analytics, research, and business reporting. De‑identified/aggregated data does not identify you and may be used for any purpose.
6) AI processing & model providers
- To generate outputs you request, we may process your prompts, documents, and related context using models we host or third‑party AI model providers under contract. We require such providers to use your information only to deliver the Services to you and not for their own advertising or profile building.
- No model training on your content: we do not use your workspace content or your model inputs and outputs to train AI models, whether our own or a third party’s. Our contracts with model providers prohibit them from using your content to train or improve their models. If we ever offer an opt‑in program that changes this, we will clearly ask for your permission first.
- Logging: prompts, context, and outputs may be logged for up to 30 days to operate, troubleshoot, and secure the Services, after which they are deleted, unless longer retention is required for a specific security or abuse investigation or by law. Access to these logs is limited, controlled, and audited.
- Human review: a limited number of authorized personnel may review content only for abuse investigation, debugging, or to resolve a support request you initiate, and are bound by confidentiality and access controls.
7) How we share information
We do not sell your personal information.
We share information with:
- Service providers/Processors that host infrastructure, store data, provide analytics, customer support tools, payment processing, email delivery, logging, and security services. Our current providers are listed on our subprocessors page;
- Integrations you enable, to the extent needed to perform the integration you configure;
- Professional advisors (lawyers, auditors, insurers) under confidentiality obligations;
- Compliance and safety: when required by law, subpoena, or to protect rights, safety, and the integrity of the Services;
- Business transfers: as part of a merger, acquisition, financing, or sale of assets. We will continue to protect your information consistent with this Policy.
Service providers may access personal information only to perform services on our behalf and are required to protect it. Our Services may also contain links to third‑party websites or services; their practices are governed by their own privacy policies, and we are not responsible for their content or practices.
8) Data retention
We keep personal information for as long as your account is active and as needed to provide the Services. After account closure:
- Workspace content is deleted from our active systems within 90 days;
- Backups expire on a rolling schedule within 35 days of the data leaving active systems;
- Billing and tax records are kept as required by law, typically up to 7 years;
- Security and audit logs are kept for up to 12 months.
We may retain information longer where required by law or necessary to establish, exercise, or defend legal claims, after which we delete or de‑identify it.
9) Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including least‑privilege access controls, audit logging, encryption in transit and at rest, and routine backups. Passwords are hashed using industry‑standard algorithms, and we recommend enabling multi‑factor authentication (MFA) where available. No method of transmission or storage is 100% secure; if we become aware of a breach affecting your information, we will notify you as required by law. To report a security vulnerability, email [email protected].
10) International data transfers
We process and store information in the United States, and some of our infrastructure providers support regional hosting, including in the EU (see our subprocessors page for locations by provider). Data protection laws in the locations where we process information may differ from those in your jurisdiction. Where we transfer personal information from a jurisdiction that restricts international transfers, we implement appropriate safeguards, such as standard contractual clauses, where required by applicable law.
11) Your rights & choices
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal information, to object to or restrict certain processing, to withdraw consent where processing is based on consent, and to not be discriminated against for exercising any of these rights. We extend the core of these rights (access, correction, deletion, and portability) to all users as a matter of practice, regardless of location.
- How to exercise your rights: update profile information in the app, or email [email protected], preferably from the address associated with your account. We will verify your identity by email confirmation or by asking you to authenticate in‑product, and respond within 45 days or as applicable law requires. You may use an authorized agent where allowed by law; we may require proof of authorization and verification of your identity.
- Export: you can request a machine‑readable export of your workspace content at the same address. Exports may exclude proprietary system logs and data we are legally required to retain.
- Appeals: if we deny your request, you may appeal by replying to our decision email with “Privacy Appeal.” We will review and respond within the timeframe required by applicable law. You may also lodge a complaint with your local data protection authority.
- Email preferences: you may opt out of non‑transactional emails by using the unsubscribe link in those messages.
- Cookies & signals: control cookies via your browser or device settings; essential cookies may be required for the Services to work. We honor Global Privacy Control (GPC) signals as a valid opt‑out of sale or sharing where applicable law requires. We do not respond to Do Not Track (DNT) signals.
12) U.S. State privacy notice (CA/CO/CT/UT/VA/OR/TX)
This section provides disclosures for residents of certain U.S. states with comprehensive privacy laws and serves as our “Notice at Collection” for California.
Categories of personal information collected (last 12 months):
- Identifiers: name, email, IP address, device identifiers.
- Commercial information: subscription tier, transaction history (via payment processor).
- Internet/electronic activity: usage analytics, logs, crash reports.
- Geolocation: coarse location from IP (no precise geolocation).
- Inferences: product preferences derived from usage.
- Sensitive personal information: account login credentials (passwords are hashed; we do not collect government IDs, precise geolocation, or biometric data).
Sources: directly from you; your devices/browsers; integrations you enable; our service providers.
Purposes: to provide and secure the Services; improve features; process transactions; support; comply with law; prevent fraud/abuse.
Disclosure for business purposes: we disclose the above categories to service providers and integrations you enable, under contracts restricting their use to our business purposes.
Sale/Share: we do not sell personal information and we do not share it for cross‑context behavioral advertising as defined by CA law. We honor Global Privacy Control (GPC) signals as an opt‑out of sale or sharing where applicable.
Your state privacy rights (where applicable): access/know, correct, delete, portability, opt out of targeted advertising (if any), opt out of sale/share (if any), and limit use/disclosure of sensitive personal information. We do not discriminate for exercising your rights. To exercise these rights, or to appeal a decision, use the process described in Section 11.
Retention: see Section 8. We retain each category of personal information for the periods needed to fulfill the purposes described above, comply with law, and protect our rights, after which we delete or de‑identify the data.
Children: we do not have actual knowledge of selling or sharing personal information of consumers under 16.
13) Children’s privacy
The Services are not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will take appropriate action.
14) Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will notify you by email or in‑product notice before they take effect, and we will post the new Policy and update the “Last updated” date. Prior versions of this Policy are available on request.
15) Contact us
For questions or requests about this Policy or your personal information, including security vulnerability reports, email [email protected].
Keevs Health Inc. (Documentation.AI)
2925 Manor Bridge Drive, Alpharetta, GA 30004, USA