Contents
TABLE OF CONTENTS

Privacy Policy

Last updated: July 15, 2026

This Privacy Policy explains how DocsKoala ("DocsKoala", "we", "us", or "our") collects, uses, shares, and retains information when you use our documentation platform, public help centers, and in-app widget (collectively, the "Service"). It applies to our customers (organizations and their members) and, in more limited ways described below, to end users who interact with a customer's help center or widget. By using the Service, you agree to the collection and use of information as described here. See also our Terms of Service.

1. Information we collect

We collect the following categories of information:

1.1 Account information

When you sign up, we collect your name, email address, and authentication identifiers from your sign-in provider (such as GitHub or an email-based login), via our authentication provider. If you join an organization, we store your role and membership within that organization, and an authentication session cookie is used to keep you signed in.

1.2 Repository and pull request data

When you connect a GitHub repository, we receive merged pull request events, including diffs, titles, descriptions, file paths, and associated metadata, via a GitHub App installation and webhooks. We process this data to detect customer-facing changes and draft or update help articles. We do not access repositories you have not explicitly connected, and we do not read your source code outside the context of a merged pull request's diff.

1.3 Content you create

We store the help articles, drafts, review notes, edits, and version history your team creates or approves within the Service, along with any images or screenshots associated with them, and configuration such as your help center's branding and connected domains.

1.4 Widget, help center, and search usage

When end users interact with your public help center or embedded widget, we collect search queries, AI chat questions and answers, and feedback (such as thumbs up/down) to generate answers, improve answer quality, and help your team find documentation gaps. We do not require end users to create an account to search a help center or ask the widget a question.

1.5 Payment information

Subscription payments are handled by a third-party payment processor acting as merchant of record. We do not collect or store full card numbers, bank details, or other raw payment credentials on our own servers; we retain billing metadata such as plan tier, invoice history, and subscription status as provided back to us by the payment processor.

1.6 Usage and log data

We automatically collect technical data such as IP address, browser type, device information, referring pages, and pages visited, for security, debugging, abuse prevention, and product analytics purposes.

1.7 Communications

If you contact us for support or other inquiries, we retain the content of that communication and any information you choose to include in it.

2. How we use your information

We use the information we collect to:

  • Provide, operate, and maintain the Service, including generating and updating documentation;
  • Classify pull requests and draft or revise help articles using AI models;
  • Power search and AI-answered questions in your help center and widget;
  • Process payments, manage subscriptions, and prevent fraud;
  • Send account, billing, security, and product notifications;
  • Provide customer support and respond to your requests;
  • Monitor, secure, and improve the reliability and performance of the Service;
  • Understand aggregate usage patterns to improve the product;
  • Comply with legal obligations and enforce our Terms of Service.

3. AI processing of your data

Pull request diffs, help article content, and end-user questions are sent to third-party large language model providers to classify changes, draft documentation, and answer widget and search questions. DocsKoala itself never uses your content to train any model. Whether a given third-party LLM provider uses API-submitted data to train their own general-purpose models depends on that provider's own policy, which can change and which we do not independently audit or guarantee. Draft content passes through an automated editorial review step before it reaches your team for human approval; nothing is published to your help center or widget without that approval.

Your approved help articles are indexed to power AI answers and search on your own help center and widget: your widget's answers get better as your team publishes more articles, not because any model is being trained, but because there is more of your own approved content for it to find and cite. This retrieval is scoped per project: a request against one customer's help center or widget can only retrieve and cite that same customer's own approved content. Your content is never pooled with another customer's content, used to answer another customer's widget or help center, or used to train any model.

4. How we share your information

We share information only with:

  • Infrastructure and hosting providers that host our application, database, and file storage;
  • LLM providers that classify pull requests, draft articles, and answer widget and search questions on our behalf;
  • Our payment processor, which handles subscription billing as merchant of record and may independently be a data controller for payment-related information under its own privacy policy;
  • Email providers that deliver transactional and account notifications;
  • Other members of your organization, for content you create or actions you take within a shared workspace;
  • Successors, in the event of a merger, acquisition, financing, or sale of assets, subject to standard confidentiality obligations;
  • Authorities, where required to comply with law, legal process, or to protect our rights, users, or the public.

We do not sell your personal information, and we do not share it for third-party advertising purposes.

5. Data retention and deletion

We retain account and organization data for as long as your account or organization is active and for a reasonable period afterward for legal, billing, security, and dispute-resolution purposes. Pull request diffs used to draft an article are retained only as long as reasonably needed to generate and refine that draft.

Canceling a paid subscription stops future billing but does not, by itself, delete your organization's data; your content remains available if you resubscribe or reactivate. If you want your organization and its associated data deleted, you can delete the organization from your settings, or contact us at contact@docskoala.com to request deletion. We aim to complete deletion requests within a commercially reasonable period, and will retain only what we are legally required to keep (such as billing records) after that. If any part of a deletion request cannot be completed immediately through self-service, we will confirm with you directly once it is done.

6. Cookies

We use essential cookies, including an authentication session cookie set by our authentication provider, to keep you signed in and to remember basic preferences. We do not use third-party advertising cookies. Where analytics cookies are used, they are limited to understanding aggregate product usage, and end users browsing a public help center or using the widget are not required to accept any non-essential cookie to search or ask a question.

7. Data security

We apply industry-standard safeguards, including encryption in transit, role-based access controls, webhook signature verification, and row-level tenant isolation in our database, to protect your data against unauthorized access. Access to production data is restricted to personnel who need it to operate or support the Service. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. International data transfers

Your information may be processed in countries other than your own, including the United States, where our infrastructure and service providers operate. Where required by applicable law, we rely on appropriate safeguards, such as standard contractual clauses or equivalent mechanisms, for such transfers.

9. Your rights

Depending on your location, you may have the right to access, correct, export, or delete the personal information we hold about you, to object to or restrict certain processing, or to withdraw consent where processing is based on consent. You can exercise most of these rights directly from your account settings, or by contacting us at contact@docskoala.com. We will respond to verifiable requests within the timeframe required by applicable law. If you are not satisfied with our response, you may have the right to lodge a complaint with your local data protection authority.

10. End users of a customer's help center or widget

If you interact with a help center or widget powered by DocsKoala, your search queries and questions are processed on behalf of, and under the control of, the organization that operates that help center, who is the data controller for that interaction. This Privacy Policy describes how DocsKoala, as a data processor, handles that information on their behalf; for questions about how a specific organization uses your information, please contact that organization directly.

11. Children's privacy

The Service is intended for business use and is not directed at children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us so we can remove it.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Service before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.

13. Contact us

If you have questions about this Privacy Policy or how we handle your data, contact us at contact@docskoala.com.