DONAVIQ · PRIVACUTPrivacyTermsRefundsRetentionSafe useSupport

Production V1 · United States

Privacy Policy

Updated September 25, 2026

PRIVACUT is operated under the DONAVIQ brand by its owner. This policy explains how the V1 service handles information when you use its account, billing, text, and searchable PDF redaction features. The initial V1 offering is limited to customers in the United States.

Information we process

Account information includes the normalized email supplied by Cloudflare Access, a random internal account ID, plan and subscription state, usage counts, purchased-credit balance, and limited billing-event records. Stripe processes payment details on its own hosted pages; PRIVACUT stores Stripe references and normalized billing outcomes, not card numbers.

Document processing

V1 supports pasted text and one searchable PDF at a time. PDF bytes, rendered pages, findings, manual regions, and generated output remain in your browser. Extracted page text is sent over an encrypted connection to the PRIVACUT detection service and processed in request memory. PRIVACUT does not intentionally retain submitted text, source documents, detected values, redaction regions, or generated documents on its servers.

Purposes and data minimization

We use the minimum information needed to authenticate accounts, provide detection and redaction, enforce plan allowances, maintain billing state, prevent duplicate charges, respond to failures, protect the service, and meet legitimate financial or legal duties. Application logs exclude request bodies, document content, detected values, authorization headers, and payment secrets.

Before sign-in, a signed first-party cookie records only the current monthly free-operation count and an idempotency value. It contains no document text, detected values, file names, email address, advertising identifier, or third-party tracking data. Clearing browser data removes this guest-allowance state.

Storage and retention

Active account data is retained while needed to provide the service. Eligible ordinary closed or dormant account metadata and privacy-safe operational or security metadata are deleted immediately when safe or otherwise within a maximum target of 30 days. Financial, tax, accounting, refund, dispute, chargeback, and fraud-prevention records are a separate category and are retained only as legitimately necessary; they are not automatically deleted under the ordinary 30-day rule. Provider recovery windows may temporarily preserve recoverable database state, which remains subject to the same lifecycle controls after a restore.

Your controls

Signed-in users can export the account metadata PRIVACUT associates with them. Account deletion removes eligible account, subscription, usage, entitlement, credit, and related operational metadata after active or unresolved subscriptions end. De-identified billing events and Stripe records may remain for the separate financial-record purposes above.

Service providers and safeguards

Cloudflare provides authentication, edge delivery, application hosting, security controls, and the D1 metadata database. Stripe provides hosted checkout, payment processing, subscription management, and billing records. PRIVACUT uses encrypted transport, bounded requests, access controls, tenant-scoped account operations, signed billing webhooks, security headers, and privacy-safe logging. No service can guarantee absolute security.

Your responsibilities and contact

Only process information you are authorized to handle, review every proposed redaction, and inspect the downloaded result before sharing it. For access, correction, deletion, or privacy questions, contact donaviqtools@gmail.com. Do not email documents, card numbers, passwords, or other unnecessary sensitive information.