Privacy Policy
Last Updated: January 2026
Introduction
DocuRaksha ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we handle your information when you use our mobile application and web viewer.
Privacy-First Design: DocuRaksha is built with a zero-knowledge
architecture. We cannot access, read, or decrypt your documents.
Information We Collect
DocuRaksha is designed with privacy-first principles:
- Document Data: Your scanned documents and images are stored locally on your device and encrypted
- Master Password: Used to derive encryption keys, never stored in plain text
- Settings: Your app preferences stored locally
We do NOT collect:
- Your documents or images
- Your master password
- Personal identification information
- Location data
- Usage analytics
Data Storage & Encryption
Your data security is our top priority:
- All documents are encrypted using AES-256-GCM encryption
- Your master password is used to derive encryption keys via PBKDF2 (100,000 iterations)
- Encryption keys are stored in secure device storage
- All data remains on your device unless you enable cloud sync
Cloud Sync (Optional)
If you enable Google Drive sync:
- Your encrypted vault is uploaded to your personal Google Drive
- Data is encrypted before upload - Google cannot read your documents
- Only you can decrypt the data with your master password
- You can delete cloud data at any time from Settings
Third-Party Services
We use minimal third-party services:
- Google ML Kit: For OCR text recognition (processed locally on your device)
- Google Drive API: For optional cloud sync (encrypted data only)
No analytics or tracking services are used.
Your Rights
You have full control over your data:
- Delete all app data at any time
- Export your documents as encrypted backup
- Disable cloud sync and delete cloud data
- Use the panic PIN to show an empty vault if needed
Contact Us
For privacy questions, contact us at: docurakshaprivacy@gmail.com