Privacy Policy

What data we collect, why, and your rights under the GDPR.

Last updated: 16 July 2026

This policy explains what personal data we process when you use univerdev.com and the Docora app, and the rights you have under the GDPR and German data protection law (BDSG).

1. Who is responsible

The controller under Art. 4(7) GDPR is:

Universus Developers – Ibrahim Ali Germany [email protected]

You can reach us about any data protection question at that address. We are not required to appoint a Data Protection Officer under Art. 37 GDPR.

2. Data minimisation

Docora processes your documents on your own device. Our server only handles your account, billing, and — when you use an online AI feature — acts as a gateway to the AI provider. We don't store your document contents.

We don't sell your data, and we don't use it for advertising or profiling.

3. What we process

We process these categories of data, each on the legal basis shown (Art. 6(1) GDPR):

PurposeDataLegal basis
Account & loginName, email, hashed password, verification statusArt. 6(1)(b) — contract
Session securityDevice fingerprint, user-agent, IP address, session cookiesArt. 6(1)(f) — legitimate interest (preventing account sharing and abuse)
PaymentsPlan, transaction history, Stripe customer ID. Card details go straight to Stripe and never reach us.Art. 6(1)(b) — contract; Art. 6(1)(c) — tax retention
Online AI featuresThe content of a single AI request, passed to the provider you chose and not kept afterwardsArt. 6(1)(b) — contract
Emails (verification, password reset)Email address, languageArt. 6(1)(b) — contract

4. Cookies

We use only strictly necessary cookies: a login token and a CSRF token. Your language choice is stored locally.

These are required for the service you asked for, so under § 25(2) TTDSG they need no consent. We use no analytics or tracking cookies, so there's no cookie banner.

5. Who processes your data

Your account data lives on our own server in Germany (Hetzner). For specific tasks we use these providers, acting on our instructions under Art. 28 GDPR:

PurposeDataLegal basis
Account server & databaseOur own server (Hetzner, Germany)Germany (EU)
Website hostingVercelUSA — EU SCCs
PaymentsStripeUSA — EU SCCs
Bot protectionCloudflare TurnstileUSA — EU SCCs
Rate limitingUpstashEU region
EmailsResendUSA — EU SCCs
Online AI (on request)The provider you pick (e.g. Google, Mistral, Anthropic, OpenAI)EU SCCs

6. Transfers outside the EU

Some providers above are in the USA. For those transfers we rely on the EU Standard Contractual Clauses (Art. 46 GDPR). Ask us if you'd like a copy.

7. How long we keep it

• Account data: until you delete your account. • Billing records: up to 10 years, as German tax law requires (§ 147 AO, § 257 HGB). • Security logs: a short time, then deleted. • AI request content: not kept after the result.

Deleting your account erases your profile, devices, and settings. We keep only what the law requires us to.

8. Your rights

You can exercise any of these for free by emailing [email protected]:

• Access a copy of your data (Art. 15) • Correct it (Art. 16) • Delete it (Art. 17) — or delete your account from the dashboard • Restrict processing (Art. 18) • Get your data in a portable format (Art. 20) • Object to processing based on legitimate interest (Art. 21) • Withdraw consent at any time (Art. 7(3))

You can also complain to a supervisory authority (Art. 77 GDPR) — in Germany, the data protection authority of your federal state.

9. Security

We protect your data with TLS in transit, hashed passwords, restricted access, and device-based session checks (Art. 32 GDPR).

10. Changes

If we update this policy, the current version is always here with the date above.