Privacy Policy
What data we collect, why, and your rights under the GDPR.
Last updated: 16 July 2026
This policy explains what personal data we process when you use univerdev.com and the Docora app, and the rights you have under the GDPR and German data protection law (BDSG).
1. Who is responsible
The controller under Art. 4(7) GDPR is:
Universus Developers – Ibrahim Ali Germany [email protected]
You can reach us about any data protection question at that address. We are not required to appoint a Data Protection Officer under Art. 37 GDPR.
2. Data minimisation
Docora processes your documents on your own device. Our server only handles your account, billing, and — when you use an online AI feature — acts as a gateway to the AI provider. We don't store your document contents.
We don't sell your data, and we don't use it for advertising or profiling.
3. What we process
We process these categories of data, each on the legal basis shown (Art. 6(1) GDPR):
| Purpose | Data | Legal basis |
|---|---|---|
| Account & login | Name, email, hashed password, verification status | Art. 6(1)(b) — contract |
| Session security | Device fingerprint, user-agent, IP address, session cookies | Art. 6(1)(f) — legitimate interest (preventing account sharing and abuse) |
| Payments | Plan, transaction history, Stripe customer ID. Card details go straight to Stripe and never reach us. | Art. 6(1)(b) — contract; Art. 6(1)(c) — tax retention |
| Online AI features | The content of a single AI request, passed to the provider you chose and not kept afterwards | Art. 6(1)(b) — contract |
| Emails (verification, password reset) | Email address, language | Art. 6(1)(b) — contract |
5. Who processes your data
Your account data lives on our own server in Germany (Hetzner). For specific tasks we use these providers, acting on our instructions under Art. 28 GDPR:
| Purpose | Data | Legal basis |
|---|---|---|
| Account server & database | Our own server (Hetzner, Germany) | Germany (EU) |
| Website hosting | Vercel | USA — EU SCCs |
| Payments | Stripe | USA — EU SCCs |
| Bot protection | Cloudflare Turnstile | USA — EU SCCs |
| Rate limiting | Upstash | EU region |
| Emails | Resend | USA — EU SCCs |
| Online AI (on request) | The provider you pick (e.g. Google, Mistral, Anthropic, OpenAI) | EU SCCs |
6. Transfers outside the EU
Some providers above are in the USA. For those transfers we rely on the EU Standard Contractual Clauses (Art. 46 GDPR). Ask us if you'd like a copy.
7. How long we keep it
• Account data: until you delete your account. • Billing records: up to 10 years, as German tax law requires (§ 147 AO, § 257 HGB). • Security logs: a short time, then deleted. • AI request content: not kept after the result.
Deleting your account erases your profile, devices, and settings. We keep only what the law requires us to.
8. Your rights
You can exercise any of these for free by emailing [email protected]:
• Access a copy of your data (Art. 15) • Correct it (Art. 16) • Delete it (Art. 17) — or delete your account from the dashboard • Restrict processing (Art. 18) • Get your data in a portable format (Art. 20) • Object to processing based on legitimate interest (Art. 21) • Withdraw consent at any time (Art. 7(3))
You can also complain to a supervisory authority (Art. 77 GDPR) — in Germany, the data protection authority of your federal state.
9. Security
We protect your data with TLS in transit, hashed passwords, restricted access, and device-based session checks (Art. 32 GDPR).
10. Changes
If we update this policy, the current version is always here with the date above.