DocNimble Privacy Policy
This policy explains what DocNimble processes on your device, on the shared website, and—only when you deliberately use an advanced tool—through the protected Worker Core.
Last updated:
1. Who operates DocNimble
DocNimble is operated by Support IT Ventures. Privacy questions and eligible data requests can be submitted through the contact form. The application is designed around data minimisation and purpose limitation; this page is not a substitute for independent legal advice about your own obligations when processing documents.
2. Processing tiers
Browser / device-only tools
Tools labelled client transform supported files in browser memory. The selected file is not intentionally uploaded to DocNimble's worker endpoint. Ordinary web requests for the page and its assets still occur; the exact boundary and current dependency limitation are explained on Privacy Proof.
Shared website functions
Registration, login, support forms, settings, rate limiting and billing records use the shared web application and database. Passwords are stored as password hashes, not readable passwords.
Worker tools
Advanced conversion, OCR, repair or AI tools require deliberate server processing. Inputs and outputs use random job identifiers, protected storage, signed requests, checksums, expiring downloads and cleanup. Tool pages must disclose this before submission.
3. Data we may hold
Depending on the feature used, records may include name, email, account state, password hash, sign-in/security timestamps, payment-provider identifiers, invoices, support messages, support-reference and page/tool/error context, screenshots you deliberately attach, rate-limit/security hashes, consent preference and operational job metadata. File contents and extracted text are not intended for analytics logs.
4. Payments and vendors
When billing is enabled, Razorpay may process payment information under its own terms. DocNimble stores only the identifiers and accounting records needed to verify the transaction and entitlement. Google services may be used for Search Console, consent-controlled Analytics and—only after readiness/approval—advertising. A configured certified CMP may also process consent signals under its own policy.
5. Cookies, analytics and advertising
Essential security/session storage is used where required. Optional analytics and advertising are consent-controlled. The built-in preference panel is not represented as a Google-certified CMP. See the Cookie and Consent Policy.
6. Support chat and WhatsApp
The floating support widget uses a random HttpOnly visitor identifier so an anonymous browser can continue the same support thread without creating an account. The guided bot works without external AI. When you deliberately attach a screenshot it is stored in protected support storage and served only through authorised routes. Opening support or reporting an error does not upload the document you are working on. If WhatsApp is enabled, link mode opens WhatsApp with the support reference and page path; optional Cloud API mode is used only after the operator configures and enables it.
7. Retention
Worker job files and tokens are intended to be short-lived and removed by scheduled cleanup. Account, billing and support records can require longer retention for security, service, accounting, dispute or legal purposes. The operator should configure and audit retention rather than promising deletion periods the live host has not verified.
8. Security
Implemented safeguards and host-verification boundaries are described on the Security page. No system can promise absolute security. Do not submit material you are not authorised to process.
9. Your choices and requests
You can use supported public browser tools without an account, reject optional consent categories, stop using worker tools, request correction of eligible account/support data, or request deletion where retention duties do not require continued storage. Identity verification may be required before an account-data request is actioned.
10. Children and sensitive documents
DocNimble is a general document utility and is not designed to solicit children’s personal data. Exam and identity documents can contain sensitive information; use client-side tools where available and follow the issuing authority’s instructions.
11. Changes
Material changes are dated on this page. Product behaviour, vendors and legal requirements can change, so this policy is reviewed alongside releases.