Legal

Privacy Policy

Effective date: June 29, 2026

1. Who we are

DocFlow is an AI-powered code documentation service available at AICodeDocumentationGenerator.com. The service helps developers generate README updates, API documentation, changelog drafts, and code explanations from GitHub repository activity.

For privacy questions or data requests, contact [email protected].

2. Information we collect

Account data: GitHub user ID, username, avatar URL, email address when GitHub makes it available, and authentication/session records needed to keep you signed in.

GitHub App data: installation ID, repository names, repository owner, default branch, repository visibility, pull request metadata, changed file paths, generated documentation history, and configuration settings you choose in the dashboard.

Billing data: subscription plan, checkout status, Creem customer ID, Creem subscription ID, payment event IDs, and payment status. We do not store full card numbers or bank details. Creem processes payment details on its hosted checkout and customer portal.

Usage and security data: IP address, browser type, device information, pages viewed, request logs, error logs, and abuse-prevention signals.

3. Code, repository content, and AI processing

DocFlow connects to GitHub through a GitHub App. Depending on the permissions granted, DocFlow may read pull request diffs, file paths, repository metadata, and selected file contents needed to generate documentation.

DocFlow is not designed to store full repository source code. We may store repository metadata, configuration, generated documentation output, processing history, and limited technical logs needed to operate and debug the service.

To generate documentation, relevant code context may be sent to the AI model provider or AI API endpoint configured for DocFlow. The current production configuration uses DeepSeek as the AI provider, with deepseek-chat as the default model. We use this processing to provide the requested documentation output, not to sell your code. We do not intentionally use customer repository content to train our own public model.

4. How we use information

We use collected information to authenticate users, connect GitHub repositories, generate documentation, manage subscriptions, process payments, prevent abuse, provide support, improve reliability, and comply with legal obligations.

We may send service emails about account access, billing, security, product updates, and support. Marketing emails, if any, will include an unsubscribe option.

5. Third-party services

GitHub provides authentication, GitHub App installation, repository access, and webhook events.

Creem provides hosted checkout, subscription management, payment processing, payment webhooks, and billing portal access.

Cloudflare provides hosting, Workers, D1 database, edge security, and related infrastructure.

Plausible-style analytics may be used to understand aggregate site traffic. Google Analytics is only loaded if a Google Analytics ID is configured for the site.

DeepSeek currently provides the default AI model endpoint for DocFlow documentation drafts. If DocFlow changes production AI providers or models, this Privacy Policy and public product documentation should be updated before re-review.

6. Cookies, local storage, and analytics

We use essential cookies and local storage for authentication, OAuth state validation, dashboard sessions, theme preference, and checkout flow continuity.

Analytics tools may collect page views and technical usage data. See our Cookie Policy for details and browser-level controls.

7. Retention and deletion

We keep account, installation, configuration, billing, and processing records for as long as needed to provide the service, meet legal and tax obligations, resolve disputes, and prevent abuse.

You may uninstall the GitHub App from GitHub, disconnect repositories where supported, or contact [email protected] to request account deletion or data export. Some billing, security, and legal records may be retained where required by law or legitimate business needs.

8. International users and rights

Depending on your location, you may have rights to access, correct, delete, restrict, or export your personal information, and to object to certain processing. Contact us to exercise these rights.

DocFlow is operated through cloud infrastructure that may process data in multiple regions. By using the service, you understand that data may be processed outside your country of residence.

9. Security

We use HTTPS, access controls, secret management, webhook verification, and Cloudflare-managed infrastructure controls to protect service data. No internet service can guarantee perfect security, so you should only grant repository access that is appropriate for your use case.

10. Changes

We may update this Privacy Policy as the product changes. Material changes will be posted on this page with a new effective date.

This policy is provided for transparency and is not legal advice.