d
Docilis
← Back to home

Privacy Policy

Last updated: 12 April 2026 · Version 1.1

Summary for LinkedIn users: Docilis accesses your LinkedIn account only to publish content you've approved. We delete LinkedIn profile data within 24 hours of account disconnection and social activity data within 48 hours. You can export or delete all your data at any time from the Settings screen.

Docilis ("we", "us", or "our") is a product of Elucent Pty Ltd, registered in Australia. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use the Docilis platform at docilis.app and related services. Docilis serves knowledge-work professionals including researchers, academics, consultants, executives, and policy professionals.

By using Docilis, you agree to the collection and use of information as described in this policy. This policy is at least as stringent as LinkedIn's own data handling requirements.

1. Information We Collect

1.1 Account Information

When you create a Docilis account, we collect:

  • Email address
  • Name and professional details you provide (role, organisation, area of expertise)
  • Password (stored as a secure hash — we never store plaintext passwords)
  • Subscription and billing information (processed by Stripe — we do not store card details)

1.2 LinkedIn Data

When you connect your LinkedIn account, we collect and store:

  • Profile data: Your LinkedIn display name, email address, and person identifier (URN). Used to identify your account and address you by name.
  • OAuth access token: A credential that allows Docilis to publish content on your behalf. Stored securely and never shared with third parties.
  • Post analytics (if enabled): Impression counts, reaction counts, and comment counts on posts published through Docilis. This data is fetched from LinkedIn's API and stored in your account to populate your analytics dashboard.
LinkedIn data retention periods:
LinkedIn profile data (name, email, URN) is deleted within 24 hours of you disconnecting your LinkedIn account or deleting your Docilis account.
LinkedIn social activity data (post analytics, impression counts) is deleted within 48 hours of account disconnection or deletion.

1.3 Content You Create

We store the following content you generate or import through Docilis:

  • AI-drafted posts and your edits to them
  • Your voice profile and writing samples
  • Your expert profile, expertise areas and topics, and inspiration library
  • Uploaded images and generated AI images
  • RSS feed preferences and watchlist topics
  • Published post history and scheduling information

This content is yours. You can export it or delete it at any time (see Section 6).

1.4 Usage Data

We collect anonymised usage events to understand how the product is used and improve it — for example, which features are used, when pipeline runs occur, and error events. This data is stored in our own database and is not shared with third-party analytics services.

1.5 Technical Data

Standard web server logs including IP addresses, browser type, and request timestamps. Retained for up to 30 days for security and debugging purposes.

2. How We Use Your Information

We use your information to:

  • Operate and deliver the Docilis service
  • Authenticate your identity and maintain session security
  • Publish content to LinkedIn and other platforms on your behalf
  • Generate AI-drafted content using your voice profile and expert profile
  • Display your content history and analytics in your dashboard
  • Send transactional emails (account verification, password reset, billing receipts, trial reminders)
  • Monitor service health and diagnose technical errors
  • Comply with legal obligations

We do not use your data for advertising, do not sell it to third parties, and do not use it to train AI models without your explicit consent.

2a. Legal Bases for Processing (GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, we process your personal data under the following legal bases:

  • Contract (Article 6(1)(b)): Processing your account information, billing data, and content to deliver the service you have signed up for.
  • Legitimate interests (Article 6(1)(f)): Anonymised usage analytics to improve the product; error monitoring to maintain service reliability; fraud prevention and security. Our legitimate interests are not overridden by your rights in these cases.
  • Legal obligation (Article 6(1)(c)): Retaining billing records for the period required by applicable tax law.
  • Consent (Article 6(1)(a)): Sending you marketing communications (if you opt in). You may withdraw consent at any time by unsubscribing.

3. Third-Party Services and Sub-Processors

Docilis uses the following third-party services to operate. Each acts as a data processor under our instructions and is subject to a data processing agreement with Elucent:

  • LinkedIn Corporation — social platform authentication and content publishing. Your use of LinkedIn is also governed by LinkedIn's Privacy Policy.
  • Anthropic PBC (Claude API) — AI text generation. Post drafts and voice profile data are sent to Anthropic's API for processing. Anthropic does not retain your data to train models under their API usage terms.
  • fal.ai — AI image generation. Image prompts are sent to fal.ai for processing. No personally identifiable information is included in image prompts.
  • Railway (Railway Corp) — cloud infrastructure hosting. Your data is stored on Railway's PostgreSQL database service and object storage. Data is hosted in the United States.
  • Stripe, Inc. — payment processing. Card details and billing information are handled directly by Stripe and never stored by Docilis. Governed by Stripe's Privacy Policy.
  • Sentry (Functional Software, Inc.) — error monitoring. Error reports may include anonymised stack traces and request context. No user content or LinkedIn data is included in error reports.
  • Resend — transactional email delivery. Your email address is shared with Resend solely for the purpose of delivering emails you've requested (receipts, notifications, trial reminders, etc.).

We will notify you of any material changes to our sub-processors by updating this page and, for changes that meaningfully affect how your data is handled, by email with at least 14 days' notice.

4. Data Storage and Security

Your data is stored on Railway's infrastructure in the United States. We implement the following security measures:

  • All data in transit is encrypted using TLS 1.2 or higher
  • Passwords are hashed using industry-standard algorithms (bcrypt)
  • OAuth tokens are stored encrypted at rest
  • Access to production systems is restricted to authorised personnel
  • Session tokens are HTTP-only cookies with SameSite protection
  • API rate limiting is enforced on all endpoints

While we take reasonable precautions, no system is perfectly secure. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and relevant supervisory authorities within 72 hours of becoming aware of the breach, as required by applicable law.

5. Data Retention

We retain your data for as long as your account is active, subject to the following specific retention periods:

  • LinkedIn profile data — deleted within 24 hours of LinkedIn account disconnection
  • LinkedIn social activity data (analytics, impression counts) — deleted within 48 hours of LinkedIn account disconnection
  • Account and content data — deleted within 30 days of account deletion
  • Billing records — retained for 7 years as required by Australian tax law (GST Act)
  • Server and access logs — retained for 30 days then automatically purged
  • Anonymised usage analytics — retained indefinitely in aggregated, non-identifiable form
  • Error monitoring data — retained for 90 days then purged by Sentry

6. Your Rights

You have the following rights regarding your personal data:

6.1 Access

You can view all data associated with your account through the Docilis dashboard at any time. For a full structured data export, use the "Export my data" function in Settings, which provides a complete JSON file of your account data.

6.2 Rectification

You can update your profile, voice settings, and other account information directly in the app at any time.

6.3 Deletion

You can delete all your data using the "Delete all data" function in Settings. This permanently removes your account, all drafts, all analytics, all LinkedIn data, and all other personal information. This action cannot be undone. We complete deletion within 30 days; LinkedIn-specific data is deleted within the LinkedIn-mandated timeframes above.

6.4 Portability

You can export your data in JSON format at any time from Settings → Data Management.

6.5 Disconnect LinkedIn

You can disconnect your LinkedIn account at any time from Settings → Connections. This immediately revokes our access to your LinkedIn account and triggers deletion of your LinkedIn data within the timeframes specified above.

6.6 EEA and UK Rights

If you are located in the EEA or UK, you also have the right to object to processing based on legitimate interests, the right to restrict processing in certain circumstances, and the right to withdraw consent where processing is based on consent. To exercise any of these rights, contact [email protected].

6.7 Complaints

If you believe we have handled your data inappropriately, please contact us at [email protected]. You also have the right to lodge a complaint with:

  • Australia: The Office of the Australian Information Commissioner (OAIC) at oaic.gov.au
  • EEA: Your local data protection supervisory authority
  • UK: The Information Commissioner's Office (ICO) at ico.org.uk

7. Cookies

Docilis uses the following cookies:

  • session — an HTTP-only, SameSite=Lax cookie that authenticates your session. Strictly necessary for the service to function. Expires after 30 days of inactivity.

We do not use advertising cookies, tracking pixels, or third-party analytics cookies. We do not use cookies to track you across other websites. We do not use any non-essential cookies that would require prior consent under the EU ePrivacy Directive or UK PECR.

We use localStorage to remember your display preferences (such as billing period selection). This is not a cookie and contains no personally identifiable information.

The currency detection feature on our marketing site (docilis.ai) uses a third-party IP geolocation API (ipapi.co) to infer your approximate country from your IP address. This is a single anonymous request; no cookie is set and no personal data is stored as a result.

8. Children's Privacy

Docilis is not directed at anyone under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

9. International Data Transfers

Your data is processed in the United States by our infrastructure provider (Railway) and by certain sub-processors listed in Section 3. By using Docilis, you acknowledge that your data will be transferred to and processed in the United States.

For users in the European Economic Area (EEA) or the United Kingdom, we ensure that transfers of personal data to the United States are carried out subject to appropriate safeguards. Where we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission, or the UK International Data Transfer Agreement, as the lawful transfer mechanism, copies are available on request from [email protected].

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email with at least 14 days' notice before the change takes effect, and by updating the "Last updated" date above. Continued use of Docilis after a policy change constitutes acceptance of the updated policy.

Previous versions of this policy are available on request.

11. Contact Us

For any privacy-related questions, requests, or concerns:

  • Email: [email protected]
  • Postal: Elucent Pty Ltd, Melbourne, Victoria, Australia

We aim to respond to all privacy inquiries within 5 business days.

© 2026 Elucent Pty Ltd. All rights reserved. Privacy · Terms · Home