DocuForge
Features Pricing Docs
Sign in Get started free
Legal

Privacy Policy

Last updated August 2026. Plain-English version: we collect what we need to run your invoices and your account, nothing more, and we don't sell or share it.

Who operates DocuForge

DocuForge is operated by Thorvald Rovers, a Full Stack Developer based in Belgium. This policy covers the DocuForge web app, API, and marketing site.

What data we collect

Account data. Your email address and a password, stored as a salted hash (Argon2). We never store your password in a form we, or anyone who gained access to our database, could read back.

Invoicing data. Whatever you put on an invoice through the web builder: client names, invoice numbers, line items, and amounts, kept so you can find and redownload past invoices from your archive. Also your saved brand profile: company name, brand color, and a logo image, applied automatically to invoices you generate.

Bank details. If you add bank details to your brand profile to put payment instructions on your invoices — an IBAN/BIC for the EU/SEPA QR code, or a bank name/account number/routing number for an international wire transfer — the IBAN and account number are encrypted (AES-256-GCM) before they're stored, with the encryption key kept outside the database. We decrypt them only to show them back to you in your own dashboard and to generate payment details on your own invoices.

Usage data. A count of how many invoices you've generated this month, used only to enforce the free plan's monthly limit.

Billing data. If you upgrade to Pro, Stripe processes your payment directly on its own infrastructure. We store your Stripe customer and subscription IDs so we can recognize your account's plan. We never see or store your card details.

API access. If you use the paid API, we store a one-way hash of your API key, never the raw key, so we can verify requests without being able to read the key back out.

The free demo

The playground on our homepage does not require an account. To prevent abuse, we keep a temporary, in-memory count of requests per IP address. It is never written to disk and is cleared automatically whenever the server restarts.

Cookies

We set one cookie, docuforge_session, when you sign in. It is HttpOnly (client-side scripts cannot read it) and SameSite=Lax, expires 30 days after issue, and is used only to keep you signed in. We do not use analytics or advertising cookies.

Legal basis for processing

Processing your account and invoicing data is necessary to provide the service you signed up for (performance of a contract). Keeping a temporary per-IP count on the demo endpoint is a legitimate interest in preventing abuse of a free, unauthenticated feature.

Third-party sharing

We don't sell or share your data for marketing purposes. Stripe processes payments for Pro subscriptions, and Stripe's own privacy policy governs the payment data it holds. We do not use analytics services, advertising networks, or tracking pixels anywhere on this site.

Data retention

Your account, invoices, and brand profile are kept for as long as your account exists. If you would like your account and its data deleted, contact us at the email below and we will remove it.

Your rights

If you are in the EU/EEA or UK, GDPR gives you the right to access, correct, export, or delete your personal data, and to object to how it is processed. To exercise any of these rights, email us at the address below.

Changes to this policy

If anything material changes about what we collect or why, we'll update the date at the top of this page.

Contact

Questions about this policy or your data: [email protected].

DocuForge API. Built from the architecture spec, rendered by itself.
Playground Features Pricing Docs Sign in
© 2026 Thorvald Rovers · Privacy Policy