1. Scope and controller
This policy applies to the DocxAPI website, dashboard, REST API, billing flows, and related support. DocxAPI is operated by SearchOps in Brazil. SearchOps acts as controller for account, billing, and website data. For document content submitted through the API, we generally act as a processor on the customer's instructions.
2. Data we process
Account and authentication
When you sign in with Google, we receive identifiers needed to create and secure your account, such as name, email address, provider identifier, and profile image when available. We do not receive your Google password.
API and usage data
We process hashed API-key identifiers, key labels, account plan, generation status, timestamps, usage totals, response format, and technical request identifiers. Raw API keys are shown only when created or rotated and are stored as hashes.
Billing
Stripe processes payment details. We store identifiers and status information needed to manage subscriptions, purchases, invoices, credits, and webhook delivery. DocxAPI does not store complete payment-card numbers.
Technical data
Server logs may include IP address, user agent, route, response status, request ID, timing, and error details. We ask users not to place sensitive document content in URLs, filenames, or support messages.
3. Document content
Content sent to /v1/generate is processed to create the requested DOCX file. For file and Base64 responses, temporary conversion files are removed after the response finishes or fails. For temporary URL responses, the output is retained on application storage for up to the configured download period, currently 24 hours, and then removed by cleanup routines.
DocxAPI does not use submitted document content to train machine-learning models. Remote resources referenced by submitted content are blocked during conversion.
4. Purposes and legal bases
- Provide, authenticate, meter, bill, and support the service under our contract with you.
- Protect accounts, investigate abuse, and maintain service integrity based on legitimate interests and legal obligations.
- Maintain transaction and tax records where required by law.
- Measure website traffic only after consent, where consent is required.
- Communicate material service, security, billing, or policy updates.
6. Retention
We retain account and billing records while the account is active and afterward as needed for legal, security, dispute, and accounting purposes. Usage and security logs are kept only as long as reasonably necessary for operations and abuse prevention. Temporary URL documents are scheduled for removal after the configured 24-hour validity period. Backups may retain deleted database records for a limited recovery cycle.
7. Your choices and rights
Depending on your location, including under Brazil's LGPD, you may request confirmation of processing, access, correction, deletion, portability, information about sharing, or withdrawal of consent. You may also object to or request review of certain processing.
Requests can be sent to the contact below. We may verify your identity and may retain information where law or legitimate security needs require it. You can change analytics consent at any time using .
8. Contact and updates
Privacy questions and data-subject requests: contato@searchops.com.br. We may update this policy as the product or law changes. Material changes will be identified by a new effective date and, when appropriate, communicated in the service.