Privacy Policy
Effective 2026-10-03
DocSwitch is built to see as little of your data as possible: tools marked On-device never send your files anywhere, cloud files are deleted within 60 minutes, and you use the app without giving us your name or e-mail. This policy explains, in plain words, what we do collect, why, how long we keep it, who else receives it, and how you can see or delete it. It applies to the DocSwitch app for Android and iOS, the docswitch.app website and the E-sign signing pages. The data controller is LYTEHOSTING LLC (contact details in section 11).
1. The short version
- On-device tools (merge, split, compress, rotate, protect, scan, OCR, sign yourself and more): your file stays on your phone. We receive nothing, not even the file name.
- Cloud tools (Word, Excel, PowerPoint, PDF/A and other heavy conversions): the file you choose is uploaded over an encrypted, certificate-pinned connection, scanned for malware, converted, delivered back to you and deleted from our servers automatically within 60 minutes (immediately if you delete it). We never open, read, index, train on or log the contents.
- Account: a random identifier. No name, no e-mail, no password, no phone number.
- E-sign: the document you send and the signers' names and contact details are stored encrypted for the retention period you see when you send (30 days free, one year Premium), then deleted; an audit record without document content is kept until you delete your account.
- Crash reports and diagnostics: optional, switchable in Settings, scrubbed of file names and document text.
- Ads (free version): Google AdMob, only with the consent you give in the prompt, and never for Premium users.
- Notifications: optional; the server sends only generic texts ("Someone just signed your document") through Apple's and Google's delivery services.
- Purchases: handled by Apple or Google; we only learn that your account has Premium.
- You can export everything we hold about your account and delete it all, in the app, at any time.
2. What we collect and why
The table below lists every category of data, where it comes from, why we process it and the legal basis we rely on under the EU/UK GDPR, the Nigeria Data Protection Act 2023 and similar laws.
| Data | Source | Purpose | Legal basis | Kept for |
|---|---|---|---|---|
| Anonymous account id (random) | Generated by the app | Keep your allowances, purchases and settings together; prevent abuse | Contract (providing the Service) | Until you delete the account |
| Files you send to a cloud tool, and the result | You | Produce the conversion you asked for | Contract | ≤ 60 minutes, then deleted; the input is deleted the moment the job ends |
| Job metadata: tool type, status, file size and page count, timestamps, error codes (never file names or contents) | The app | Run the job, count allowances, fix failures, answer support requests | Contract; legitimate interest (reliability) | Until you delete the account; failed-job diagnostics 30 days |
| Daily usage counters (documents, cloud conversions, OCR pages) | The app and our server | Enforce the free allowances | Contract | Until you delete the account; on-device counters stay on your phone |
| Device-integrity statement (Google Play Integrity token / Apple App Attest key id and attestation) | Your phone's operating system | Confirm the app is a genuine store install before cloud features are enabled; prevent fraud | Legitimate interest (security, fraud prevention) | Verified immediately; only a short-lived device token (hours) and, for referrals, a salted hash of a device identifier are kept |
| Install identifier (hashed with a secret salt) | Your phone | Stop the same device claiming referral rewards repeatedly | Legitimate interest (fraud prevention) | Until you delete the account |
| Invite code and referral records (who referred whom, by anonymous id) | The app | Pay out the referral rewards | Contract | Until either account is deleted |
| E-sign: the document, field values, signature images, signers' names and e-mail addresses or phone numbers, access codes (hashed), the IP address and browser type of each signer action, consent text version, timestamps and document hashes | You (the sender) and the signers | Deliver the signing request, verify signers as you chose, produce the signed document and its audit trail | Contract (with the sender); legitimate interest and, for signers, performance of the task they were asked to do | Document and signature images: 30 days (free) or one year (Premium), or until you void it; audit record: until the sender deletes the account |
| Premium entitlement (which plan, until when) and rewarded-ad grants | Apple / Google via RevenueCat; our server | Unlock Premium; grant rewards | Contract | Until you delete the account |
| Push notification token (an opaque device registration id) and your on/off choice | Your phone, when you turn notifications on | Tell you when a signing link could not be delivered, someone signed or declined, or everyone has signed; the message text is generic and the app loads the details after you tap | Consent (the Settings switch) | Until you turn notifications off or delete the account; a token the provider reports dead is deleted at once |
| Crash reports and diagnostics: device model, OS version, app version, a redacted error description and the screens visited before the error | The app (optional) | Find and fix crashes | Consent (the Settings switch, on by default; you can turn it off at any time) | 90 days at our crash-report provider |
| Advertising identifier and ad-interaction data | Your phone, via Google AdMob | Show ads in the free version; measure them | Consent (the consent prompt; App Tracking Transparency on iOS) | Governed by Google's policy; not stored by us |
| Rating and feedback (1–5 stars and an optional short note) | You | Improve the app | Consent | 12 months; unlinked from your account on deletion |
| Aggregate usage counters (for example how many paywall views per day, in total) | The app | Understand how the app is used | Legitimate interest | 400 days; these totals contain no user id and cannot be linked to you |
| Server logs: request id, hashed account id, route, status, timing, error code; the website's logs are off | Our servers | Security, debugging, abuse prevention | Legitimate interest | 30 days |
| Support e-mails you send us | You | Answer you | Legitimate interest | 2 years |
3. What we never collect
- Your name, e-mail address or phone number for using the app (signers you invite give theirs so the request can reach them).
- The contents, names or text of files processed on your device.
- The contents or text of cloud files beyond the minutes needed to convert them. Our logs never contain file names, file bytes, extracted text, tokens or e-mail addresses; a code rule and an automated test enforce this.
- Your location, contacts, photos library (the system picker hands us only the file you pick), microphone, health or browsing data.
- Payment card details: Apple or Google holds them.
4. Who receives data (processors and other recipients)
We share data only with the providers below, each bound by a contract, and only what their job needs:
| Recipient | What | Why | Where |
|---|---|---|---|
| Apple Inc. / Google LLC | Purchase status; device-integrity statements; push and system services | App distribution, payments, integrity | USA (standard contractual clauses / adequacy as applicable) |
| Apple Push Notification service / Google Firebase Cloud Messaging | The push token and the generic notification text (never a document title, a name or an address) | Deliver notifications to your phone | USA |
| RevenueCat, Inc. | Anonymous account id, purchase status | Recognise your Premium purchase across devices | USA |
| Google AdMob (Google LLC / Google Ireland Ltd.) | Advertising identifier, consent signal, ad events | Ads in the free version | USA / EU |
| Functional Software, Inc. (Sentry) | Crash reports (scrubbed) | Crash fixing | USA |
| E-mail and SMS delivery providers | Signers' e-mail addresses or phone numbers, the request link or one-time code (never the document) | Deliver E-sign requests | |
| Our hosting provider (data centre in the United States) | All server data, encrypted at rest for E-sign | Running the Service | |
| Backup storage (encrypted before upload) | Encrypted database and E-sign backups (age-encrypted before upload; the key never leaves our control) | Disaster recovery |
We do not sell personal data and we do not share it with data brokers. We disclose data to authorities only when the law requires it, and we will tell you where the law allows. If the Service is sold or merged, data transfers with it under this policy.
Signers: if someone asks you to sign a document through DocSwitch, the sender decides what is in the document and who signs; we process your name, contact details, signature and the technical record of your signing session on the sender's behalf and for the audit trail. Questions about the document itself go to the sender; questions about how we handle your data go to privacy@docswitch.app.
5. International transfers
Our servers are located in the United States. Some providers above are in the United States or elsewhere. Where data about people in the European Economic Area, the United Kingdom, Switzerland or Nigeria is transferred to another country, we rely on an adequacy decision, the European Commission's standard contractual clauses or the UK addendum, or the equivalent mechanism under the Nigeria Data Protection Act.
6. How we protect data
- Encrypted, certificate-pinned connections between the app and our servers; cleartext connections are disabled in the app.
- Cloud files live in private storage behind short-lived signed URLs and are deleted within 60 minutes by an automatic sweep; E-sign documents are encrypted with a per-document key.
- Every upload is scanned for malware before processing; converters run in isolated sandboxes without network access.
- Files on your phone are kept in app-private storage; keys and tokens are kept in the phone's secure keystore.
- Logs are scrubbed by code before they are written, and tested for it.
- Backups are encrypted before they leave the server. Access to servers is key-based and limited to the people who operate the Service.
- No system is perfectly secure; if a breach affecting your data happens we will notify you and the relevant authority as the law requires (within 72 hours under the GDPR and the Nigeria Data Protection Act).
7. Your rights and how to use them
Depending on where you live, you have the right to access, correct, export, delete and object to the processing of your personal data, to restrict it, to withdraw consent, and to complain to a supervisory authority. In the app:
- See what is on our servers right now: Settings → Privacy dashboard (lists every cloud file and E-sign document and lets you delete each one at once).
- Export everything we hold about your account: Settings → Account → Export my data (a JSON file).
- Delete everything: Settings → Account → Delete my account and data (see docswitch.app/delete for exactly what happens).
- Turn crash reports off: Settings → Diagnostics.
- Change ad consent: Settings → Privacy → Ad preferences (re-opens the consent prompt); on iPhone also Settings → Privacy & Security → Tracking.
Because accounts are anonymous, we can only act on data linked to the account id in the app you are using; please use the in-app controls first. For anything else, write to privacy@docswitch.app and include the account id shown under Settings → About. We answer within 30 days (one month under the GDPR, which can be extended once).
Complaints: you can complain to the Nigeria Data Protection Commission (ndpc.gov.ng), the UK Information Commissioner's Office (ico.org.uk), your EU data-protection authority, or your local regulator. We would appreciate the chance to resolve your concern first.
California residents: we do not sell personal information. Personalised advertising through AdMob may count as "sharing" under the CPRA; you can opt out through the ad-consent prompt in Settings and through the Global Privacy Control / your device's limit-ad-tracking setting. You also have the rights to know, delete and correct, and not to be discriminated against for using them.
8. Children
The Service is not directed at children under 13 (or the higher age your country sets for data-protection consent), and we do not knowingly collect personal data from them. The ad consent prompt and the stores' age settings apply. If you believe a child has used the Service, contact privacy@docswitch.app and we will delete the data.
9. The website and cookies
docswitch.app is a static site with no JavaScript, no analytics and no cookies of our own. The E-sign signing pages use one strictly necessary session value to keep your signing session and set no advertising or analytics cookies. The site links to the Apple App Store and Google Play; those sites have their own policies.
10. Changes to this policy
We will post any change here and update the date at the top. For material changes that reduce your rights or widen what we collect we will tell you in the app at least 30 days in advance and, where the law requires it, ask for your consent again.
11. Contact
LYTEHOSTING LLC, a Colorado limited liability company (Colorado Secretary of State ID 20231575159), 1500 N Grant St, Ste R, Denver, CO 80203, United States · privacy@docswitch.app (data-protection enquiries) · support@docswitch.app (everything else).