docrew.Back to app

How Docrew processes your invoices

A plain-language summary of what happens to the documents you upload.

Placeholder text: this notice has not been reviewed by legal counsel and must be before launch.

What we send
Each invoice file you upload (PDF or image) is sent securely to a third-party AI service that reads the document and returns the extracted fields. Nothing else from your workspace is sent.
Who processes it
A third-party AI processing provider acting on Docrew's behalf. It is the only third party that sees invoice contents. A list of sub-processors is available on request.
Where files are stored
In a private, encrypted storage bucket for your workspace only. Access uses short-lived signed links, and workspaces cannot see each other's data.
Raw extraction output
Kept encrypted at rest with a key specific to your workspace, so extractions can be audited. It is never shown to other users.
Logs
Docrew's logs record job and file identifiers and statuses. Invoice contents and personal data are not written to logs.
Bank details
Account numbers are masked in the app by default. Revealing one is recorded in the audit log.
Retention
Files and results stay until you delete a batch. Automatic retention (7 / 30 / 90 days, or delete after download) is coming, along with delete-all-my-data.
Usage information
When you sign in we record the time, your approximate country (from your connection, or your browser language if that is not available) and your browser type. We do not store your IP address. The Docrew team also sees when each upload happened, how long it took to process, and which files failed and why, but not the contents of your invoices in those logs.
Consent
The person who creates a workspace confirms this notice. Docrew records who agreed and when.

Version 2026-09-v1. Questions or deletion requests: contact your workspace owner or Docrew support.