Privacy Policy
Last updated 17 September 2026
docs2blog reads documents you point it at, turns them into articles, and publishes them where you tell it to. This page describes exactly what that means for your data — including the one thing we do not keep.
The short version
We do not store the contents of your documents. When you build an article, docs2blog fetches the document from the source you connected, converts it in memory, and sends the result to the publishing target you chose. The text of the document is not written to our database. What we keep is the metadata around it: the title, the tags and stage you set, and the scores from each run.
We do not sell your data, we do not share it with advertisers, and there is no analytics or advertising tracker anywhere on this site or in the app.
What we store
Your account
- Your email address, and your name and profile picture if you signed in with Google.
- If you signed up with a password, a
scrypthash of it with a per-account random salt. The password itself is never stored and cannot be recovered from the hash. - A session record when you sign in, and the time you were last seen.
Your workspace
- Workspaces and teams, their members’ email addresses, and each member’s role.
- Article metadata: title, folder, category, tags, topics and stage. Not the article body.
- The result of each run: SEO and GEO scores, error and warning counts, word count and focus keyword.
- Comments you write on an article, and a workspace activity feed of comments, publishes and stage changes.
- Calendar entries you schedule, and a record of what was published where — target, post id and slug.
- Usage events, which are how a hosted plan is metered.
Connected accounts
When you connect Google Drive, OneDrive, SharePoint, Dropbox or Box, we store the access and refresh tokens that account issues us. They are written to disk on our server with file permissions that allow only the application to read them, and they are used for nothing except reading the documents you ask for. Disconnecting a source from the dashboard deletes the stored token immediately.
Credentials for publishing targets — a WordPress application password, a Ghost Admin API key, a webhook signing secret — are stored the same way and used only to publish what you ask us to publish.
Google user data
Signing in with Google gives us your email address, name and profile picture, and nothing else. Connecting Google Drive is a separate step that requests read access to your documents so they can be converted, plus the ability to create documents that docs2blog itself makes.
docs2blog’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained from Google is used only to provide and improve the features you asked for. It is never sold, never used for advertising, and never read by a human except where you have explicitly asked us to, where it is required for security or to comply with the law, or where the data has been aggregated and made anonymous.
Cookies
Every cookie we set is functional. There are no analytics or advertising cookies.
d2b_session— keeps you signed in.d2b_oauth_stateandd2b_source_state— short-lived values that prove a returning authorization request is one we started, which is what stops a forged callback.d2b_workspace— remembers which workspace you are looking at.
Who else touches your data
- Akamai (Linode) — hosts the application and the database, in the United States.
- Cloudflare — sits in front of the site, terminating TLS and proxying requests.
- Google, Microsoft, Dropbox and Box — only the ones you choose to connect, and only to read what you point at.
- Your publishing targets — the WordPress, Ghost, Sanity or webhook endpoint you configure receives the articles you publish. Those systems are yours, and their handling of that content is governed by whatever terms you have with them.
How it is protected
- All traffic to the site is encrypted in transit.
- The database accepts no connections from the public internet. Administrative access reaches it only over a private VPN, and every other inbound port on the server is closed.
- Passwords are hashed with scrypt and compared in constant time.
- Stored third-party tokens are readable only by the application account on the server.
No system is perfectly secure, and we will not pretend otherwise. If you find a vulnerability, please report it to [email protected] before disclosing it.
Keeping and deleting
We keep your workspace data for as long as your account exists, because it is the workspace. You can disconnect any source at any time, which deletes that token. To delete your account and everything in it, write to [email protected] and we will remove it.
Depending on where you live you may have rights to access, correct, export or delete the personal data we hold about you, and to object to how we use it. Ask at the same address and we will act on it.
Children
docs2blog is a tool for publishing professionals and is not directed at children. We do not knowingly collect personal data from anyone under 16.
Changes
If this policy changes in a way that affects you, we will update the date at the top of this page and, for anything material, tell you in the app before it takes effect.
Contact
Questions about this policy, or about what we hold on you: [email protected].