---
title: Data handling
description: Where your data lives, how it is protected, how long it stays, and how to take it with you or have it removed.
---

# Data handling

Where your data lives, how it is protected, how long it stays, and how to take it with you or have it removed.

## Where it lives

The hosted service runs on Railway: the application, the database and the store that keeps signed PDFs. Sign-in identities are kept with Google (Firebase). Payments are handled by Stripe, and email is sent through Resend; none of them is given your documents' contents except what an email must carry. The companies are listed under Sub-processors. You cannot yet choose a region; the self-hosted edition runs wherever you run it.

## Keeping workspaces apart

Every table that holds workspace data has row-level security in the database itself, forced on, so a bug in the application cannot read another workspace's rows. The application connects as a role that cannot switch it off.

## Protecting it

Data in transit travels over TLS. Secrets we store for you (webhook signing secrets, a custom mail server's password, two-step secrets) are sealed with AES-256-GCM under a key that is kept apart from the database. API keys are stored only as a digest, so we cannot read one back to you. Whether the stored PDFs are encrypted on disk depends on the storage service's own settings and is not separately claimed.

## What is kept, and for how long

A signed document is kept for the retention period you set in Settings, or indefinitely if you leave it empty, and is never deleted inside that period. Unsigned drafts are yours to delete at any time. The API call log is kept 30 days; email delivery records are kept with the document they belong to.

## Taking it with you

Download any signed copy as a PDF; export a document's audit log, the workspace's audit log, the people list and each form's responses as CSV; read everything through the API. The self-hosted edition keeps all of it on your own machine.

## Removing it

Delete a person and their signed documents are detached from them while the signed record stays for its retention period; their unsigned documents are removed. To close a workspace or remove everything that can be removed, write to privacy@docustay.app from the owner's address.

## What we do not do

We do not sell data, we do not read your documents, and we do not use your documents to train a model.

## A worked example: leaving

A studio closes its Docustay workspace. The owner downloads every signed PDF, exports the people list and each form's responses as CSV, and reads the rest through the API. The signed records stay for the keep period the owner set; after it they can be removed, and the owner writes to privacy@docustay.app to ask for the rest to be deleted. The same exports work on a self-hosted install, where everything is already on the studio's own machine.

## What the API call log holds

A line per call a key made: the time, the key's name, the method, the route, the result, how long it took and the request id. Never what was sent. It is kept 30 days and then removed, and the owner can read it in Settings under Developers.

## Self-hosting

If keeping data in your own place matters more than convenience, run Docustay yourself. The self-hosted edition is the same product, free, and sends nothing to us except an anonymous daily count unless you turn that off.

## Questions to ask any signing service

Where is the data, who can read a document, what happens to a signed record when a person asks to be removed, can I leave with everything, and is any of it used to train a model. The answers for Docustay are on this page.

## Keep reading

- [Security](/trust/security)
- [Privacy](/trust/privacy)
- [Sub-processors](/trust/sub-processors)
- [Self-host](/self-host)
- [Data Processing Addendum](/legal/dpa)
