Privacy Policy
Version 1.0 · Last updated July 9, 2026
This is a plain-language policy for a new product and is provided for transparency; it is not legal advice and does not create an attorney-client relationship.
1. Introduction
At Sanket Bodhare, d/b/a DocuWright (“DocuWright,” “we,” “us,” or “our”), we value your privacy and take seriously our responsibility to safeguard the data you and your clients entrust to us. This Privacy Policy (the “Policy”) describes how we collect, store, access, and otherwise process information relating to identifiable individuals in connection with the DocuWright service at docuwright.com (the “Service”). In this Policy, “Personal Data” means any information that, on its own or combined with other available information, can identify an individual.
DocuWright is a document-automation subscription for solo and small law firms. We are committed to protecting privacy in accordance with applicable US state privacy laws, including the following, where they apply to you:
- California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA) and California Online Privacy Protection Act (CalOPPA)
- Colorado Privacy Act (CPA)
- Utah Consumer Privacy Act (UCPA)
- Connecticut Data Privacy Act (CTDPA)
- Virginia Consumer Data Protection Act (VCDPA)
- Texas Data Privacy and Security Act (TDPSA)
- Oregon Consumer Privacy Act (OCPA)
- Montana Consumer Data Privacy Act
- Delaware Personal Data Privacy Act
- Nebraska Data Privacy Law
- New Hampshire Data Privacy Act
- New Jersey Data Privacy Act
- Minnesota Consumer Data Privacy Act
- Maryland Online Consumer Protection Act
- Kentucky Consumer Data Protection Act (KCDPA)
- Tennessee Information Protection Act (TIPA)
- Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
- Indiana Consumer Data Protection Act (INCDPA)
- Iowa Consumer Data Protection Act (ICDPA)
This Policy applies when you create a DocuWright firm account, use the Service, upload documents, subscribe to a paid plan, receive communications from us, or when your clients complete an intake form you have shared with them. It does not apply to third-party websites or services that you may reach through links we provide; those are governed by their own privacy practices.
2. Personal Data We Collect
We collect only what we need to run the Service. Depending on how you use DocuWright, this includes:
- Account Information: your name, firm name, and email address, plus authentication data such as a hashed password and session records. If you sign in with Google, we receive basic profile and email information from Google to create and link your account.
- Subscription and Billing Information: your plan and subscription status, and billing records. Card payments are handled by our payment processor, Dodo Payments, as merchant of record. We do not receive or store full payment card numbers (see Section 6).
- Firm Content: the past documents you upload, the templates built from them, the intake answers your clients submit, and the documents generated from those answers. Firm Content is covered in detail in Section 3.
- Support and Communications: information you provide when you contact us for support, report a problem, or otherwise communicate with us.
- Device and Usage Data: limited technical information collected automatically when you use the Service, such as your IP address, login and authentication records, and timestamps, used to operate and secure the Service.
We do not solicit sensitive personal data about you, and we do not collect payment card numbers ourselves. Where sensitive information appears inside Firm Content, it is handled as described in Section 3.
3. How We Handle Your Documents and Client Data
This section is the heart of how DocuWright treats the information that matters most to a law firm. Please read it carefully.
- Firm Content belongs to the law firm.The past documents an attorney uploads, the templates built from them, and the intake answers a firm's clients submit (together, “Firm Content”) belong to the law firm.
- We act as a processor, not the owner.With respect to Firm Content, DocuWright acts as a data processor on behalf of the law firm, which is the controller. We process Firm Content solely to provide the Service: building that firm's templates and generating that firm's documents.
- We never train AI models on Firm Content.We do not use Firm Content, uploaded documents, or client intake data to train, fine-tune, or improve any AI models, and we do not sell or share it. When we build a firm's templates, the relevant document text is sent to our AI subprocessor, Anthropic, only to build that firm's own templates. Neither we nor the subprocessor use it to train models.
- The AI restructures; it does not author.The AI restructures the attorney's existing language into fill-in fields, conditional sections, and repeating sections. It does not generate, suggest, or invent legal content. If it cannot confidently map a section, it flags that section for attorney review rather than writing anything.
- Sensitive data inside Firm Content. Firm Content may incidentally contain sensitive personal data, for example health or financial details inside an estate-planning document. We do not solicit sensitive data. Where it appears in Firm Content, the law firm is responsible for having obtained any consents required by law, and we process it only to provide the Service.
- The firm stays in control. The firm controls this data. You can delete individual templates and submissions, or your entire account, which removes the associated uploaded and generated documents from our storage (see Section 8).
4. How and Why We Use Personal Data
We process Personal Data to provide, maintain, secure, and improve the Service. Our purposes include:
- Creating and administering your firm account and authenticating your identity;
- Providing the core Service: building your templates and generating your documents from Firm Content;
- Processing your subscription and managing billing through our payment processor;
- Providing customer and technical support and communicating with you about the Service;
- Maintaining a safe and secure environment, and investigating and preventing security incidents, fraud, and abuse;
- Complying with our legal, tax, and accounting obligations.
Where we process Personal Data to deliver the Service to you, we do so because it is necessary to perform our agreement with you. Other processing is grounded in our legitimate interest in operating and protecting the Service, or in your consent where required by law.
5. Cookies and Analytics
We use only strictly-necessary and functional cookies. We do not use advertising or third-party tracking cookies, and we do not need a cookie consent banner. Specifically, we set:
- Session authentication cookies that keep you signed in and mark whether a session should persist beyond the current browser session;
- A transient OAuth state cookie used only during the Google sign-in redirect to protect that flow, and cleared when the flow completes;
- A preference cookie that remembers a dashboard nudge you have dismissed.
For usage measurement we use privacy-friendly, cookieless analytics (Vercel Web Analytics). It sets no cookies, stores nothing in your browser, does not track or fingerprint individuals across sites, and collects no personal data. We do not use Google Analytics or any cookie-based or third-party advertising analytics.
6. Subprocessors and Sharing
We do not sell your data or your clients' data. We share Personal Data only with the service providers (subprocessors) that are required to run the Service, and only for that purpose:
- Vercel: application hosting;
- Neon: PostgreSQL database (account records, intake answers, and references to your files);
- Cloudflare: file storage for uploaded and generated documents, and DNS;
- Anthropic: AI template building, used only to restructure your own text, and never to train models;
- Resend: transactional email;
- Google: optional sign-in, if you choose to use it;
- Dodo Payments: payment processing as merchant of record.
Dodo Payments is the merchant of record for your subscription and handles all card data. DocuWright never receives or stores full payment card numbers.
We may also disclose Personal Data where we are legally required to do so, for example to comply with a valid legal request, to enforce our agreements, or to protect the rights, safety, and property of DocuWright, our users, or others. Where it is lawful and practical to do so, we will tell you before such a disclosure.
7. International Data Transfer and Storage
We host on US-region infrastructure. Because we and our subprocessors may operate across borders, your Personal Data may be transferred to and maintained on servers located outside your state, province, or country, where data-protection laws may differ from those in your jurisdiction. We take appropriate steps to ensure your Personal Data is treated securely and in accordance with this Policy and applicable law.
8. Retention and Deletion
We retain Personal Data only for as long as necessary for the purpose for which it was collected and to the extent required by applicable law. When we no longer need Personal Data, we remove it from our systems or take steps to anonymize it.
When a firm deletes its account, we delete its account data, templates, uploaded documents, and generated documents. You can also delete individual templates and submissions at any time, which removes the associated documents from our storage. To request deletion of your account and its data, email support@docuwright.com.
Even after account deletion, we retain the minimal records necessary for fraud prevention, tax, accounting, and legal compliance, as permitted by law. For example, we may keep a record that a particular email address or payment method previously used a free trial, so we can enforce our trial and anti-abuse rules.
9. How We Keep Your Data Safe
We maintain organizational and technical safeguards designed to protect Personal Data from accidental loss and from unauthorized access, use, alteration, or disclosure. The connection between your browser and the Service uses encryption wherever Personal Data is involved. We require the subprocessors that process Personal Data on our behalf to have appropriate security measures in place. In the event of a data breach, we will notify you and any applicable regulator when we are legally required to do so.
10. Children's Privacy
The Service is intended for use by law firms and their authorized users. We do not knowingly collect Personal Data from children under the age of 18.
11. Your Privacy Rights
Depending on your state of residence and the law that applies to you, you may have some or all of the following rights regarding your Personal Data. Note that many of these rights, when they concern Firm Content, are directed by the law firm as the controller of that data.
- Right to Access (CCPA/CPRA, CPA, VCDPA, CTDPA, UCPA): you have the right to learn whether we are processing your Personal Data and to request a copy of the Personal Data we process about you.
- Right to Rectification (CPRA, CPA, VCDPA, CTDPA): you have the right to have incomplete or inaccurate Personal Data we process about you corrected.
- Right to Deletion (CCPA/CPRA, CPA, VCDPA, CTDPA, UCPA): you have the right to request that we delete Personal Data we process about you, unless we need to retain it to comply with a legal obligation or to establish, exercise, or defend legal claims.
- Right to Opt Out (CPRA, CPA, VCDPA, CTDPA, UCPA): you have the right to opt out of the processing of your Personal Data for targeted advertising, the sale of Personal Data, or profiling with legal or similarly significant effects. We do not sell Personal Data, do not use it for targeted advertising, and do not conduct such profiling.
- Nondiscrimination (CCPA/CPRA, CPA, VCDPA, CTDPA, UCPA): you have the right not to be denied service or given an altered experience for exercising your rights.
- Right to Appeal (CPA, VCDPA, CTDPA): where applicable, you have the right to appeal our decision on a rights request. If you disagree with the outcome of an appeal, you may contact your state attorney general.
If you have consented to a particular use of your Personal Data, you may withdraw that consent at any time. To exercise any of these rights, email us at support@docuwright.com. For your privacy and security, we may need to verify your identity before acting on a request.
12. Merger or Acquisition
If we are involved in a merger, acquisition, or sale of assets, your Personal Data may be transferred. We will provide notice before your Personal Data is transferred and becomes subject to a different privacy policy.
13. Changes to This Policy
We may update this Policy from time to time. When we make changes, we will post the updated version on this page and revise the “Last updated” date above. Material changes may also be communicated to account holders.
14. Contact Us
To request a copy of your information, ask that your data be deleted, exercise any of your privacy rights, or ask a question about your privacy, email us at support@docuwright.com. We handle all privacy requests by email; there is no separate form to fill out.
Privacy Policy v1.0. A plain-language policy for a new product, provided for transparency and pending review by a licensed attorney.