← Back to DocBurst

Privacy Policy

This Privacy Policy describes how DMiller Tech LLC d/b/a DocBurst(“DocBurst,” “we”) collects, uses, and protects information in connection with the DocBurst service. It should be read together with our Data Processing Agreement and Cookie Policy.

What we collect

  • Account identity. Your email address and, if you sign in with Google, your name - both via Firebase Authentication. If you use email/password sign-in instead, we store a securely hashed password (Firebase handles this; we never see or store your password in plain text).
  • Configuration data. Routing rules, saved sender (SMTP) credentials (encrypted at rest with AES-256-GCM), directory-lookup connection details, and anchor-map settings you choose to save.
  • Usage and audit metadata. Per-burst outcomes (page counts, routing decisions, delivery status), timestamps, and your plan tier and monthly send volume - kept to operate the Service, enforce plan limits, and give you an audit trail of what was sent.
  • Document content - in transit only. The PDFs you upload, and the pages/attachments produced from them, are processed in memory to build and dispatch your burst. Document bytes are never written to disk or a database and are discarded once a preview expires or a burst completes.

How we use it

To operate the Service (split and route your documents, send the emails or files you direct), to enforce plan limits and prevent abuse, to maintain the audit trail this kind of document-routing tool exists to provide, and to communicate with you about your account. We do not sell your personal information.

Who we share it with

We use a small number of subprocessors to operate the Service: Firebase/Google Cloud (authentication), a Postgres database host (settings and audit storage), and Resend (our platform default email sender, used only when you have not connected your own mailbox). See the DPA for the full list and the safeguards each is bound by. We do not share your data with third parties for their own marketing purposes.

Your rights (GDPR / CCPA)

Depending on where you live, you may have the right to access, correct, delete, or export your personal information, and to object to or restrict certain processing. To exercise any of these rights, contact us at docburstsupport@gmail.com. We will respond within the timeframe required by applicable law.

Data retention

Uploaded document content is retained only for the duration needed to build and dispatch a burst (typically minutes; a preview plan expires automatically after 15 minutes). Account, configuration, and audit data are retained for as long as your account is active, or as needed to comply with legal obligations, after which they are deleted or anonymized.

Security

Saved credentials (SMTP passwords, database connection secrets) are encrypted at rest with AES-256-GCM. All traffic to the Service is encrypted in transit (TLS). Access to the underlying database is scoped per-account and never exposed directly to the browser.

Children

The Service is not directed to children and is not intended for their use.

Changes to this Policy

We may update this Policy from time to time; material changes will be reflected by an updated “Last updated” date below.

Contact

docburstsupport@gmail.com

Last updated August 7, 2026.