Security & Data

Data Handling

Where your data is stored, who processes it, and what happens when you delete.

This page describes where your knowledge lives and how it's protected.

Where your data is stored

Your documents, their content and version history, and the embeddings that power search all live in Docpipe's managed database, scoped to your organization. A few specifics:

  • Uploaded files (images and attachments) are kept in a private store, never publicly listable. When a document loads media, Docpipe checks your access to the space and then serves the file through a short-lived signed link that expires after an hour.
  • Integration tokens — the credentials Docpipe uses to reach Slack, Jira, Linear, and similar — are stored encrypted at rest and can only be decrypted by privileged server-side functions. Disconnecting an integration revokes them.
  • API keys for the MCP server are stored only as a one-way hash. The full key is shown once and never retrievable — if it's lost, you revoke it and create a new one.

Who else processes your data

To provide the product, Docpipe shares specific data with a small set of service providers:

  • OpenAI — powers the AI features; receives document content and prompts to generate responses and embeddings (see AI & your data).
  • Your connected integrations — Slack, GitHub, Jira, Linear, and Confluence exchange content and links with Docpipe as you use them.
  • Billing and email providers — process your subscription and send transactional email (invitations, notifications).
  • Product analytics — usage data, which can include AI interactions, for quality and reliability.

The Docpipe Privacy Policy is the authoritative, current list of subprocessors and the data each receives.

Deleting and disconnecting

  • Removing a member frees their seat and revokes any API keys they created.
  • Disconnecting an integration revokes its stored credentials. For Jira and Linear, it also permanently deletes the links between your documents and that provider's issues — reconnecting doesn't restore them. See Jira and Linear.
  • Downgrading your plan never deletes your documents or spaces. Existing content stays available to read; only creating more is capped, and Pro-only features turn off.

Need a copy of your data, a data processing agreement, or help deleting an organization? There's no self-serve export today — contact the team and they'll help.