Skip to main content

Privacy And Security

Document.Bot is local-first, but not every operation is automatically offline. Your privacy boundary depends on your workspace, selected AI provider, indexing mode, enabled tools, and account setup.

Local-First Means You Choose The Folder

Document.Bot starts with files in a folder you select. It does not require uploading a batch of files to a generic chat tool before you can start.

That does not mean every AI or indexing action stays on your device.

Check Your Provider Boundary

Before using sensitive documents, confirm:

  • which chat model is selected
  • whether the model is local, hosted by Document.Bot, connected through ChatGPT Login, or connected through your own provider key
  • whether indexing is local or hosted
  • whether image attachments or rendered document pages may be sent to the model
  • whether your organization has approved that provider

Use The Privacy Badge As A Quick Check

Some builds show a top-bar Privacy badge. Use it as a quick status check before working with sensitive files.

The badge is green only when both AI chat and workspace indexing are running locally. If either AI chat or workspace indexing can send content to an online or hosted service, the badge is red.

Click the badge to see separate rows for:

  • AI Chat
  • Workspace indexing

This distinction matters. Choosing an offline chat model does not automatically make workspace indexing offline. If you switch chat to an offline model while indexing is still online, Document.Bot may show a checkpoint so you can decide whether to keep online indexing or switch indexing offline too.

The Privacy badge is a product status indicator, not a compliance certificate. Your organization still needs to decide which providers, indexing modes, workspaces, and documents are approved.

Use Focused Workspaces

The safest workspace is a focused folder for one task. Avoid selecting broad folders that may include unrelated personal, customer, or company files.

File Actions Stay Reviewable

Review AI-assisted actions before accepting them, especially when a workflow may:

  • write or modify files
  • delete or rename files
  • convert documents
  • use external tools
  • send content to an online AI provider

Compliance Claims

Document.Bot can support sensitive and regulated document workflows, but it does not make a workflow compliant by itself.

Your organization remains responsible for:

  • data handling policies
  • provider approval
  • audit requirements
  • final document decisions
  • legal, compliance, or regulatory advice

Reporting Problems

If you report a privacy or security issue, include the app version, operating system, selected provider type, and a description of the workflow. Do not send private source files unless support explicitly asks for a safe reproduction package.