Document Lake

Privacy Policy

Effective July 21, 2026

This policy explains what Juno AI Labs, Inc. (“Document Lake”, “we”) collects when you use the hosted service at document-lake.com, and what we do with it. If you self-host the open-source software, this policy does not apply — your deployment is yours.

What we collect

  • Account information. When you sign in with an identity provider (Google), we receive and store your email address, name, and avatar URL. We never receive your password.
  • Your documents. Files you upload, the markdown representations, extracted facts, tags, and embeddings derived from them. This is the point of the product; it is your data and we process it only to provide the service to your workspace.
  • Usage and billing records. AI usage metering (tokens and cost per request), your prepaid credit ledger, and — if you top up — payment records handled by Stripe. We never see full card numbers.
  • Audit logs. Per-workspace logs of actions (uploads, views, searches, member changes) with the acting account, kept so workspace owners can review access.
  • Operational logs. Request metadata (route, latency, status, hashed IP) for reliability and abuse prevention. Document content never appears in operational logs.

How we use it

To operate the service: storing and retrieving your documents, running the AI features you invoke, billing prepaid credits, securing accounts, and providing support. We do not sell personal data, use your documents to train models, or use them for advertising. AI processing is performed by the sub-processors listed on our sub-processors page under agreements that prohibit training on your content.

Storage, security, and retention

Data is stored on Cloudflare infrastructure. Documents are encrypted with per-workspace envelope encryption (AES-256-GCM) on top of provider-level encryption at rest; see the security page. EU-region workspaces keep primary document data in EU jurisdiction storage. When you delete a document or workspace, its content becomes unrecoverable: deletion destroys the workspace encryption keys (crypto-shredding) in addition to removing stored objects. Ledger and audit records are retained as required for accounting and security.

Your rights

Depending on your location (including under GDPR and CCPA), you may have rights to access, correct, export, delete, or restrict processing of your personal data. Workspace owners can export documents and audit logs directly in the product. For anything else, contact privacy@document-lake.com and we will respond within 30 days.

Changes

We will post changes here and, for material changes, notify workspace owners by email before they take effect.