This policy explains the personal and organisation data Exodocs processes, how we use it, who we share it with, and the rights you have over it. For the technical detail on how we protect it, see our Security page.
Last updated June 2026 · Exodocs ("we", "us", "Exodocs")
Exodocs keeps engineering documentation honest by connecting your code repositories to your documentation hub and alerting your team when docs drift from the code they describe. To do that we process a deliberately small amount of data. We sell nothing, we advertise to no one, and we store as little as the product allows.
This policy applies to people who create an Exodocs account, members invited into an organisation, and visitors to our website. Where your organisation administers an Exodocs account on your behalf, that organisation is the controller of the workspace data, and Exodocs processes it as a service provider under their instructions.
We do not sell your data, use it for advertising, or use your private workspace content to train our own models.
Where the GDPR or similar laws apply, we process your data on the basis of contract (to deliver the service you signed up for), legitimate interests (to secure and improve the service), consent (for optional communications and AI features you switch on), and legal obligation (for tax and accounting records).
We share data only with the sub-processors that make Exodocs work: hosting and database, caching, AI processing, payments, and the integrations you connect (GitHub, Notion, Confluence, Slack). The full list, with what each one processes and where, is maintained on our Security page.
We may also disclose information if required by law, or to protect the rights, safety, and security of Exodocs and its users. If Exodocs is ever involved in a merger or acquisition, we will notify you before your data becomes subject to a different privacy policy.
When you use AI features, relevant context is sent to our AI provider, Anthropic, for processing. That context includes commit messages, file paths, documentation page text, and, for documentation generation, sampled source files. Untrusted content is sanitised against prompt-injection patterns before it reaches the model.
You stay in control. Every AI feature can be turned off in your organisation settings. With AI disabled, no workspace content is sent to our AI provider.
We keep data only as long as it is needed. When you remove a documentation page or repository, we deactivate it and stop tracking it immediately. When you disconnect an integration, its stored credentials are removed from our database right away. Cached page content and file trees expire automatically within 24 hours.
When a subscription lapses or you close your account, your organisation enters a 90-day suspension grace period, after which all of its data, including deactivated pages and repositories, is permanently purged. You can request earlier deletion at any time.
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. Most of this is self-service inside the app; for anything else, email us and we will action verified requests within 30 days.
Exodocs uses a single, essential session cookie to keep you signed in and to protect against cross-site request forgery. We do not use third-party advertising or cross-site tracking cookies. Because our cookies are strictly necessary to operate the service, no consent banner is required to set them.
We may update this policy as the product evolves. Material changes will be announced in-app or by email, and the "last updated" date above will change. Continued use after an update means you accept the revised policy.
Reach out about your data, a deletion or export request, or anything in this policy. We respond within a few business days.