7 simple privacy guarantees for your HTML Docs data.
The useful question is not whether a cloud service says your data is “private.” It is who can technically access it, why they may do so, and which uses are off limits.
Last reviewed August 16, 2026
The honest answer
Your data is not inaccessible to HTML Docs.
HTML Docs is not end-to-end encrypted or zero-knowledge. The service has to process document content to store, render, edit, synchronize, search, export, and apply features you request. Authorized production operators also have technical means to access stored data.
The privacy guarantee is therefore a boundary on access and use—not a claim of mathematical impossibility. We restrict ordinary users with document permissions, protect privileged credentials, and commit to using operator access only for defined operational reasons.
Our commitments
Seven boundaries you can hold us to.
Private documents are access controlled
Signed-in documents start private. Ordinary access is limited to the owner, authorized collaborators, workspace members with the right role, and application processes acting for them.
Sharing is an explicit choice
Private, shared-by-link, and public are different states. An unlisted link is a bearer secret: anyone who has it may receive the access you enabled. Public publishing is intentionally open.
Data is protected in transit and at rest
HTML Docs uses HTTPS in transit, hosted database encryption at rest, row-level database policies, restricted service credentials, and application authorization checks. Encryption does not make the service zero-knowledge.
Private content is not an advertising asset
We do not sell private document content, use it for targeted advertising, or use it to train an HTML Docs model. We do not intentionally copy private document bodies into product analytics or security-event metadata.
AI processing is feature scoped
Relevant content may be sent to an AI provider when you invoke or enable an AI-dependent workflow such as Docsmith, Ask, beautification, transcription cleanup, embeddings, or document conversion. Provider terms and retention rules also apply.
Operator access is limited by purpose—not impossible
Authorized operators can technically access production data. We limit that access to operating the service, resolving support you request, investigating security or abuse, restoring reliability, and meeting legal obligations. We do not browse private documents out of curiosity.
You control deletion and disconnection
You can delete documents and disconnect integrations. Active content is removed promptly; backup copies, where present, age out within 30 days unless law or an active security investigation requires longer retention.
Access map
Who can receive document data?
You and collaborators
According to the document, folder, link, and workspace permissions you choose.
HTML Docs application services
When needed to provide storage, rendering, sync, search, export, security, and other requested product behavior.
Authorized operators
Only for support you request, service reliability, security or abuse investigation, legal obligations, and tightly scoped administration.
Service providers
Only to operate the service or provide a feature you invoke, under their applicable contracts and policies.
Anyone with a public or unlisted link
Public pages are open. Unlisted links grant the configured access to whoever possesses the link or token.
The AI boundary
HTML Docs does not train an HTML Docs model on private document content. AI features are different: when you use or enable one, the relevant prompt, document passage, transcript, image, or retrieved context may be sent to the configured inference provider.
As of this page’s review date, OpenAI states that API inputs and outputs are not used for model training by default, and Anthropic states the same for its commercial offerings unless a customer opts in or submits material through an applicable feedback program. Those providers control their own retention, abuse-monitoring, and policy exceptions, so their current terms remain part of the boundary.
If content must never leave the core HTML Docs processors, do not use AI-dependent features for that content.
Data privacy FAQ
Can the HTML Docs operator read my private documents?
Technically, yes. Authorized production credentials and database administration can access stored content. HTML Docs is not a zero-knowledge service. The commitment is to restrict that access to defined operational, support, security, reliability, and legal purposes—not to claim that access is cryptographically impossible.
Are documents end-to-end encrypted?
No. Connections and hosted storage are encrypted, but HTML Docs must process document content on its servers to render, edit, search, synchronize, export, and apply requested AI features. Do not describe the product as end-to-end encrypted or zero-knowledge.
Does HTML Docs train AI models on my documents?
HTML Docs does not use private document content to train an HTML Docs model. If you use an AI-powered feature, the content needed for that request may be processed by the selected provider. As of this page’s review date, OpenAI’s API and Anthropic’s commercial offerings state that customer inputs and outputs are not used for model training by default, subject to their current terms and opt-in or feedback exceptions.
Does noindex make a page private?
No. Noindex is a search-engine instruction, not an access control. A public or unlisted page can still be opened by someone who has its URL. Use private access for confidential material.
What should I avoid storing in HTML Docs?
Do not store passwords, private keys, API tokens, or secrets in document markup. Do not use HTML Docs for regulated or highly sensitive data unless the required contracts, product configuration, and internal controls have been reviewed and approved.
Policies and supporting references
This page explains the product boundary in plain language. The formal Privacy Policy and Terms of Service control where they differ.
Have a privacy question or deletion request? Contact support.