Privacy and data protection policy — Docmint
Last updated: September 24, 2026
DOCMINT (accessible through the domain https://docmint.app/), hereinafter simply referred to as "Docmint", "we" or "our", values maximum transparency, security, and privacy in the processing of its users' data ("User", "Data Subject" or "you").
This Privacy Policy ("Policy") aims to inform, in a clear and accessible manner, how we process personal data in compliance with the General Data Protection Law (LGPD - Federal Law No. 13.709/2018), the Brazilian Civil Rights Framework for the Internet (MCI - Federal Law No. 12.965/2014), and other applicable laws.
1. fundamental principle: privacy by design
Docmint was designed under the technical premise of non-custody of files and absolute privacy:
- Your files are NOT sent to our servers: When you select a file for registration or validation, the calculation of the cryptographic hash (mathematical fingerprint) is executed exclusively locally, in your own browser and device (client-side).
- Zero Content Access: The Docmint team, our servers, and our core algorithms do not and will never have access to the text, images, codes, photos, trade secrets, or any information contained within the documents you submit to the platform.
- Only the string of characters resulting from the mathematical calculation (the Hash) transits through our infrastructure to be anchored in the blockchain network.
2. what data we process (and what we do not process)
For better understanding, we divide the data into the categories below:
Content of Documents
What it covers: PDF files, DOCX, images, blueprints, source codes, audios, etc.
Does Docmint store it? NO. They never transit or are saved on Docmint servers.
Record Metadata
What it covers: One-way hash of the file, file name, title and description provided by the User, blockchain transaction identifier, and timestamp.
Does Docmint store it? YES. They are processed to enable registration and are publicly recorded on IPFS and the blockchain — so they must not contain personal or sensitive data.
Account Data
What it covers: Email and name provided at sign-in (Google or email, via the Privy authentication provider), the address of the digital wallet created for the User, credit balance and statement.
Does Docmint store it? YES. Required to identify the User and provide the service.
Financial and Payment Data
What it covers: Payment identifier, amount, currency, date/time and status. Data such as tax ID, bank or card details are handled directly by the gateways (Mercado Pago and Stripe).
Does Docmint store it? YES, only the reconciliation data above. Docmint does not store card data.
Connection and Navigation Records
What it covers: Source IP address, logical port, connection date and time, browser type.
Does Docmint store it? YES. Mandatory collection for compliance with the Brazilian Civil Rights Framework for the Internet (art. 15).
3. purposes and legal bases of processing (art. 7 of the LGPD)
We process strictly necessary data for the following purposes, supported by their respective legal hypotheses:
3.1. Contract Execution and Service Provision (Art. 7, V, LGPD)
- Purpose: To calculate and issue the blockchain transaction corresponding to the hash locally generated by the User; issue the receipt and provide the priority validation tool.
- Data used: Document hash, order identifier, and payment confirmation.
3.2. Compliance with Legal and Regulatory Obligation (Art. 7, II, LGPD)
- Purpose: To store application access logs (IP address, date, and time) for the legal term of 6 (six) months, as expressly determined by Article 15 of Law No. 12.965/2014 (Brazilian Civil Rights Framework for the Internet).
- Accounting/Tax Purpose: To maintain a history of financial transactions and PIX payments to comply with tax requirements and regulations of the Central Bank of Brazil (BACEN).
3.3. Legitimate Interest and Platform Security (Art. 7, IX, LGPD)
- Purpose: Prevention of fraud, Distributed Denial of Service (DDoS) cyberattacks, exploitation of vulnerabilities, and preservation of the technical stability of the service.
- Data used: Technical request logs, error telemetry, and HTTP request metadata.
4. the public nature of the blockchain and the LGPD
The User recognizes and accepts the peculiarities inherent to blockchain technology:
- Immutability and Public Transparency: Blockchains are globally distributed and decentralized public networks. Any information recorded on them is technically indelible (cannot be edited, corrected, or deleted by anyone, including Docmint developers).
- Mathematical Pseudonymization of the Hash: The file's hash (e.g., SHA-256 algorithm) is a one-way function. From the hash, it is mathematically impossible to reconstruct or deduce the original content of the document or the identity of whoever generated it.
- Best Practices Recommendation for the User: If your file contains highly sensitive personal data of third parties (e.g., medical reports with exposed names and CPFs), it is recommended to evaluate the need for prior pseudonymization before submitting the file to the platform, fully safeguarding the privacy of third parties should you publicly disclose the original file in the future.
5. data sharing with third parties
Docmint does not sell, rent, or share personal data for behavioral advertising or third-party direct marketing purposes.
Data sharing occurs only in the following strictly necessary situations:
- Financial Institutions and Payment Gateways: Entities authorized by the Central Bank of Brazil to facilitate the processing and instant reconciliation of payments via PIX.
- Cloud Infrastructure Providers: High-security standard servers contracted to host the web code, DNS routing, and attack protection (e.g., AWS, Vercel, Cloudflare).
- Blockchain Networks: The public hash and timestamp are transmitted and replicated to the decentralized validator nodes that make up the used blockchain ecosystem.
- Government and Judicial Authorities: Upon a valid court order, a substantiated request from a competent authority, or when expressly required by legal determination.
6. international data transfer
Due to the use of a global cloud infrastructure and the decentralized nature of blockchain networks (whose validator nodes are spread across multiple countries), strictly necessary technical data (encrypted logs and hashes) may be transferred internationally.
All transfers comply with the parameters established by articles 33 and following of the LGPD, adopting standard contractual clauses and rigorous security and encryption protocols.
7. data retention and disposal period
- User Files: ZERO retention. The original files never touch our servers.
- Application Access Logs (Marco Civil): Stored confidentially for the mandatory period of 6 (six) months, being subsequently discarded in a secure and automated manner.
- Financial and Tax Data: Maintained for the prescriptive periods foreseen in the Civil Code, the National Tax Code, and BACEN resolutions (generally 5 years).
- Hash and Metadata on the Blockchain: Remain perpetually registered on the decentralized blockchain network, guaranteeing the perpetuity of the User's technical proof for all posterity.
8. information security
Docmint adopts technical, organizational, and operational measures designed to protect the data under its responsibility against unauthorized access, accidental or unlawful incidents of destruction, loss, alteration, or communication, such as:
- End-to-end encrypted traffic via secure HTTPS / TLS protocol;
- Strict policies of Least Privilege for administrative access;
- Perimeter protection against cyberattacks and code injection;
- Deliberate absence of a user document repository, eliminating at the source the risk of mass leaks of private files.
9. rights of the data subject (art. 18 of the LGPD)
You, as the Data Subject, have the right to obtain from Docmint, at any time and upon formal request:
- Confirmation and Access: Confirmation of the existence of processing and access to your registration and payment data;
- Correction: Rectification of incomplete, inaccurate, or outdated registration data;
- Anonymization, Blocking, or Elimination: Of unnecessary, excessive, or non-LGPD compliant personal data;
- Information on Sharing: Information about the public and private entities with which we share your data;
- Revocation of Consent: In cases where processing was based exclusively on express consent.
Important caveat regarding Blockchain: Given the mathematical immutability of distributed networks and Docmint's lack of central control over mined blocks, the right of elimination or alteration does not apply to hashes already anchored in the blockchain, which in themselves do not constitute directly identifiable personal data.
11. data protection officer (DPO) and contact
To exercise any of your rights as a data subject, raise questions about information processing, or send communications related to this Policy, contact our Data Protection Officer (DPO) directly:
- Official LGPD Service Channel: [email protected] (or official support form at https://docmint.app/)
- Responsible: Data Protection Officer / Docmint Legal Team
We will respond to your request within the deadlines and terms set by the regulations of the National Data Protection Authority (ANPD).
12. changes to this policy
Seeking the constant improvement of our security standards, we may update this Privacy Policy at any time.
The changes will take effect from the date of their official publication at https://docmint.app/privacy. Continued use of the platform after any revision will constitute knowledge and agreement with the new processing terms.
13. applicable law and forum
This Policy is drafted and interpreted in strict compliance with the laws of the Federative Republic of Brazil, especially Law No. 13.709/2018 (LGPD) and Law No. 12.965/2014 (Marco Civil da Internet).
Any disputes that cannot be resolved amicably will be submitted to the forum of the district of the User's domicile, in cases protected by the Consumer Defense Code, or to the forum of the district of Docmint's operational headquarters.
