Trust, security & how our AI works
Last updated: 3 September 2026
DullDocs holds inspection evidence for regulated settings — including sensitive staff documents like DBS certificates. This page states plainly where that data lives, who processes it, exactly what our AI sees and when, and the controls you keep. We would rather publish a precise answer than an impressive one: where something is still being verified, this page says so.
DullDocs helps organise, monitor and prepare document evidence. It does not replace professional compliance, safeguarding, fire-safety, legal or Ofsted advice, and does not certify compliance.
Where your data lives
DullDocs application functions and our private document store run in Dublin (EU). The region of our application database is being verified, so we make no EU-only claim for it yet. DullDocs is operated from the UK and contracts under UK law, and personal data is handled under UK GDPR. We describe our hosting as EU, not UK, because that is where it is. We are evaluating a move to UK-region hosting and will update this page if and when that ships.
How your document files are held
Uploaded documents, the text we read out of them and staff photographs are held as files, separately from the database. They are kept in a private store: a request for one has to carry our storage credential, so a file address on its own does not return the file. Files uploaded before 3 September 2026 were held differently and have all been moved into that private store. Inside DullDocs, who can open a document is decided by the role settings below, and downloads of sensitive documents are recorded in your audit log.
Subprocessors
Every third party that processes data on our behalf, what we send them, and where they run:
- Lovable Cloud / Supabase — Public website hosting and website-tool database services. Data sent: Website enquiries, free-scan contact details and results, calculator configuration and related events; separate from the application workspace database Region: Website database region is being verified; no UK-only or EU-only claim is made for this service
- PostHog — Product analytics: how DullDocs is used, so it can be improved. Data sent: Counts and timings against a code that stands for your organisation, and a code that stands for a signed-in user. Never document contents, file names, dates read from your documents, decision reasons, staff or children’s names, email addresses, page addresses or IP addresses. No session recording, no screen capture and no cookies. Region: European Union (PostHog Cloud EU)
- Cloudflare — Public website delivery, DNS and edge security. Data sent: Requests to our public pages, including IP address and user agent Region: Global edge network
- Render — Background processing for Ofsted Inspector Briefings. Data sent: Published Ofsted inspection data and briefing job records. It holds no credential for the DullDocs application database, so it never sees your documents, staff records or evidence. Region: Frankfurt, EU
- Vercel — Application hosting and document file storage (Vercel Blob). Data sent: All application traffic; uploaded document files Region: Application functions run in Dublin, EU (dub1). Document files are held in a private store in Dublin, EU (dub1). Files uploaded before 3 September 2026 were previously held in Washington DC, US (iad1); they have all been moved, and no customer document, extracted text or staff photograph is held outside the EU. Organisation logos, which are published material, remain in the older store.
- MongoDB Atlas — Database (organisation, requirement, staff-record and document metadata). Data sent: Application data, including extracted document text and staff records Region: Region is being verified; no UK-only or EU-only claim is made for this service
- Stripe — Payments and subscription billing. Data sent: Billing contact details and payment information (card data is entered directly with Stripe) Region: EU/US (global payment infrastructure)
- Resend — Transactional email (reminders, document requests, acknowledgements, declarations) and receiving documents emailed to your DullDocs address. Data sent: Recipient name and email address, plus the message content of each notification; and, where you use email-in, the emails sent to your DullDocs address, including their attachments Region: EU/US
- WhatsApp (Meta), via a self-hosted WhatsApp gateway reached through an ngrok tunnel — Internal alerts to the DullDocs team when something happens on an account (a new sign-up, a payment, a failed card, a cancellation, a support request). Data sent: Account facts only: your organisation name, the name and email address of the person on the account who triggered the event, the plan, amounts charged or refunded, how many settings you hold, and the domain of anyone invited to your team. For inspector briefings it also includes the inspector reference you bought a briefing about. Never documents, never their contents, and never the text of a support message. Region: Global (Meta)
- ngrok — Tunnel that carries the internal alerts in the WhatsApp row above from the application to the self-hosted WhatsApp gateway. Data sent: The text of each of those internal alerts passes through the tunnel: account facts only, never documents, never their contents, and never the text of a support message. Region: Not verified; no location claim is made for this service
- OpenAI / Anthropic (whichever is configured) — AI document classification, date and name extraction, evidence checks, reading scans and photographs, the Ask DullDocs assistant, report summaries and recommendations, chase email drafts and Projects. Data sent: For each document with readable text: the first 6,000 characters of its text with the filename, to classify it; the first 6,000 characters plus, for a longer document, up to 4,000 characters of later passages that introduce a person (up to 10,000 in all), without the filename, to read dates and names; and, when it matches one of our standard requirements, the first 5,000 characters with the requirement, organisation and setting names, without the filename, for the evidence check. Assume this applies to every document we can read text from. For photographs and PDF scans with no readable text, the image or PDF file itself is sent automatically on upload, without the filename, up to 12 MB and 20 pages per call; what the provider reads from it then goes through the same three calls. Scans longer than 20 pages are sent in parts of up to 20 pages, to a maximum of 60. For an organisation that has accepted the DullDocs Terms of Service and Customer Data Processing Agreement dated 24 September 2026, a complete-document analysis also sends the extracted text of every page, with the filename, to find restrictions, missing dates and integrity problems, but only once DullDocs switches it on for that organisation, which its Legal agreements page in Settings shows; it is not made for photographs or scans. Ask DullDocs sends your question with requirement names (including your own custom requirement names), categories, severities, statuses, dates and setting names, status counts, and staff names, job roles and statuses (inactive staff by job role and status only). Report summaries send status counts, the readiness score and up to eight requirement names. Drafting a chase email sends the requirement name or action title, not the due date. Projects send the project type, name, goal, location and setup answers you type; drafting a project support document also sends the setting name and the checklist and linked requirement titles. Region: United States
- Companies House API — Company-name lookup during signup. Data sent: The company name or number you type: public-register data only, no staff or document data Region: UK
- Google Maps Places — Address autocomplete on site/address forms. Data sent: The address text you type into an address field Region: Global (Google)
- Microsoft (OneDrive) (only if you connect it) — Optional read-only cloud-drive import. Data sent: Files in the folders you explicitly select, read-only Region: Your Microsoft tenant
- Google Drive (only if you connect it) — Optional read-only cloud-drive import. Data sent: Files you explicitly select (least-privilege drive.file scope by default), read-only Region: Your Google account
What our AI sees — and when
The active AI provider for this deployment is: OpenAI (rendered from live configuration, so this line cannot go stale).
- What is sent, and when: When a document is processed, DullDocs sends its extracted text to our AI provider to work out what the document is, to read dates and names from it and to check it looks like reasonable evidence. Assume that the text of any document you upload will be sent: we do not promise that some documents are handled without AI, because in the software we run today they are not. Each call has its own limit. Classifying the document sends the first 6,000 characters of its text with the filename, the type of setting and our list of requirement types. Reading dates and names sends the first 6,000 characters and, for a longer document, up to 4,000 characters of later passages that introduce a person, such as "certificate holder" or "has completed", so up to 10,000 characters in all; it does not send the filename. The evidence check runs when the document matches one of our standard requirements and sends the first 5,000 characters with your organisation name, the setting name and the name of that requirement, so the model can tell "wrong company" from "right company"; it does not send the filename either. For an organisation that has accepted the DullDocs Terms of Service and Customer Data Processing Agreement dated 24 September 2026, a complete-document analysis also sends the extracted text of every page, with the filename, to find restrictions, missing dates and integrity problems, but only once DullDocs switches it on for that organisation; it is made only for a document whose every page has readable text of its own. The organisation's Legal agreements page in Settings shows whether it is on. A document whose processing did not finish is sent again automatically, and retrying the analysis sends it again, so one document can involve more than three calls.
- Photographs and scans: Photographs and scans are different: there is no text to extract, so the file itself is sent to the provider to be read, the image as uploaded or the PDF. This happens automatically when the file is uploaded or imported, rather than only when someone asks for it. That call does not send the filename, and each call is limited to 12 MB and 20 pages; a file or part over 12 MB is not sent. The text the provider reads is then used for the same three calls as any other document, so classification receives the filename. A scan longer than 20 pages is read in parts in the background: DullDocs sends a copy of the next 20 pages (10 if 20 pages would exceed 12 MB) and repeats the calls for each part until it has found what the requirement needs, reached the end of the file or read 60 pages. A part that could not be read may be sent again.
- Other places AI is used: Asking a question with Ask DullDocs sends your question (up to 800 characters) with details of up to 120 requirements you can see: the requirement name, including names you gave your own requirements, its category, severity, status, whether it is recommended practice, setting name, expiry and review dates and an internal reference. It also sends counts of requirements by status and the name, job role and status of each staff member you can see; inactive staff are sent by job role and status only. This information is cut at 9,000 characters. Report summaries, including those for a mock inspection or an inspection, send counts of requirements by status and the readiness score, and the names of up to eight high-priority requirements that are missing, expired or out of date. Drafting a chase email sends the requirement name or the action title, which for your own requirements includes the name you gave it; the due date is not sent. Projects send the project type, name (up to 200 characters), goal (up to 2,000 characters), any location you enter and your answers to its setup questions (cut at 4,000 characters); drafting a project support document sends the project name and type, the setting name, the titles of its checklist items and linked requirement, and your setup answers (cut at 1,500 characters). None of these features sends document content.
- What AI can decide: nothing final. AI suggestions route through deterministic rules — classification attaches automatically only at 90%+ confidence, evidence below a confidence of 0.7 can never satisfy a requirement, and an AI-extracted date that no deterministic read corroborates routes to human review. The full published methodology is at /methodology.
- What we retain: We cache what the AI worked out, so re-reading the same file does not cost another call. That cache holds the extracted dates, names and document type, and the model’s classification result. For a scan or photograph it records where the text we read off the page is stored, rather than keeping a second copy in the cache. The transcription is stored as that document’s extracted text. Earlier scan-reading versions are kept so an ongoing read can finish safely; deleting the document or its extracted text removes all those versions. The cache does not hold the prompts we send or the images themselves. Deleting a document’s extracted text or your data purges it, and our AI usage metrics record only counts and timings, never content.
- Training: We send document content to our AI providers only to provide the service. We are completing verification of the account-level data-processing terms with each provider, including retention and model training, and will state the confirmed position here once done.
Access control & audit
- Sensitive staff evidence (DBS certificates, references, identity documents) is restricted to manager-level roles; downloads of sensitive documents are audit-logged — including denied attempts.
- Sign-in is passwordless (one-time email codes) — there is no password database to breach. Every account also requires a second factor: a six-digit code from a standard authenticator app (Google Authenticator, Microsoft Authenticator, Authy, 1Password or any compatible app). It is mandatory, not optional, and it applies to every person who can sign in — including anyone arriving on a magic link. The pairing secret is encrypted at rest (AES-256-GCM) and recovery codes are stored only as hashes.
- Staff members never get logins. They interact through single-purpose, time-limited, revocable secure links (uploads, policy acknowledgements, declarations) — each action is recorded with a full audit trail.
- Cloud-integration tokens are encrypted at rest (AES-256-GCM).
- Owners and admins have an in-app audit log of security-relevant actions at Account settings → Audit log.
Children’s data
DullDocs does not ask for, structure, or store per-child records: there are no child profiles, no registers, no observation or development tracking, and no per-child SEND records in the product. Where a regulator expects child records to exist, a manager attests where those records are kept (for example, your nursery-management system or paper files) — the records themselves stay in your existing systems. Documents you choose to upload can incidentally contain names, which is why sensitive-document access controls and audit logging apply to everything you store with us.
Your data, your controls
All of these are live, self-serve controls at Account settings → Data retention:
- Delete all extracted document text (the AI cache is purged with it).
- Delete all uploaded files.
- Export your data as JSON (sites, staff records, requirement statuses, document metadata, actions, reports and your organisation’s audit log). Original file binaries are not included in this export today — a full archive export is on our roadmap.
- Request deletion of your whole organisation — requests are verified and processed manually.
Openly on our roadmap
- UK-region hosting (we will only claim it here once it is true).
- Confirmed account-level AI data-processing terms, stated on this page.
- One-click full archive export (documents + metadata).
Questions about anything on this page — or anything missing from it — are welcome: privacy@dulldocs.com.