DullDocs

Trust, security & how our AI works

Last updated: 8 July 2026

DullDocs holds inspection evidence for regulated settings — including sensitive staff documents like DBS certificates. This page states plainly where that data lives, who processes it, exactly what our AI sees and when, and the controls you keep. We would rather publish a precise answer than an impressive one: where something is still being verified, this page says so.

DullDocs helps organise, monitor and prepare document evidence. It does not replace professional compliance, safeguarding, fire-safety, legal, Ofsted or CQC advice, and does not certify compliance.

Where your data lives

DullDocs application functions run in Dublin (EU) and our database is hosted in the EU. DullDocs is operated from the UK and contracts under UK law, and personal data is handled under UK GDPR — but we describe our hosting as EU, because that is where it is. We are evaluating a move to UK-region hosting and will update this page if and when that ships.

Subprocessors

Every third party that processes data on our behalf, what we send them, and where they run:

  • VercelApplication hosting and document file storage (Vercel Blob). Data sent: All application traffic; uploaded document files Region: Application functions pinned to Dublin, EU (dub1). Document file storage region: verification in progress — we will publish it here once confirmed.
  • MongoDB AtlasDatabase (organisation, requirement, staff-record and document metadata). Data sent: Application data, including extracted document text and staff records Region: EU
  • StripePayments and subscription billing. Data sent: Billing contact details and payment information (card data is entered directly with Stripe) Region: EU/US (global payment infrastructure)
  • ResendTransactional email (reminders, document requests, acknowledgements, declarations). Data sent: Recipient name and email address, plus the message content of each notification Region: EU/US
  • OpenAI / Anthropic (active provider shown above)AI document classification, date/name extraction, and the Ask DullDocs assistant. Data sent: For eligible documents only: up to the first 6,000 characters of extracted text plus the filename. Ask DullDocs sends your question with requirement names, statuses and dates, site names, and active staff names. Projects features send the project and site names, project goals and intake answers you type. Report summaries send requirement names and status counts. Drafting a chase email sends the requirement or action title and its due date. Full image content is sent only when image AI is enabled and, in our current configuration, a person manually requests analysis of that document. Region: United States
  • Companies House APICompany-name lookup during signup. Data sent: The company name or number you type — public-register data only, no staff or document data Region: UK
  • Google Maps PlacesAddress autocomplete on site/address forms. Data sent: The address text you type into an address field Region: Global (Google)
  • Microsoft (OneDrive) (only if you connect it)Optional read-only cloud-drive import. Data sent: Files in the folders you explicitly select, read-only Region: Your Microsoft tenant
  • Google Drive (only if you connect it)Optional read-only cloud-drive import. Data sent: Files you explicitly select (least-privilege drive.file scope by default), read-only Region: Your Google account

What our AI sees — and when

The active AI provider for this deployment is: OpenAI (rendered from live configuration, so this line cannot go stale).

  • What is sent: for an eligible document, up to the first 6,000 characters of its extracted text plus the filename — nothing else.
  • When: by default, text AI runs only when our deterministic classifier is uncertain about a document; confidently-matched documents never leave our infrastructure for classification. Image analysis runs only when image AI is enabled and a person manually requests it.
  • What AI can decide: nothing final. AI suggestions route through deterministic rules — classification attaches automatically only at 90%+ confidence, evidence below a confidence of 0.7 can never satisfy a requirement, and an AI-extracted date that no deterministic read corroborates routes to human review. The full published methodology is at /methodology.
  • What we retain: our AI cache stores only derived fields (extracted dates, names, document type) — never raw text, prompts, responses or images — and it is purged when you delete a document’s text or your data. Our AI usage metrics are content-free.
  • Training: Our AI providers are engaged to process document content only to provide the service. Our configuration and provider agreements are intended to prevent customer content being used to train generalised models; we are completing verification of the account-level data-processing terms with each provider and will state the confirmed position here once done.

Access control & audit

  • Sensitive staff evidence (DBS certificates, references, identity documents) is restricted to manager-level roles; downloads of sensitive documents are audit-logged — including denied attempts.
  • Sign-in is passwordless (one-time email codes) — there is no password database to breach. Two-factor authentication for customer accounts is on our roadmap.
  • Staff members never get logins. They interact through single-purpose, time-limited, revocable secure links (uploads, policy acknowledgements, declarations) — each action is recorded with a full audit trail.
  • Cloud-integration tokens are encrypted at rest (AES-256-GCM).
  • Owners and admins have an in-app audit log of security-relevant actions at Settings → Audit log.

Children’s data

DullDocs does not ask for, structure, or store per-child records: there are no child profiles, no registers, no observation or development tracking, and no per-child SEND records in the product. Where a regulator expects child records to exist, a manager attests where those records are kept (for example, your nursery-management system or paper files) — the records themselves stay in your existing systems. Documents you choose to upload can incidentally contain names, which is why sensitive-document access controls and audit logging apply to everything you store with us.

Your data, your controls

All of these are live, self-serve controls at Settings → Data retention:

  • Delete all extracted document text (the AI cache is purged with it).
  • Delete all uploaded files.
  • Export your data as JSON (sites, staff records, requirement statuses, document metadata, actions, reports and your organisation’s audit log). Original file binaries are not included in this export today — a full archive export is on our roadmap.
  • Request deletion of your whole organisation — requests are verified and processed manually.

Openly on our roadmap

  • Two-factor authentication for customer sign-in.
  • UK-region hosting (we will only claim it here once it is true).
  • Confirmed account-level AI data-processing terms, stated on this page.
  • One-click full archive export (documents + metadata).

Questions about anything on this page — or anything missing from it — are welcome: privacy@dulldocs.com.