Skip to content
Sharedora Back to Sharedora

Privacy Policy

What we hold, who else touches it, and how to get rid of it. Nothing inside a document you upload is sent to an AI model unless you turn that on, per document.

Last updated 16 August 2026 · Sharedora is operated by Dynamic Upgrade LLC

1. Who we are

Sharedora is operated by Dynamic Upgrade LLC (“we”, “us”). For anything in this policy, including a request to access or delete your data, write to support@sharedora.com.

2. What we collect

  • Your account. Email address and display name, from the account you sign in with. If you sign in with Google, we receive those from Google; we never receive your Google password.
  • What you add. The documents, notes and text you put into a Mind, their filenames, and the questions you ask.
  • What the product derives, and only where you have consented: extracted page text, search indexes, and proposed dates or tasks awaiting your approval.
  • Operational records. Activity history for each Mind, and server logs containing request metadata and object keys. Logs do not contain document contents.
  • Billing details are handled by Stripe. We store your Stripe customer and subscription identifiers and your subscription status. We never see or store your card number.

3. Consent: nothing is read until you say so

Before any content inside a document is sent to an AI model, we ask. Each document carries three independent choices, all off by default: read the words, find dates and details, and look at pictures. Adding a new document never inherits a previous answer.

You can change any of them later, in either direction. Withdrawing consent deletes the extracted passages and stops future processing. It cannot recall what was already sent — the product says so at the moment you decide, and so do we here.

“Store without reading” is a supported outcome: a document can live in Sharedora as a file you can find and download, with nothing ever sent anywhere.

4. Who else processes your data

We use these providers, and no others receive your content:

  • Amazon Web Services — hosting, file storage, sign-in infrastructure, queues and logs. Data is stored in the US East (N. Virginia) region.
  • Supabase — the PostgreSQL database holding your account, Minds, metadata and any extracted text.
  • Google — the Gemini API, which receives document text and your questions only for the documents where you turned that on. We use the paid tier, under which Google states that prompts are not used to improve their products. Google also provides optional sign-in.
  • Stripe — payments. Stripe receives your email and payment details directly.
  • Resend — transactional email. When you invite someone, Resend receives their email address, your display name, and the name of the Mind.

We do not sell your data, we do not share it with advertisers, and nothing you add is used to train any AI model — by us or by the model vendor.

5. Analytics and cookies

Sharedora runs no analytics, no tracking pixels and no third-party scripts, on this site or in the product. We do not know which pages you visited.

Sharedora sets one cookie of its own, which is strictly necessary: it holds your sign-in session so you are not logged out on every page load. Signing in also passes through Amazon Cognito’s hosted sign-in page, which sets its own cookies on its own domain to complete that step. There is no consent banner because there is nothing optional to consent to.

6. Deleting your data

  • A single document — delete it in the app at any time.
  • A whole Mind — the owner can delete it, which removes its documents, extracted text, conversations and files.
  • Your entire account — from your settings. This deletes the Minds you own, cancels any subscription, and removes your profile and sign-in record.

Deletion completes within 30 days, not instantly, and we would rather say so than round it. Our file storage keeps previous versions for 30 days as protection against accidental or malicious mass deletion, and database backups have a similar window. After those windows pass, the data is gone.

Three things deliberately survive, and you should know which:

  • Documents you added to a Mind somebody else owns. They stay with that Mind, no longer attributed to you. Otherwise a shared Mind would lose material the moment a contributor left. Delete those documents individually first if you want them gone.
  • The record that a consent decision was made, without your identity attached. A deleted account must not erase the fact that permission was given or withdrawn for a document that still exists.
  • Stripe’s financial records. Deleting your account cancels your subscription. Stripe retains transaction records to meet its own legal obligations, and we cannot delete those.

7. Your rights

You can access everything you have added at any time by downloading it — including after you stop paying, which is deliberate. To request a copy, a correction, or deletion, write to support@sharedora.com and we will respond within 30 days. Depending on where you live you may have additional rights under laws such as the GDPR or the CCPA; we will honour those requests through the same address.

8. Children

Sharedora is not intended for children under 13, and we do not knowingly create accounts for them. Adults do sometimes store material about their children — a school Mind, a medical Mind — and that material is treated like any other document in the account that holds it.

9. Security

Files are encrypted at rest and in transit. Every request is authenticated, and the database enforces per-user access rules at the row level, so one account cannot read another’s material even if the application asked it to. Access to a Mind is by explicit invitation only.

No system is perfect. If you find a security problem, please write to support@sharedora.com.

10. Changes

If we change this policy in a way that materially affects what happens to your data, we will say so by email before it takes effect. The date at the top always reflects the current version.