Privacy Policy

Last updated: September 22, 2026

At SudoDocs ("we", "us", or "our"), accessible from https://sudodocs.com, one of our main priorities is the privacy of our visitors and users. This Privacy Policy document contains types of information that is collected and recorded by SudoDocs and how we use it.

1. Data Controller

For the purposes of the General Data Protection Regulation (GDPR), the Data Controller is SudoDocs. If you have any questions regarding your data, please contact us at admin@sudodocs.com.

2. Information We Collect

We collect information to provide better services to all our users. This includes:

  • Account Information: Name, email address, and password hash when you register for an account.
  • Billing Information: Payment details for individual subscriptions (processed securely to cover server and LLM costs; we do not store full credit card numbers).
  • Integrated Data: When you connect third-party tools (GitHub, GitLab, Jira, Slack), we process code snippets, commit messages, and issue descriptions to generate documentation.
  • Usage Data: Information on how you use the application, creating documentation, and API interactions.

3. How We Use Your Information

We use the information we collect in various ways, including to:

  • Provide, operate, and maintain our website and application.
  • Generate automated documentation using Artificial Intelligence (LLMs).
  • Improve, personalize, and expand our website.
  • Send you emails regarding your account, updates, or billing.
  • Find and prevent fraud.

4. AI Processing & Third Parties

SudoDocs utilizes Google Cloud Vertex AI to generate documentation. All AI processing occurs within our secure Google Cloud environment. We do not send your data to external third-party AI providers for content generation.

We may share data with the following categories of third parties:

  • Cloud & AI Infrastructure: Google Cloud Platform (for hosting, database, and Vertex AI services).
  • No Model Training: In accordance with Google Cloud's Data Governance policies, your proprietary code and documentation data are not used to train foundation models. Your data remains isolated to your organization's context.
  • Payment Processors: Paddle (Merchant of Record for handling billing transactions).

5. GDPR Data Protection Rights

We would like to make sure you are fully aware of all of your data protection rights. Every user is entitled to the following:

  • The right to access: You have the right to request copies of your personal data.
  • The right to rectification: You have the right to request that we correct any information you believe is inaccurate.
  • The right to erasure: You have the right to request that we erase your personal data, under certain conditions.
  • The right to restrict processing: You have the right to request that we restrict the processing of your personal data.
  • The right to data portability: You have the right to request that we transfer the data that we have collected to another organization, or directly to you.

6. Security

We take the security of your data seriously. We use industry-standard encryption (SSL/TLS) for data in transit and at rest. However, no method of transmission over the Internet is 100% secure.

7. SudoDocs Capture (Chrome Extension)

This section covers the SudoDocs Capture Chrome extension specifically, in addition to the general terms above, which still apply. Where anything here is more specific than the sections above, this section governs for the extension.

What the extension does

SudoDocs Capture lets you record what you do in a web product - as a click-through walkthrough, a narrated screen recording, or an annotated screenshot - and turns it into a shareable link inside your own SudoDocs organization. Nothing is captured until you explicitly start a recording from the extension's popup, and nothing is captured after you stop it.

What data the extension collects, and where it goes

Everything the extension captures is sent to your own SudoDocs organization (by default app.sudodocs.com, or a different address you set in the extension's Options page if your organization uses a private/self-hosted deployment). SudoDocs Capture does not send any data to any other party, and does not include any third-party analytics, advertising, or tracking code.

Depending on the mode you use, a capture session may include:

  • Screenshots of the tab you're recording, including whatever is visible on the page at the moment you click (Interactive mode) or when you take the screenshot (Screenshot mode). You can optionally drag to select just part of the tab before capturing, in any mode - only the selected area is captured, not the whole tab.
  • Screen recording video, together with tab audio and, if you grant a one-time microphone permission, your own microphone audio too, only while Recording mode is actively running. The microphone is optional - a recording still works with just the tab's own video and audio if you don't grant mic access.
  • Click locations and the page URL of each step, for Interactive mode's step-by-step playback.
  • Text you type into caption fields when editing a capture afterward, and any text you choose to draw onto a Screenshot-mode image with the built-in annotation tool.

Because this is a general-purpose recording tool, whatever is visible on your screen during a capture session - which may include personal data, credentials visible in a UI, payment or health information, or other sensitive content depending on what page you're capturing - is included in what gets uploaded. SudoDocs Capture includes a redaction tool (draw a box over any part of a screenshot to permanently black it out) for exactly this reason; use it before sharing a capture that includes something you don't want visible. Video recordings cannot be redacted after the fact - review what will be in frame before you start recording.

What's stored locally, on your device

  • A revocable API key that authenticates the extension to your SudoDocs organization, stored using Chrome's local extension storage. This key is not visible to, or accessible from, any website you visit.
  • The state of a recording currently in progress (e.g. which tab it's following), cleared automatically when the browser session ends.
  • Your configured SudoDocs instance address (Options page).

None of the above is ever transmitted anywhere except to your own SudoDocs organization as part of an active or just-finished capture.

Permissions the extension requests, and why

  • Tab capture: captures the active tab's video and audio for Recording mode.
  • Scripting: injects a small script into the page you're recording, to detect clicks for Interactive mode and to show the on-page region-selection tool.
  • Tabs: detects which tab is active and follows page navigation, so a recording keeps working correctly when you click a link.
  • Offscreen document: runs the audio/video mixing and encoding work in a hidden document, required by Chrome's extension platform for microphone/tab-audio access outside a visible tab.
  • Storage: stores your SudoDocs connection (API key, instance address) and in-progress recording state, as described above.
  • Alarms: schedules a one-time alarm to automatically stop a Recording-mode capture once it reaches your plan's length limit, so it doesn't run indefinitely.
  • Notifications: shows a one-time system notification if starting a capture fails at a point where the extension's popup is already closed. Never used for anything else.
  • Host permission (all sites): a capture can be started on any site you choose to record - the extension has no fixed list of supported sites, so it requests the ability to run on any page you invoke it on. It does nothing on a page unless you actively start a capture there.

Data retention and deletion

Captured content lives in your SudoDocs organization's storage, governed by your organization's own data retention settings and subject to deletion by anyone with edit access to it, the same as any other file in your organization's account. Disconnecting the extension (Options page → Disconnect) revokes and deletes the locally-stored API key immediately; it does not delete anything already uploaded to your organization.

8. Contact Us

If you have any questions about this Privacy Policy, please contact us by email: admin@sudodocs.com.