Security
How your writing is protected.
In plain words, checked against what the product actually does rather than written to sound reassuring.
Your documents
A document is private by default. Only you, and anyone you have specifically shared it with, can open it. That rule is enforced in the database itself, not only in the app, so a page cannot be opened by somebody guessing its address: the database is asked to check who is asking before it hands back a single row.
Everything travels between your browser and Docmode over an encrypted connection, and your content is encrypted at rest in the database. Docmode's own server can still read it, because features like AI writing help need the actual words to work on. That is a deliberate choice, not an oversight, and it is why Docmode does not claim to be end to end encrypted: claiming that while a feature needs plaintext to function would be false, so we say plainly instead what is true. Docmode reads a document only to run a feature you asked for, or when investigating abuse.
Signing in
Two factor sign in is available on every plan, with single use backup codes for when you do not have your authenticator to hand. You get an email alert the moment a new device signs in, or if two factor is turned off, and a list of every signed in session that you can end from anywhere, at any time.
Publishing and sites
Publishing a document, or a whole folder as a site, gives it a public web address on purpose: that is what publishing means. Anyone with the address can read it, and search engines can find and index it unless you have switched on a password, which keeps a page out of search results.
Site passwords
A site password is turned into a scrambled fingerprint before it is stored, with a unique random ingredient mixed in for that one site. The password itself is never stored anywhere, and that fingerprint cannot be turned back into the original: not by us, not by anybody who got hold of the database. If you forget it, it can only be replaced, never recovered.
A locked page is never sent to a reader's browser until the password they typed is correct. It is not delivered and hidden with styling, so there is nothing in the page for anybody to find by looking at what their browser received. Changing or removing a site's password immediately signs out everyone who was using the old one, on every device, so being able to change it means what it should.
AI features
When you use an AI feature, the relevant text is sent to Anthropic to produce the result, and nothing is sent unless you trigger an action yourself. We do not use anything you write to train AI models.
Plans
Nothing is ever deleted for falling outside a plan's limits. A version of a document past the free plan's window, or a site password set while on a paid plan, stays exactly where it is and keeps working; moving back up brings it back into view rather than restoring it from somewhere else.
What this does not cover
A published page, locked or not, is public in the sense that matters: it is meant to be read by people who are not signed in. A site password is a gate, not encryption. Anyone who knows the password, or who was ever shown a page while it was unlocked, can keep and share what they saw, the same as they could with any web page. If you need real confidentiality, a published site is the wrong tool for it, whatever password is on it.
We do not claim any certification, audit, or security standard we have not actually been through, and we will not describe anything here as unbreakable. If something on this page ever stops being true, we would rather you hear it from us than find out the hard way.
Questions about any of this? Get in touch.