LikhaDocs LogoLikhaDocs
Back to LikhaDocs
Legal document

Privacy Policy

This Policy explains what personal information LikhaDocs processes, why it is needed, who may receive it, how long it is kept, and how you can exercise your rights.

Effective July 31, 2026Last updated July 31, 2026
On this page

1. Who is responsible for your information

The personal information controller for LikhaDocs is John Paul Naag, the individual operator of the service. LikhaDocs is currently operated from Trece Martires City, Cavite, Philippines and is not yet registered as a separate business entity.

Privacy questions and requests may be sent to kuyajp123@gmail.com or discussed through the mobile number listed in the Contact section. Email is the preferred channel because it provides a written record and supports identity verification.

2. Scope of this Policy

This Policy applies to the LikhaDocs website, authenticated account areas, Narrative Report Builder, Weekly Report Workspace, billing pages, support communications, and related application features. It does not control independent websites or services that you visit outside LikhaDocs.

3. Information we process

Account information

Name, email address, Supabase account identifier, password-authentication status, connected Google identity, account dates, and authentication records managed by Supabase.

Profile information

Display name and optional profile image. Profile images may be stored in a public avatar bucket so they can be displayed in account and shared-workspace interfaces.

Narrative reports

Report title, student and group-member details, course and campus information, supervisor information, OJT dates and schedule, company and department details, report sections, weekly journals, references, generated content, and report status.

Files and images

Word templates, reference reports, PDFs, figures, appendix images, filenames, file size, file type, dimensions, verification results, and storage paths.

Weekly-report workspace

Folder names, descriptions, week numbers, date ranges, narratives, source information, imported JSON content, and accepted copies.

Sharing information

Sender and recipient account identifiers, recipient email, source-folder name, transfer payload, optional message, transfer status, notifications, and response dates.

Billing information

Product selected, order identifier, price and currency, payment and checkout status, provider identifiers, entitlement dates, AI-credit grants, attempts, export reservations, and payment history. LikhaDocs does not ask for your banking password, QRPh wallet PIN, or MPIN.

Usage and security

Feature usage, AI credits and attempts, export counts, upload quota records, rate-limit events, blocked requests, parser failures, and privacy-preserving hashed identifiers used for security investigations.

Browser-local information

Unsigned weekly-report workspaces, legacy or hidden presentation drafts, theme preferences, and temporary interface state stored in your browser where applicable.

Support information

Emails, screenshots, attachments, transaction references, report identifiers, and other information you send when asking for help, making a complaint, or exercising a privacy right.

4. How information is collected

  • Directly from forms, report fields, uploads, settings, and support communications.
  • From Google when you choose Google authentication, subject to Google’s own notices and permissions.
  • From PayMongo when a checkout is created, paid, expired, cancelled, or reconciled.
  • From another user when they send you a weekly-report folder or include you in shared content.
  • From public webpages or documents you specifically provide or ask LikhaDocs to research.
  • Automatically through authentication cookies, server logs, abuse controls, file verification, and usage accounting.

5. Purposes and lawful bases

LikhaDocs processes information for the following purposes:

Provide the service

To create and authenticate accounts, save reports, prepare Word documents, manage weekly entries, and perform requested sharing. This is generally necessary to perform the service requested by the user.

AI assistance

To generate or improve requested report content, research selected sources, and account for AI credits and attempts. AI processing is initiated by the user and is necessary to provide the selected Premium feature.

Payments

To create checkout sessions, confirm payment, activate paid access, display payment history, investigate duplicate or missing access, prevent fraud, and meet accounting or legal obligations.

Security and integrity

To validate uploads, prevent malicious requests, enforce limits, investigate abuse, protect accounts, and keep the service reliable. This is based on the legitimate interests of users and the operator, and on legal duties where applicable.

Communication and support

To send verification and password-reset emails, provide account or billing assistance, respond to complaints, and process privacy requests.

Legal compliance

To respond to lawful requests, preserve evidence, resolve disputes, and comply with tax, accounting, consumer, privacy, and other applicable obligations.

LikhaDocs does not currently use personal information for behavioural advertising, sell personal information, or make legal, employment, admission, credit, or similarly significant decisions solely through automated processing.

6. AI processing

When you request a Premium AI feature, relevant report information may be sent to Google’s Gemini service through the server. Depending on the feature, this may include typed report details, weekly narratives, extracted text from an uploaded reference document or PDF, selected website content, requested section names, and instructions needed to produce the output.

LikhaDocs stores AI output in the report when needed to display, review, prepare, or download it. AI output may be inaccurate and must be reviewed by the user. Avoid providing unnecessary sensitive, confidential, privileged, or restricted information. Use of Gemini is also subject to Google’s applicable service and privacy terms.

The Gemini API key is kept on the server and is not sent to the browser. LikhaDocs does not use AI output as the sole basis for a decision that significantly affects a person’s rights or opportunities.

7. Uploaded files and images

Supported uploads first pass through a private quarantine and verification process. LikhaDocs may record the original filename, declared and verified type, size, dimensions, cryptographic hash, verification status, and failure reason. Unverified browser uploads cannot be written directly to final report storage.

Abandoned pending quarantine uploads are currently targeted for cleanup after approximately one hour. Failed upload records and remaining quarantine objects are targeted for cleanup after approximately 24 hours. Finalised report files remain until the related report or file is deleted, a verified deletion request is fulfilled, or another retention need applies.

Profile avatars are intended for display and may be publicly retrievable through their storage URL. Narrative report documents, reference materials, templates, and report images are intended to remain access-controlled.

8. Sharing and service providers

Personal information may be disclosed to the following recipients when necessary:

  • Users you select: a weekly-report recipient receives the shared payload and, after acceptance, owns a separate editable copy.
  • Supabase: authentication, database, storage, realtime notifications, and related infrastructure.
  • Vercel: application hosting, delivery, and server execution.
  • Google Gemini: requested AI generation and source-assisted writing.
  • PayMongo: QRPh checkout, payment processing, payment status, and dispute investigation.
  • Gmail and Nodemailer-based email delivery: verification, password recovery, transactional communication, and support-related email.
  • Authorised administrators and support personnel: limited access where necessary to investigate support, security, payment, or legal issues.
  • Authorities or professional advisers: when required by law or reasonably necessary to protect rights, users, or the service.

LikhaDocs does not sell report content or personal information to advertisers. Providers process information under their own contracts and privacy obligations.

9. International processing

Cloud, payment, email, hosting, and AI providers may process or store information in countries outside the Philippines. Their infrastructure locations may change. LikhaDocs uses established providers and limits disclosure to information reasonably needed for the requested service, security, payment, or legal purpose.

10. Cookies and browser storage

LikhaDocs uses essential authentication cookies to keep users signed in and temporary security cookies for flows such as password recovery and legal acceptance. These cookies are needed for account and security functions.

The Weekly Report Workspace can store unsigned user work in local storage before sign-in. Theme preferences, temporary interface state, and legacy or hidden presentation drafts may also be stored locally. Browser-local information stays on that browser unless you sign in and use a feature that synchronises or uploads it. Clearing browser data can permanently remove local-only work.

LikhaDocs does not currently use advertising cookies or a dedicated behavioural-analytics SDK. If non-essential analytics or advertising technologies are introduced, this Policy and any required consent controls will be updated before use.

11. Retention

Account and profile

Kept while the account remains active, until a verified deletion request is fulfilled, or longer where needed for a lawful obligation, dispute, fraud prevention, or security purpose. Self-service account deletion is not currently available.

Narrative reports

Kept until the user deletes the report, a verified deletion request is fulfilled, the account is closed, or a lawful exception requires limited retention.

Weekly folders and entries

Kept until manually deleted by the user or removed through a verified account or privacy request. They are not deleted by the temporary-system cleanup job.

Notifications and transfers

Read notifications are currently deleted after 30 days; unread notifications after 90 days. Pending transfers expire after 30 days. Accepted, rejected, cancelled, and expired transfer records are targeted for deletion after 90 days. An accepted copied folder remains until its owner deletes it.

Temporary uploads

Abandoned pending uploads are targeted for cleanup after about one hour. Failed upload records are targeted for cleanup after about 24 hours.

Billing and AI accounting

Kept for as long as reasonably necessary to administer access, credits, payment disputes, fraud prevention, accounting, tax, and legal obligations. A fixed public deletion period is not currently configured.

Security events

Security event records are currently retained without an automatic deletion period. This retention practice is under review. The records use hashes and bounded metadata rather than raw email addresses, user identifiers, or IP addresses where the security-event system is used as designed.

Support communications

Kept for as long as reasonably necessary to resolve the request, maintain a support history, handle disputes, and meet legal obligations.

Backups

Deleted information may remain temporarily in provider backups until ordinary backup rotation or secure deletion processes complete.

12. Security

LikhaDocs uses safeguards including authentication, Supabase Row Level Security, server-only privileged keys, access-controlled storage, upload quarantine and verification, origin checking, rate limiting, Content Security Policy controls, encryption for sensitive administrator settings, and privacy-preserving security-event hashing.

No system can guarantee absolute security. Users should protect their login methods, avoid uploading information that is not needed, keep independent copies of important documents, and promptly report suspected unauthorised access.

13. Your privacy rights

Subject to applicable law and appropriate verification, you may request information about processing, access to personal information, correction, objection, erasure or blocking, portability, and assistance with a privacy complaint. Rights may have lawful limitations, including when information must be retained for a transaction, investigation, legal obligation, or the rights of another person.

LikhaDocs does not yet provide a complete self-service privacy dashboard. Requests are handled manually by email. Visit the privacy request page or email kuyajp123@gmail.com. Reasonable identity verification may be required before information is disclosed, corrected, exported, or deleted.

You may also file a complaint with the National Privacy Commission if you believe your privacy rights have been violated.

14. Children and minors

LikhaDocs is intended mainly for college students but can be used for academic purposes by younger users. A user below 18 must have permission and supervision from a parent or legal guardian. Paid purchases by a minor must be authorised by a parent or legal guardian.

LikhaDocs does not knowingly ask children to provide more information than is needed for the selected academic function and does not currently collect age or date of birth. A parent or guardian may contact the privacy email to ask about, correct, or request deletion of a minor’s information, subject to verification.

15. Data incidents

LikhaDocs investigates suspected security incidents and takes steps to contain, correct, and document them. Where notification is required, affected users and the appropriate authority will be notified in accordance with applicable law and available contact information.

16. Changes to this Policy

This Policy may be updated when features, providers, retention practices, legal requirements, or processing activities change. The page will show the current version and effective date. Material changes will be communicated at the next practical opportunity. Previous versions will be retained internally and may be provided on request.

17. Contact and complaints

Privacy contact and service operator

John Paul Naag

LikhaDocs

Operating location: Trece Martires City, Cavite, Philippines

Email: kuyajp123@gmail.com

Mobile: +63 953 177 1034

LikhaDocs aims to review ordinary support, billing, and privacy complaints within 7 calendar days after receiving enough information to investigate.