Documents

Security and data

Where the files live, who can reach them, how often we back them up, and what we don't promise. No certifications we don't hold.

Last updated: September 22, 2026

01

Where the data lives

The application, the database and the PDF files run on a single server in a DigitalOcean data centre in Frankfurt am Main, Germany — inside the European Economic Area.

Source files, page previews and the database sit on a block volume attached to that server. We do not use external object storage.

Backups leave that data centre: they go to a machine in Poznań, Poland, over an encrypted WireGuard link. That is the only place outside Frankfurt where your files are kept.

02

Who has access

One person has access to the server — the owner of the service, over an SSH key only. Password login is disabled.

We do not read the contents of documents as part of routine work. Access to a client's files happens only while diagnosing a reported fault, and only as far as finding it requires.

The key the server uses to send backups is restricted on the receiving machine to a handful of copy commands. Stolen from the server, it does not give a shell.

03

Encryption

Traffic between the browser and the service runs over HTTPS only. The certificate renews automatically.

Passwords are stored as bcrypt hashes with twelve rounds. We have no technical way to read your password.

Session cookies are encrypted and marked `httpOnly` and `secure`, so no script on the page can read them.

Backup transport is encrypted by WireGuard.

What we don't do: we do not add a second layer of encryption to PDF files inside the application. They sit on the provider's disk, protected by access control on the server rather than by a separate key.

04

Backups and restores

A database dump and a mirror of the files go out every night. We keep thirty daily database copies.

Once a week a script restores a fresh dump into a separate, temporary database and checks that accounts and documents are actually there. A backup nobody has restored is only a hope.

A failed backup sends an alert to the owner of the service. Silence is not treated as success.

Recovery from the loss of the whole server is measured in hours, not minutes: a new server has to be provisioned and the image, database and files restored. We do not run a standby environment that takes over traffic by itself.

05

Subprocessors

The companies that process data in connection with running the service. Changes to this list are published on this page together with the date.

  • DigitalOcean, LLC — server, disk and network. Region: Frankfurt, Germany. Scope: everything the application writes, including PDF files and the database.
  • Stripe Payments Europe, Ltd. and Stripe, Inc. — payments under Managed Payments, where Stripe is the merchant of record. Scope: email address, billing details and transaction history. We never see card data.
  • Resend (Plus Five Five, Inc.) — transactional email: address confirmation, password reset, comment digests. Scope: recipient email address and message content. Servers in the United States.
  • Telegram Messenger Inc. — technical alert channel for the owner of the service. Scope: failure notifications, no client data.

Two subprocessors operate outside the European Economic Area (Stripe, Inc. and Resend). Those transfers rely on the European Commission's standard contractual clauses.

06

How long we keep files

A document is deleted one hundred and eighty days after the last activity on paid plans, and thirty days on the free plan. The PDFs, page previews and comments go with it.

Fourteen days before deletion we send a warning by email. A document that has not been warned is not deleted.

Deleting an account removes documents, files, comments and links immediately. Backups from earlier days expire on their own cycle — after thirty days at the latest.

07

Reporting a vulnerability

If you found a hole, write to app@rounds.page. We reply on business days.

One request: do not test on other people's documents and do not pull data that isn't yours. Your own account and your own file are enough to check almost everything.

We run no bounty programme. We thank you for the report and tell you when it is fixed.

08

What we don't have

This section exists so the previous seven can be read without suspicion.

  • No ISO 27001 certificate and no SOC 2 report, and none planned this year.
  • No secondary data centre. A server failure means downtime until the restore completes.
  • No round-the-clock on-call. Alerts go to one person.
  • No two-factor login for the author's panel. It is on the list.
  • No separate application-level encryption key for PDF files.

If your client requires any of these, say so before signing — we'll answer honestly whether and when we can meet it.