Doc Doctor is a Chrome browser extension for mortgage brokers that helps assemble an
application document checklist (Profile and WASH 4) and export it by copy, email, or PDF.
This policy explains what the extension does and does not do with information.
In short: the applicant names and checklist details you enter stay on your
device — they are never uploaded to our servers, sold, or shared. To run and improve the
tool we do send your sign-in details, a small amount of non-identifying usage data, and we
fetch notices from our server, all as described below.
Information we process
Sign-in details. When you sign in, your email address and password are
sent over an encrypted (HTTPS) connection to our server solely to authenticate you.
We do not use them for any other purpose.
Session & local settings. After a successful sign-in, a session
token is stored locally in the browser (chrome.storage.local) so you stay
signed in, along with the IDs of any notices you have dismissed. These are device-local,
the token is removed when you sign out, and neither is shared with third parties.
Usage analytics. To understand how the tool is used, the extension
sends our server a record when a session starts and when you copy, email, or export a
checklist. Each record contains only the type of action, simple counts (number of
applicants and checklist items), a random session identifier, and a one-way,
non-reversible fingerprint of the applicant name(s). It never includes the applicant
names themselves or any checklist content, and the fingerprint cannot be used to
recover a name.
Notices. The extension asks our server for admin-authored notices to
display (for example, product updates). This is a read-only request; the IDs of notices
you dismiss are remembered locally so they do not reappear.
Applicant & checklist data. The applicant names, deal indicators,
and checklist entries you type are held only in the panel's memory to build and export
your checklist. This content is not transmitted to any server and not
persisted — it is cleared when the panel is closed or reset.
What we do not do
We do not upload, store, or share the applicant names or checklist content you enter.
We do not sell or rent any data, and we do not use advertising.
We do not use your data to determine creditworthiness or for lending decisions.
We do not read your browsing history or the content of other websites or tabs.
Exports (copy, email, PDF)
Copy, PDF, and email exports are generated on your device from the information you entered.
When you choose to email or share an export, it goes only to the recipient you select,
through the application you use to send it. We do not receive a copy.
Permissions
Side panel — to show the Doc Doctor tool in the browser side panel.
Storage — to keep your sign-in session token and dismissed-notice IDs on your device.
Access to our backend domain — so the extension can sign you in,
confirm your access is active, sign you out, record the usage analytics described above,
and fetch notices. No other sites are accessed.
Data security & retention
Communication with our server uses HTTPS. Your account record (name, email, and access
status) is retained on our server for as long as your access is active, so administrators
can manage invitations and access. Usage-analytics records (action type, counts, session
identifier, and the one-way fingerprint) are retained to help us understand and improve the
tool. Applicant names and checklist content are never retained because they never leave your
device.
Children
Doc Doctor is a professional tool and is not intended for use by children.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected here with a
new "Last updated" date.