Ce contenu est actuellement disponible en anglais.
Trust & Security
Version 1.0 — Effective 12 August 2026
This page explains, in plain language, how Dr Moot protects the questions you ask and the documents you upload - and exactly who can see them. It only makes claims we can stand behind; where our Privacy Policy is more precise, it governs.
Questions? legal@drmoot.com.
What happens to a document you upload
A deliberation is a structured conversation between several AI models. When you attach a document or ask a question, that content is sent to the model providers holding the panel's seats - in a Moot, that can be three independent labs plus a Chair - solely to produce your answer. This is more provider exposure per question than a single-model chat, and it is deliberate: independent labs checking each other is the product.
Every provider receives your content under commercial API terms that prohibit training on it. Providers may retain API traffic briefly for abuse monitoring under their own policies; they do not use it to train their models.
Encryption and storage
- All traffic to and within the Service is encrypted in transit (TLS).
- Uploaded documents are stored encrypted at rest in private cloud storage. Nothing is ever placed in publicly accessible storage.
- Conversations and deliberation records are stored encrypted at rest in our database.
Access control
- Documents are only reachable through authenticated requests scoped to your account. File downloads use short-lived signed links generated per request - there are no permanent public URLs.
- Organization content is scoped to the organization's members and roles.
Deletion and retention
- Deleting a conversation permanently deletes it - its messages, deliberation steps, and any uploaded documents, including the stored files. This happens when you delete, not on a schedule.
- Deleting your account deletes your content with it.
- Encrypted database backups exist for disaster recovery and expire automatically; they are not used for any other purpose.
Who at Dr Moot can see your content
We do not end-to-end encrypt your content, and no product in this category truthfully can - our systems must read your question to convene a panel on it. What protects you is restriction and policy, not impossibility:
- Our team does not read your content in the normal course of operating the Service.
- Authorized team members may access content only for: support you have asked for, investigating abuse or a security incident, and complying with a legal obligation.
- We will never sell your content or share it beyond the sub-processors listed below.
Training
We do not train AI models on your content. Our model providers are contractually prohibited from training on it too. If that position ever changes, it will be by explicit, opt-in consent — never silently.
Sub-processors
Your content is handled by a small set of named providers, each under data-processing terms - cloud hosting, encrypted document storage, an encrypted database, the AI model providers holding your panel's seats, payments, and transactional email. The full named list, with locations and each provider's role, is on our Sub-processors page, which we update whenever the list changes.
What we don't claim
We believe a trust page should be as notable for what it doesn't say. We do not claim independent security certifications (such as SOC 2) at this time, and we will not describe our security as "military-grade" or "zero-knowledge" - terms which, for a product that must read your content to work, would be marketing rather than fact. As the Service matures, this page will grow with what we can prove.