Privacy Policy

Last updated: August 22, 2026

This Privacy Policy explains how [OPERATOR LEGAL NAME], operating as Doquery (“Doquery”, “we”, “us”), collects, uses, shares, and protects information when you use our websites, applications, APIs, and related services (the “Service”). We act as the data controller for the personal data described here.

1. Data We Collect

Account information. Email address, name (and optional preferred name), hashed password, plan and billing status, and settings you configure.

Your content. Documents, notes, web pages, media, and other files you upload or sync (including via the Obsidian plugin), plus data we derive from them to power the Service: extracted text, chunks, vector embeddings, search indexes, summaries, generated audio, and knowledge-graph entries.

Chat and query content. The questions you ask, conversations you have with the AI (including via the API and MCP server), and the answers generated, so you can revisit your history and so the Service can maintain context and optional memory features you control.

Usage and billing records. Metered usage (queries, tokens, documents, TTS time, API/MCP calls), plan limits, timestamps, response times, and event logs (such as logins and document actions) kept for security auditing. Payment card details are collected and stored by Stripe, not by us.

Technical data. IP address, browser/device information, and approximate region derived from requests, used for security, rate limiting, and debugging. On the marketing site we also collect analytics events (see Section 7).

2. How We Use Data

  • to provide the Service: indexing your content, answering your queries, generating audio, and syncing your integrations;
  • to operate accounts, subscriptions, metering, and billing;
  • to secure the Service: authentication, abuse and fraud prevention, rate limiting, and audit logging;
  • to support you and respond to requests;
  • to understand aggregate product usage and improve the Service;
  • to comply with legal obligations.

We do not sell your personal data, and we do not use your uploaded content or conversations to train our own or third-party foundation models.

Where GDPR applies, our legal bases are: performance of a contract (providing the Service you signed up for), legitimate interests (security, abuse prevention, product improvement), consent (where required, e.g. marketing-site analytics), and legal obligation (tax and accounting records).

3. Subprocessors and Sharing

We share data only with service providers (subprocessors) that help us run the Service, under contracts restricting their use of the data, and in the limited other cases below. Our current subprocessors:

ProviderPurposeLocation
AnthropicAI language models (chat, answers, summarization)United States
OpenAIAI language models and embeddingsUnited States
StripePayment processing and subscription billingUnited States
ElevenLabsText-to-speech audio generationUnited States
CloudflareHosting, content delivery, and storageGlobal (US-based)
Fly.ioApplication hostingUnited States
SupabaseManaged database hostingUnited States
Redis Cloud (Redis Ltd.)Caching, queues, and rate limitingUnited States
Google (Google Analytics)Website analytics on the marketing siteUnited States

Content you query is sent to the AI providers (Anthropic, OpenAI) only as needed to answer your requests, and text you convert to audio is sent to ElevenLabs. If you bring your own API key (BYOK), requests using it are sent to that provider under your own agreement with them.

We may also disclose data if required by law or legal process, to protect the rights, safety, or property of users or the public, or as part of a merger, acquisition, or asset sale (in which case this policy continues to apply to the transferred data).

4. International Transfers

Our subprocessors are primarily located in the United States. Where data of EU/UK/Swiss users is transferred internationally, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework certifications of our providers.

5. Security

We protect data with measures including encryption in transit (TLS), password hashing, encrypted storage of user API keys, scoped API keys with rate limits, audit logging, and access controls. No system is perfectly secure; if we learn of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.

6. Data Retention

We keep your account data and content for as long as your account is active. When you delete a document, its file, chunks, and embeddings are deleted from the live systems. When you delete your account (Section 8), your account record, documents, conversations, and derived data are deleted from the live systems promptly.

Residual copies may persist in encrypted backups for up to 30 days before being overwritten. We retain minimal audit and usage logs (not document content) for up to 90 days for security and abuse prevention, and billing records for as long as tax and accounting law requires.

7. Cookies and Analytics

The app (app.doquery.ai) uses only essential storage: authentication tokens and preferences needed for the Service to function. It does not use third-party advertising or analytics cookies.

This marketing site (doquery.ai) uses Google Analytics to understand how visitors find and use the site; Google Analytics sets cookies and receives your IP address and page-view events. The site also records anonymous first-party funnel events (page views, clicks, sign-up-form interactions) tied to a random identifier stored in your browser's local storage — this identifier is not linked to your app account. You can block these cookies with your browser settings or a content blocker without affecting the app.

8. Your Rights and Controls

You can exercise the following at any time:

  • Access and correction — view and edit your profile and content in-app.
  • Deletion — delete individual documents and conversations in-app, or delete your entire account from the settings page (Danger Zone), which removes your account, content, and derived data as described in Section 6 and cancels any active subscription.
  • Export — request a copy of your data by emailing support@doquery.ai; we will provide it in a common machine-readable format.
  • Objection and restriction — contact us to object to or restrict specific processing.

9. GDPR (EU/UK/Swiss Users)

If you are in the EU, UK, or Switzerland, you have the rights of access, rectification, erasure, restriction, data portability, and objection under the GDPR (and equivalent laws), plus the right to withdraw consent at any time where processing is based on consent. We respond to verified requests within one month. You also have the right to lodge a complaint with your local supervisory authority, though we would appreciate the chance to address your concern first.

10. CCPA (California Residents)

If you are a California resident, you have the right to know what personal information we collect (Section 1), to access and delete it, to correct it, and to not be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined in the CCPA/CPRA, and we do not use sensitive personal information other than to provide the Service. You may exercise your rights in-app or via the contact in Section 12, including through an authorized agent.

11. Children

The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.

12. Changes and Contact

We may update this policy from time to time; material changes will be announced by email or in-app notice before they take effect, and the “Last updated” date above always reflects the current version.

Privacy questions and requests: support@doquery.ai.