Legal
Privacy
Last updated: July 13, 2026
This policy explains what personal data Dokeo processes, why, and the choices and rights you have. It applies to dokeo.co, app.dokeo.co, and the Dokeo API. Dokeo is the data controller for account data and the data processor for content you submit on behalf of your organization.
1. What we collect
- Content you submit (text or a URL) so we can score, generate, or route it for review.
- Scan results (score, verdict, and the checks that ran) stored in your tenant's audit log.
- Account data: your email, a hashed password, and optional phone; plan and credit balance.
- Operational data: API keys, request metadata, and rate-limit counters needed to run and secure the Service.
2. What we do not collect
- We do not store the content you scan beyond what your audit log needs.
- We do not sell scan data, account data, or anything else.
- We do not run tracking pixels, ad networks, or third-party analytics on your pages.
- We do not train any AI model on your content.
3. Legal basis for processing (GDPR)
Where GDPR applies, we process personal data on these bases: to perform our contract with you (providing the Service, billing); our legitimate interests (securing and improving the Service, preventing abuse); your consent (optional features such as AI rewrites); and to meet legal obligations.
4. Account data and auth
Account data (your email and a bcrypt-hashed password) is stored on our own infrastructure (Fly.io). We do not use a third-party authentication provider. Billing is handled by our payment processors, Stripe and Razorpay; we never see or store your card or UPI details.
5. AI rewrites (opt-in)
Scoring runs entirely on our servers and never sends your content to a third-party AI. If you opt into an AI rewrite, that specific content is sent to our subprocessor Zhipu AI (GLM 5.2, via the z.ai API) to generate the rewrite. Under the z.ai API terms, it is not used to train their models. Rewrites are opt-in per action.
6. Subprocessors
We use these subprocessors to run the Service:
- Fly.io - application hosting and data storage (US).
- Vercel - marketing site and app front end.
- Zhipu AI (z.ai) - AI rewrites only, on content you opt in.
- Stripe and Razorpay - payment processing.
We will give notice of new subprocessors to customers under a DPA before they process your data.
7. Cookies
We use a single first-party session cookie to keep you signed in. No third-party tracking cookies, no retargeting. Optional analytics, if ever enabled, are strictly opt-in.
8. Data location and international transfers
The Service runs on Fly.io in the US region today. EU / regional data residency is planned but not yet live, and we will not claim it until it ships. If you access the Service from outside the US, your data is transferred to and processed in the US; where required, such transfers rely on appropriate safeguards (e.g. Standard Contractual Clauses) available under our DPA.
9. Data retention
We keep account data for as long as your account is active. Scan/audit-log entries are retained for your tenant until you delete them or close your account. On deletion we remove your data from production within 30 days, excluding data we must keep for legal or accounting reasons.
10. Security
Traffic runs over TLS. Data at rest lives on an encrypted volume. API requests use HMAC-protected per-tenant keys; session cookies are HttpOnly, Secure, and SameSite=Lax; user-supplied URLs are SSRF-guarded before we fetch them. We have not completed a SOC 2 audit and do not claim one. See our Security page for the current, honest details.
11. Your rights
Depending on where you live (GDPR, UK GDPR, CCPA/CPRA and similar), you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. We do not sell personal data. To exercise a right, email privacy@dokeo.co; we action verified requests within 30 days.
12. Data Processing Addendum (DPA)
For customers who need one, we offer a Data Processing Addendum covering our processing of personal data on your behalf, subprocessors, and international transfer safeguards. Request it at legal@dokeo.co.
13. Children
Dokeo is a business tool and is not directed to children under 16. We do not knowingly collect their data.
14. Changes to this policy
We will post the updated policy here with a new date and, for material changes, give at least 14 days' notice. The date at the top always reflects the current version.
15. Contact
Questions or a privacy request? Get in touch or email privacy@dokeo.co.