Skip To Content
Legal

Privacy Policy

What personal data Docket collects, why we collect it, where it is processed, and what control you have over it.

In Plain Terms

The Short Version

A summary of what matters most, in ordinary language. It is a guide to the document below, not a replacement for it — where the two differ, the full text governs.

We do not sell your data

And we do not use your content to train third-party AI models. Your material is processed to run the service for you and nothing else.

Credentials are encrypted and never sent to the browser

WordPress application passwords and Google OAuth tokens are encrypted at rest with AES-256-GCM and decrypted only server-side, at the moment they are used.

Google access is read-only

We request read-only Search Console and Analytics scopes and cannot change anything in your Google properties. Disconnecting revokes the token and deletes our copy.

You can delete it

Deleting a website removes its articles, connections, analytics records and audit entries. Deleting your account removes everything linked to it.

Pending legal review. This document describes how the product actually works, but it has not yet been reviewed by a qualified lawyer and the bracketed fields below still need completing. Do not rely on it as final terms.

01

Who We Are

Docket is a content intelligence and publishing platform operated by Docket Ltd., registered at [Registered address]. In this policy “Docket”, “we” and “us” refer to that entity, and “you” refers to the account holder.

For the content you create in Docket you are the data controller and we act as your processor. For your own account and billing data, we are the controller.

02

What We Collect

Account information

Your email address, and your name if you provide one or if it is returned by Google when you sign in with a Google account. Passwords are handled by our authentication provider and stored only as salted hashes. We never see or store your password in readable form.

Content profile information

Everything recorded about a business you produce content for: name, website address, industry, description, brand voice and tone rules, audience and persona notes, SEO targets, visual preferences, competitor names and publishing settings. Some fields are populated automatically by reading your public website; all of them are editable by you.

Connection credentials

If you connect a WordPress site we store its address, the username and the application password you generate. That password is encrypted at rest with AES-256-GCM and is never returned to the browser. It is decrypted only server-side, at the moment we publish on your behalf. Use an application password rather than your account password so you can revoke our access independently.

If you connect a Google account for Search Console or Analytics we store the resulting OAuth tokens, also encrypted at rest with AES-256-GCM and never exposed to the browser. We request read-only scopes and cannot change anything in your Google properties. Disconnecting revokes the token with Google and deletes our copy.

Content and analytics data

Articles, metadata and generated images we produce for you; the search and engagement metrics we retrieve from any Search Console or Analytics property you link; and an audit log of actions taken in your account, such as when a website was analysed, an article generated, or a post published.

03

How We Use It

  • To operate your account and keep each website separate from other customers’.
  • To generate content. Your profile information is sent to an AI model as context so output matches your business and voice.
  • To publish to the destination you connect, and to record what was published and where.
  • To report on performance, and to surface which published pages have the most to gain from being improved.
  • To diagnose faults, secure the service and respond when you contact support.

We do not sell your personal data, and we do not use your content to train third-party AI models.

04

Who Processes It

We use a small number of providers to run the service. Each receives only the data it needs:

  • Supabase — authentication, database and file storage. Holds your account, websites, articles, encrypted credentials and generated images.
  • Lovable — hosting, and the gateway through which our AI requests are made.
  • Google — the Gemini models that generate text and images, reached through that gateway. Separately, the Search Console and Analytics APIs when you choose to connect them.
  • Your WordPress site — the destination you nominate. Content you approve is sent there, at which point it is governed by your own site’s policies.

Generated images are currently referenced by your published posts as time-limited links to our storage. If you need published media hosted entirely on your own site, contact us.

05

Content Read From Websites

When you give us a website address we fetch its publicly available pages to infer your business, brand and audience. We treat that content strictly as data, never as instructions, and store only what is needed to produce your profile. Only supply addresses you are entitled to have analysed.

06

Retention

We keep your data for as long as your account is active. Deleting a website removes its articles, connections, analytics records and audit entries. Deleting your account removes your account record and everything linked to it. Backups may persist for up to [retention window] after deletion before being overwritten.

07

Your Rights

Depending on where you live you may have the right to access, correct, export or delete your personal data, to object to certain processing, or to withdraw consent. You can edit profile data and disconnect integrations yourself at any time inside the product; for anything else, write to us and we will respond within the period the applicable law requires. If you are unhappy with our response you may complain to your local data protection authority.

08

Security

Access to your data is enforced at the database level by row-level security, so one account cannot read another’s. Third-party credentials are encrypted at rest and only ever decrypted server-side. No system is perfectly secure, but if a breach affects your personal data we will notify you and any relevant regulator as the law requires.

09

Children

Docket is a business product and is not intended for anyone under 16. We do not knowingly collect data from children.

10

Changes

We will update this page when our practices change and revise the date shown alongside the contents. If a change materially affects you we will tell you directly rather than relying on this page alone.

11

Contact

Questions, requests or complaints: support@docket.app, or write to [Registered address].

Questions about this document? support@docket.app