Legal

Privacy Policy

Last updated: July 6, 2026

How Dckrd handles account, authentication, organization, developer, product, AI-assisted, and enterprise operations data across Dckrd and its subbrands.

1. Overview

This Privacy Policy explains how Dckrd collects, uses, stores, shares, and protects personal data when you use Dckrd accounts, websites, applications, APIs, developer tools, identity services, subbrands, and pre-release product experiences.

Dckrd is currently a pre-launch brand and project. References to Dckrd, we, us, or our mean the Dckrd project and its operator(s), unless a specific legal entity is identified in a signed agreement. Before paid public launch, we expect to publish the legal entity name, registered address, and representative or data protection officer details where required.

2. Scope

This policy covers Dckrd-operated services, including identity and access tools, OAuth and OpenID Connect services, organization workspaces, developer tools, websites, APIs, media, messaging, events, streaming, ingest, search, automation, AI-assisted features, network intelligence, personal productivity, and enterprise evidence or operations products.

A customer organization may separately control content, records, evidence, messages, workpapers, and workflows inside its workspace. Where Dckrd processes that data for the organization, the organization may be the controller and Dckrd may be a processor or service provider.

3. Personal data we collect

We collect personal data you provide directly, personal data generated by your use of the services, personal data provided by organizations or connected applications, and personal data received from service providers or integration partners.

  • Account and profile data such as name, handle, email address, phone number, profile image, language preference, account status, and communication preferences.
  • Authentication and security data such as password state, passkey registration metadata, multi-factor enrollment, recovery progress, session records, device signals, IP address, user agent, audit events, and security logs.
  • Organization and developer data such as memberships, roles, verified domains, OAuth client metadata, redirect URIs, scopes, consents, API keys, application activity, repository or deployment metadata, and administrative actions.
  • Customer content such as records, evidence documents, files, messages, prompts, outputs, financial assumptions, ledger references, legal entity records, tax organizer workpapers, controls, audit trails, and workflow data that you or your organization submit.
  • Support, billing, payment, contract, operational, and communication records when you contact us, buy services, request support, or receive account, security, legal, or administrative notices.
  • Usage, diagnostics, and analytics data such as pages viewed, features used, requests, errors, latency, identifiers, cookie or local storage data, and approximate location inferred from IP address.

4. Sensitive and special category data

Dckrd does not require users to submit sensitive or special category personal data for ordinary account use. Some services, especially evidence, finance, legal, tax, communications, media, or organization workspaces, may allow users to upload documents or records that contain sensitive data.

You and your organization are responsible for having a lawful basis and appropriate permissions before submitting sensitive data, confidential records, third-party personal data, financial data, legal materials, health-related information, biometric data, criminal offense data, or children's data.

Where feasible, redact unnecessary sensitive information before upload and limit access to users who need it.

5. How we use personal data

We use personal data to provide, secure, maintain, improve, and support the services; authenticate users; process consent; administer organizations; operate developer integrations; process support requests; send service notices; detect abuse; troubleshoot issues; comply with law; and protect rights, safety, and service integrity.

  • Contract necessity, including creating accounts, providing services, administering workspaces, processing transactions, and delivering requested features.
  • Legitimate interests, including security, fraud prevention, abuse detection, service improvement, diagnostics, product analytics, customer support, legal defense, and responsible product development.
  • Consent, including optional cookies, marketing communications, and optional features where consent is required. You may withdraw consent where applicable.
  • Legal obligation, including tax, accounting, sanctions, security, law enforcement, regulatory, and compliance obligations.

6. AI-assisted processing

Some features may use models or AI service providers to classify, search, summarize, extract, draft, route, or prepare actions from content you submit. Inputs and outputs may contain personal data if you include it.

We use AI processing to provide the requested feature, operate and secure the service, and improve product quality where permitted by your settings, contract, and applicable law. Enterprise agreements may restrict model providers, retention, or training uses.

Do not submit personal data, confidential records, trade secrets, or regulated data to AI-assisted features unless you have authority to do so and the feature is appropriate for that data.

7. Cookies and similar technologies

We use essential cookies and similar technologies for sign-in, session security, fraud prevention, consent preferences, load balancing, and basic service operation.

We may use optional analytics or product measurement cookies only where permitted by law and, where required, with your consent.

8. Sharing and disclosure

We share personal data when needed to operate the services, when you direct us to do so, when an organization manages your access, when a connected application receives data you authorize, or when needed for security, compliance, legal process, or protection of rights.

  • Service providers and subprocessors such as hosting, database, security, email, support, analytics, payment, storage, model, and infrastructure providers.
  • Organizations and administrators that manage accounts, domains, workspaces, evidence repositories, applications, roles, policies, billing, or audit logs.
  • Connected applications, APIs, identity providers, and integration partners when you or your organization authorize the connection.
  • Professional advisers, auditors, insurers, authorities, courts, law enforcement, or regulators where needed for compliance, legal process, security, or rights protection.
  • Successors or transaction participants if Dckrd forms a legal entity, restructures, raises financing, sells assets, merges, or transfers part of the business, subject to appropriate confidentiality and data protection measures.

9. No sale of personal data

We do not sell personal data. We do not disclose OAuth, account, workspace, or customer content to connected applications unless the user, organization, or applicable configuration authorizes that disclosure.

10. International transfers

Dckrd services, providers, and users may be located in different countries. Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we will use appropriate safeguards where required, such as standard contractual clauses, approved transfer mechanisms, supplementary measures, or certified frameworks when available.

Before paid enterprise launch, Dckrd should publish or provide an appropriate subprocessor and transfer posture for customer review where required.

11. Retention

We keep personal data for as long as needed to provide the services, maintain security records, satisfy legal obligations, resolve disputes, enforce agreements, support audits, preserve organization integrity, and restore backups.

Retention periods vary by data type. Session and diagnostic data may be shorter lived; account, billing, security, audit, evidence, and organization records may be kept longer where needed by the service, customer instructions, law, or legitimate security and compliance needs.

12. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing of personal data, and to withdraw consent where processing is based on consent.

People in the European Economic Area, United Kingdom, and Switzerland may also have the right to lodge a complaint with a supervisory authority. You can manage some account settings directly in Dckrd account surfaces or contact privacy@dckrd.com.

For organization-controlled workspaces, we may need to refer requests to the organization that controls the relevant account, domain, content, application, or membership.

13. Security

We use technical and organizational safeguards designed to protect personal data, including access controls, authentication controls, encryption where appropriate, logging, monitoring, backup practices, and security review. No system is perfectly secure, so users and administrators should keep credentials, factors, devices, API tokens, and client secrets protected.

14. Children

Dckrd services are not directed to children under the age required by applicable law. If we learn that a child provided personal data without appropriate authorization, we will take steps to delete it where required.

15. Changes

We may update this policy as services, laws, or operational practices change. The updated date above shows when the policy was last revised. Material changes will be communicated where required by law or contract.

16. Contact

Privacy questions and requests can be sent to privacy@dckrd.com. Legal notices can be sent to legal@dckrd.com. Security reports can be sent to security@dckrd.com.