Skip to content
Legal

Privacy policy for the Dory app

This policy applies to the use of Dory in the app. It informs you under Art. 13 GDPR.

Last updated: 27 August 2026

This privacy policy informs you under Art. 13 GDPR which personal data we (DoryAI) process when you use Dory. It supplements the terms of use (EULA). The contract with your organisation and the data processing agreement are set out in the terms and their Annex 1.

1. Who is responsible for what?#

When you use Dory there are two data protection roles you should know about:

  • Your organisation is the controller for the content you enter and process in Dory. That includes your inputs (prompts), uploaded files, generated answers and all data Dory retrieves from connected third-party systems (for example HubSpot, Gmail, Calendar). If you want to exercise a right of access, erasure or objection regarding that data, contact your organisation.
  • The provider of Dory (Georg Ortner, trading as DoryAI, below “we” or “us”) is the controller only for the data we need in order to run Dory technically. That is account data, login activity, pseudonymised usage data and server logs. This policy applies to that data.

2. Controller and contact#

Georg Ortner (sole trader, trading as DoryAI)
Rigaer Straße 47A
10247 Berlin
VAT ID: DE405789769

Email: support@dory-ai.com

3. Which data we process as controller#

3.1 Account and login data#

  • What: name, email address, encrypted password or session token, time of the last login.
  • Purpose: authentication and access control.
  • Legal basis: Art. 6 (1) (b) GDPR (performance of the user relationship), Art. 6 (1) (f) GDPR (legitimate interest in secure authentication).
  • Retention: as long as your organisation’s account exists. When a subscription ends, the account stays readable; there is no retention period and no automatic deletion job. Data is deleted only on your organisation’s explicit request, and then within one month (§ 9.3 of the terms and Annex 1 A1.8).

3.2 Usage data of the app (product analytics)#

  • What: views of areas of the app, features used, response times and error messages, and technical details about the device.
  • How: the measurement runs without cookies and without recognition across sessions. Our analytics tool PostHog stores the identifier only in the browser’s memory (persistence: 'memory'); once the tab is closed it is gone. Nothing is stored on your device, which is why we do not ask for consent for it either.
  • What does not happen: no automatic capture of every click, no session recording, no heatmaps and no connection to the measurement on the website dory-ai.com. The two domains are measured separately and are not merged.
  • Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in troubleshooting, stability and product improvement). You can object to this processing under Art. 21 GDPR.
  • Retention: 12 months.

Important: we evaluate this data only in aggregate. There is no monitoring or assessment of the performance or behaviour of individual people.

3.3 Server logs#

  • What: IP address (truncated), timestamp, endpoint called, HTTP status.
  • Purpose: security, abuse detection, error analysis.
  • Legal basis: Art. 6 (1) (f) GDPR.
  • Retention: 30 days, then automatic deletion.

3.4 Payment data#

If your organisation takes out a subscription or buys credits, we and our payment provider Stripe Payments Europe, Ltd. process the data needed for that.

  • What: name and email address of the ordering person, billing address, VAT identification number, means of payment, invoices and payment receipts.
  • Purpose: handling the payment, managing the subscription, invoicing, VAT, preventing fraud.
  • Legal basis: Art. 6 (1) (b) GDPR, Art. 6 (1) (c) GDPR (tax retention) and Art. 6 (1) (f) GDPR (fraud prevention).
  • Where: Stripe processes in the EU and in the USA, safeguarded by EU standard contractual clauses under Art. 46 GDPR.
  • Retention: invoices and payment receipts for ten years, in line with the statutory retention period. The card data itself never reaches our systems.

3.5 Support requests#

If you contact support@dory-ai.com directly, we process your message and contact details in order to deal with your request (Art. 6 (1) (f) GDPR). Retention: up to 24 months after the matter is closed.

4. Data processed on behalf of your organisation#

All content you actively process in Dory is processed by us exclusively on the instructions of your organisation and on its behalf (Art. 28 GDPR, Annex 1 to the terms). That includes:

  • your prompts and Chats;
  • uploaded Documents and files;
  • generated answers;
  • data from connected third-party systems (for example HubSpot, Gmail, Google Calendar, Linear, Notion, Airtable, ClickUp, Asana) that Dory retrieves live in order to answer your request;
  • audio recordings you make in Dory; they are transcribed and stored as text.

This is how long that data stays:

  • Persistent storage: Chats, messages, stored memories, uploaded Documents and transcripts stay in our database until your organisation deletes them or requests deletion of the account.
  • Not persistent: live queries to third-party systems are cached only briefly per Chat and discarded afterwards.

OAuth connections to third-party systems: when you connect an integration (for example Google Drive, HubSpot), the OAuth access tokens are managed through our sub-processor Nango. We ourselves never store your passwords for those services.

For this data, your organisation is your point of contact.

5. Sub-processors#

To run Dory we use the following service providers. Data processing agreements under Art. 28 GDPR are in place with all of them. For providers based outside the EU, transfers are based on EU standard contractual clauses under Art. 46 GDPR and, where available, on a certification under the EU-US Data Privacy Framework.

Infrastructure and storage

ProviderPurposePlace of processing
Render Services, Inc.Hosting of the backend, the background worker and the frontendFrankfurt (EU); provider based in the USA, EU standard contractual clauses
Supabase, Inc.Database, authentication, file and vector storageFrankfurt (EU); provider based in the USA, EU standard contractual clauses
Redis (betrieben über Render)Streaming of answers in flight, event bus, task queueFrankfurt (EU)

Language models and audio

ProviderPurposePlace of processing
OpenAI, L.L.C.Language models (GPT), claim verification, text embeddingsUSA, safeguarded by EU standard contractual clauses
OpenRouter, Inc.Gateway to every other language model; selects the upstream model providerUSA; the upstream model provider may sit outside the EU. EU standard contractual clauses
Groq, Inc.Audio transcriptionUSA, safeguarded by EU standard contractual clauses

Integrations and tools

ProviderPurposePlace of processing
NangoManaging the OAuth tokens of your own integrationsUSA, safeguarded by EU standard contractual clauses
FirecrawlWeb search and page retrievalUSA, safeguarded by EU standard contractual clauses
E2B (FoundryLabs, Inc.)Running code in isolated sandboxesUSA, safeguarded by EU standard contractual clauses
DataForSEO LLCSearch engine, keyword and domain dataUSA, safeguarded by EU standard contractual clauses
RapidAPILinkedIn lookupsUSA, safeguarded by EU standard contractual clauses

Payment, operations and communication

ProviderPurposePlace of processing
Stripe Payments Europe, Ltd. / Stripe, Inc.Payment processing, subscriptions, invoices, VATIreland (EU) and USA, safeguarded by EU standard contractual clauses
Resend, Inc.Sending product emailUSA, safeguarded by EU standard contractual clauses
Pydantic Services Inc. (Logfire)Operational monitoring, debugging, tracesUSA, safeguarded by EU standard contractual clauses
PostHog, Inc.Product analytics inside the app, without cookies and without cross-device recognitionEU endpoint (Frankfurt); provider based in the USA, EU standard contractual clauses
Linear Orbit, Inc.Receiving the feedback and bug reports you send usUSA, safeguarded by EU standard contractual clauses

The same list appears in Annex 1 to the terms. It is the current version; we announce changes to your organisation in advance.

6. Transfers to providers of language models#

When you send Dory a request, your input and the content relevant for answering it (for example tool results from HubSpot or Gmail) are transferred to the provider of the model you have chosen, so that the answer is generated there.

  • Models from OpenAI we call directly. That is also where the text embeddings are created with which Dory searches your own content.
  • All other models run through the gateway OpenRouter, which selects the executing provider by availability and speed.
  • Audio is transcribed by Groq.
No model call is limited to the EU. Permanent storage of your data takes place in Frankfurt (section 7), processing by a language model does not: it happens wherever the respective provider runs the model, and that can be outside the EU. Transfers are based on EU standard contractual clauses under Art. 46 GDPR. An earlier version of this policy spoke of EU endpoints; that was not accurate and is corrected here.

In addition:

  • Your inputs are not used to train the models.
  • Retention at the respective provider is governed by that provider’s own terms, usually a limited retention for abuse detection. We do not configure a retention guarantee of our own and therefore do not state a period here that we could not stand behind. An earlier version of this policy named 30 days; that statement has been removed.

7. Storage in the EU#

Permanent storage of your data (Chats, memories, Documents, transcripts) takes place on servers in the European Union, in Frankfurt am Main, through Supabase and Render.

Further sub-processors for supplementary functions are based in the USA, among them OpenRouter for language models, Groq for transcription, Nango for OAuth tokens, Firecrawl for web search, E2B for code execution, DataForSEO and RapidAPI for data queries, and Logfire for operational monitoring. Transfers to these providers are based on EU standard contractual clauses under Art. 46 GDPR.

8. Your rights#

Under the GDPR you have the right to:

  • access (Art. 15)
  • rectification (Art. 16)
  • erasure (Art. 17)
  • restriction of processing (Art. 18)
  • data portability (Art. 20)
  • object (Art. 21)
  • lodge a complaint with a supervisory authority (Art. 77)

Important, on who is responsible: for content you enter into Dory, your organisation is the right point of contact. For account data, usage data, logs and support requests, contact support@dory-ai.com.

9. Data security#

We use technical and organisational measures under Art. 32 GDPR, among them:

  • encryption of transmission (TLS) and of storage (encryption at rest)
  • role and access controls following the least-privilege principle
  • regular backups and separate backup systems
  • logging of security-relevant events

10. Changes to this policy#

We adapt this policy when the processing changes, for example when there are new sub-processors or features. The current version is linked in your account. In the case of substantial changes we inform you at your next login.

This document exists in German and English. In the event of any discrepancy, the German version prevails.