This privacy policy informs you under Art. 13 GDPR which personal data we (DoryAI) process when you use Dory. It supplements the terms of use (EULA). The contract with your organisation and the data processing agreement are set out in the terms and their Annex 1.
1. Who is responsible for what?#
When you use Dory there are two data protection roles you should know about:
- Your organisation is the controller for the content you enter and process in Dory. That includes your inputs (prompts), uploaded files, generated answers and all data Dory retrieves from connected third-party systems (for example HubSpot, Gmail, Calendar). If you want to exercise a right of access, erasure or objection regarding that data, contact your organisation.
- The provider of Dory (Georg Ortner, trading as DoryAI, below “we” or “us”) is the controller only for the data we need in order to run Dory technically. That is account data, login activity, pseudonymised usage data and server logs. This policy applies to that data.
2. Controller and contact#
Georg Ortner (sole trader, trading as DoryAI)
Rigaer Straße 47A
10247 Berlin
VAT ID: DE405789769
Email: support@dory-ai.com
3. Which data we process as controller#
3.1 Account and login data#
- What: name, email address, encrypted password or session token, time of the last login.
- Purpose: authentication and access control.
- Legal basis: Art. 6 (1) (b) GDPR (performance of the user relationship), Art. 6 (1) (f) GDPR (legitimate interest in secure authentication).
- Retention: as long as your organisation’s account exists. When a subscription ends, the account stays readable; there is no retention period and no automatic deletion job. Data is deleted only on your organisation’s explicit request, and then within one month (§ 9.3 of the terms and Annex 1 A1.8).
3.2 Usage data of the app (product analytics)#
- What: views of areas of the app, features used, response times and error messages, and technical details about the device.
- How: the measurement runs without cookies and without recognition across sessions. Our analytics tool PostHog stores the identifier only in the browser’s memory (
persistence: 'memory'); once the tab is closed it is gone. Nothing is stored on your device, which is why we do not ask for consent for it either. - What does not happen: no automatic capture of every click, no session recording, no heatmaps and no connection to the measurement on the website dory-ai.com. The two domains are measured separately and are not merged.
- Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in troubleshooting, stability and product improvement). You can object to this processing under Art. 21 GDPR.
- Retention: 12 months.
Important: we evaluate this data only in aggregate. There is no monitoring or assessment of the performance or behaviour of individual people.
3.3 Server logs#
- What: IP address (truncated), timestamp, endpoint called, HTTP status.
- Purpose: security, abuse detection, error analysis.
- Legal basis: Art. 6 (1) (f) GDPR.
- Retention: 30 days, then automatic deletion.
3.4 Payment data#
If your organisation takes out a subscription or buys credits, we and our payment provider Stripe Payments Europe, Ltd. process the data needed for that.
- What: name and email address of the ordering person, billing address, VAT identification number, means of payment, invoices and payment receipts.
- Purpose: handling the payment, managing the subscription, invoicing, VAT, preventing fraud.
- Legal basis: Art. 6 (1) (b) GDPR, Art. 6 (1) (c) GDPR (tax retention) and Art. 6 (1) (f) GDPR (fraud prevention).
- Where: Stripe processes in the EU and in the USA, safeguarded by EU standard contractual clauses under Art. 46 GDPR.
- Retention: invoices and payment receipts for ten years, in line with the statutory retention period. The card data itself never reaches our systems.
3.5 Support requests#
If you contact support@dory-ai.com directly, we process your message and contact details in order to deal with your request (Art. 6 (1) (f) GDPR). Retention: up to 24 months after the matter is closed.
4. Data processed on behalf of your organisation#
All content you actively process in Dory is processed by us exclusively on the instructions of your organisation and on its behalf (Art. 28 GDPR, Annex 1 to the terms). That includes:
- your prompts and Chats;
- uploaded Documents and files;
- generated answers;
- data from connected third-party systems (for example HubSpot, Gmail, Google Calendar, Linear, Notion, Airtable, ClickUp, Asana) that Dory retrieves live in order to answer your request;
- audio recordings you make in Dory; they are transcribed and stored as text.
This is how long that data stays:
- Persistent storage: Chats, messages, stored memories, uploaded Documents and transcripts stay in our database until your organisation deletes them or requests deletion of the account.
- Not persistent: live queries to third-party systems are cached only briefly per Chat and discarded afterwards.
OAuth connections to third-party systems: when you connect an integration (for example Google Drive, HubSpot), the OAuth access tokens are managed through our sub-processor Nango. We ourselves never store your passwords for those services.
For this data, your organisation is your point of contact.
5. Sub-processors#
To run Dory we use the following service providers. Data processing agreements under Art. 28 GDPR are in place with all of them. For providers based outside the EU, transfers are based on EU standard contractual clauses under Art. 46 GDPR and, where available, on a certification under the EU-US Data Privacy Framework.
Infrastructure and storage
| Provider | Purpose | Place of processing |
|---|---|---|
| Render Services, Inc. | Hosting of the backend, the background worker and the frontend | Frankfurt (EU); provider based in the USA, EU standard contractual clauses |
| Supabase, Inc. | Database, authentication, file and vector storage | Frankfurt (EU); provider based in the USA, EU standard contractual clauses |
| Redis (betrieben über Render) | Streaming of answers in flight, event bus, task queue | Frankfurt (EU) |
Language models and audio
| Provider | Purpose | Place of processing |
|---|---|---|
| OpenAI, L.L.C. | Language models (GPT), claim verification, text embeddings | USA, safeguarded by EU standard contractual clauses |
| OpenRouter, Inc. | Gateway to every other language model; selects the upstream model provider | USA; the upstream model provider may sit outside the EU. EU standard contractual clauses |
| Groq, Inc. | Audio transcription | USA, safeguarded by EU standard contractual clauses |
Integrations and tools
| Provider | Purpose | Place of processing |
|---|---|---|
| Nango | Managing the OAuth tokens of your own integrations | USA, safeguarded by EU standard contractual clauses |
| Firecrawl | Web search and page retrieval | USA, safeguarded by EU standard contractual clauses |
| E2B (FoundryLabs, Inc.) | Running code in isolated sandboxes | USA, safeguarded by EU standard contractual clauses |
| DataForSEO LLC | Search engine, keyword and domain data | USA, safeguarded by EU standard contractual clauses |
| RapidAPI | LinkedIn lookups | USA, safeguarded by EU standard contractual clauses |
Payment, operations and communication
| Provider | Purpose | Place of processing |
|---|---|---|
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Payment processing, subscriptions, invoices, VAT | Ireland (EU) and USA, safeguarded by EU standard contractual clauses |
| Resend, Inc. | Sending product email | USA, safeguarded by EU standard contractual clauses |
| Pydantic Services Inc. (Logfire) | Operational monitoring, debugging, traces | USA, safeguarded by EU standard contractual clauses |
| PostHog, Inc. | Product analytics inside the app, without cookies and without cross-device recognition | EU endpoint (Frankfurt); provider based in the USA, EU standard contractual clauses |
| Linear Orbit, Inc. | Receiving the feedback and bug reports you send us | USA, safeguarded by EU standard contractual clauses |
The same list appears in Annex 1 to the terms. It is the current version; we announce changes to your organisation in advance.
6. Transfers to providers of language models#
When you send Dory a request, your input and the content relevant for answering it (for example tool results from HubSpot or Gmail) are transferred to the provider of the model you have chosen, so that the answer is generated there.
- Models from OpenAI we call directly. That is also where the text embeddings are created with which Dory searches your own content.
- All other models run through the gateway OpenRouter, which selects the executing provider by availability and speed.
- Audio is transcribed by Groq.
In addition:
- Your inputs are not used to train the models.
- Retention at the respective provider is governed by that provider’s own terms, usually a limited retention for abuse detection. We do not configure a retention guarantee of our own and therefore do not state a period here that we could not stand behind. An earlier version of this policy named 30 days; that statement has been removed.
7. Storage in the EU#
Permanent storage of your data (Chats, memories, Documents, transcripts) takes place on servers in the European Union, in Frankfurt am Main, through Supabase and Render.
Further sub-processors for supplementary functions are based in the USA, among them OpenRouter for language models, Groq for transcription, Nango for OAuth tokens, Firecrawl for web search, E2B for code execution, DataForSEO and RapidAPI for data queries, and Logfire for operational monitoring. Transfers to these providers are based on EU standard contractual clauses under Art. 46 GDPR.
8. Your rights#
Under the GDPR you have the right to:
- access (Art. 15)
- rectification (Art. 16)
- erasure (Art. 17)
- restriction of processing (Art. 18)
- data portability (Art. 20)
- object (Art. 21)
- lodge a complaint with a supervisory authority (Art. 77)
Important, on who is responsible: for content you enter into Dory, your organisation is the right point of contact. For account data, usage data, logs and support requests, contact support@dory-ai.com.
9. Data security#
We use technical and organisational measures under Art. 32 GDPR, among them:
- encryption of transmission (TLS) and of storage (encryption at rest)
- role and access controls following the least-privilege principle
- regular backups and separate backup systems
- logging of security-relevant events
10. Changes to this policy#
We adapt this policy when the processing changes, for example when there are new sub-processors or features. The current version is linked in your account. In the case of substantial changes we inform you at your next login.
This document exists in German and English. In the event of any discrepancy, the German version prevails.