Legal

Privacy Policy

Effective: 23 July 2026 · applies to dockhouse.ai and the Dockhouse beta service

Dockhouse is a service that connects your marketing accounts (Google Search Console, Google Analytics, and — later — ad platforms) to AI agents you already use, over the Model Context Protocol. A service that connects to your accounts owes you a policy written to be read, not skimmed past. The short version: we collect the minimum, we encrypt what we hold, we never sell or train on your data, and disconnecting really disconnects.

1. Who is responsible

The data controller is Nicolas Estrem, 1 Impasse du Montcalm, 31500 Toulouse, France.

Contact for anything in this policy: privacy@dockhouse.ai.

2. What this policy covers

Two things: the website at dockhouse.ai (what everyone sees today) and the Dockhouse service (the private beta that connects Google accounts to your AI agents). The service sections apply from the moment you connect an account.

3. Data we collect on the website

4. Data we collect in the service (beta)

When you connect a Google account:

What we deliberately do not do: your Google data (queries, analytics, campaign metrics) passes through Dockhouse to your AI agent and is not stored beyond the transient processing needed to answer the request. We do not warehouse it, build profiles from it, resell it, or use it to train models.

5. Google user data — Limited Use

Dockhouse's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practice that means data obtained through Google APIs is used only to provide the features you asked for; it is never used for advertising, never sold, never used to train generalized AI models, and never read by a human except with your explicit consent for support, for security investigation, or where the law requires it.

We request the narrowest scopes that work — read-only wherever read-only exists. If write-capable features ship in the future, they will request additional scopes separately, at the moment you opt in, and every write will require your explicit approval.

6. Where your data lives and how it's protected

Dockhouse runs on Cloudflare's developer platform. Data in transit is TLS-encrypted; tokens at rest are envelope-encrypted with keys held separately from the data. Access to production systems is limited to the operator. We prefer EU jurisdictions for stored data where the platform allows it.

Retention: waitlist emails until launch or your deletion request; OAuth tokens until you disconnect (or we detect revocation on Google's side); usage metadata up to 13 months for operations and billing; technical logs up to 30 days.

7. Who else is involved

We sell nothing to anyone. We share data only with processors needed to run the service:

If this list grows (for example, an email or billing provider), this page will be updated before the change takes effect.

8. Your rights

You can ask for access to, correction of, deletion of, or a portable copy of your personal data, object to or restrict processing, and withdraw consent at any time — write to privacy@dockhouse.ai and we'll answer within 30 days. You can also lodge a complaint with the French data protection authority (CNIL) or, if you're elsewhere in the EU/EEA, with your local supervisory authority.

Disconnecting Google: removing a connection in Dockhouse deletes the stored token and revokes it at Google. You can also revoke Dockhouse's access yourself at any time from your Google account permissions — the service will treat that as a disconnect.

9. Children

Dockhouse is a professional tool and not directed at anyone under 16. We do not knowingly collect data from minors.

10. Changes

If this policy changes materially, the effective date above changes with it, and beta members are notified by email before the new version applies.