Privacy Policy
Dockhouse is a service that connects your marketing accounts (Google Search Console, Google Analytics, and — later — ad platforms) to AI agents you already use, over the Model Context Protocol. A service that connects to your accounts owes you a policy written to be read, not skimmed past. The short version: we collect the minimum, we encrypt what we hold, we never sell or train on your data, and disconnecting really disconnects.
1. Who is responsible
The data controller is Nicolas Estrem, 1 Impasse du Montcalm, 31500 Toulouse, France.
Contact for anything in this policy: privacy@dockhouse.ai.
2. What this policy covers
Two things: the website at dockhouse.ai (what everyone sees today) and the Dockhouse service (the private beta that connects Google accounts to your AI agents). The service sections apply from the moment you connect an account.
3. Data we collect on the website
- Waitlist email. If you request early access, we store the email address you give us, when you gave it, and roughly where the request came from (country-level). Legal basis: your consent. We use it for exactly one thing — contacting you about the Dockhouse beta and launch. Unsubscribe or ask for deletion at any time.
- Technical logs. Our host, Cloudflare, processes IP addresses and request metadata to serve the site and protect it from abuse. Legal basis: legitimate interest (security and operation). We keep server-side logs no longer than 30 days.
- No tracking. This site sets no advertising or analytics cookies and runs no third-party trackers. Cloudflare may set strictly-necessary security cookies to distinguish humans from bots.
4. Data we collect in the service (beta)
When you connect a Google account:
- Account identifiers — your Google account email and the identifiers of the properties you choose to connect (Search Console sites, GA4 properties, ad accounts).
- OAuth tokens — the credentials Google issues so Dockhouse can query your data on your behalf. Refresh tokens are envelope-encrypted at rest; short-lived access tokens exist only inside your session's isolated runtime.
- Usage metadata — which tool was called, when, by which of your connectors, and operation counts. We use this to run the service, enforce fair use, and (later) bill. It does not include the content of your marketing data.
- Your account with us — email and authentication details for signing in to Dockhouse itself.
What we deliberately do not do: your Google data (queries, analytics, campaign metrics) passes through Dockhouse to your AI agent and is not stored beyond the transient processing needed to answer the request. We do not warehouse it, build profiles from it, resell it, or use it to train models.
5. Google user data — Limited Use
Dockhouse's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice that means data obtained through Google APIs is used only to provide the features you asked for; it is never used for advertising, never sold, never used to train generalized AI models, and never read by a human except with your explicit consent for support, for security investigation, or where the law requires it.
We request the narrowest scopes that work — read-only wherever read-only exists. If write-capable features ship in the future, they will request additional scopes separately, at the moment you opt in, and every write will require your explicit approval.
6. Where your data lives and how it's protected
Dockhouse runs on Cloudflare's developer platform. Data in transit is TLS-encrypted; tokens at rest are envelope-encrypted with keys held separately from the data. Access to production systems is limited to the operator. We prefer EU jurisdictions for stored data where the platform allows it.
Retention: waitlist emails until launch or your deletion request; OAuth tokens until you disconnect (or we detect revocation on Google's side); usage metadata up to 13 months for operations and billing; technical logs up to 30 days.
7. Who else is involved
We sell nothing to anyone. We share data only with processors needed to run the service:
- Cloudflare, Inc. — hosting, networking, storage (global edge; safeguarded by standard contractual clauses).
- Google LLC — the API provider for the accounts you connect; your requests necessarily reach Google.
If this list grows (for example, an email or billing provider), this page will be updated before the change takes effect.
8. Your rights
You can ask for access to, correction of, deletion of, or a portable copy of your personal data, object to or restrict processing, and withdraw consent at any time — write to privacy@dockhouse.ai and we'll answer within 30 days. You can also lodge a complaint with the French data protection authority (CNIL) or, if you're elsewhere in the EU/EEA, with your local supervisory authority.
Disconnecting Google: removing a connection in Dockhouse deletes the stored token and revokes it at Google. You can also revoke Dockhouse's access yourself at any time from your Google account permissions — the service will treat that as a disconnect.
9. Children
Dockhouse is a professional tool and not directed at anyone under 16. We do not knowingly collect data from minors.
10. Changes
If this policy changes materially, the effective date above changes with it, and beta members are notified by email before the new version applies.