Last updated June 24, 2026

Privacy Policy

This Privacy Policy explains how Doku collects, uses, stores, and shares information when you use our websites, dashboard, Playbooks, agent handoffs, and connector features.

Who we are

Doku provides a Playbook Network and governed tool surface for agent-assisted work. In this policy, "Doku", "we", "us", and "our" refer to the Doku service. If you use Doku through a company, workspace, or organization, that workspace may also control how its members use Doku.

Information we collect

We collect information you provide directly, information generated by your use of Doku, and information we receive when you connect third-party services.

  • Account information, such as name, email address, authentication state, and profile.
  • Workspace and project information, including members, roles, settings, and access.
  • Playbook and agent activity, including run state, tasks, questions, answers, approvals, evidence, connector handoffs, logs, and audit events.
  • Connector information, including provider names, connected account metadata, granted scopes, OAuth tokens, refresh tokens, and other credentials required to provide approved connector actions.
  • Files, URLs, prompts, instructions, outputs, and other content that you or an authorized agent provide to Doku.
  • Usage, device, diagnostic, and security information, such as IP address, browser, timestamps, request metadata, error logs, and product analytics.
  • Communications with us, including support, security, and legal requests.

How we use information

We use information to provide, secure, support, and improve Doku. This includes authenticating users, operating workspaces, running Playbooks, coordinating agent work, creating handoff links, enforcing policies and approvals, executing connector actions, recording evidence and audit history, debugging issues, preventing abuse, and complying with legal obligations.

Connectors and OAuth provider data

When you connect a provider such as Google, Microsoft, Cloudflare, Slack, or another service, Doku uses the connected account data only to provide the connector features you authorize. Doku stores credentials in a protected credential store and does not expose raw provider tokens to agents. Connector actions are checked against Doku authorization, provider scopes, workspace policy, and applicable approvals before they run.

For Google APIs, Doku uses Google user data only to provide user-facing features that you request or authorize, such as sign-in, connector setup, resource discovery, and approved connector actions. Doku does not sell Google user data, use it for advertising, or use it to train generalized AI or machine learning models. Doku's use and transfer of information received from Google APIs is intended to follow the Google API Services User Data Policy, including Limited Use requirements.

Agent and automation activity

Doku is designed so agents act through Doku-controlled authorization paths. When you ask an agent or external harness to perform work, that agent or harness may receive the instructions, context, handoff URLs, connector results, and other information needed to complete the task. Doku records run state, decisions, approvals, evidence, and audit events so users and workspace administrators can review what happened.

How we share information

We share information only as needed to operate Doku and the services you authorize.

  • With infrastructure, database, authentication, analytics, email, security, and support providers that help us operate Doku.
  • With third-party connector providers when you connect an account or ask Doku to perform an approved connector action.
  • With workspace members, administrators, or authorized agents according to workspace permissions, member access, and handoff context.
  • When required to comply with law, protect rights, prevent abuse, or secure Doku.
  • In connection with a merger, acquisition, financing, or sale of assets.

Doku does not sell customer data.

Data retention

We retain information for as long as needed to provide Doku, maintain security and audit records, comply with legal obligations, resolve disputes, and enforce agreements. Workspace data, run history, connector metadata, approvals, and audit records may be kept while the workspace is active and for a reasonable period afterward. OAuth tokens and connector credentials are deleted or revoked when you disconnect the provider, delete the workspace, or request deletion, subject to backup, security, and legal retention needs.

Security

We use technical and organizational safeguards designed to protect information, including access controls, credential isolation, encryption where appropriate, audit records, and separation between platform secrets and customer connector credentials. No online service can guarantee absolute security, but we work to reduce risk and respond to security issues.

Your choices and rights

You may request access, correction, deletion, or export of your personal information. You may disconnect third-party providers from Doku, revoke provider access through the provider account, or ask us to delete connector credentials associated with your workspace. Some requests may be limited by security, audit, legal, or workspace administrator obligations.

International use

Doku may process information in the United States and other countries where we or our service providers operate. If you use Doku from outside those countries, you understand that your information may be transferred to and processed in jurisdictions that may have different data protection laws.

Cookies and analytics

Doku may use cookies, local storage, and similar technologies to keep users signed in, remember preferences, protect the service, understand usage, and improve reliability. You can control cookies through your browser settings, but disabling them may affect product functionality.

Children

Doku is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child provided personal information to Doku, contact us so we can take appropriate action.

Changes

We may update this Privacy Policy from time to time. When we make material changes, we will update the date above and may provide additional notice through the website, dashboard, or email.

Contact

For privacy questions or data requests, contact privacy@usedoku.com.