Legal

Privacy policy

Effective July 10, 2026

Who operates Docket

Docket is operated by The Hypertext Studio. Questions, access requests, and deletion requests can be sent to support@docket.hypertext.studio.

Information we collect

We process account profile details, passkey and session metadata, the organizations and work you create, product settings, support communications, and technical logs needed to secure and operate Docket. We do not store passkey private keys.

When you authorize a connector, we also process the provider account identifier, granted scopes, encrypted OAuth access and refresh tokens, synchronization cursors, and the data needed to provide that connector.

Google user data

Google access is optional and requested incrementally. Calendar access lets Docket list your calendars, display selected events, detect changes, and create, update, or delete events when you use editing features. Tasks access supports two-way task synchronization. Drive read-only access lets you find and attach files you choose. Gmail modify access lets Docket read relevant message metadata and content and apply mailbox actions you request.

Docket uses Google user data only to provide or improve the user-facing features you initiate. We do not sell Google user data, use it for advertising, transfer it to data brokers, or use it to train generalized artificial-intelligence models.

Docket's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Storage and sharing

OAuth bearer tokens are encrypted before database storage. Docket stores application data with contracted infrastructure providers, including Google Cloud, Neon, Vercel, and Cloudflare, only as needed to host, secure, back up, and deliver the service. We may also disclose information when required by law or to protect users and the service.

Retention and your controls

Connector data remains while the account is linked and as needed for synchronization. Unlinking a Google account removes its encrypted tokens and cached Calendar data. You can also revoke Docket in your Google Account security settings. Organization records that originated from a connector may remain as Docket work history but lose access to the provider and are marked for reconnection.

Account deletion uses a 14-day recovery period. After that period Docket deletes the account and associated personal data, subject to limited security, legal, and backup retention obligations. You may export your data before deletion.

Security, changes, and rights

We use access controls, encryption, tenant isolation, audit logging, and operational monitoring appropriate to the data we process. No system is completely secure. Depending on where you live, you may have rights to access, correct, export, restrict, object to, or delete personal information.

We will update this page when practices materially change and will provide additional notice when required. Contact support to exercise a right or raise a concern.