Privacy policy
Effective [DATE]. Datagoat is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS] ("Datagoat", "we"). Contact: privacy@datagoat.io.
This policy covers datagoat.io, api.datagoat.io, the Datagoat MCP server, the Datagoat API and the Datagoat SDKs.
What we collect
- Account details. When you sign in, our authentication provider (Clerk) gives us your name, email address and a user identifier. Agents that register for a test key have no account. We keep a salted hash of the registering IP address, for rate limiting.
- API keys. We store a hash of each key and its first characters, never the key itself.
- Data you send. The rows you send for analysis, the questions you ask, the actions you record, and the outcomes you report. You choose what these contain.
- Answers. The chances, reasons and signed Verdicts we return.
- Usage. Counts of fits and answered cases per month, for billing.
- Service logs. Request metadata (time, route, status, duration, IP address, request identifier). Logs do not contain your rows.
How we use it
We use it to answer your questions, to meter usage, to secure and operate the service, and to contact you about your account. We do not sell your data. We do not use your rows or answers to build models for anyone else: every model is fitted for one workspace, from that workspace's data. Datagoat does not send your data to AI model providers.
When you use Datagoat through an AI assistant (Claude, ChatGPT or another MCP host), the assistant sends us the tool arguments and receives our answers. What the assistant keeps is governed by its provider's policy.
How long we keep it
| What | How long |
|---|---|
| Rows sent with an ask | Deleted when the call ends |
| Datasets you store, and their profile (column names, and the values of columns with at most 12 distinct values) | Deleted 24 hours after last use, or when you delete them |
| Answers | 24 hours |
| Fitted models (no rows) | 90 days |
| Reported outcomes and recorded actions | For as long as the model's track record is kept, or until you ask us to delete them |
| Usage counts and billing records | As long as the law requires |
| Account details and API keys | Until you delete your account |
| Service logs | [30] days |
Details are on the Your data page.
Who processes it for us
| Provider | Purpose | Region |
|---|---|---|
| Vercel | Hosting the website, API and MCP server | [REGION] |
| Neon | The database of accounts, keys, dataset records and usage | [REGION] |
| Clerk | Sign-in and OAuth | [REGION] |
| Modal | Running the analysis engine | [REGION] |
| [OBJECT STORE PROVIDER] | Temporary storage of rows under analysis | [REGION] |
We share data with others only when the law requires it, or to protect the service and its users.
Your choices and rights
- Delete a stored dataset at any time with
dg_delete_dataset. Otherwise it is deleted automatically. - Revoke API keys on the keys page.
- Ask us to access, correct, export or delete your personal data, or to delete your account, at privacy@datagoat.io. We answer within 30 days.
- Depending on where you live, you may have further rights, including the right to complain to a data-protection authority.
Data you should not send
Datagoat is not designed for health information about identifiable people, payment card or bank account numbers, government identifiers, or credentials. Do not send them.
Security
Traffic is encrypted in transit (HTTPS). Keys are stored hashed. Rows are held in memory while a call runs and are stored only in the analysis engine's object store, for the periods above. Every answer is signed, so it can be checked for tampering.
Children
Datagoat is not directed at children under 16, and we do not knowingly collect their data.
Changes
We will post changes here and update the effective date. If a change materially reduces your rights, we will tell account holders by email before it takes effect.