Legal

Privacy Policy

What data we collect, why we collect it, who processes it, and the rights you have over it. Written to be readable, not buried in legalese.

Last updated · 22 September 2026 · Version 1.2

01Summary

The short version

We collect what we need to run the Service (account info, payment info, what you do in the app) and connect you to integrations you opt into (Google Search Console, etc.). We don't sell your data. We don't train third-party AI models on your content. We process data through trusted vendors listed below. You can export, correct, or delete your data anytime by emailing support@dorqa.io.

02Who we are

Dorqa is operated by BirdMatrix LLP, a Limited Liability Partnership registered in India under LLP ID AAY-2584, with its registered office in Gurugram, Haryana. For the purposes of GDPR, India's Digital Personal Data Protection Act, 2023 (DPDPA), and similar laws, BirdMatrix LLP is the data controller for personal data processed through the Service.

03What we collect

We collect the following categories of data when you use Dorqa:

CategoryWhat's includedSource
Account data
Name, email address, password (hashed), profile preferences, language, timezone
You
Billing data
Billing name, billing address, country, GSTIN/VAT number where applicable, payment method tokens (we do not store card numbers)
You · Razorpay · Paddle
Project data
Domains, URLs, keywords, tracked queries, custom AI prompts, brand mention terms, competitor lists, reports, and other content you submit
You
Integration data
When you connect Google Search Console, Google Analytics, YouTube, or similar accounts, we receive the data those services authorise — typically search queries, impressions, clicks, video metadata, and analytics
Third-party APIs you authorise
Usage data
Pages visited, features used, actions taken, error logs, performance metrics, session duration
Automatic (in-app)
Device & technical
IP address, browser type, operating system, device type, referrer URL, approximate location (country/city level for currency detection)
Automatic (HTTP)
Communications
Support tickets, emails you send us, feedback submissions, survey responses
You

04Why we collect it

We process personal data on the following legal bases:

  • Contract — to create and maintain your Account, deliver the Service you subscribed to, process payments, and provide support
  • Legitimate interest — to improve the Service, monitor for fraud and abuse, secure our infrastructure, and communicate product updates relevant to your use
  • Consent — for marketing emails (which you can unsubscribe from anytime), optional analytics cookies, and integrations you choose to connect
  • Legal obligation — to comply with tax, accounting, and regulatory requirements applicable to BirdMatrix LLP

05How we use it

We use your data to:

  • Run your Account, projects, reports, and tracked queries
  • Generate the SEO, AI Visibility, Local SEO, YouTube, Trend, and Audience Intelligence outputs you ask for
  • Detect rising trends, citation gaps, and audience signals through our processing pipelines
  • Charge you for paid Plans and issue invoices and receipts
  • Respond to support requests and resolve issues
  • Send Service announcements (always), product newsletters (only if you opt in)
  • Detect and prevent abuse, fraud, scraping, and security threats
  • Improve features and algorithms using aggregated, de-identified usage patterns
What we do not do

We do not sell your data to third parties. We do not use your project data, integrations, or content to train third-party AI models. We do not share your data with advertisers for behavioural targeting. We do not access your connected Google Search Console or YouTube data for any purpose other than generating your reports.

06Sub-processors

We use the following third-party processors to operate the Service. Each is bound by data-protection terms and processes data only on our instructions and for the purposes listed.

Infrastructure & hosting

SupabaseEU
Database, authentication, storage, edge functions. Stores all account, project, and report data.
supabase.com/privacy →
CloudflareGlobal
CDN, DNS, DDoS protection, marketing site hosting (dorqa.io via Cloudflare Pages).
cloudflare.com/privacypolicy →
Lovable.devEU
Application development environment. May process app metadata and code.
lovable.dev/privacy →
GitHubUSA
Source code repository for marketing site and application code.
github.com/privacy →

Payment processors

RazorpayIndia
Processes INR payments for Indian customers. Receives billing details and processes card/UPI/netbanking data directly.
razorpay.com/privacy →
PaddleUK · USA
Merchant of Record for international USD payments. Handles billing, taxes (sales tax, VAT, GST), and card processing.
paddle.com/legal/privacy →

Data & intelligence APIs

DataForSEOUSA
Primary SEO data API — keyword research, rank tracking, SERP data, backlinks. Receives queried keywords and domains, not user identity.
dataforseo.com/privacy →
Ahrefs FirehoseSingapore
Backlink and referring domain intelligence. Receives queried domains.
ahrefs.com/privacy →
GroqUSA
LLM inference for trend clustering and content analysis. Receives only the data needed for inference; no user identity attached.
groq.com/privacy →
Jina AIGermany
Content reading, embeddings, and semantic search for trend and content modules.
jina.ai/legal →

AI visibility tracking

OpenAI (ChatGPT)USA
Tracks brand citations in ChatGPT responses for AI Visibility module. Sends only the prompts you configure.
openai.com/privacy →
Google (Gemini)Global
Tracks citations in Gemini responses. Sends only the prompts you configure.
policies.google.com/privacy →
Anthropic (Claude)USA
Tracks citations in Claude responses. Sends only the prompts you configure.
anthropic.com/privacy →
PerplexityUSA
Tracks citations in Perplexity responses. Sends only the prompts you configure.
perplexity.ai/privacy →

Integrations you authorise

Google APIsGlobal
Google Search Console, Google Analytics 4, YouTube Data API. We access only the scopes you grant and only for delivering your reports.
policies.google.com/privacy →
Public sourcesGlobal
Trend Intelligence ingests from Reddit, Hacker News, Product Hunt, GitHub, and Y Combinator using their public APIs and respecting their terms.
Public APIs →
Google API Limited Use

Dorqa's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request read-only access to Google Search Console and Google Analytics (GA4) data, use it solely to display search and analytics insights to you in the app, and never sell it, use it for advertising, or use it to train generalized AI/ML models. You can revoke access anytime by disconnecting your Google account.

Communication & operations

Email providerUSA · EU
Transactional email (account, billing, support). Specific provider may evolve; current provider available on request.
request current vendor →
Newsletter providerUSA · EU
Manages newsletter subscriptions for opt-in communications. You can unsubscribe at any time.
request current vendor →

This list may evolve as the Service grows. We update this page when sub-processors change. For a current authoritative list at any time, email support@dorqa.io.

07Sharing & disclosure

We do not sell your personal data. We share data only:

  • With sub-processors listed above, strictly to operate the Service
  • With your authorisation when you connect an integration or share a report
  • With professional advisors (lawyers, accountants, auditors) under confidentiality, where reasonably necessary
  • For legal reasons when required by valid legal process — court order, subpoena, regulatory request — or to protect our rights, property, or safety, or those of our users or the public
  • In a business transition such as a merger, acquisition, or sale of assets, in which case affected users will be notified and offered options consistent with this policy

08Cookies & tracking

We use a minimal set of cookies and similar storage technologies:

  • Essential cookies — required for authentication, session management, and security. Cannot be disabled.
  • Preference storage — local storage to remember theme (dark/light) and currency (INR/USD) preference.
  • Analytics — privacy-respecting analytics for understanding aggregate usage patterns. No cross-site tracking, no advertising identifiers.

We do not use third-party advertising cookies, retargeting pixels, or behavioural tracking across other websites.

09Data retention

We retain your data for the following periods:

  • Account data — for the lifetime of your Account, plus 30 days after closure to allow reactivation
  • Project & report data — for the lifetime of your Account; historical depth depends on your Plan (12 months on Free, up to 24 months on paid Plans)
  • Billing & tax records — for 7 years after the transaction, as required by Indian tax and accounting law
  • Support communications — for 3 years after the last message
  • Aggregated, de-identified data — may be retained indefinitely for product analytics and improvement

You can request earlier deletion at any time, subject to our legal obligations to retain certain records.

10Security

We protect your data with industry-standard measures:

  • Encryption in transit (HTTPS/TLS 1.2+) and at rest (database-level encryption via Supabase)
  • Hashed passwords (we never see or store passwords in plain text)
  • Role-based access controls and audit logging on internal systems
  • Regular dependency updates and infrastructure patching
  • Limited employee access on a need-to-know basis

No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the appropriate authorities in line with applicable law (GDPR Article 33/34, DPDPA Section 8(6)).

11International transfers

BirdMatrix LLP is based in India. Some of our sub-processors are based in the EU, UK, USA, Singapore, or other jurisdictions. When we transfer data internationally, we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) where applicable and the data-protection commitments of our sub-processors.

12Your rights

Depending on your location, you have rights under GDPR (EEA/UK), DPDPA (India), CCPA (California), or similar laws, including the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Delete your data, subject to our legal retention obligations
  • Export your data in a portable, machine-readable format
  • Restrict or object to certain processing
  • Withdraw consent at any time for processing based on consent
  • Lodge a complaint with your local data protection authority

To exercise any of these rights, email support@dorqa.io. We will respond within 30 days. We do not charge for reasonable requests and we do not retaliate against users who exercise their rights.

13Children

Dorqa is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact support@dorqa.io and we will delete it promptly.

14AI assistants

You can connect your Dorqa account to an AI assistant, such as ChatGPT or Claude, using Dorqa's connector at https://mcp.dorqa.io/mcp. See the AI assistants guide.

How the connection works. When you connect, the assistant sends you to a Dorqa sign-in and consent page. The assistant never sees your Dorqa password. After you click Allow, Dorqa issues the assistant an access token that lasts one hour and a refresh token that lasts 30 days. We store only a one-way hash of each token, never the token itself.

What the assistant can read. Only when you ask it something, and only through read-only tools:

  • the projects (websites) in your Dorqa workspace, including your team's projects if you are part of a team, and whether Search Console and Analytics are connected;
  • each project's Dorqa Brief: Search Console and Google Analytics figures, site audit results, domain overview, AI visibility results, internal link suggestions, questions people ask, audience research and watched trends, as already stored in Dorqa;
  • Dorqa's shared question bank (public questions from search and communities, with search volume).

What the assistant cannot do. It cannot change anything in Dorqa or on your website, run paid lookups, spend your credits, or see your billing details, payment methods or password.

What Dorqa receives from the assistant. The tool request only: which tool, and inputs such as a project domain or a topic. Dorqa does not receive your conversation with the assistant. Your conversation is handled by the assistant's provider under their own privacy policy (for example OpenAI's or Anthropic's).

What Dorqa stores. The name the assistant registered with (for example "ChatGPT"), the address it returns you to, hashed tokens, when you connected and when the connection was last used. We keep these while the connection is active and delete them within 90 days of it ending.

Third parties. Dorqa does not sell or share data received through this connection. Data you choose to have an assistant read is sent to that assistant's provider at your request.

Disconnecting. In Dorqa, open your account menu, then AI assistants, then Disconnect. Access ends immediately. You can also remove Dorqa inside the assistant.

15Changes

We may update this Privacy Policy from time to time to reflect changes in the Service, our processors, or applicable law. Material changes will be communicated by email or in-app notification at least 30 days in advance. The "Last updated" date at the top reflects when this policy was most recently modified.

16Contact

For questions about this Privacy Policy or to exercise your rights, contact us:

Data controllerBirdMatrix LLP
LLP IDAAY-2584
Registered officeGurugram, Haryana, India
Privacy contactsupport@dorqa.io
Websitedorqa.io
Applicationapp.dorqa.io