On this page

Privacy

Last updated August 26, 2026

Doorwick is a small, independent product operated by Dovecore Software LLC, and this policy is written directly and in plain language. It explains what the hosted service, the embeddable widget, and the native iOS and Android operator apps handle, why they handle it, and how to ask a person about it.

Who we are

Doorwick is an independent software product operated by Dovecore Software LLC. Dovecore Software LLC is responsible for operating the hosted Doorwick service, the native iOS and Android operator apps, and this marketing site. For privacy questions and requests, email privacy@doorwick.com.

What we collect

Account and workspace data. We store the email address and credentials you use to sign in — email and password, or Google, GitHub, or LinkedIn — workspace membership and role information, billing identifiers, site keys, allowed domains, widget settings, AI-provider configuration, knowledge sources, canned replies, and other settings you choose to add.

Widget and conversation data. We store messages, supported files a visitor chooses to attach, filenames and file metadata, conversation state, timestamps, routing-group selections, ratings or feedback, and any name, email, or external identity a visitor chooses to share. An anonymous device token keeps conversation history attached to the visitor’s browser. If a visitor requests an emailed transcript, we use the supplied address to deliver that transcript. Doorwick does not fingerprint visitors or follow them around the web.

Operator apps (iOS and Android). The operator inbox is also available as native iOS and Android apps. Those apps store a session token prefixed dwm_ in the platform secure store (iOS SecureStore / Android Keystore). They may also store a device name, an Expo push token, and notification preferences so we can deliver handoff and reply alerts. Operators can attach files through the system document picker; those attachments become conversation data as described above.

Technical and security data. Servers necessarily receive request metadata such as IP address, user agent, route, and time. We use operational logs to run, secure, and diagnose the service—not to build advertising profiles.

Marketing analytics. The marketing site uses Google Analytics 4 to understand visits and improve its pages. Google Analytics can collect session statistics, approximate location, browser and device information, referral information, and page interactions. With analytics consent, it uses first-party cookies such as _ga and _ga_* to distinguish visitors and sessions.

Before analytics consent, Doorwick sets Google Consent Mode to deny analytics and advertising storage; Google may receive limited cookieless measurements. Advertising storage, advertising user data, and advertising personalization remain disabled when analytics is allowed. Your choice is stored in your browser as doorwick:analytics-consent. Doorwick does not sell customer or visitor data.

Who decides what

Dovecore Software LLC controls account, billing, security, marketing-site, and service-operation data needed to provide Doorwick. For visitor conversations and knowledge that a customer puts into a workspace, the workspace owner decides why the data is collected and how it is used; Dovecore Software LLC processes it through Doorwick on that owner’s behalf.

Workspace operators can see the conversations in workspaces they are allowed to access. Workspaces are isolated by design, even when one operator account uses the unified inbox across several sites.

Self-hosted customers operate their own deployment and are responsible for the privacy notices, infrastructure, access controls, retention, and processors used by that deployment.

Who processes data with us

  • Hetzner provides the production compute and database infrastructure for the hosted service.
  • Stripe hosts checkout and the billing portal and processes payment details under Stripe’s own terms. Doorwick stores Stripe customer and subscription identifiers but does not receive card numbers.
  • Resend provides transactional email delivery when email is configured.
  • Google Analytics measures use of the public marketing site subject to the visitor’s analytics choice. Google processes that measurement data under its own terms and privacy documentation.
  • The workspace owner’s selected AI provider processes the conversation and relevant knowledge sent to draft an answer. The workspace owner supplies the provider and API key, and that provider’s terms apply. Supported choices include Anthropic, OpenAI, Fireworks, Ollama, and OpenAI-compatible endpoints.
  • Google, GitHub, and LinkedIn process sign-in when an operator chooses those buttons. Doorwick stores the resulting account identity, not the provider password.
  • Expo provides the operator-app runtime and registers push tokens.
  • Apple Push Notification service (APNs) delivers iOS alerts to the operator apps.
  • Firebase Cloud Messaging (FCM) delivers Android alerts to the operator apps.

We will update this list before adding a core hosted-service processor that handles customer content.

Where data lives and international transfers

The primary hosted Doorwick service currently runs on infrastructure in Ashburn, Virginia, United States. Stripe, Resend, Expo, Apple APNs, Google FCM, the OAuth providers, and a workspace owner’s AI provider may process data in other countries described in their own policies.

If you use the hosted service from another country, your data may therefore be transferred to and processed in the United States or another processor location. Customers who require a specific transfer mechanism should contact privacy@doorwick.com before using the hosted service.

How long we keep it, and deletion

Account and workspace data stays in the active service while the account or workspace is open. Conversations, their claimed attachments, and knowledge stay until the workspace owner closes the workspace or asks Doorwick to delete them. Unclaimed attachment uploads are temporary and are removed rather than kept as conversation content. Security and operational logs are kept only as long as needed to investigate and operate the service.

Archiving is reversible. An archived account keeps its credentials, identities, memberships, preferences, and shared history so that a later verified sign-in can restore it. Notifications stop and its sessions and registered push devices are revoked while it is archived.

Permanent account deletion removes personal account data. Doorwick removes the login, credentials, identities, sessions, preferences, pending personal uploads, notification records, and workspace memberships. Shared or co-owned workspaces and their customer-controlled conversations remain, but the deleted operator's authorship is anonymized. Eligible workspaces owned only by the deleted person are removed.

Current separate-backup retention window: 0 days. Doorwick does not currently maintain a separate application backup archive, so deleted records are not retained in a backup copy. This policy will be updated before a backup system with a non-zero retention window is introduced.

When a verified deletion request is completed, Doorwick's activity history retains only stable account and workspace identifiers and non-sensitive counts needed for security and operations. It does not retain the deleted email address, credential, message body, provider payload, or Stripe secret. Additional retention may be required for fraud prevention, security, or another legal obligation. Stripe retains payment records under its own policy.

Access, correction, export, and deletion

Account holders can correct many details in the product, export conversations from the dashboard, and archive or permanently delete their account from the web Account page or the iOS and Android app Settings screen. The public account deletion guide explains every path and what happens next.

You may also ask to access, correct, export, restrict, or delete personal data by emailing privacy@doorwick.com from the address connected to the account. We may need enough information to verify that the request belongs to you.

If you chatted through a customer’s widget, contact that workspace owner first because they control the conversation. You can also contact Doorwick with the site, approximate date, and information needed to locate the conversation, and we will coordinate with the workspace owner where appropriate.

How we protect it

Dovecore Software LLC operates Doorwick with workspace access limited by membership and role, each workspace’s records scoped to that workspace, encrypted transport for the hosted service, hashed passwords, verified webhook signatures, provider credentials and site-key secrets encrypted at rest, and native-app session tokens stored in the platform secure store (SecureStore / Keystore) rather than ordinary app storage. Access to production systems is limited to people who need it to operate the service.

No system is perfectly secure. Doorwick does not claim a security or compliance certification it has not earned.

Contact

Questions, rights requests, deletion requests, or complaints: privacy@doorwick.com. Contract and legal questions: legal@doorwick.com.