Privacy Policy

How Doverity collects, uses, and protects personal data.

Last updated: September 4, 2026

1. Who we are

Doverity is built and operated by Ornate Software Solutions Pvt Ltd, a company registered in India. Our registered office is C-202, IT Park Tower 8, CBD Belapur, Navi Mumbai 400614, India. In this policy, "Doverity", "we", "us", and "our" mean Ornate Software Solutions Pvt Ltd.

This policy covers two things:

  • The Site — the website at https://doverity.com.
  • The service — the hosted SEO platform at app.doverity.com.

It sits alongside our Terms and Conditions, which you also accept when you use Doverity.

Email support@doverity.com with any question about your data. That address also reaches our grievance officer, whom you can contact under India's Digital Personal Data Protection Act, 2023.

Doverity is also an open-source project you can self-host. If you run your own instance, you are the operator of it: you choose what it collects and you are responsible for that data. This policy describes the hosted service we run.

2. What we collect

  • Account data. Your name, email address, and password. Your password is stored only as a hash — we never see it in plain text.
  • Organization data. The name and settings of the workspace you set up.
  • Billing identifiers. Your Razorpay customer and subscription IDs and the plan you are on. We never receive your card number or bank details; Razorpay holds those.
  • Credit ledger entries. Records of your metered usage and credit balance, so the app knows what you have used and what is left.
  • Google connection data. The OAuth tokens that let us read the Google Search Console or Google Analytics data you connect, plus the connection details: which site or property you picked and which Google account it belongs to.
  • What you submit. Keyword searches, the sites you audit, the pages you inspect, the prompts you send to Doverity AI, and anything else you type into the service.
  • Server logs. Standard request logs such as IP address, timestamps, URLs, and browser type.
  • Analytics. Cookieless Plausible analytics on the public Site. In the hosted service, PostHog product analytics, error capture, and session replay recordings. Form inputs are masked in those recordings, and text we have flagged as sensitive is masked out as well. PostHog respects your browser's Do Not Track setting.

3. How we use it

  • to create and secure accounts and sign you in;
  • to operate, maintain, and protect the service;
  • to process billing and keep your credit ledger accurate;
  • to fetch the SEO data you ask for and run the AI features you use;
  • to answer your support requests;
  • to understand how the product is used so we can fix what is broken and improve the rest;
  • to send transactional email — address verification, password resets, billing notices, and service announcements.

We do not sell your personal data, and we do not share it for anyone else's advertising. We do not use Google user data for advertising or to train AI models.

4. Who we share it with

We share your data with a short list of providers, each used only on our instructions to run the service for you:

  • Cloudflare — hosts the service and stores data in its D1, R2, and KV storage.
  • Razorpay — processes payments. It receives the billing identity data needed to charge your subscription.
  • DataForSEO — supplies keyword, backlink, and rank-tracking data. It receives your query and returns the data you asked for.
  • OpenRouter — routes AI requests to model providers when you use Doverity AI.
  • Google — the Search Console and Google Analytics APIs you connect.
  • Plausible — cookieless analytics on the public Site.
  • PostHog — product analytics, error capture, and session replay in the hosted service.

We may also disclose information where the law requires it, or where we have a good-faith belief that it is necessary to protect someone's rights, safety, or property, or to detect and stop fraud and abuse.

5. Google user data

You can sign in with Google and connect Google Search Console or Google Analytics to the service. When you do, we read Google user data through Google's APIs with your permission. This section adds to the rest of this policy.

What we can see. Every Google API scope we request is read-only. We cannot change anything in your Google account. Signing in with Google gives us your name, email address, and profile picture so we can create and recognize your account. Connecting Search Console gives us search performance data for the sites you authorize — queries, pages, clicks, impressions, average positions, and URL inspection results. Connecting Analytics gives us report data for the property you choose — traffic and acquisition metrics, landing page and page performance, key events, ecommerce outcomes, site search terms, audience breakdowns by device and country, and configuration details such as your list of properties, data streams, and measurement settings. We also receive the email address of the account you connected, so we can show you which one is linked.

What we do with it. We use Google user data only to run the features you asked for: showing that a connection works, building the SEO reports and insights you requested, and returning the data you asked for, including through AI assistants or MCP clients that you connected yourself. We do not use it for advertising. We do not use it to develop, improve, or train AI or machine learning models. We do not sell it, and we do not hand it to data brokers or advertisers.

Where it goes. Google user data leaves our systems in only three cases. If you connect the service to an AI assistant or other MCP client and request data through it, the results are returned to that client and its own privacy terms apply. If you use Doverity AI, the data needed to answer you is processed by an AI model reached through OpenRouter. And Cloudflare hosts the systems that handle this data on our behalf.

How we protect it. The OAuth tokens that grant access to your Google account are encrypted at rest, and everything travels over encrypted connections. Search Console and Analytics report data is fetched on demand to answer your request and is not stored in our databases.

Keeping or deleting it. Because report data is not stored, there is no copy of it for us to delete. While an integration is connected we keep its tokens and connection details. Disconnecting an integration in your settings removes that connection straight away, and the tokens for a Google account are deleted once none of your projects use it. You can also revoke Doverity's access yourself at any time at https://myaccount.google.com/permissions. Deleting your account revokes our access with Google and erases the data that came with it.

Limited Use. Doverity's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. AI features

When you use Doverity AI, your prompt and the service data needed to answer it are sent to AI models reached through OpenRouter, so that you get a response back. Model output can be incomplete, out of date, or plain wrong — check anything important before you act on it. We do not send your Google user data to train models.

7. Cookies

The public Site uses cookieless analytics, so there is nothing to consent to and no banner. The hosted service uses the session and authentication cookies it needs to keep you signed in. We do not run third-party advertising trackers.

8. Retention and deletion

We keep your account data for as long as your account is active. Delete your account and we erase your organization's data, including its projects and credit history — although we retain the financial and ledger records that Indian law requires us to keep, for as long as it requires.

Google report data is never stored, so there is nothing to delete there. Disconnecting an integration deletes its tokens and connection details. Server logs and analytics records age out on their normal schedule.

9. Your rights

You can ask us to:

  • give you a copy of the personal data we hold about you;
  • correct it if it is wrong or incomplete;
  • erase it;
  • stop processing it by withdrawing your consent;
  • look into a complaint you have raised with us.

These are the rights India's Digital Personal Data Protection Act, 2023 gives you, and we honor similar requests from anywhere — including the access, rectification, erasure, restriction, portability, and objection rights that EU law provides. Email support@doverity.com and we will deal with it.

10. International transfers

The service runs on Cloudflare's global network, so your data may be processed in a country other than your own. Where the law requires a specific safeguard for those transfers, we put it in place.

11. Children

Doverity is not directed at children. As our Terms and Conditions state, you must be at least 18 to use it. If we learn that we have collected personal data from someone under 18, we will delete it.

12. Changes and contact

When we change this policy we will update the date at the top and post the new version on this page. Material changes get a clearer heads-up on the Site, and we may email you as well.

Questions, requests, and grievances:

Doverity — Ornate Software Solutions Pvt Ltd, C-202, IT Park Tower 8, CBD Belapur, Navi Mumbai 400614, India.

Email: support@doverity.com