Privacy Policy

Effective August 11, 2026

This Privacy Policy describes how UEVNS PTE. LTD. ("Dokki", "we", "us" or "our") collects, uses, discloses, retains, transfers, and protects personal data in connection with the Dokki service at dokki.one, our hosted Model Context Protocol (MCP) servers, plugins, connectors, and related services (collectively, the "Services"). UEVNS PTE. LTD. operates the Services. Our Data Protection Officer may be contacted at privacy@dokki.one.

Our role and enterprise customer data

For personal data that we collect and use for our own purposes, such as account, billing, security, support, and website data, UEVNS PTE. LTD. is the organization responsible for that processing. Where an enterprise customer determines the purposes and means of processing personal data in its Dokki workspaces, the customer acts as the organization or data controller and UEVNS PTE. LTD. acts as its data intermediary or data processor. We process that customer data on the customer's documented instructions and under the applicable agreement. Requests concerning customer-controlled workspace data should normally be directed to that customer.

Information we collect and its sources

How we use information

Where applicable law requires a legal basis, we rely on performance of a contract, compliance with legal obligations, legitimate interests in operating and protecting the Services, or consent, as appropriate to the relevant purpose.

Plugins, connectors, and MCP clients

A connected client authenticates to Dokki using an available authorization method, such as OAuth or an API key. Its access is limited by the authorization granted to it and Dokki's applicable organization, workspace, role, and resource permissions. At your direction, a client may read, create, edit, search, or publish authorized resources. You can revoke supported connections from Dokki settings. Revocation prevents new access through that credential but does not retrieve information that an external client previously received.

AI features

When you invoke an AI feature, Dokki sends the instructions, content, and context needed to perform that request to the selected or configured model provider. Dokki does not use workspace content to train its own general-purpose AI models. A model provider's handling of data is governed by the service configuration and the provider terms applicable to that processing. Enterprise agreements may include additional data-processing terms.

Sharing and disclosure

We do not sell personal data or workspace content. We may disclose data:

Service providers are permitted to process personal data only for the services they provide to us and are subject to contractual confidentiality and data-protection obligations, as applicable.

Cookies, local storage, and analytics

Dokki uses cookies or similar storage that are necessary for authentication, security, preferences, and core service functions. On our public marketing pages, we may also use optional analytics and advertising measurement services, including Vercel Analytics and Speed Insights, Cloudflare Web Analytics, Ahrefs Web Analytics, and Google Ads measurement. We do not load these marketing technologies in authenticated Dokki workspace pages. These services may process identifiers, device and browser information, IP address, pages viewed, and interaction or performance events according to their applicable terms.

Where applicable law requires prior consent, optional analytics and advertising measurement remain disabled until you accept them. In other regions, these technologies may operate when you visit our public marketing pages, subject to this Policy. Rejecting them does not prevent you from using Dokki. You can change your choice at any time using . Changing your preference controls future loading; you may also clear existing browser storage through your browser settings.

Data retention and deletion

We retain personal data only while it is reasonably needed for the purposes described above, including to provide an active account or workspace, protect the service, meet contractual and legal obligations, resolve disputes, and enforce agreements. Retention varies by the data's nature, sensitivity, purpose, and legal requirements. When data is no longer needed, we delete or de-identify it. Deletion from active systems may not immediately remove limited copies from backups, logs, or records that must be retained for security, fraud prevention, or legal purposes; those copies remain protected and are removed or overwritten under their applicable lifecycle.

International data transfers

We and our service providers may process personal data in countries or territories other than the country where it was collected. Where personal data is transferred outside Singapore, we take steps required by applicable law to ensure that the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to the protection under Singapore's Personal Data Protection Act 2012. Where another transfer regime applies, we use an applicable recognized transfer mechanism or exception. Contact our Data Protection Officer for information about safeguards relevant to your personal data.

Security

We use administrative, technical, and organizational measures designed to protect personal data, including encryption in transit, access controls, tenant-aware authorization, and row-level security for stored workspace data. Connector secrets managed by Dokki are stored encrypted. No system is completely secure, and users are responsible for protecting their accounts, credentials, and authorized clients.

Your choices and rights

Subject to applicable law and exceptions, you may request access to personal data that we hold about you, information about how it was used or disclosed, or correction of an error or omission. Depending on your location, you may also have rights to deletion, restriction, objection, or portability. You may withdraw consent by giving us reasonable notice. Withdrawal does not affect processing that occurred before withdrawal; depending on the personal data and purpose involved, it may prevent us from continuing to provide a relevant feature or the Services. We will explain the likely consequences before completing the withdrawal where required.

We may verify your identity and authority before acting on a request. You may also submit a complaint to us or to the competent data protection authority. To exercise a right, withdraw consent, or submit a complaint, email privacy@dokki.one. If an organization controls the relevant workspace, you should normally submit the request to that organization first.

Children

Dokki is intended for business and professional use and is not directed to children. If you believe a child provided personal data without the authorization required by applicable law, contact us so we can review and take appropriate action.

Changes to this policy

We may update this Privacy Policy to reflect changes in the service, our practices, or law. We will post the updated policy and effective date here and provide additional notice when appropriate or required.

Contact us

For privacy questions, rights requests, withdrawal of consent, or complaints, contact our Data Protection Officer at privacy@dokki.one.