DDAI Privacy Policy

Effective date: 2026.08.10
Last updated: 2026.08.10
Version: 2.0


1. Overview

This Privacy Policy describes how DATA DISCOURSE AI, INC. ("Data Discourse AI," "DDAI," "we," "our," or "us") collects, uses, shares, and protects information.

It applies to:

  • our websites, including www.datadiscourse.ai (the "Sites");
  • the DDAI application, chat interface, and dashboard;
  • the DDAI MCP server and ODBC endpoints, through which data may be accessed by AI clients and business intelligence tools; and
  • our related products and services (collectively, the "Services").

By accessing or using the Sites or Services, you agree to this Privacy Policy.

This Privacy Policy does not apply to our employees or job applicants, which are covered by a separate notice.

Age restriction. The Services are intended for businesses, not consumers. They are not directed to individuals under 16, and we do not knowingly collect personal information from individuals under 16. If we learn we have collected such information, we will delete it.


2. The most important thing to understand: two very different kinds of data

DDAI handles two categories of information that are governed differently. Please read this section first — the rest of this policy depends on the distinction.

2.1 Account and Site Data — we are the controller

This is information about you and your organization as our customer: your name, work email, account credentials, billing details, support correspondence, and how you use our Sites and Services. We decide how this information is used, and this Privacy Policy governs it directly. Section 4 describes it.

2.2 Connected Business Data — we are a processor acting on your instructions

When you connect a data source such as HubSpot, QuickBooks, or Stripe, we ingest records from that source into a data environment we operate for your organization. That may include information about your customers, contacts, invoices, deals, and payments — including personal information about individuals who are not our customers.

For this data:

  • Your organization is the controller (or "business," under U.S. state privacy laws). We act as a processor (or "service provider").
  • We process it only on your organization's documented instructions and only to provide the Services to your organization.
  • We do not sell it, share it for cross-context behavioral advertising, or use it for our own marketing.
  • We do not use it to train, fine-tune, or improve any artificial intelligence or machine learning model — not ours, and not any third party's. Our agreements with our AI subprocessors prohibit this. See Section 6.
  • If an individual whose data appears in your connected sources contacts us to exercise a privacy right, we will refer them to your organization and assist you in responding, as required by law and our agreement with you.

Our processing of Connected Business Data is governed by our customer agreement and Data Processing Addendum ("DPA"), which controls over this Privacy Policy in the event of a conflict. To request a copy of the DPA, contact us using Section 15.


3. Summary of what we do and don't do

Do we sell your personal information? No.
Do we sell or share Connected Business Data? No.
Do we use your business data to train AI models? No.
Do we use AI to process your data? Yes — see Section 6.
Can other DDAI customers see your data? No — each customer's data is stored in a separate database schema with its own credentials. See Section 8.
Do we use cookies and analytics on our Sites? Yes — see Section 9.
Can you delete your data? Yes — see Sections 11 and 12.

4. Personal information we collect, why, and who we share it with

Category Examples Purpose for processing Categories of third parties shared with
Identifiers Name, email address, account ID, user ID, device ID, IP address, transaction identifiers Provide, support, and improve the Services; authenticate users; communicate with you; billing and administration; security and fraud prevention; marketing our Services Service providers; analytics and advertising partners
Customer records Name, business address, telephone number, billing contact. Our payment processor collects transaction data (date, amount, card details, postal code) — we do not store full payment card numbers Provide and support the Services; billing, invoicing, and collections; customer support Payment processor; service providers; professional advisors
Commercial information Subscription tier and plan, products or services purchased or considered, connected data sources, billing history Provide and support the Services; billing; account management; product analytics Service providers
Internet and usage activity Pages viewed, features used, chat and MCP query volume and timestamps, tool calls, error and diagnostic logs, referring URL, browser and device type Operate, secure, and improve the Services; troubleshoot; detect abuse; measure product usage Service providers; analytics providers
Approximate geolocation Coarse location inferred from IP address Security, fraud prevention, and regional service configuration Service providers
Authentication and access credentials Account credentials (hashed), OAuth tokens and refresh tokens for connected sources, MCP client registrations, API keys Authenticate you; maintain authorized connections to your data sources; enforce per-tenant access controls; audit access Service providers (identity and infrastructure)
Content you submit Chat prompts and questions, saved queries, semantic model definitions and metric names, support tickets, feedback Deliver the Services; generate answers; provide support; improve the Services (see Section 6 for limits on AI training) AI model providers; service providers
Audit records Records of MCP tool calls, queries executed, the identity making them, and timestamps Security, compliance, incident investigation, and customer-facing audit trails Service providers; disclosed to your organization's administrators

We do not intentionally collect sensitive personal information (such as government identifiers, precise geolocation, health information, or biometric data) about our users, and we ask that you not submit it to the Services. Connected Business Data may contain categories of information determined by your own source systems, which is why the controller/processor distinction in Section 2 matters.


5. How we collect information

  • Directly from you — when you create an account, fill out a form, subscribe to our newsletter, contact support, respond to surveys, or interact with our marketing.
  • Automatically — through cookies, analytics tools, server logs, and application telemetry when you use the Sites or Services (see Section 9).
  • From your connected data sources — when you authorize a connection to HubSpot, QuickBooks, Stripe, or another supported source, we ingest data from that source using the permissions you grant. We request read-only access wherever the source supports it.
  • From service providers and partners — such as our payment processor, identity providers, and marketing platforms.
  • From social media — if you interact with our accounts, we may receive your name, username, profile, and interaction data.

6. Artificial intelligence, automated processing, and model providers

This section describes how AI is used in the Services. It is intended to satisfy transparency expectations under U.S. state privacy laws and the requirements of AI platform directories and app marketplaces.

6.1 How the Service uses AI

When you ask a question in DDAI chat, or when an AI client queries our MCP server, we:

  1. send your question, together with relevant metadata (table names, column names, metric definitions, and the semantic model for your organization) to a third-party large language model provider;
  2. receive back a proposed query, which is validated against a read-only allow-list and executed against your organization's own data environment; and
  3. send the resulting rows back to the model provider so it can render an answer in plain language, unless you are using an interface that returns results directly.

This means query results — which may include Connected Business Data — are transmitted to our AI model provider as part of generating an answer. They are transmitted in transit under encryption and processed under a contract that prohibits training on them.

6.2 Our AI model provider

We currently use Anthropic, PBC as our large language model provider, under Anthropic's commercial terms.

  • Anthropic does not train its models on data submitted through its commercial API.
  • We do not consent to, and have not enabled, any use of your inputs or outputs for model training.
  • We may change or add model providers. We will update the subprocessor list (Section 10) and, where required, provide advance notice.

6.3 Limits we commit to

  • We do not use Connected Business Data, chat prompts, chat outputs, or query results to train, fine-tune, or evaluate any AI model.
  • We do not use one customer's data to answer another customer's questions or to improve results for another customer.
  • We do use aggregated, de-identified operational metrics (for example, "average queries per week," "percentage of queries that returned an error") to improve the Services. These metrics do not identify you, your organization, or any individual, and we do not attempt to re-identify them.

6.4 Accuracy and automated decision-making

AI-generated answers may be incomplete or incorrect. The Services are decision-support tools; they are not a substitute for professional accounting, tax, legal, or financial advice. We do not use AI to make automated decisions that produce legal or similarly significant effects about individuals. Where the Services surface a score or signal about one of your customers, that output is a suggestion for your organization to evaluate, and your organization is responsible for how it is used.

6.5 Human access to your data

We restrict human access to Connected Business Data to a limited number of authorized personnel, only where necessary to operate the Services, investigate a security incident, or respond to a support request you initiate. Such access is logged. We do not routinely review the contents of your data or your chat conversations.


7. The DDAI MCP server and third-party AI clients

DDAI operates a Model Context Protocol (MCP) server that lets AI clients — including Claude.ai, Claude Code, and other MCP-compatible tools — query your organization's data with your authorization.

7.1 How access is authorized

  • Connections use OAuth 2.0 with dynamic client registration and PKCE. You authorize a client explicitly; we never ask for or store your credentials for third-party AI tools.
  • Each connection is bound to a single tenant and authenticates as a read-only database role scoped to that tenant's schema only.
  • The tools we expose are read-only. They can list tables, describe schemas, retrieve the semantic model, compile metric queries, and run validated read-only queries. They cannot write, modify, or delete your data.
  • Queries are validated against an allow-list and bounded by execution timeouts.
  • Every tool call is logged, including the identity, the tool invoked, and the time.

7.2 Important: what happens once data reaches your AI client

When you connect a third-party AI client to DDAI, data returned by our MCP server is delivered to that client and becomes subject to that provider's privacy policy and terms — not ours. For example, if you connect Claude.ai, the query results appear in your Claude conversation and are handled under Anthropic's consumer or commercial terms, as applicable to your account.

We cannot control, and are not responsible for, how a third-party AI client stores, retains, or processes data after we deliver it. Please review the privacy policy of any AI client before connecting it, and consider which of your organization's users should be permitted to establish connections.

7.3 Revoking access

You can revoke an MCP connection at any time from your DDAI account settings, which immediately invalidates the associated credentials. You should also disconnect the connector inside the AI client itself. Revoking a connection stops future access; it does not delete data the AI client has already received.


8. Tenant isolation

Each DDAI customer's data is stored in its own dedicated database schema, accessed through its own dedicated database role with permissions restricted to that schema. There is no shared data layer between customers, and one customer's credentials cannot read another customer's schema. This is enforced structurally by database permissions, not solely by application logic.


9. Cookies, analytics, and marketing

Our Sites use cookies and similar technologies for essential functionality, preferences, security, and analytics. We use Google Analytics, Google Tag Manager, and other tools to understand how visitors use our Sites.

  • You can manage cookies through your browser settings.
  • You can opt out of Google Analytics via Google's browser opt-out add-on.

We do not use cookies, analytics, or advertising technologies inside the authenticated DDAI application in a way that transmits Connected Business Data to advertising partners.


10. How we share information, and our subprocessors

We share information with:

  • Service providers and subprocessors — cloud infrastructure, data pipeline, AI model, payment, email, support, analytics, and security vendors, each bound by contract to use the information only to provide services to us.
  • Your organization — if you use the Services under an account administered by your employer, your administrators may access your account information and usage records.
  • Professional advisors — legal, accounting, insurance, and audit providers.
  • Legal authorities and other parties — where we believe disclosure is required by law, subpoena, or legal process, or is necessary to enforce our rights, investigate fraud or abuse, or protect the safety of any person.
  • In a corporate transaction — in connection with a merger, acquisition, financing, or sale of assets, subject to this Privacy Policy or a successor policy with equivalent protections.
  • With your consent or at your direction — including when you authorize an MCP connection or a third-party integration.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under U.S. state privacy laws.

Current subprocessors

Subprocessor Purpose Data processed
Microsoft Azure Application and database hosting Account Data; Connected Business Data
Fivetran Data pipeline / source ingestion Connected Business Data
Anthropic, PBC Large language model processing Chat prompts, semantic model metadata, query results
Stripe Payment processing and subscription billing Billing and transaction data
Google Gmail Account, support, and product email Name, email address
Google (Analytics, Tag Manager) Website analytics Site usage data, IP address
Squarespace Marketing website hosting Site usage data, form submissions
HubSpot Service Hub Customer support Name, email, support correspondence

We maintain the current list (available on request) and will provide notice of material changes to customers as described in our DPA.


11. How we protect information

We maintain administrative, technical, and physical safeguards designed to protect information against loss, misuse, and unauthorized access, disclosure, alteration, or destruction. These include:

  • encryption of data in transit (TLS) and at rest;
  • per-tenant database isolation with dedicated, least-privilege credentials (Section 8);
  • read-only enforcement and query validation for all AI and MCP access paths;
  • audit logging of data access;
  • role-based access control and least-privilege administrative access;
  • monitoring, alerting, and a documented incident response process; and
  • vendor security review for subprocessors.

No system is perfectly secure, and we cannot guarantee the security of any information. If we become aware of a breach affecting your personal information, we will notify you as required by applicable law and our agreement with you.


12. How long we retain information

Data Retention
Account and billing records For the life of the account, then as required for legal, tax, and accounting obligations (7 years)
Connected Business Data For the life of the account. When you disconnect a source, we cease ingestion and delete the associated data within 30 days
Chat conversations and saved queries Until you delete them, or within 30 days of account termination
Audit and security logs 24 months
Marketing contact data Until you unsubscribe or request deletion
Backups Deleted data persists in encrypted backups for up to 35 days before being overwritten

On termination, we delete or return Connected Business Data as specified in our customer agreement. We may retain de-identified or aggregated data indefinitely.


13. Your privacy rights

13.1 U.S. state privacy rights

If you are a resident of a U.S. state with a comprehensive consumer privacy law — including California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia — you may have the following rights, subject to exceptions and limitations under applicable law:

  • Right to know the categories and specific personal information collected, the sources, the purposes, and the categories of third parties we share it with;
  • Right to access a copy of your personal information;
  • Right to correct inaccurate personal information;
  • Right to delete personal information we collected from you;
  • Right to data portability in a portable, machine-readable format;
  • Right to opt out of sale, of sharing for cross-context behavioral advertising, and of profiling in furtherance of decisions producing legal or similarly significant effects;
  • Right to appeal a denial of a request; and
  • Freedom from discrimination for exercising these rights.

Requests about Connected Business Data. If your request concerns information we process on behalf of one of our customers (Section 2.2), we will direct you to that customer, who is the controller.

13.2 How to exercise your rights

Contact us using Section 15. Your request must include enough information for us to verify your identity — typically by confirming account details, or by providing verification information we reasonably request. We cannot fulfill a request we cannot verify. Information provided for verification is used only for that purpose.

An authorized agent may submit a request on your behalf with written authorization and, where required, verification of your identity.

We will acknowledge receipt and respond substantively within 45 calendar days, or notify you in writing of an extension of up to a further 45 days (90 days total). You may appeal a decision by contacting us; we will respond to appeals within the time required by applicable law.

You may submit a request to know twice within a 12-month period unless applicable law grants additional rights.

Persons with disabilities may request this notice in an alternative format by contacting us.

13.3 Nevada

Nevada residents have the right to opt out of the sale of certain covered information. We do not engage in such sales.

13.4 California "Shine the Light"

California residents may request information about disclosures of certain categories of personal information to third parties for those third parties' direct marketing purposes during the prior calendar year. Contact us as described below.

13.5 Individuals outside the United States

We currently offer the Services only in the United States, and the Services are not directed to residents of other countries. Information we collect is stored and processed in the United States.


14. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated policy here and revise the "Last updated" date. For material changes, we will provide notice — by email to account administrators or through the Services, unless a shorter period is required by law. Your continued use of the Sites or Services after the effective date constitutes acceptance.


15. Contact us

DATA DISCOURSE AI, INC.
5915 SE TAYLOR ST
Portland, OR 97215