Skip to content

Privacy Policy

How we use personal data, who receives it, how long we keep it, and your choices.

  • Version 3 October 2026

1. Controller

U-Mutation GmbH
Sonderburger Straße 13 13357 Berlin Germany

Privacy contact: legal@doping.ai

2. Data we process

  • Account data: email address, organization, user ID, login provider, session information, Workspace, and plan.
  • Submitted and public website data: domains, URLs, page content, metadata, structured data, screenshots, and Tracker context.
  • Assessment data: Probes, assistant answers, recommendation outcomes, Competitors, Citations, Content improvements, scores, and Radar content.
  • Billing data: customer and subscription identifiers, plan, payment status, and invoice information. Full card details are handled by the payment provider.
  • Communications: email address, topic, message and optional name from contact enquiries, forwarded through Resend to our business inbox. Contacting us does not enroll you in marketing.
  • Email delivery: preferences, marketing consent records, queued messages, delivery status, bounces, complaints, and unsubscribe records. We also record visits to Overview and Radar to avoid sending irrelevant follow-ups.
  • Technical data: timestamps, operation identifiers, errors, service state, IP address where processed by hosting or authentication systems, and security logs.

Account and billing information needed to provide the service is required for that purpose; without it, we may be unable to create or administer your account. Marketing consent is optional.

3. Purposes and legal bases

Contact enquiries rely on Article 6(1)(b) GDPR for requested pre-contractual steps or contractual support where applicable, Article 6(1)(c) for legal obligations, or Article 6(1)(f) for our legitimate interest in answering other business enquiries. No separate consent is required. To prevent spam, we keep your email address and submission count in server memory for up to one hour.

  • Provide the requested service: Article 6(1)(b) GDPR where the individual is a party to the contract, including accounts, Profiles, assessments, Trackers, monitoring, billing, and support. For users acting on behalf of an organization, Article 6(1)(f) GDPR applies where necessary for our legitimate interest in providing and administering that organization’s service.
  • Meet legal duties: Article 6(1)(c) GDPR, including tax, accounting, and lawful disclosure obligations.
  • Protect and improve service reliability: Article 6(1)(f) GDPR. Our legitimate interests are preventing misuse, securing accounts, diagnosing failures, and operating a reliable service.
  • Analyze public business information: Article 6(1)(f) GDPR for personal data in public-source research. Our legitimate interest is measuring how publicly available business information appears in assistant answers.
  • Deliver results and service notices: the service-delivery bases described above. Initial results are emailed automatically. Monitoring assessment emails are enabled for new accounts; unsubscribe through an email link or Email preferences in Account. Essential account, security, and billing notices may still be sent when needed.
  • Send marketing emails: Article 6(1)(a) GDPR, based on your separate consent. You can withdraw consent at any time without affecting the lawfulness of processing before withdrawal. Accepting the Terms is not marketing consent.
  • Manage email delivery and relevance: Article 6(1)(f) GDPR. Our legitimate interests are honoring preferences, preventing duplicate or unwanted messages, handling delivery failures, and avoiding irrelevant follow-ups. We do not use email opens to infer activity.

4. AI processing and sources

Data comes from you and your organization, selected login and payment services, submitted domains, public web pages, configured AI-model and search services, and the systems used to operate doping.ai.

Probes and relevant public business context are sent to configured AI-model or search services. Returned answers, available Citation URLs, and derived recommendation outcomes are stored. Do not submit confidential information or personal data that is unnecessary for the assessment. doping.ai does not make solely automated decisions that produce legal or similarly significant effects about individuals.

5. Device storage

doping.ai stores authentication information needed to maintain a secure signed-in session and a preference that remembers the Profile expressly selected by the user. Authentication storage remains until sign-out, expiry, or deletion and can persist for up to 400 days. The Profile preference persists for up to one year. Your selected display theme is saved in local storage until you change it or clear that storage.

This storage is used under § 25(2) no. 2 TDDDG. Related personal-data processing follows the service-delivery and security bases described above. Browser controls can delete or block stored information, but blocking authentication storage prevents sign-in.

6. Website analytics

With your optional consent, we use Open Analytics, provided by AGHAZADA LLC (United States), to understand use of our public website. It measures page visits, referrers, campaign parameters, browser and device information, approximate location, interactions, engagement and performance. It excludes sign-in and private application pages, account and assessment data, and form contents. Google Analytics is not used.

Open Analytics redacts its standard sensitive URL parameters and removes fragments; other parameters and sanitized referrer paths may remain. It derives a short-lived pseudonymous visitor identifier from the IP address and browser information, then discards the raw IP address. Visitor analytics is stored and processed in Helsinki, Finland, under the provider’s Data Processing Agreement.

Processing relies on Article 6(1)(a) GDPR. The tracker uses memory only, without analytics cookies or persistent device storage. We save your consent choice in local storage for 180 days under § 25(2) no. 2 TDDDG. Accept and Reject are equally available. Use Cookie settings to withdraw at any time; withdrawal stops future collection without affecting earlier lawful processing. We also honor Global Privacy Control and Do Not Track.

Analytics history is kept while our site exists in Open Analytics and is deleted when we remove the site or account. Under the provider’s standard terms, it expires 30 days after a paid subscription lapses or 10 days after a trial ends without a subscription. Encrypted analytics backups stay in the same EU region: daily copies expire after 30 days and weekly copies after 84 days. Deleted data ages out of existing backups; deletion instructions are re-applied before restored data is served. These periods are separate from application backups below.

7. Recipients and international transfers

Data is shared only as required with service providers for hosting, database and authentication, AI-model and search processing, payments, transactional email, operational logging, website screenshots, and optional federated login. It may also be disclosed to advisers, authorities, or courts where legally required.

Hetzner Online GmbH hosts the application in Nuremberg, Germany, processing application requests and associated technical data. Supabase Pte. Ltd provides managed authentication, application database storage and website screenshot storage, processing account details, sign-in data and stored application content. Vercel Inc. provides AI Gateway services. Requests to the gateway and downstream AI services include Probes, business and website content, answers, evaluation inputs and request metadata, including account identifiers. Configured models and services include OpenAI, Google, Anthropic, Perplexity, xAI, Meta-family models and Typesafe AI’s Jev evaluation service. The downstream inference provider depends on gateway routing. Cloudflare, Inc. provides Browser Rendering to capture public website content and screenshots and extract business information. Cloudflare Email Routing forwards support and legal correspondence to our Gmail inbox, operated by Google. These email services process sender and recipient details, message content, attachments and delivery information. Plus Five Five, Inc. (Resend) delivers account, results and other platform emails and forwards Enterprise inquiries, processing recipient details, message content, links and delivery information. Stripe Payments Europe, Limited provides subscription payment and billing services, processing customer and company details, account identifiers, subscription records and payment information. Stripe also processes data for its own legal, fraud-prevention and payment-service obligations. Better Stack, Inc. processes operational logs, including identifiers, request URLs, timings and error information, for service monitoring and troubleshooting. Google and Microsoft provide optional sign-in when selected by the user, processing sign-in requests and exchanging account identity information. Google also supplies website icons requested directly by the browser, receiving the requested domain or URL and browser request information, including the IP address. External websites receive requests when we inspect public pages. External image hosts receive browser request information, including the IP address, when their images are displayed.

Some recipients may process data outside the European Economic Area. Such transfers require an adequacy decision or appropriate safeguards such as the European Commission’s Standard Contractual Clauses. Copies of applicable safeguards may be requested at legal@doping.ai.

Where personal data is transferred outside the European Economic Area, we rely on an applicable adequacy decision or appropriate safeguards, such as the European Commission's standard contractual clauses. You can request details of the applicable safeguards by contacting legal@doping.ai.

8. Retention and deletion

Use Delete this account in Account to permanently delete your account and every Workspace you own, including their assessments and screenshots. Your memberships and account-owned records in other Workspaces are also removed. Other members lose access to deleted Workspaces but keep their own accounts. There is no waiting period or recovery window.

If deletion fails, your account remains available for retry; subscriptions may already be cancelled and some screenshots removed. We keep no anonymised copy of deleted assessments. Shared public business information used independently across accounts remains.

  • Account and Workspace data: We retain account and Workspace data while the account or Workspace exists. When account deletion completes, the account and all Workspaces it owns are deleted from the application database immediately, without a grace period. Separately retained records are described below.
  • Assessment data: We retain stored assessments and associated personal data while their Profile and Workspace exist. Successful account deletion removes assessments belonging to the deleted account or its owned Workspaces, together with their screenshots. Other users' independently held Profiles for the same business are not deleted; records owned by the deleted account within them are removed. Removing a Tracker stops new cycles but does not delete its existing history.
  • Operational and security logs: The retention period is 30 days, subject to the legal exceptions below.
  • Support and other correspondence: The retention period for support and other business correspondence is 30 days, subject to the legal exceptions below.
  • Email preferences, consent, delivery and suppression records: Account-linked preferences, consent history, activity and application delivery records are removed when account deletion completes. Email-provider records and separate suppression records used to prevent unwanted or undeliverable email have a retention period of 30 days, subject to the legal exceptions below. Suppression records are not removed by the account-deletion operation.
  • Backups: The retention period for application backups is 30 days. Deleted data may remain in an existing backup until that backup expires.
  • Billing records: for the retention period required by applicable tax and commercial law.

Separate logs, correspondence, email suppression records, billing records and backups follow the periods above. Deletion does not erase emails already held in recipients’ inboxes.

Data may be retained longer where required by law or necessary to establish, exercise, or defend legal claims.

9. Your rights

Subject to the GDPR conditions, you may request access, correction, deletion, restriction, and portability. You may object to processing based on Article 6(1)(f) GDPR. Where processing relies on consent, you may withdraw it at any time. You may object to direct marketing at any time. Send requests to legal@doping.ai.

You may lodge a complaint with a supervisory authority, in particular where you live, work, or believe an infringement occurred.

We may verify your identity and authority before acting on a request. Statutory exceptions remain applicable.

10. Changes

Material changes will be dated on this page and communicated through the service or by email where legally required.