Privacy policy

Effective [DATE]. Datagoat is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS] ("Datagoat", "we"). Contact: privacy@datagoat.io.

This policy covers datagoat.io, api.datagoat.io, the Datagoat MCP server, the Datagoat API and the Datagoat SDKs.

What we collect

How we use it

We use it to answer your questions, to meter usage, to secure and operate the service, and to contact you about your account. We do not sell your data. We do not use your rows or answers to build models for anyone else: every model is fitted for one workspace, from that workspace's data. Datagoat does not send your data to AI model providers.

When you use Datagoat through an AI assistant (Claude, ChatGPT or another MCP host), the assistant sends us the tool arguments and receives our answers. What the assistant keeps is governed by its provider's policy.

How long we keep it

What How long
Rows sent with an ask Deleted when the call ends
Datasets you store, and their profile (column names, and the values of columns with at most 12 distinct values) Deleted 24 hours after last use, or when you delete them
Answers 24 hours
Fitted models (no rows) 90 days
Reported outcomes For as long as the model's track record is kept, or until you ask us to delete them
Usage counts and billing records As long as the law requires
Account details and API keys Until you delete your account
Service logs [30] days

Details are on the Your data page.

Who processes it for us

Provider Purpose Region
Vercel Hosting the website, API and MCP server [REGION]
Neon The database of accounts, keys, dataset records and usage [REGION]
Clerk Sign-in and OAuth [REGION]
Modal Running the analysis engine [REGION]
[OBJECT STORE PROVIDER] Temporary storage of rows under analysis [REGION]

We share data with others only when the law requires it, or to protect the service and its users.

Your choices and rights

Data you should not send

Datagoat is not designed for health information about identifiable people, payment card or bank account numbers, government identifiers, or credentials. Do not send them.

Security

Traffic is encrypted in transit (HTTPS). Keys are stored hashed. Rows are held in memory while a call runs and are stored only in the analysis engine's object store, for the periods above. Every answer is signed, so it can be checked for tampering.

Children

Datagoat is not directed at children under 16, and we do not knowingly collect their data.

Changes

We will post changes here and update the effective date. If a change materially reduces your rights, we will tell account holders by email before it takes effect.