Privacy Policy
Last updated: July 2026
Docandtell ("we", "us") provides a service that connects to your own third-party tools (such as GitHub, Vercel, Stripe, Sentry, Intercom, Slack, and Telegram) to detect anomalies in your business and notify you about them. This policy explains what data we collect, why, and how it's handled.
What we collect
- Account information: your email address and workspace name, via Supabase Auth.
- Connected service data: events from any third-party source you choose to connect (deploys, errors, payments, support tickets), plus the access tokens/webhook secrets needed to receive that data. These are encrypted at rest (Supabase Vault) and never shown in plain text after initial setup.
- Usage data: how you interact with the dashboard, for the purpose of improving the product.
- Billing information: handled entirely by Stripe — we don't store your card details ourselves.
How we use it
Connected data is used to detect anomalies specific to your business, generate plain-English explanations (using Anthropic's Claude API, where configured), and deliver alerts through the channels you've set up (Telegram, Slack, email via Resend, or the dashboard). We do not sell your data or use it to train third-party models beyond what's needed to generate your own alerts.
Third parties we rely on
Supabase (database, auth, encrypted secret storage), Stripe (billing), Anthropic (LLM explanations), Resend (transactional email), and Vercel (hosting) — plus whichever of GitHub, Vercel, Stripe, Sentry, Intercom, Slack, or Telegram you choose to connect as a data source. Each of those has its own privacy policy governing how they handle data on their end.
Data retention and deletion
You can disconnect any source at any time from the Connections page, which stops new data from being collected. You can request deletion of your account and all associated data by contacting us at the email below.
Security
Connected-service credentials are stored using Supabase Vault (encrypted at rest) and are only decrypted server-side, at the moment they're needed to verify an incoming webhook or make an authorized API call on your behalf.
Contact
Questions about this policy: support@docandtell.com