Privacy Policy
Version 2026-09-28 · Effective September 28, 2026
This Privacy Policy explains how DoubleX ("DoubleX", "we", "us") processes personal data in connection with the DoubleX platform at infra.doublex.ai, its console, API, MCP server, command-line tool and hosted apps (the "Service"). It applies to people who create an account or use the Service ("builders"), visitors of our site, and, in the limited way described in section 2, end users of apps published by our customers.
It is written to meet Brazil's General Data Protection Law (LGPD, Law 13,709/2018), the EU and UK General Data Protection Regulation (GDPR) and US state privacy laws such as the California Consumer Privacy Act (CCPA/CPRA).
1. Who is responsible
For account, billing, site and platform operation data, DoubleX is the controller.
Contact for any privacy matter, including our data protection officer ("encarregado"): privacy@doublex.ai.
2. Two roles: controller and processor
Data about you as a builder (your account, your organization, how you use the Service) is processed by DoubleX as controller, under this Policy.
Data that you or your AI agent load into the Service (tables, files, metrics, apps) and data of end users you invite to your apps belong to the customer that published them. For that data the customer is the controller and DoubleX is a processor acting on the customer's instructions, under section 4 of the Terms of Service. If you are an end user of an app hosted on DoubleX, the company or person that runs the app decides how your data is used; send your requests to them. If you contact us, we will forward your request to them.
3. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account | name, email, sign-in method (email and password or Google), identifier at our authentication provider | you, WorkOS, Google |
| Organization | organization name, members and roles, plan, projects | you |
| Billing | billing email, plan, invoices, payment status, country and tax data. Card data is handled by Stripe and never reaches us | you, Stripe |
| Usage and security | API, MCP and console requests, IP address, user agent, timestamps, audit events (who changed what and when), errors | automatically |
| Credentials | hashes and metadata of personal access tokens and MCP connections (never the token in clear text) | automatically |
| Communications | messages you send to us | you |
| Cookies | session cookie for signing in, language preference, your cookie choice; analytics cookies only if you accept them (section 5A) | automatically |
We do not use advertising or cross-site tracking cookies, and we do not buy personal data.
4. Why we use it and legal bases
| Purpose | LGPD basis (art. 7) | GDPR basis (art. 6) |
|---|---|---|
| Create and operate your account and provide the Service | performance of contract (V) | contract (b) |
| Billing, invoices and tax obligations | contract (V) and legal obligation (II) | contract (b) and legal obligation (c) |
| Security, fraud and abuse prevention, audit trail | legitimate interest (IX) and exercise of rights (VI) | legitimate interests (f) |
| Service emails (security, billing, changes to terms) | contract (V) | contract (b) |
| Improving the Service with aggregated usage metrics | legitimate interest (IX) | legitimate interests (f) |
| Site analytics with Google Analytics, only after you accept analytics cookies | consent (I) | consent (a) |
| Responding to authorities and legal claims | legal obligation (II) and exercise of rights (VI) | legal obligation (c) and legitimate interests (f) |
Where we rely on legitimate interest, we have weighed it against your rights; you may object as described in section 8. We do not make decisions with legal effect about you based solely on automated processing.
5. AI
DoubleX does not provide an AI model and does not send your data to an AI provider of its own choice. AI features in apps use the customer's own AI provider and key; that provider is chosen by the customer and processes data under the customer's agreement with it. We do not use your data or Customer Data to train AI models.
5A. Cookies and analytics
The console uses cookies that are necessary for it to work: the session cookie that keeps you signed in, your language preference and the record of your cookie choice (kept for 12 months). They do not need consent.
With your consent only, the console at infra.doublex.ai uses Google Analytics 4 to understand how the site is used (pages visited, device type, approximate location derived from the IP address). We use Google's Consent Mode: until you choose, nothing is stored and analytics storage stays denied; if you accept, only analytics storage is enabled. Advertising storage, ad personalization and Google signals are always off. The _ga cookies are set only on the console's host, for up to 2 years, and page addresses are sent without query strings and with identifiers replaced, so they carry no account data. Apps published by our customers do not load our analytics.
You can change your choice at any time on the Cookies page; withdrawing consent stops collection from then on. Google processes this data as our processor under the Google Ads and Measurement data processing terms.
6. Sharing and subprocessors
We share personal data only with the providers below, which process it on our behalf under contracts with confidentiality and security obligations, with authorities when the law requires, and with a successor in a merger or acquisition. We do not sell or "share" personal data for cross-context behavioral advertising, as those terms are defined in the CCPA.
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud (Google LLC) | hosting, database, data lake, app runtime, end-user sign-in (Identity Platform), logs | Brazil (São Paulo, southamerica-east1) |
| Cloudflare, Inc. | DNS, network edge, TLS certificates, routing to apps and custom domains | global network |
| WorkOS, Inc. (AuthKit) | builder sign-in and account identity | United States |
| Stripe, Inc. and affiliates | payments, subscriptions, invoices | United States and other countries |
| Google (Sign in with Google) | only when you choose to sign in with Google | United States and other countries |
| Google LLC (Google Analytics 4) | site analytics, only with your consent (section 5A) | United States and other countries |
A transactional email provider will be added to this list before we send email through it. We will update this list at least 15 days before adding a subprocessor that processes Customer Data.
7. International transfers
Customer Data and our main database are stored in Brazil. Some providers above process account and billing data outside Brazil, in particular in the United States. We carry out these transfers under the mechanisms of the law that applies: for the LGPD, art. 33 and the standard contractual clauses of ANPD Resolution CD/ANPD 19/2024; for the GDPR and UK GDPR, the European Commission's standard contractual clauses, the UK addendum or an adequacy decision, including the EU-US Data Privacy Framework where the provider is certified.
8. Your rights
Depending on where you live, you have the right to:
- confirm whether we process your data and access it;
- correct incomplete, inaccurate or outdated data;
- request anonymization, blocking or deletion of unnecessary or unlawfully processed data;
- data portability;
- delete data processed with your consent, and withdraw consent;
- information about who we share data with;
- object to processing based on legitimate interest;
- restrict processing (GDPR);
- know, delete and correct personal information, and not be discriminated against for exercising your rights (CCPA/CPRA);
- lodge a complaint with a supervisory authority: in Brazil, the ANPD (Autoridade Nacional de Proteção de Dados); in the EU or UK, your local data protection authority.
Most account data can be seen and changed in the console. For anything else, write to privacy@doublex.ai from the email of your account. We may need to confirm your identity. We answer within 15 days, or within the shorter period that the law applicable to you requires. You may use an authorized agent where the law allows.
9. Retention
| Data | How long |
|---|---|
| Account and organization | while the account is active; deleted when you close the account, except as below |
| Projects and Customer Data | until you delete the project; resources deleted within 7 days of deletion |
| Database backups | point-in-time recovery for 7 days; weekly exports kept for 35 days |
| Deleted data lake files | recoverable for 7 days, then deleted |
| App logs | 7 days on the free plan, 30 days on paid plans |
| Analytics data (Google Analytics) | up to 14 months in Google Analytics; _ga cookies up to 2 years or until you withdraw consent |
| Audit events | as long as needed to meet legal obligations and to exercise or defend rights |
| Billing and tax records | for the period required by tax law (in Brazil, at least 5 years) |
10. Security
We apply encryption in transit and at rest, logical isolation between customers with a catalog, credentials and policies per project, access tokens with limited scopes, stored only as hashes, secrets kept in a secret manager and referenced by name, validation of SQL before execution, least-privilege access for our team and an audit trail of changes. No system is completely secure; if an incident creates relevant risk or damage to you, we will notify you and the competent authorities as the law requires.
11. Children
The Service is not intended for anyone under 18, and we do not knowingly collect their data. If you believe a minor has given us personal data, contact us and we will delete it.
12. Changes to this Policy
We may update this Policy. We will announce material changes at least 30 days in advance, by email or in the console. The version and date are at the top of this page.
13. Contact
DoubleX · privacy@doublex.ai