Privacy Policy

Last updated: May 4, 2026

1. Introduction

Dottr of IQ ("we," "our," "us," or the "Company") is committed to protecting your privacy and personal data. This Privacy Policy ("Policy") explains how we collect, use, disclose, retain, and safeguard your information when you access or use our service ("Service"). By using the Service, you consent to the data practices described in this Policy. If you do not agree with any part of this Policy, you must discontinue use of the Service immediately.

2. Information We Collect

Information You Provide Directly

  • Account Information: Email address, name, professional credentials, specialty field, and profile picture
  • Content: Documents you upload, analyses you create, templates you configure, and any other materials submitted through the Service
  • Communications: Messages, feedback, support requests, and correspondence you send to us
  • Payment Information: Billing details processed through our third-party payment processors (we do not directly store full payment card numbers)

Information Collected Automatically

  • Usage Data: Pages visited, features used, time spent, actions taken, click patterns, and interaction sequences
  • Device Information: Browser type and version, operating system, device identifiers, screen resolution, and hardware specifications
  • Log Data: IP address, access times, referring URLs, error logs, and diagnostic data
  • Cookies and Tracking Technologies: Session identifiers, preference data, and analytics information (see Section 9)

3. How We Use Your Information

We use collected information for the following purposes, each constituting a legitimate interest or contractual necessity:

  • Provide, operate, maintain, and improve the Service
  • Process your content and generate AI-powered analyses and outputs
  • Communicate with you about updates, features, security alerts, and support
  • Ensure the security, integrity, and availability of the Service and prevent fraud or abuse
  • Comply with legal obligations, law enforcement requests, and regulatory requirements
  • Analyze aggregated and anonymized usage patterns to enhance user experience and Service performance
  • Enforce our Terms of Service and other agreements
  • Protect the rights, property, and safety of Dottr of IQ, our users, and the public

4. AI Processing and Third-Party Services

Your content may be processed by AI systems operated by us and our third-party service providers (including Google AI and other machine learning platforms) to deliver the Service's core functionality. You acknowledge and agree that:

  • Content submitted for AI processing may be transmitted to and processed on servers operated by third-party AI providers
  • While we implement contractual and technical safeguards, content processed by third-party AI systems may be subject to their respective privacy policies and data handling practices
  • We do not use your content to train our or third-party AI models without your explicit, separate consent
  • We cannot guarantee the absolute confidentiality of data processed through third-party AI systems
  • You are solely responsible for ensuring that content you submit for AI processing does not contain protected health information (PHI) or other data whose processing would violate applicable laws

5. Data Sharing and Disclosure

We may share your information in the following circumstances:

  • Service Providers: Third-party vendors, contractors, and agents who perform services on our behalf (hosting, analytics, AI processing, payment processing, customer support), subject to contractual confidentiality obligations
  • Legal Requirements: When required by law, subpoena, court order, or governmental regulation, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others
  • Business Transfers: In connection with any merger, acquisition, reorganization, sale of assets, or bankruptcy proceeding, in which case your information may be transferred as a business asset
  • With Your Consent: When you explicitly authorize sharing for a specific purpose
  • Aggregated/De-identified Data: We may share anonymized, aggregated data that cannot reasonably be used to identify you for research, analytics, or business purposes

We do not sell your personal information to third parties for their direct marketing purposes.

6. Data Security

We implement commercially reasonable technical and organizational measures to protect your data, including encryption in transit (TLS) and at rest, access controls, regular security assessments, and incident response procedures. However, no method of electronic transmission or storage is 100% secure. WE CANNOT AND DO NOT GUARANTEE THE ABSOLUTE SECURITY OF YOUR DATA. You acknowledge that you transmit data to and through the Service at your own risk, and you are responsible for maintaining the security of your account credentials and any devices used to access the Service.

7. Data Retention

We retain your personal information for as long as your account is active or as reasonably needed to provide the Service, comply with our legal obligations (including tax, accounting, and regulatory requirements), resolve disputes, enforce our agreements, and prevent fraud. We may retain certain information in anonymized or aggregated form indefinitely. Upon account deletion, we will remove your personal data within a commercially reasonable timeframe, except where retention is required or permitted by law. Backup copies may persist for up to 90 days following deletion.

8. Your Rights

Depending on your location and applicable law, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your data, subject to legal retention requirements
  • Portability: Request transfer of your data in a structured, machine-readable format
  • Restriction: Request limitation of processing in certain circumstances
  • Objection: Object to processing based on legitimate interests or direct marketing
  • Withdraw Consent: Where processing is based on consent, withdraw that consent at any time (without affecting the lawfulness of prior processing)

To exercise these rights, contact us at the address below. We will respond within the timeframe required by applicable law (typically 30 days). We may request verification of your identity before processing your request. Certain requests may be subject to exceptions or limitations under applicable law.

9. Cookies and Tracking Technologies

We use cookies, web beacons, pixels, and similar tracking technologies to maintain your session, remember preferences, authenticate users, and analyze usage patterns. Essential cookies are strictly necessary for the Service to function and cannot be disabled. Analytics and preference cookies may be managed through your browser settings. Disabling certain cookies may impair Service functionality. We do not respond to "Do Not Track" browser signals at this time due to the lack of an industry-wide standard for compliance.

10. International Data Transfers

Your information may be transferred to, stored, and processed in the United States and other countries where our service providers maintain facilities. These countries may have data protection laws that differ from those in your jurisdiction. By using the Service, you consent to such transfers. We implement appropriate safeguards for international data transfers, including Standard Contractual Clauses (SCCs) approved by the European Commission, data processing agreements, and compliance with applicable data protection frameworks.

11. Children's Privacy

The Service is not intended for, directed to, or designed to attract individuals under the age of 18. We do not knowingly collect, solicit, or maintain personal information from children under 18. If we become aware that we have collected data from a child under 18, we will take prompt steps to delete such information. If you believe a child has provided us with personal data, please contact us immediately.

12. Healthcare Data Disclaimer

DOTTR OF IQ IS NOT A COVERED ENTITY UNDER THE HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) AND THE SERVICE IS NOT DESIGNED OR INTENDED TO STORE, PROCESS, OR TRANSMIT PROTECTED HEALTH INFORMATION (PHI) AS DEFINED UNDER HIPAA. YOU ARE SOLELY RESPONSIBLE FOR ENSURING THAT YOU DO NOT UPLOAD, TRANSMIT, OR OTHERWISE SUBMIT ANY PHI OR PATIENT-IDENTIFIABLE INFORMATION TO THE SERVICE. IF YOU REQUIRE HIPAA-COMPLIANT DATA PROCESSING, YOU MUST SEEK AN ALTERNATIVE SERVICE. WE DISCLAIM ALL LIABILITY ARISING FROM YOUR SUBMISSION OF PHI TO THE SERVICE.

13. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by posting the revised Policy on this page, updating the "Last updated" date, and where required by law, providing additional notice (such as email notification). Your continued use of the Service after any changes to this Policy constitutes your acceptance of the updated Policy. We encourage you to review this Policy periodically.

14. Contact Us

If you have questions about this Privacy Policy, our data practices, or wish to exercise your data rights, please contact us at: privacy@dottrofiq.com

California Privacy Rights (CCPA/CPRA)

California residents have additional rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act, including: the right to know what personal information is collected, disclosed, and sold; the right to delete personal information; the right to correct inaccurate personal information; the right to opt out of the sale or sharing of personal information; and the right to non-discrimination for exercising privacy rights. We do not sell or share personal information as defined by CCPA/CPRA. We do not use sensitive personal information for purposes beyond those permitted by CCPA/CPRA. To exercise your rights, contact us at privacy@dottrofiq.com. We will verify your identity before processing your request.

European Privacy Rights (GDPR)

If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR) and equivalent legislation, including access, rectification, erasure, restriction, portability, and objection. Our legal bases for processing include: performance of our contract with you, our legitimate interests (such as security and service improvement), compliance with legal obligations, and your consent where applicable. You may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. You have the right to lodge a complaint with your local supervisory authority. For EEA data subjects, our data protection contact can be reached at privacy@dottrofiq.com.