Privacy Policy
Effective August 3, 2026
Dough is a business tool used by finance and accounting teams. Most of the information we handle belongs to the companies that use Dough, not to individuals — and we treat it that way. This policy explains what we collect, why, who we share it with, and what you can ask us to do about it.
Who we are
Dough is operated by Use Dough, Inc., a Delaware corporation (“Dough,” “we,” “us”). Our place of business is 625 2nd Street, Suite 205, San Francisco, CA 94107. You can reach us at help@usedough.com.
This policy covers the Dough web application, our command-line tool, and our API and Model Context Protocol (MCP) endpoints (together, the “Service”).
Controller and processor
Dough is sold to organizations. When a company subscribes and connects its systems, that company decides what data enters the Service and for what purpose; it is the controller of that data, and we act as its processor. We handle that data on the company’s documented instructions.
If you use Dough because your employer gave you an account, your employer administers that account. Requests to access, correct, export, or delete data in it are usually best directed to them first. We will help them respond, and we will route a request sent to us directly to the right place.
For the limited information we collect about our own business — who signed up, who contacted support, how the Service is performing — we are the controller.
What we collect
Account and identity data
When you sign in, we receive your email address, display name, and an identifier for you from your organization’s identity provider, along with your organization’s identifier and your role within Dough. We record when you were last active. We never receive or store your password. Authentication happens through your identity provider or through our authentication vendor.
Customer Data
This is the substance of the Service: financial, accounting, and operational records that your organization connects or uploads — general ledger data, transactions, charts of accounts, spreadsheets, saved queries, table mappings, and the documents you store in Dough. It also includes the proposals your team creates for posting to an accounting system, and the record of who approved them.
Customer Data may incidentally contain personal information — a vendor contact’s name, an employee reference in a memo line. We do not seek that information out and we do not use it to build profiles of anyone.
Integration credentials
When an administrator connects a system such as QuickBooks Online or BigQuery, we store the resulting access and refresh tokens so the connection keeps working. These are encrypted before they are written down (see “How we protect it”).
Usage and log data
We record operational telemetry for each request: the path, the HTTP method, the response outcome, how long it took, and the organization, user identifier, and email address of the signed-in user. We keep this to debug failures, investigate security events, and understand which parts of the product are used. We call out the email address explicitly because it is personal information and many policies quietly omit it.
The public pages you are reading now — this policy and our terms — sit outside that logging path. Reading them is not recorded against you.
What we do not collect
- We do not use advertising cookies or third-party tracking pixels, and we do not run behavioral advertising.
- We have never sold personal information, and we do not share it for cross-context behavioral advertising.
- We do not ask for or store bank credentials, payment card numbers, or government identification numbers.
How we use it
- To provide the Service: sync, store, query, and display your data.
- To run the agent features you invoke — which means sending the relevant Customer Data to a language model provider so it can answer.
- To carry out writes your organization has approved, such as posting an approved journal entry to QuickBooks Online.
- To secure the Service: authenticate you, enforce permissions, and maintain audit records of sensitive actions.
- To diagnose problems, monitor reliability, and improve the product.
- To communicate with you about support, security, and service changes.
- To comply with law and enforce our agreements.
We do not train machine learning models on Customer Data in any form that identifies you. We may use inputs and outputs to train or otherwise improve the Service, but only once they have been anonymized or aggregated so that they no longer identify your organization, your customers, or any individual. The language model providers we send data to are contractually prohibited from training their own models on it.
We do not use Customer Data to benchmark one customer against another, and your workspace only ever shows your own organization’s data — we never combine Customer Data across customers to answer someone else’s question.
Who we share it with
We share information with the service providers below. They process it on our behalf, under contract, for the purposes described here and no others, and they are not permitted to use it for their own purposes. This list may change as our service providers change; we keep it current, and we will update it before a new provider begins processing your data.
| Anthropic | Large language model provider. Processes Customer Data submitted to agents in order to generate responses. Anthropic does not train its models on data submitted through its commercial API. |
|---|---|
| Datadog | Application monitoring and log management. Receives operational telemetry, which includes the email address of the signed-in user (see “Usage and log data” above). |
| Google Cloud (BigQuery) | The data lake. Each customer's synced financial and operational data is held in a dataset dedicated to that customer. |
| Intuit | QuickBooks Online. Receives only the entries a customer's authorized approver has explicitly approved for posting, plus the read requests needed to render them. |
| Polytomic | Data integration. Runs the authorization flow by which an administrator connects a source system, holds the resulting credentials for that source, and performs the scheduled syncs that copy records from it into the customer's data lake dataset. |
| Supabase | Primary application database and file storage. Hosts account records, configuration, uploaded files, and encrypted integration credentials. |
| Vercel | Application hosting and delivery. Processes requests in transit and retains short-lived runtime logs. |
| WorkOS | Authentication and enterprise single sign-on. Handles sign-in and brokers identity information from a customer's own identity provider. |
We may also disclose information when the law requires it, to protect our rights or someone’s safety, or to an acquirer in a merger or sale of assets — in which case this policy continues to govern the data until it is replaced by one you are told about.
Tools you connect yourself
Dough exposes an interface that third-party AI assistants and developer tools can connect to, over the Model Context Protocol. If your organization enables such a connection, that tool can request your data from Dough, and what it requests is sent to whoever operates it — under your agreement with them, not ours. We do not send them anything on our own, and we do not control what they do with it.
We deliberately do not list those operators above. They are not our subprocessors, we have no contract with them covering your data, and which ones are reachable depends entirely on what you choose to connect. Treat enabling a connection as a decision about where your data may go.
How we protect it
- Data is encrypted in transit with TLS, and at rest by our infrastructure providers.
- Integration credentials — OAuth access and refresh tokens — receive a second layer of application-level encryption using AES-256-GCM with envelope-encrypted keys, so they are never readable in the database, including by anyone with direct database access.
- Access is scoped by organization throughout. Every request is bound to a verified identity, and the organization is derived from that identity rather than from anything the caller supplies.
- Writes to a connected accounting system require explicit human approval by a designated approver before anything is posted. Agents propose; people decide.
- Sensitive actions are recorded in an audit log attributable to a specific user.
Support access.A small number of authorized Dough personnel can view a customer’s workspace to investigate a problem. Every such session is explicitly initiated, tied to the individual staff member, and recorded. We do not browse customer data outside of that.
No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting your data, we will notify the affected organization without undue delay.
How long we keep it
We keep Customer Data for as long as your organization’s account is active. On termination, we delete or return it in accordance with the applicable agreement, and delete residual copies from backups on our normal backup cycle.
Operational logs are retained on a rolling window sufficient for debugging and security investigation. Audit records of approvals and other sensitive actions are kept longer, because their purpose is to remain available for later review. We may retain information where the law requires it.
How we decide how long
We do not keep everything for the same period. What determines each one:
| Customer Data | Kept while your organization's account is active. On termination we delete or return it per the applicable agreement, and residual copies age out of backups on our normal backup cycle. |
|---|---|
| Account and identity data | Kept while the account exists, then removed with it. We do not retain a profile of you after your organization's account closes. |
| Integration credentials | Kept only while the connection is live. Disconnecting revokes them; they are deleted when the connection is removed or the account closes. |
| Operational logs | A rolling window set by what debugging and security investigation actually require — long enough to investigate an incident found weeks later, not indefinite. |
| Audit records | Kept longer than operational logs, because their entire purpose is to remain available for later review. Retained for the life of the account and any period the law or your agreement requires. |
Your choices and rights
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal information, to object to or restrict certain processing, and to withdraw consent. California residents have rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them; because we do not sell or share personal information for cross-context behavioral advertising, there is nothing to opt out of on that front.
To exercise a right, contact help@usedough.com. Where we hold the data on behalf of your employer, we will refer the request to them and support their response. We will not charge you for a reasonable request, and we will verify your identity before acting.
United States state privacy rights
Comprehensive privacy laws now apply in a number of states, including California, Colorado, Connecticut, Texas, and Virginia. Which of them cover you depends on where you live and on whether a given law reaches a company of our size. Rather than parse that for you, we extend the same rights to everyone who asks:
- Know and access— what personal information we hold about you, where it came from, why we have it, and who we share it with.
- Correct inaccurate personal information.
- Delete personal information we hold about you.
- Portability— a copy in a usable format.
- Appeal a decision we make on any of the above. Tell us and a different person will review it.
Several of these laws also give you the right to opt out of the sale of personal information, of sharing it for cross-context behavioral advertising, and of profiling that produces legal or similarly significant effects. We do none of those things, so there is nothing for you to opt out of. We also do not use or disclose sensitive personal information for any purpose that would give you a right to limit it. Exercising a right will never cause us to treat you differently.
Most personal information in Dough belongs to a business account, and much of it sits inside records your employer controls. Where that is the case we act on their instructions — so we will route your request to them and help them answer it, rather than acting unilaterally on data that is theirs.
International transfers
We operate in the United States, and our providers may process data in the United States and other countries. Where a transfer is restricted by applicable law, we put appropriate safeguards in place before it happens — such as standard contractual clauses or another recognized transfer mechanism.
Children
Dough is a business product and is not directed to children. We do not knowingly collect personal information from anyone under 18.
Changes to this policy
We may update this policy. If a change is material, we will raise the effective date at the top and notify account administrators before it takes effect. Continued use after that date means the updated policy applies.
Contact
Questions, requests, or complaints: help@usedough.com.
Use Dough, Inc. · 625 2nd Street, Suite 205, San Francisco, CA 94107