Dorven/ Privacy Policy

Effective August 20, 2026 (updated from August 17, 2026)

Privacy Policy

1. Who we are

Dorven Inc. ("Dorven", "we", "our") operates the Dorven UX review platform at dorven.ai and app.dorven.ai. This policy describes how we collect, use, and protect your information.

Questions? Email jiteshvats@dorven.ai.

2. What we collect

Account data — name, email address, and authentication credentials collected via Clerk when you sign up.

Scan data — the URLs you submit for review, screenshots you upload for analysis, and the HTML/DOM content captured by the browser extension. The browser extension only captures content from pages you are actively viewing in your own browser session — including authenticated pages, but only when you are personally logged in to that service. This content is processed by AI and then stored in association with your account.

Usage data — scan history, project names, fixed/open issue counts, scheduled review settings, and team membership records.

Billing data — subscription tier and billing status managed through Stripe. We do not store raw card numbers; Stripe handles payment processing.

Technical data — IP address, browser type, and general device type logged automatically by our infrastructure.

Enterprise inquiries — if you submit an Enterprise quote request, we collect the contact and usage information you provide in order to prepare a proposal.

3. How we use your data

  • To perform UX analysis on the URLs, screenshots, and page content you submit
  • To display findings, track fixes, and maintain your review history
  • To enforce subscription quotas and manage team access
  • To send transactional emails (scan results, team invites, scheduled review alerts)
  • To prepare custom proposals for Enterprise inquiries
  • To improve our AI models and scan quality — using aggregated, de-identified data only

We do not sell your data. We do not use your data for advertising.

4. AI processing

Page content, screenshots, and DOM captures you submit are sent to Anthropic's Claude API for analysis. Anthropic processes this data as a sub-processor under their API terms. By using Dorven you consent to this processing. We pass only the minimum content needed for analysis — we do not send your email, name, or billing details to AI providers.

Scan findings are AI-generated and may vary between runs. They are provided for informational purposes and do not constitute professional advice.

5. Data retention

Your scan history, projects, and account data are retained for the lifetime of your account. You may delete individual scans from the Dorven dashboard. To delete your entire account and all associated data, email jiteshvats@dorven.ai.

Stripe retains billing records per their own retention policy.

6. Data sharing

We share data only with third-party sub-processors required to operate the service — including infrastructure, authentication, payment, AI analysis, and email providers. We do not sell your data or share it with advertisers. A full list of sub-processors is available at dorven.ai/sub-processors.

Cross-border data transfers: Your data is stored and processed in the United States. If you are located in Canada, India, the EU, or another jurisdiction outside the US, your personal information will be transferred to and processed in the US, which may have different data protection standards than your home country. By using Dorven you consent to this transfer. [Specific transfer mechanism wording pending attorney review for PIPEDA and DPDP compliance.]

7. Security

All data is transmitted over TLS. Database access is protected by Supabase Row Level Security (RLS) policies ensuring users can only access their own data. We conduct regular security reviews and patch vulnerabilities promptly.

No method of transmission or storage is 100% secure. If you discover a security vulnerability, please report it to jiteshvats@dorven.ai.

Breach notification: In the event of a data breach that affects your personal information, we will notify affected users without undue delay and within timeframes required by applicable law (including PIPEDA and the DPDP Act where applicable). We will also notify relevant regulatory authorities as required.

8. Your rights

You may request access to, correction of, or deletion of your personal data at any time. To exercise any of these rights, email jiteshvats@dorven.ai.

Note on deletion and team content: Deletion rights apply to your personal account data and scans not associated with a team workspace. For content submitted to a Studio team project, deletion requests will be coordinated with the team owner — team workspace content ownership is governed by Section 7 of our Terms of Service.

Depending on where you are located, you may have additional rights under local law:

  • US residents — the universal rights above (access, correction, deletion) apply to you. There is no comprehensive US federal privacy law; California residents have additional rights under CCPA/CPRA as described below.
  • EU/UK residents have rights under GDPR/UK GDPR, including data portability and the right to object to processing.
  • Canadian residents have rights under PIPEDA (Personal Information Protection and Electronic Documents Act). Our designated Privacy Officer for PIPEDA purposes is Jitesh Vats — contact: jiteshvats@dorven.ai. [Specific PIPEDA compliance wording pending attorney review.]
  • Indian residents have rights under the Digital Personal Data Protection Act (DPDP Act). Our designated Grievance Officer for DPDP purposes is Jitesh Vats — contact: jiteshvats@dorven.ai. [Specific DPDP compliance wording pending attorney review.]
  • California residents may have rights under the California Consumer Privacy Act (CCPA/CPRA), including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale of personal information. We do not sell your personal information.

9. Cookies

Strictly necessary: Authentication session cookies set by Clerk. These are required for the service to function and are always active.

Optional analytics cookies: If you accept via the cookie consent banner, we set a PostHog analytics cookie to understand how Dorven is used — which pages are visited and how features are used. No personal data (name, email, or IP address) is collected. Session recording is disabled. You can decline at any time; no analytics cookies will be set if you decline.

Local storage: Your theme preference (light/dark/system) and certain guest-scan usage counters are stored in localStorage on your device and are not transmitted to us.

10. Changes to this policy

We may update this policy as our product evolves. We will notify active subscribers by email for material changes. The effective date at the top of this page reflects the most recent revision.