Legal
Privacy Policy
Last updated: February 20, 2026
DataDirector (“we,” “us,” or “our”) is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the DataDirector application (the “Service”). Please read this policy carefully. By using the Service, you consent to the practices described herein.
1. Information We Collect
Account Information. When you create an account, we collect your email address and password (stored in hashed form). If you register with a registration key, we record the key used for access-level validation.
Usage Data. We collect information about how you interact with the Service, including queries submitted, features used, session duration, and timestamps. This helps us improve query accuracy and user experience.
Automatically Collected Data. We may collect device type, browser type, IP address, and general location (city/state level) through standard server logs. We use this data for security, rate limiting, and service optimization.
Voter Data (Processed, Not Collected). DataDirector queries publicly available voter registration data on your behalf. We do not collect, copy, or store voter records — all queries execute against the source database in real-time and results are streamed directly to your session.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Authenticate your identity and manage your account access level
- Process and respond to your natural language queries accurately
- Enforce rate limits and prevent abuse (40 messages/day for guest users, 100 messages/day for registered users)
- Communicate with you about service updates, security alerts, or support requests
- Analyze usage patterns to improve query accuracy and AI performance
- Comply with legal obligations
3. Data Sharing and Disclosure
We do not sell your personal information. We may share information in the following circumstances:
Service Providers. We use third-party services for hosting (Supabase), AI processing (OpenAI via AI Gateway), and authentication. These providers process data on our behalf under contractual obligations to protect your information.
AI Processing. When you submit a query, your natural language input is sent to our AI provider to interpret and translate into database queries. We do not send voter record data to the AI provider — only your query text and the resulting structured filters.
Legal Requirements. We may disclose information if required by law, subpoena, or legal process, or if we believe disclosure is necessary to protect the rights, property, or safety of DataDirector, our users, or the public.
4. Data Security
We implement industry-standard security measures to protect your information, including:
- Encrypted data transmission (HTTPS/TLS)
- Hashed password storage
- Read-only database access — the Service cannot modify voter data
- Server-side API key management (keys are never client-exposed)
- Rate limiting to prevent abuse
- Regular security audits
No method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we take commercially reasonable steps to protect your data.
5. Data Retention
We retain your account information for as long as your account is active. Chat history and query logs are retained to support continued conversations and improve service quality. You may request deletion of your account and associated data at any time by contacting us. Upon account deletion, we will remove your personal data within 30 days, except where retention is required by law.
6. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate personal data
- Deletion: Request deletion of your personal data
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to certain processing of your personal data
To exercise these rights, contact us at privacy@datadirector.app. We will respond within 30 days.
7. Cookies and Tracking
The Service uses essential cookies for authentication (session tokens) and preference storage (e.g., sidebar state, theme selection). We do not use advertising cookies or third-party tracking pixels. No data is shared with advertising networks.
8. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will take steps to delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, notify you via email or a prominent notice within the Service. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.
10. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at: privacy@datadirector.app
DataDirector