Data we collect
We collect account profile information, workspace metadata, provider account setup status, API keys in hashed form, billing and lifecycle events, audit logs, configuration details, and support or sales messages you submit.
Provider data
When you connect Discord or Telegram accounts, dataz.md stores provider credentials in the configured secret store and uses them to serve read-only API requests. Responses may include message, member, contact, chat, channel, server, forum, invite, and metadata surfaces exposed by the connected provider account.
Use of data
We use data to authenticate users, operate workspaces, provision runtimes, route API traffic, secure the service, bill activated accounts, troubleshoot issues, and comply with legal or provider obligations.
Website analytics
We use Google Analytics and Google Tag Manager (GA4 and GTM) to measure public-page traffic and product funnel events. For our U.S.-only launch, analytics is on by default; we do not require prior opt-in. Google may receive page URL and referrer information, browser and device details, network-derived location information, and the limited event metadata described below.
Our analytics events contain page type, CTA destination, provider or setup mode, route family, result category, and status-code metadata as applicable. We do not intentionally send names, email addresses, workspace or tenant IDs, API keys, provider credentials, full API paths, message content, or API response bodies to Google Analytics. Team browsers can be marked as internal traffic and excluded from reporting.
When analytics is allowed, Google may set first-party _ga and property-specific _ga_* cookies or use similar browser identifiers. These cookies may persist for up to two years unless they are shortened or removed by browser settings or by your privacy choice. dataz.md stores your analytics choice in local storage under dataz-analytics-choice. We deny advertising storage, advertising user data, Google Signals, and ad-personalization signals in the site configuration; we do not use this analytics setup for remarketing.
Your analytics choice
You can turn analytics off at any time on this browser. An opt-out stops future analytics events, prevents Google analytics scripts from loading on later page views, and attempts to remove readable Google Analytics cookies. It does not delete analytics records collected before the opt-out. If your browser sends a Global Privacy Control signal, analytics stays off even if an earlier browser choice allowed it.
Loading this browser's analytics choice…
Sharing
We do not sell customer data. We may share data with infrastructure, authentication, payment, email, security, logging, and support providers as needed to operate dataz.md, or when required by law.
Security
We use tenant scoping, API key hashing, secret-store references, audit logging, and runtime isolation controls. Customers remain responsible for protecting their login sessions, provider accounts, and dataz.md API keys.
Deletion
Workspace and provider-account deletion follow the Data Retention Policy. Current code revokes API keys, disables routes, destroys runtime resources through a retryable background workflow, and marks hosted records deleted. Encrypted provider credentials and identity metadata are retained so an authorized restore can reuse the existing connection. Login profile data is anonymized only after every owned workspace is fully deleted.