Docket

PRIVACY POLICY

What we hold, and why.

Effective 14 August 2026

The short version#

Docket runs on your hosting, not ours. It has no account, no licence key and no telemetry. Once you have the code, the software does not report to us and we could not watch it if we wanted to.

We hold four small things about you: the email address your purchase came with, the GitHub username we sent the repository invitation to, any support emails you write, and, if you asked for it, your newsletter subscription.

No cookies on our website, no third-party trackers, no advertising scripts, no fingerprinting.

Your customers' data never reaches us. Your support centre stores it in your own repository on your own hosting. We have no access to it.

Who is the data controller?#

The data controller for any personal data we hold about you is:

EntityTJH/CO LIMITED (trading as THEODORE HQ)
RegisteredA company registered in England and Wales. Company number 16589593.
OfficeFairway House, Links Business, Fortran Rd, St. Mellons, Cardiff, CF3 0LT, United Kingdom.
Emailsupport@theodorehq.com

Given the small scale and low-risk nature of our processing, we are not required to appoint a Data Protection Officer and have not done so. For any data question, contact us at the email above.

Why this policy is short#

Most software companies hold your data because their software runs on their servers. Docket does not work that way, and that changes what there is to disclose.

You are buying source code. You run it in your own GitHub repository, on your own hosting account, under your own domain. Your customers' reports, their replies and their email addresses are written to your repository and are read by your site. None of it passes through us at any point. That is a property of how the software is built rather than a promise about our conduct, which is why it is worth more than a promise.

So this policy covers our shop, our support inbox and our website. It cannot cover your support centre, because we are not in it.

What Docket sends us when you run it#

On the free edition, nothing at all. It has no updater in it, so it makes no request to us for any reason, ever.

On the paid editions, one thing, once a day: the update check. Docket asks theodorehq.com/docket/releases-pro.json or releases-studio.json whether a newer version exists, and downloads it only if you merge the pull request it opens. The request identifies itself as docket-updater and carries no licence key, no repository name, no domain, no account and no unique identifier. There is nothing in it that distinguishes your install from anybody else's. It runs inside GitHub's own infrastructure rather than on your server, so the network address our host records belongs to GitHub, not to you.

To stop it entirely, delete .github/workflows/docket-update.yml from your repository. Nothing else depends on it, and your support centre carries on working. You would then take new versions by hand when you choose to.

The free edition's badge is a plain link. "Powered by Docket" is an ordinary anchor pointing at our website. It loads nothing, calls nothing and reports nothing. We learn that somebody clicked it only in the same sense that any website learns somebody arrived from a link.

There is nothing else. No analytics, no crash reports, no diagnostics, no licence validation, no heartbeat. Docket has no licence key to check, which is the honest reason there is no call to make.

Your support centre, and whose responsibility it is#

Once you install Docket, the personal data your board handles is yours to control and yours to answer for. Under UK GDPR you are the data controller for it. We are not a processor of it either, because it never reaches us.

That includes the email address of every person who writes in, the display name they type, and everything published on your board. LEGAL-CHECKLIST.md in the repository sets out in plain English what that commits you to, including the part that catches people out: git history is permanent, so Docket encrypts submitter email addresses before they are written to your repository rather than storing them in readable form.

The services Docket can use on your behalf, if you switch them on, are yours as well. Email notifications go through your own Resend or Postmark account under your own API key. The automatic first reply goes to whichever AI provider you configured, under your own key and your own billing. Your repository is your own GitHub account. We hold none of those keys and see none of that traffic.

What personal data do we hold, and on what basis?#

Four categories. The law requires us to name a lawful basis under Article 6 of the UK GDPR for each.

DataWhy we hold itLawful basis
Purchase email and order recordTo deliver your edition, honour your licence, and answer questions about your purchase. We receive it from Polar, the Merchant of Record that processes the sale.Contractual necessity (Art 6(1)(b))
GitHub usernameThe one thing we must have to give you what you bought. We never ask you for it and never store it ourselves: after paying, you connect your own GitHub account to Polar, and Polar invites that account to the private repository on our behalf. Once it accepts, we can see that account's public profile in the repository's collaborator list, as anyone with access to a repository can.Contractual necessity (Art 6(1)(b))
Support emailsWhatever you write to us, and our reply.Contractual necessity for questions about your purchase (Art 6(1)(b)); our legitimate interests in answering everyone else (Art 6(1)(f))
Newsletter subscriptionThe same email address, used to send occasional product updates about Docket. You opt in at checkout via an unticked box, never pre-ticked, and every email has a one-click unsubscribe.Consent (Art 6(1)(a))

We hold no card details, at any point. Polar takes payment through Stripe and we never see the number.

We make no automated decisions about you and do not profile you.

How long do we keep it?#

Purchase email and order recordSeven years after your last purchase, to meet HMRC tax-record requirements (Schedule 11 of the VAT Act 1994 and the corresponding income-tax rules).
GitHub usernameFor as long as your access lasts, which is indefinitely, because your licence does not expire. Ask us to remove your access and the record goes with it.
Support emailsTwo years, then deleted, unless you ask us to keep them for an open issue.
Newsletter subscriptionUntil you unsubscribe, plus thirty days while we process it.

Cookies and this website#

No cookies. No analytics. No third-party trackers, no advertising scripts, no fingerprinting, and nothing saved in your browser's storage. Our web fonts are served from this site, so loading a page makes no request to anyone else.

We do not know which pages you visited, where you came from, or that you were here at all, unless you buy something or write to us. That is not a policy we are being modest about; there is no measurement running to be modest about.

If we ever add analytics, it will be a privacy-friendly, cookieless tool, this section will say so before it starts, and there will be a way to opt out here.

Who handles your data, and international transfers#

We keep suppliers to a minimum. Where one is based outside the UK, an approved UK transfer safeguard is in place.

PolarUnited StatesThe Merchant of Record and seller of record for your purchase. For the data it collects at its own checkout, your email, country, and payment and tax details, Polar acts as a separate, independent controller under its own terms; for anything it handles purely on our behalf it acts as our processor. Polar uses Stripe as its payment processor, and we never receive your card details. See Polar's data-processing agreement and privacy policy.
GitHubUnited StatesHosts the private repositories your edition is delivered through. GitHub is part of Microsoft, which is certified under the UK Extension to the EU-US Data Privacy Framework, and GitHub's Data Protection Agreement also incorporates the UK International Data Transfer Addendum.
VercelUnited StatesHosts this website. Vercel is certified under the UK Extension to the EU-US Data Privacy Framework, and its data-processing agreement also incorporates the UK International Data Transfer Agreement.
Apple iCloudIrelandRuns our support@theodorehq.com mailbox. For UK and EU users this is controlled by Apple Distribution International Limited in Ireland, within the EEA, with Standard Contractual Clauses for any onward transfer.

You can ask us for more detail on any of these safeguards at support@theodorehq.com.

Your rights under UK GDPR#

AccessAsk for a copy of the data we hold (Art 15).
RectificationCorrect anything inaccurate (Art 16).
ErasureAsk us to delete your data, subject to the HMRC retention above (Art 17).
RestrictionPause our processing while a dispute is resolved (Art 18).
PortabilityReceive your data in a structured, common format (Art 20).
ObjectObject to processing based on legitimate interests, including marketing (Art 21).
Withdraw consentUnsubscribe from the newsletter at any time (Art 7(3)).
No automated decisionsWe make none about you (Art 22).

To exercise any of these, email support@theodorehq.com. We respond within thirty days, free of charge.

One practical note on erasure. We can delete what we hold and remove your repository access. We cannot delete the copy of the source code you downloaded, and we would not want to: it is yours, your licence is perpetual, and your support centre keeps running whatever happens to your record with us.

Complaints#

If you are unhappy with how we have handled your personal data, you have the right to complain to us directly, a right under section 164A of the Data Protection Act 2018. The easiest way is to email support@theodorehq.com. We will acknowledge your complaint within 30 days, investigate it, and tell you the outcome.

You also have the right to complain to the UK Information Commissioner's Office (ICO): Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Helpline: 0303 123 1113. ico.org.uk/make-a-complaint. You can contact the ICO at any time, though we would appreciate the chance to resolve things for you first.

Children#

Docket is a developer tool and is not directed at children under 13, the UK age of digital consent under section 9 of the Data Protection Act 2018. We do not knowingly collect any personal data from anyone under 13. If you believe we hold such data in error, email us and we will delete it promptly.

Changes to this policy#

If we change this policy we will update the date at the top, and email anyone on the customer list a plain-English summary of what changed at least fourteen days before it takes effect. We will not start collecting more from existing customers.

Contact#

For any questions or concerns, email support@theodorehq.com. Every message is read by a person.

See also our terms of sale.