Privacy Policy
Dukon AI · Last updated: 29 July 2026 · dukonai.com
🌐 Юридически действующая версия этого документа — английская (ниже). Вопросы на русском или узбекском: support@dukonai.com.
🌐 Ushbu hujjatning yuridik kuchga ega versiyasi — inglizcha (quyida). Savollarni rus yoki o'zbek tilida yozishingiz mumkin: support@dukonai.com.
Dukon AI ("we", "the Service") is a remote MCP (Model Context Protocol) server that lets a retail store owner query their own BILLZ store data through an AI assistant such as Claude or ChatGPT. This policy explains exactly what we collect, why, and what we never do.
In one sentence: we store your email, name, an encrypted copy of your BILLZ integration key and a per-day counter of requests — and nothing else. We never store your store's business data, never sell anything, and never share data with third parties.
1. Data we collect
- Account data you provide: name, email address, password (stored only as a salted scrypt hash — we cannot read it).
- Your BILLZ integration secret key: encrypted at rest with AES-256-GCM. It is decrypted in memory only for the duration of a request you initiate, and used solely to call the BILLZ API on your behalf.
- Store identification: your BILLZ company name and subdomain, retrieved once at sign-up so you can see which store is connected.
- Usage counters: the number of tool calls per day, used to enforce plan limits.
- OAuth records: registered client applications, authorization codes and access/refresh tokens (stored as hashes only).
2. Data we do NOT collect or store
- We do not store your store's business data. Sales, revenue, stock, product and customer records are fetched from BILLZ, passed straight through to your AI assistant, and never written to our database or logs.
- We do not store the contents of your conversations with the AI assistant.
- We do not use analytics, advertising or tracking cookies. The Service sets no cookies at all.
- We do not use your data to train machine-learning models.
3. Read-only by design
All tools exposed by Dukon AI are read-only. The Service cannot create, modify or delete anything in your BILLZ account. Every tool is annotated as read-only so your AI assistant can verify this too.
4. How data is used
Your data is used exclusively to operate the Service: authenticating you, calling the BILLZ API with your key in response to your own requests, and enforcing plan limits. We do not sell, rent or share personal data with third parties. We do not transfer data to advertisers or data brokers.
5. Sub-processors
- BILLZ (billz.io) — the source of your store data; we call their API on your behalf.
- Hostinger — hosting provider for our server (data stored in their data centre, encrypted at rest by us).
- Your chosen AI assistant provider (e.g. Anthropic for Claude) receives the query results, governed by their own privacy policy.
6. Security
- All traffic is encrypted with TLS (HTTPS only, HSTS enabled).
- BILLZ keys are encrypted with AES-256-GCM, bound to your account identifier.
- Access tokens and connector tokens are stored only as SHA-256 hashes.
- Authentication uses OAuth 2.1 with PKCE; authorization codes are single-use and short-lived.
- The application runs as a non-privileged user in an isolated container with a read-only filesystem.
- Request URLs containing tokens are not written to access logs.
7. Data retention and deletion
We keep your account data for as long as your account exists. You can request deletion at any time by emailing support@dukonai.com; we delete your account, your encrypted BILLZ key and all associated tokens within 30 days. You can also revoke access instantly at any time by deleting the integration key inside your own BILLZ account — the Service then loses all access to your store.
8. Your rights
You may request access to, correction of, or deletion of your personal data, and you may withdraw consent at any time by disconnecting the connector or deleting your account. Requests go to support@dukonai.com.
9. Children
The Service is a business tool and is not directed at children under 16.
10. Changes
If this policy changes materially, we will update the date at the top of this page and notify registered users by email before the change takes effect.
11. Contact
Questions about privacy or data handling: support@dukonai.com.
← Back to the main page · Terms of Service · Documentation