Data belongs to the workspace that provides it.
This page describes the defaults in the public Dashloom software. Operators of a hosted deployment must publish their own controller identity, subprocessors, retention periods, contact method, and applicable regional notices.
Data processed
Dashloom stores account and workspace membership data, product configuration, encrypted connector and delivery credentials, normalized metrics, competitor evidence, analysis inputs and outputs, report history, usage ledgers, subscription identifiers, and product feedback needed to provide the configured service.
Models and external services
When an authorized user runs an Agent, Dashloom sends a bounded evidence bundle and the user's question to the configured model provider. Agent Quality Lab sends the same bounded bundle separately to each provider selected by an owner or administrator. BYOK deployments use providers selected by the workspace. Delivery channels and connected data providers receive only the requests needed for their configured function. A configured Custom REST endpoint receives a bounded GET request and its selected authentication header; Dashloom stores only validated normalized metrics from the response.
Telemetry and cookies
The open-source repository does not send product analytics telemetry by default. Essential cookies maintain authenticated sessions. Feedback remains inside the configured deployment. Optional anonymous diagnostics are created only when a member requests them and exclude identities, names, domains, credentials, raw values, content, and provider error messages. A deployment operator must obtain any consent required before enabling additional analytics or marketing tools.
Control
Owners can export workspace data, configure retention, revoke connections and access links, and delete the workspace. Credentials are omitted from exports. Deletion does not control copies already retained by an external provider under its own agreement.
Security
Secrets are encrypted server-side; ingestion and share tokens are stored as one-way hashes. No system can promise absolute security. Report suspected vulnerabilities through the process in the repository's Security Policy.
中文说明
本页说明公开版 Dashloom 的默认数据处理方式。托管服务运营方必须另行公布主体、子处理方、保留期限、联系方式和适用地区说明。Dashloom 默认不发送产品分析遥测;必要 Cookie 用于维持登录。产品反馈保存在当前部署内;匿名诊断只在成员主动请求时生成,并排除身份、名称、域名、凭证、原始数值、内容和 Provider 错误文本。工作空间 Owner 可以导出数据、设置保留期限、撤销连接或分享链接并删除工作空间。Agent 只向所配置模型发送有界证据和用户问题;Quality Lab 会把同一份证据分别发送给 Owner 或 Admin 选择的多个模型。