Docker Hub (Organization)
- The policy says your content is not used for AI training.
- Your data is used for personalized ads, including by third-party ad companies.
- Data is shared only with the providers who run the service.
- The documents do not say who can read your content.
Docker says it does not train on your AI prompts, but uses ads trackers, and you them.
Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.
Collected
Account and billing info, cookies, IP, usage telemetry, stored API keys, and sandbox snapshots with prompts.
Read the exact line
Privacy policy
“Docker may also collect information about how you use the Services, such as activity data, feature usage and product version data.”
Training
They run the service, bill you, market to you, and say they do not train AI on your prompts.
Read the exact line
Privacy policy
“Docker does not select the model provider for you and does not use your prompts or the provider’s responses to train AI models.”
Sharing
Service providers, payment processor Stripe, ad networks, and the AI company whose key you connect.
Read the exact line
Privacy policy
“When you do so, your prompts and the provider’s responses are transmitted to that provider under your own agreement with the provider”
Kept
Unsaved snapshots go in 7 days; other data is often kept up to 12 months unless law requires longer.
Read the exact line
Privacy policy
“Snapshots you do not implicitly save are deleted within seven (7) days of creation, after which the paused sandbox cannot be restored.”
Controls
You can update account info, unsubscribe from marketing, and ask to delete via their privacy form or support.
Read the exact line
Privacy policy
“Requests to access, change, or delete your information will be handled within 30 days.”
Fine print
waiver, as-is service, $100 cap, and you pay their legal bills.
No exact line could be verified.
Expand “Read the exact line” to see the source alongside the explanation.
What you can turn off
The controls and opt-outs their own documents describe, and where they say to find them.
Request access, correction, or deletion
https://preferences.docker.com/privacy/ or privacy@docker.com
Delete your account
https://www.docker.com/support/
Unsubscribe from marketing emails
Unsubscribe link at the bottom of Docker marketing emails, or https://preferences.docker.com/privacy
Refuse non-essential cookies in your browser
Browser cookie settings (they warn Services may not work if cookies are blocked)
If a switch is not where they say, the deletion request above still applies.
Line by line
The lines that matter most, worst first.
If someone sues over how you used Docker, you may have to pay Docker’s legal costs.
Read the exact line
Terms of service
“You will , and Docker, its affiliates, and their respective officers, directors, employees, and agents from and against any claims, damages, liabilities, losses, and expenses”
For example, if a prompt you ran leads to a copyright fight, you could be on the hook for Docker’s lawyers.
Ad companies can track you on Docker’s site and elsewhere to show targeted ads.
Read the exact line
Privacy policy
“Docker may also contract with third-party advertising networks that collect IP addresses and other Website Navigational Information on the Website and emails and on third-party websites.”
For example, visiting docker.com could later show Docker ads on another website.
If Docker causes harm, they usually will not pay more than six months of fees or $100.
Read the exact line
Terms of service
“DOCKER’S TOTAL ARISING OUT OF OR RELATED TO THESE TERMS WILL NOT EXCEED THE AMOUNTS PAID BY YOU TO DOCKER FOR THE SERVICES GIVING RISE TO THE CLAIM DURING THE SIX (6) MONTHS BEFORE THE EVENT GIVING RISE TO OR ONE HUNDRED DOLLARS ($100), WHICHEVER IS GREATER.”
For example, if a free Hub download wrecks a project, they may owe at most $100.
Keeping using the site can count as agreeing to new privacy rules they post.
Read the exact line
Privacy policy
“by using or accessing the Docker Services, you are accepting the practices described in this Privacy Policy, and you are consenting to our processing of your information as set forth in this Privacy Policy now and as amended by us.”
For example, if they add a new data use and you keep logging in, they treat that as consent.
If you save AI API keys in Docker, they keep those keys to run the service.
Read the exact line
Privacy policy
“credentials you choose to store — API keys and access tokens for third-party AI model providers and MCP-connected tools, which we store securely on your behalf”
For example, an OpenAI key you paste in can sit on Docker’s systems.
Paused sandbox snapshots can hold your AI chats and anything else in the session.
Read the exact line
Privacy policy
“snapshots may include prompts submitted to and outputs received from AI models you use, and any other information you include in them.”
For example, a secret in a prompt could sit in a snapshot for up to seven days, or longer if you save it.
Docker says it will not train its own models on your AI prompts and replies.
Read the exact line
Privacy policy
“Docker does not select the model provider for you and does not use your prompts or the provider’s responses to train AI models.”
For example, a private coding prompt should not become Docker training data, though the model vendor you chose may still see it.
You keep rights to what you type and what the AI generates for you, as between you and Docker.
Read the exact line
Terms of service
“as between Docker and you, subject to Section 18, you retain all rights in the inputs you provide to AI Features and the Output generated specifically for you in response to your inputs”
For example, code Gordon writes for you is yours to use, subject to other laws.
Kids under 13 are not allowed; teens need a parent’s consent.
Read the exact line
Terms of service
“You must be at least 13 years of age to access or use the Services.”
For example, a 12-year-old should not create a Docker ID.
Words to know
Legal words from the lines above, in plain English.
- prompt
- What you type or say to an AI to get a response. For example, asking a chatbot to write a birthday message is a prompt, and it may be stored.
- model training
- Using your content and conversations as examples to teach an AI system, which can then echo them in future answers. For example, a story you write in a chatbot may be studied by the company to make the next version of the bot.
- indemnify
- You promise to pay the company's legal costs and losses if your use of the service gets it sued. For example, if you post a song you do not own and the label sues the app, you owe the app's lawyer bills.
- affiliates
- Other companies owned by or connected to the same parent company. For example, if you use one app, its sister apps under the same owner may also get your data.
- third parties
- Any company or person other than you and the app, such as advertisers, partners or analytics firms. For example, an analytics company that receives a record of every screen you tap is a third party.
- limitation of liability
- A cap on what the company will ever pay you if something goes wrong, often only what you paid in the last year. For example, if a leak of your data costs you thousands, the most you may get back is a month's subscription fee.
- inputs and outputs
- Inputs are what you type, say or upload to an AI; outputs are what it gives back to you. For example, the question you ask a chatbot is an input and its answer is an output, and both may be stored.
How we got here · grade A · score 59/100 · 14 of 15 policy answers backed by a verified quote · 3 not stated
What does the app collect beyond what it needs to work?
They collect account and billing details plus usage, telemetry, cookies, IP address, stored API keys, and sandbox snapshots.
Does it record your voice, face or body, and what happens to that?
The documents do not describe collecting voice, face, or body data.
Are your chats and uploads used to train AI models, and is that off by default?
Docker says it does not use your prompts or the AI provider’s responses to train AI models.
Can employees or contractors read your conversations, and when?
Not stated in the documents.
Are you profiled or tracked for advertising?
They use third-party analytics and advertising networks that track browsing with cookies and IP addresses.
Do they sell or share your data, and can you opt out?
They share with service providers and say they did not sell or share California data for cross-context ads; joint promotions need consent.
What rights do they take over what you type and what the AI makes?
You keep ownership of user content and AI inputs and output; Docker’s license is to run, secure, and improve the service.
How long do they keep your data after you delete it, and can you delete it in the app?
You request deletion through their form or support; they say they handle it within 30 days. Unsaved snapshots last seven days.
Does it build a lasting memory or profile of you, and can you see, edit or turn it off?
Not stated in the documents.
Do they commit to basic security, and have they leaked data?
They describe general security measures and incorporate a vulnerability disclosure policy.
Is there a real age gate, and are teens protected?
You must be 13 or older; ages 13–17 need a parent’s consent, based on your own statement.
Will they tell you when the rules change, and is the policy specific?
The policies are dated. Material privacy changes are posted on the site; continued use counts as acceptance.
Can they close your account without warning, and can you get your data out first?
They usually give prior written notice before ending access, except for urgent harm; no data-export right is described.
If something goes wrong, who pays?
The service is as-is, liability is capped at six months of fees or $100, and you must indemnify Docker.
Do subscriptions renew on their own, and can you get a refund?
Not stated in the documents.
The privacy policy is 6,697 words at a college graduate level (Flesch reading ease 38.2); the terms are 5,139 words at a college graduate level.