1. Information we collect
We collect information you provide, information generated through your use of the service, information from connected accounts, and information from service providers.
- Account information, such as name, email address, password or sign-in method, workspace details, preferences, and support messages.
- Billing information, such as plan, subscription status, transaction records, tax details, billing address, and limited payment details from payment processors. We do not store full payment card numbers.
- Business and project information, such as your company idea, product brief, brand assets, pricing, website content, customer segments, instructions, prompts, files, code, generated output, and operational settings.
- Hosted website and app information, such as source and build artifacts, deployment settings, domains and subdomains, files, storage and database records, logs, security events, and other information needed to create, host, maintain, and support a product you operate with DoAny.
- Hosted Site Data, meaning personal information collected or stored on your behalf through a product you operate with DoAny, such as customer, visitor, lead, and other end-user names, emails, account and profile information, authentication events, form responses, uploads, public posts, messages, support conversations, consent choices, purchase records, invoices, and relationship notes.
- Integration information from third-party accounts you connect, such as tokens, account identifiers, permissions, settings, content, messages, analytics, and activity needed to provide connected workflows.
- Usage and device information, such as log data, IP address, browser type, device identifiers, pages viewed, actions taken, feature usage, diagnostic events, and approximate location derived from IP address.
- Cookie and tracking information, as described in our Cookie Policy.
2. How we use information
We use information to provide, operate, secure, support, and improve DoAny and the products or workflows you ask DoAny to create or manage.
- Create and manage accounts, workspaces, subscriptions, billing, authentication, support, and service communications.
- Build, host, deploy, update, and operate websites, apps, content, automations, customer workflows, and AI agent actions you request.
- Operate product features you enable, such as authentication, forms, uploads, databases, storage, communications, analytics, security controls, and public or private sharing.
- Process prompts, files, business data, customer data, and connected-account data to generate output and carry out your instructions.
- Send or help you send business communications, support replies, invoices, outreach, notifications, and other messages based on your settings.
- Monitor performance, debug issues, prevent fraud, protect security, enforce policies, and comply with legal obligations.
- Analyze aggregate usage, improve product quality, develop features, and understand which parts of DoAny are working.
- Send product updates, launch notes, and marketing communications where allowed. You can opt out of marketing emails.
3. AI processing and model improvement
DoAny uses AI systems and third-party AI providers to generate, transform, summarize, classify, route, and act on information. Prompts, files, business data, customer data, and generated output may be processed by those systems to provide the service.
We process Hosted Site Data on your behalf to host, maintain, support, troubleshoot, and secure your product, carry out your instructions, and comply with law. We do not use Hosted Site Data for unrelated advertising. Any use for independent product development or model training will be described in an applicable feature notice, setting, or separate agreement with you.
If you enable an AI feature in a website, app, or workflow, the information sent to that feature may be processed by a third-party AI provider. Provider retention and model-improvement practices can vary by provider, product, account type, settings, and applicable agreement. Do not direct an AI feature to process confidential or sensitive information unless your plan, configuration, notices, consents, and agreement permit it.
We may use aggregated, de-identified, or statistical information to improve DoAny, measure performance, and understand usage trends, provided it does not identify you, your customers, or your business.
4. Your websites, apps, customers, and end users
When you use DoAny to build or operate a business, website, app, support channel, sales workflow, or customer communication, you may collect personal information from your customers, visitors, prospects, and users.
For Hosted Site Data, you are generally the business, controller, or equivalent party, and DoAny acts as your service provider or processor where applicable. DoAny may separately act as a controller for the limited purposes described elsewhere in this Policy, such as account administration, security, billing, and our own legal obligations.
You are responsible for having a lawful basis; providing a legally compliant privacy notice wherever required; explaining your collection, use, and sharing of Hosted Site Data; honoring rights requests; and providing controls that let end users give, refuse, or withdraw permissions and consent where required.
Before publishing, you should review every feature that can collect or expose personal information, including forms, uploads, open-text fields, public posting, analytics, and sign-in. Collect only what you need, secure it appropriately, and monitor and moderate visitor submissions if you allow them.
DoAny-hosted products must not create, receive, maintain, transmit, or otherwise process Protected Health Information regulated by HIPAA or payment-card data subject to PCI DSS through their forms, files, databases, logs, or other storage. This does not prohibit using a supported, PCI-compliant payment processor when payment-card data is entered directly into processor-controlled checkout fields and is not handled by DoAny.
Do not use DoAny to process other sensitive personal information, government identifiers, children's information, or other high-risk data unless your plan, settings, agreements, legal basis, notices, consents, and enhanced safeguards allow it.
5. Cookies and similar technologies
We and our service providers may use cookies, local storage, pixels, SDKs, and similar technologies to keep you signed in, remember preferences, measure performance, understand usage, prevent fraud, and support marketing where enabled. See our Cookie Policy for more detail.
For a website or app you operate with DoAny, you decide which non-essential cookies and similar technologies to enable and are responsible for giving required notice, obtaining consent before using them where required, and providing an effective way to withdraw consent or change preferences.
6. How we share information
We do not sell personal information for money. We may share information in the ways described below.
- With service providers and subprocessors that help us provide hosting, storage, databases, AI processing, payments, analytics, email, support, security, monitoring, and other operations.
- With third-party services you connect or direct us to use, such as payment processors, hosting providers, email tools, social networks, ad platforms, search tools, marketplaces, and customer support tools.
- With teammates, workspace members, and account administrators according to your workspace settings.
- With customers, visitors, or the public when you publish content, launch a website or app, send messages, create public listings, or otherwise direct DoAny to make information available.
- With authorities, courts, regulators, or other parties when we believe disclosure is required by law or needed to protect rights, safety, security, or the integrity of the service.
- With a successor or prospective successor in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets.
7. Payments
Payments are processed by third-party payment providers. They collect and process payment information under their own terms and privacy policies. DoAny receives limited billing details, such as customer identifiers, plan status, invoices, payment status, and transaction metadata.
8. Retention
We retain information for as long as needed to provide the service, maintain your account, operate your products and workflows, comply with legal obligations, resolve disputes, enforce agreements, prevent abuse, and maintain backups.
You may request deletion of account information, but some information may remain in backups, logs, billing records, security records, or legal records for a limited period or as required by law. Deleting information may disable products, workflows, or customer records that depend on it.
Unpublishing a website or app does not necessarily delete its Hosted Site Data or deployed resources. Deletion timing and scope depend on the product controls available to you, your plan or agreement, backup schedules, security and fraud-prevention records, and legal-retention requirements.
9. Security
We use technical, organizational, and administrative safeguards designed to protect information. No internet service, AI system, or connected workflow can be guaranteed to be perfectly secure. You are responsible for strong passwords, account access controls, integration permissions, and reviewing agent actions.
You are also responsible for reviewing the security and access settings of products you publish, testing authentication and data-collection features, limiting access to Hosted Site Data, and promptly addressing vulnerabilities or unauthorized activity you discover.
10. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal information. You may also have the right to opt out of certain marketing, analytics, or advertising uses.
You can update account information in the product, unsubscribe from marketing emails using the link in those emails, adjust browser cookie settings, or contact us with a privacy request.
If your request concerns information collected by a DoAny customer through that customer's website, app, or workflow, contact that customer first. We will assist the customer with verified requests where required by law and our agreement with them.
11. International transfers
DoAny and our service providers may process information in the United States and other countries. Those countries may have data protection laws that differ from the laws where you live. When required, we use appropriate safeguards for international transfers.
12. Children
DoAny platform accounts are not intended for people under 18, and people under 18 may not create or use a DoAny account. We do not knowingly collect personal information through a DoAny account belonging to a person under 18. If you believe a child has created an account or provided information directly to DoAny, contact us so we can take appropriate steps.
Websites, apps, and services built or operated with DoAny may not target children under 13 or the applicable age of digital consent. If your product lawfully serves older minors, you are responsible for age-appropriate notices, consent, safeguards, and all other legal requirements, and DoAny may process that Hosted Site Data on your instructions.
13. Changes to this policy
We may update this Privacy Policy from time to time. If changes are material, we will provide notice by posting the updated policy, updating the date above, or using another reasonable method.
14. Contact
Questions or requests about privacy can be sent through the contact page or to privacy@doany.ai.