Doty — Privacy Policy
Last updated: June 21, 2026
1. Who we are and what this covers
This Privacy Policy explains how Meet Daisy, Inc. ("Doty," "we," "us"), the owner and operator of Doty, collects, uses, stores, shares, and protects information when you use our website, applications, and services (the "Services"). It applies to everyone who uses Doty. Capitalized terms not defined here have the meanings in our Terms of Service.
What Doty is, in privacy terms. Doty is a personal context and connection layer for AI. It stores the context you choose to save, and — only at your direction — accesses data in third-party services you connect ("Connected Accounts"). Doty is not an AI model; the reasoning is done by third-party AI models you choose to use. To the extent we process personal data in your Connected Accounts, we act on your behalf and on your instructions (as a processor / service provider), and you are the controller of that data. See §10.
2. Information we collect
a) Information you give us.
- Account information — name, email, authentication identifiers, and billing details (billing handled by our payment processor).
- Context you save — the preferences, notes, and personal context you choose to store in Doty so AI can serve you better.
b) Information from your Connected Accounts (only what you authorize). When you connect a service such as Gmail, Google Calendar, or Google Drive, Doty accesses the data needed to perform what you ask, within the permission scope you grant. Today this can include email messages and drafts, calendar events, and files — only as needed to carry out your requests, and only at the access tier you enable (for example, read-only versus permission to create, send, or delete). See our Terms for how scopes and Actions work.
c) Information we collect automatically.
- Usage and device data — log data, app interactions, approximate location from IP, device/browser type, and similar technical data used to operate, secure, and improve the Services.
- Cookies and similar technologies — for example, to keep you signed in and to understand how the Services are used.
3. How we use information
We use information to:
- provide, operate, secure, and maintain the Services and your account;
- carry out the requests and Actions you direct across your Connected Accounts;
- personalize Doty to you using the context you've saved;
- process payments and prevent fraud and abuse;
- comply with law and enforce our Terms;
- improve the Services, using usage data and aggregated or de-identified information (not the content of your Connected Accounts — see §4 and §5).
4. Artificial intelligence and your data
- We send what's needed to third-party AI models to fulfill your request. Your prompts and the relevant context are transmitted to third-party AI model providers (for example, Anthropic and OpenAI) acting as our sub-processors, so they can generate responses. We use these providers through their business/API channels, under terms by which they do not use your inputs or outputs to train their models and apply short retention.
- We do not train AI models on your Connected-Account content or saved context without your authorization.
- We do not use Google user data to develop, train, or improve generalized or non-personalized AI/ML models — at all (see §9, Google requirements).
- Any model improvement we perform uses usage data and aggregated/de-identified information only.
5. How we share information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only:
- with sub-processors who help us run the Services (hosting, infrastructure, AI model providers, payment processing, analytics), under contracts requiring appropriate protection and use only on our instructions;
- with the third-party services you connect, as needed to perform the Actions you direct;
- for legal reasons — to comply with law, legal process, or to protect rights, safety, and security;
- in a business transfer — as part of a merger, acquisition, or sale of assets (for Google user data, only with your explicit prior consent, per §9).
Aggregated and de-identified information. We may use aggregated or de-identified information that cannot reasonably be used to identify you to operate, analyze, and improve the Services, with safeguards against re-identification. We do not sell information that identifies you, and we never include data from your Connected Accounts (including Gmail, Calendar, Drive, or other Google user data) in any information we share or disclose for value — Connected-Account data is used solely to provide the Services to you (see §4 and §9).
6. Retention and deletion
We keep personal information only as long as needed to provide the Services, comply with law, resolve disputes, and enforce our agreements. You can delete saved context, disconnect a Connected Account, or close your account at any time; on deletion we remove or de-identify your personal information within a commercially reasonable period, except where retention is legally required. Residual copies may persist briefly in backups before being overwritten. Aggregated or de-identified data may be retained.
7. Security
We take reasonable and appropriate measures to protect information in transit and at rest, including encryption (TLS in transit; encryption at rest), access controls, and separation of each user's data and connections from others'. No method of transmission or storage is perfectly secure, but we work to protect your information and the credentials you entrust to us.
8. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal information, to object to certain processing, and to withdraw consent. You can also:
- review, change, or revoke any Connected Account's access at any time;
- delete saved context or close your account;
- opt out of any non-essential data uses we offer.
California (CCPA/CPRA): we do not sell or "share" personal information; you have rights to know, delete, correct, and to non-discrimination. EEA/UK (GDPR): our legal bases are performance of our contract with you, your consent, our legitimate interests, and legal obligations; you may lodge a complaint with your supervisory authority. To exercise rights, submit a request at doty.so/contact. Because much Connected-Account data is processed on your instructions (you are the controller), some requests about that data may be directed to you or fulfilled by you through the Services (see §10).
9. Google user data — Limited Use disclosure
Doty's access to Google services (such as Gmail, Google Calendar, and Google Drive) uses Google APIs and is governed by the Google API Services User Data Policy, including its Limited Use requirements. Specifically:
- We access Google user data only to provide and improve user-facing features of Doty that you use, and only within the scopes you authorize. We request the minimum scopes necessary.
- We do not transfer Google user data except: to provide or improve user-facing features (with your consent); for security purposes; to comply with applicable law; or as part of a merger or acquisition with your explicit prior consent.
- Humans do not read your Google user data except: with your affirmative consent for specific items; for security (e.g., investigating abuse); to comply with law; or where the data is aggregated/de-identified for internal operations.
- We do not sell Google user data, use it for advertising (including personalized or retargeted ads), or use it to determine credit-worthiness or for lending.
- We do not use Google user data to develop, train, or improve generalized or non-personalized AI/ML models.
Doty's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
10. Our role: controller vs. processor
For your account information and usage data, Doty is the controller. For personal data within your Connected Accounts (and the context you instruct us to handle), Doty acts as a processor / service provider on your behalf and on your documented instructions, and you are the controller — responsible for the lawful basis and any consents or notices required for that data and for the individuals it concerns. Where applicable law requires a data processing agreement, our Data Processing Addendum (available on request) applies. (This mirrors §11 of the Terms.)
11. International data transfers
We may process and store information in countries other than your own, including the United States. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers.
12. Children
The Services are intended for users 18 and older. We do not knowingly collect personal information from anyone under 18, and Doty is not directed to children. If we learn we have collected such information, we will delete it.
13. Changes to this Policy
We may update this Policy as the Services evolve or as law requires. We will post the updated Policy with a new effective date and, where the change is material or required, prompt you to review or consent before the new use takes effect.
14. Contact us
Questions or requests: submit at doty.so/contact, or by mail to Meet Daisy, Inc., P.O. Box 2158, Lenox, MA 01240.