Privacy policy

Effective Oct 9, 2026 . Last updated Oct 9, 2026

This policy explains how Skyfield Digital LLC, doing business as Doily (“Doily”, “we”, “us”), collects, uses and shares personal data in connection with the Doily platform, websites and apps (the “Service”). Our address is 1 Prestige Drive, Suite 202, Meriden, CT 06450, USA. Contact: [email protected]; privacy and security matters: [email protected].

1. Two roles, one short version

  • For your account, billing, our websites and our marketing, Doily is the data controller and this policy governs.
  • For data you or your organization load into a workspace about your own clients, users or business (“Client Data”), Doily is a processor acting on the workspace owner’s instructions. The workspace owner’s own privacy notice governs that data, and our Data Processing Addendum governs how we handle it. If you interact with a workspace run by an agency, that agency is responsible for your data; contact them first, and we will help them respond.

The short version: we collect what we need to run the Service, we do not sell personal data, we do not use your content to train AI models, and you can export or delete your workspace.

2. What we collect

Account data. Name, email, password credentials (hashed), workspace and role information, profile settings, two-factor enrollment, support messages.

Billing data. Plan, invoices and transaction history. Payment is handled by Stripe; we never see or store full card numbers. Stripe’s privacy policy applies to the payment itself.

Content you submit. Client records, keywords and prompts you track, documents and files you upload, notes, tasks, reports and settings.

Connected account data. When you connect a third-party tool (for example Google Search Console, Google Analytics, a CRM or an advertising account), we receive the data that connection authorizes, through the provider’s official interface, to power the features you use. Credentials and tokens are stored encrypted; we never store raw usernames and passwords for third-party tools, and you can disconnect at any time.

Tracking data we gather for you. Search results, AI engine answers and related public data about the domains, keywords and prompts you choose to track, collected through data providers and official APIs.

Usage and device data. Log data, IP address, browser and device information, pages and features used, and product analytics events. General location may be inferred from IP address. Mobile apps collect push tokens if you enable notifications.

Email interaction data. Delivery, bounce, and, for report and digest emails only, open and click events. Security and billing emails are never tracked.

We do not knowingly collect data from anyone under 18; the Service is a business tool. If you believe someone under 18 has provided us data, contact [email protected] and we will delete it.

3. How we use data

  • To provide, operate and secure the Service, including authentication, quotas, backups and fraud prevention.
  • To process payments, send invoices and manage subscriptions.
  • To run the features you use, including tracking, audits, reports, notifications and AI features.
  • To provide support and communicate about the Service (service messages cannot be opted out of while you have an account).
  • To send product news and marketing you can opt out of with one click.
  • To understand aggregate product usage and improve the Service; we may create de-identified, aggregated data and use it for lawful business purposes, never to re-identify anyone.
  • To comply with law and enforce our terms.

Legal bases where GDPR or UK GDPR applies: performance of contract (most of the above), legitimate interests (security, product analytics, B2B marketing), consent (site analytics cookies in the EU and UK, marketing where required), and legal obligation (tax and accounting records).

4. AI features and limited use

Features such as Ask Doily send relevant workspace data and your question to large language model providers to generate the answer. We configure zero data retention or no-training options with every AI provider where offered, and all are listed as subprocessors. AI providers process this data to return the response, not to train generalized models.

Data received from Google APIs is used and transferred in accordance with the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the features you connect it for; we do not sell it, use it for advertising, or allow humans to read it except with your consent, for security, to comply with law, or as needed to operate the feature.

5. When we share data

  • Subprocessors and service providers. Vendors that host and help us run the Service (hosting, storage, payments, email delivery, analytics, error tracking, data providers, AI providers), under contracts limiting their use of data to providing their service to us. The current list is published at doily.ai/subprocessors, with a mailing list for change notices.
  • Within your workspace. Members, clients and collaborators see data per the roles and permissions the workspace owner sets. White-label workspaces present the agency’s brand; the agency is the party responsible to its clients.
  • Payment flows between agencies and their clients run on the agency’s own payment account; we are not a party to them.
  • Legal. We disclose data where required by law or to protect rights, safety or the integrity of the Service, and we tell you unless the law prevents it.
  • Business transfers. In a merger, acquisition or asset sale, data may transfer with the business under this policy’s protections.

We do not sell personal data and we do not share it for cross-context behavioral advertising.

The Service and our sites may link to third-party websites and services we do not control; their own privacy policies govern what they collect.

6. Cookies and analytics

The app itself sets only cookies essential to sign-in and security. Our marketing site uses analytics (PostHog, Google Analytics) to understand traffic; visitors from the EU and UK see a consent banner, and declining loads no analytics. We honor Global Privacy Control signals on the marketing site where applicable law gives them effect. Like most sites, we do not respond to browser Do Not Track signals, for which no standard exists; GPC is the signal we honor.

7. Security

Data is encrypted in transit and at rest. Third-party credentials are encrypted with per-workspace keys under a hardware-backed key management service. Access is role-based and logged; two-factor authentication is available to all users and can be required by workspace admins. We maintain audit logs, tested backups, and an incident response process: if a breach affects your personal data, we will notify affected workspaces without undue delay and within 72 hours of becoming aware of it. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security; the DPA describes our full technical and organizational measures.

8. Retention

  • Account data: while your account exists, then deleted or anonymized within 30 days of account deletion.
  • Workspace content: while the workspace exists; after cancellation there is a 30-day read-only grace period with full export, then hard deletion on our systems, with backups aging out on their own cycle shortly after.
  • Tracking history: per the workspace’s plan retention setting.
  • Billing and tax records: 7 years, as required.
  • Email event and server logs: short rolling windows used for security and deliverability.

9. International transfers

We are a U.S. company and host the Service in the United States. Where we receive personal data protected by EU, UK or Swiss law, we transfer it under the European Commission’s Standard Contractual Clauses and the UK Addendum, incorporated through our DPA, plus supplementary technical measures described there.

10. Your rights

Depending on where you live (including the EEA, UK, California and other U.S. states with privacy laws), you may have rights to access, correct, delete, export, or restrict or object to processing of your personal data, to withdraw consent, and to not be discriminated against for exercising rights. You can exercise most of them directly: profile settings for correction, workspace export for access and portability, and workspace deletion for erasure. For anything else, email [email protected]; we respond within the time the applicable law requires and may need to verify your identity. If you are in the EEA or UK you may also complain to your supervisory authority. For Client Data in an agency’s workspace, we will route your request to the agency and support their response.

California note: we do not sell or share personal information as the CCPA defines those terms, and we collect the categories described in section 2 for the purposes in section 3.

11. Changes

We will post changes here and, for material changes, notify account holders by email or in-product notice at least 30 days before they take effect.

12. Contact

Skyfield Digital LLC (DBA Doily)
1 Prestige Drive, Suite 202, Meriden, CT 06450, USA
[email protected] and [email protected]