whatdoido?

PRIVACY POLICY

LAST UPDATED 2026-08-17

THE SHORT VERSION

We keep your email, what you typed, and the answers you got. We don't keep your files or photos — those go to the model for one request and are gone. We don't sell anything to anyone, and there is no advertising or cross-site tracking here. Analytics only run if you say yes. You can delete the whole account from this page.

The rest of this page is the same thing said carefully.

WHO WE ARE

The service is operated by whatdoido, an individual-run business based in Colorado, United States, not a registered company — practically, the person running it is the data controller for the information described here. Contact details are at the bottom of this page.

WHAT WE COLLECT

  • Account information — your email address, and your name and profile photo if you sign in with Google.
  • What you submit — the text you type or dictate, the links you paste, and the photos and files you upload for analysis.
  • Analysis results — the verdict, the summary, and any follow-up rounds tied to what you submitted.
  • Usage records — which actions you completed, points, and reminder and check-in state, so the app can show your history and progress.
  • Billing information — if you subscribe, your subscription status and identifiers from our payment processor. We never receive or store your full card number.
  • Abuse-prevention counters — a per-day count of requests, so daily limits can be enforced.

WHAT WE DON'T KEEP

The bytes of the photos and files you upload are never stored. An image or document goes to the model for the one request that analyses it, and is then dropped. Only the file name is kept afterwards, so your history has something to show you.

We don't sell or rent personal information, we don't share it for advertising, and we don't run cross-site tracking. We don't use your submissions to build a profile of you.

WHY WE USE IT

To run the service — to produce an analysis, to show you your history, to keep you signed in, and to take payment if you subscribe. Where the law requires a legal basis, this is performance of our contract with you.

To keep the service working and safe — enforcing usage limits, preventing automated abuse, and investigating misuse. The basis for this is our legitimate interest in a service that stays available and isn't abused.

To understand how the site is used — only if you consent to analytics, and you can withdraw that at any time in the cookies section below.

WHO ELSE PROCESSES IT

  • Anthropic — receives what you submit in order to generate the analysis, and any drafted message or cancellation steps. Processed under Anthropic's API terms. For details, see the Anthropic API and Data Retention Guide, the Anthropic Commercial Privacy Center, or the general Anthropic AI Policy Hub.
  • Supabase — hosts the database and the authentication system where your account and results are stored.
  • Vercel — hosts and serves the application, and processes standard request and security logs.
  • Stripe — processes payments and holds your card details directly, if you subscribe.
  • Cloudflare — its Turnstile service processes technical browser and network signals on the sign-in page to block automated abuse.
  • Google Analytics — receives ordinary page and device usage information, and only after you allow it. We do not send the contents of your submissions as analytics events.
  • BeVisible — receives request details (the page, method, host, referrer, and IP address) only when a request identifies itself as an AI crawler, like the bots behind ChatGPT, Claude, or Perplexity. It does not see traffic from ordinary visitors.

When you submit a link, or when an accurate answer depends on current information, the model may fetch that page or run a web search as part of answering.

WHERE IT GOES

These providers are based in, or process data in, the United States. If you are in the UK, the EEA, or Switzerland, using the service means your information is transferred there.

Those transfers are covered by data processing agreements with each provider that incorporate the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum for transfers out of the UK. Stripe additionally relies on its certification under the EU–US Data Privacy Framework, its UK Extension, and the Swiss–US Data Privacy Framework.

Alongside those terms, traffic to and between these services is encrypted in transit, and each provider is contractually bound to process your information only on our instructions and not for its own purposes.

You can ask us for more detail about the safeguards covering a particular transfer, using the contact address at the bottom of this page.

HOW LONG WE KEEP IT

  • Account data, submitted text and results — until you delete your account.
  • Uploaded file and photo bytes — not retained past the request that processes them.
  • Signed-out trial data — held only in the current browser tab's session, with a maximum age of 24 hours. Signed-in content is not mirrored to persistent browser storage.
  • Daily abuse-prevention counters — automatically removed after 35 days.

Copies held temporarily in infrastructure backups and security logs are removed on our hosting providers' own retention schedules.

COOKIES

We use three, and none of them are for advertising:

  • A session cookie that keeps you signed in, managed by Supabase Auth.
  • A short-lived cookie that remembers a signed-out visitor has already used their one free analysis.
  • A cookie recording your analytics choice. Google Analytics loads only after you select ALLOW, and never before.

You can change your analytics choice here at any time:

YOUR RIGHTS

Depending on where you live, you may have the right to access a copy of your information, correct it, delete it, receive it in a portable form, object to or restrict certain processing, and withdraw consent you previously gave. Withdrawing consent doesn't affect processing that already happened.

If you are signed in you can delete everything yourself, below. For anything else, contact us and we will respond within the time the law allows. You will never be charged a different price or given a worse service for exercising a privacy right.

If you think we have handled your information badly, you can complain to your local data protection authority.

DELETING YOUR ACCOUNT

If you are signed in, the button below deletes your authentication account and the database rows tied to it — your submissions, your results, and your usage records. It can't be undone.

Signed out, there is nothing here to delete from this device. Sign in to remove an existing account, or contact us and we will do it for you.

SENSITIVE INFORMATION

What you send may include medical, financial, or legal details — that is the point of the app. Send only what you are comfortable having processed as described here.

Take particular care with information about other people. If it isn't yours to share, don't send it.

CHILDREN

The service is for adults, and the terms of service require you to be 18 or over. We don't knowingly collect information from children. If you believe a child has given us information, contact us and we will delete it.

SECURITY

Traffic is served over HTTPS. Every account row in the database is scoped to its owner by row-level security, so one account cannot read another's data. The sign-in page is protected against automated abuse, and anonymous sign-ins are disabled.

No service is perfectly secure, and we can't guarantee against every possible compromise. Use a strong, unique password, and tell us if you think your account has been accessed by someone else.

CHANGES TO THIS POLICY

We may update this policy as the product changes. When we do, we will change the date at the top of this page, and for changes that materially affect your rights we will give notice before they take effect.

CONTACT

Privacy questions, or to exercise a right described above: info@whatdoido.co.

Privacy policy — whatdoido?