Dooy

Privacy Policy

Last updated: February 19, 2026

1. Who We Are

This Privacy Policy explains how Dooy processes personal data when you use our website, dashboard, file-sharing tools, billing flows, and related APIs.

2. Data We Process

Depending on the features you use, we process: account data (name, email, user ID, linked OAuth IDs), authentication data (hashed password, session data, optional 2FA secret), profile and settings data, uploaded file metadata, support and ticket content, webhook endpoint configuration, and billing metadata.

For share activity and security analytics, we may process event data such as action type (view/download), masked IP information, device/browser information, user-agent string, and country-level geolocation.

3. Sources of Data

We collect data directly from you (for example during sign up, profile edits, and uploads), from authentication providers you choose to connect (for example Google, GitHub, Discord), from payment provider events (Stripe), and from technical request metadata generated while using the service.

4. How We Use Personal Data

We use personal data to provide and secure accounts, enable uploads/downloads and sharing links, process subscriptions and one-time purchases, send transactional service emails, enforce abuse protections, operate profile/guestbook/team features, and maintain service reliability.

5. Legal Bases (Where Applicable)

Where GDPR or similar laws apply, our primary legal bases are contract performance (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f), especially security and abuse prevention), legal obligations (Art. 6(1)(c)), and consent where required (Art. 6(1)(a)).

6. Cookies, Sessions, and Analytics

We use essential cookies/session tokens for sign-in, authentication state, and security. Without these technical cookies the dashboard cannot function.

We also process operational analytics and event logs to detect abuse, understand usage, and improve service quality. Event logs can include masked IP data and device metadata.

7. Payments and Billing

Payments are processed by Stripe. We receive billing-related metadata such as customer IDs, subscription IDs, payment state, invoice data, and event timestamps. We do not store full payment card numbers.

Stripe Privacy Policy: https://stripe.com/privacy

8. Service Providers and Recipients

We do not sell personal data. We share data with processors and infrastructure providers only as needed to provide the service. Based on your enabled features, this can include:

Stripe (billing), Cloudflare R2 (file storage), Cloudflare D1 (analytics/event storage), Resend (email delivery), selected OAuth providers (Google/GitHub/Discord), and user-configured webhook endpoints (e.g. Discord/Slack/Telegram/custom HTTPS endpoint).

9. International Data Transfers

Your data may be processed in countries other than your own. Where required, we use appropriate safeguards for cross-border transfers.

10. Retention

We retain personal data only as long as necessary for service operation, security monitoring, billing, legal obligations, and dispute handling. Retention periods differ by data type.

If you request account deletion, we delete or anonymize data where possible, while retaining records required for legal, security, or accounting obligations.

11. Security

We apply technical and organizational safeguards, including access controls, secure token-based auth flows, signed upload/download URLs, and webhook signature checks where configured. No method of transmission or storage is fully risk-free.

12. Your Rights

Depending on your location, you may have rights to access, rectify, erase, restrict processing, object, data portability, and complaint rights with a supervisory authority. You may also withdraw consent where processing is based on consent.

13. Children

The service is not directed to children under the age required by applicable law. If you believe a child provided personal data, contact us for removal.

14. Contact

Privacy requests: privacy@dooy.io
Support: support@dooy.io

15. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes are reflected by updating the "Last updated" date on this page.