1. Summary
- We collect information you provide for your account, profile, groups, tasks, itineraries, expenses, and other features you use.
- Collaboration content (including tasks, chat, activity, attachments, expenses, balances, and settlements) is stored so the relevant people can work together.
- If you verify a phone number or use contact-based discovery, we process that information to help you connect with people you already know.
- We use infrastructure, authentication, messaging, and AI providers to run the Service securely.
- Optional location, Google Calendar, contact-discovery, and AI features process only the information needed when you choose to use them.
- We do not sell your personal information and do not share it for cross-context behavioral advertising.
- You can delete your account; some data may be retained or de-identified where required for safety, law, or to keep groups usable.
2. Information we collect
Information you provide
- Account: email and authentication identifiers (Sign in with Apple, Google, or email verification).
- Profile: display name, optional photo, interests or skills, and other fields you add.
- Phone number (optional): if you choose to verify a phone number, we collect the number and confirm it via a one-time SMS code so people you know can find you and so we can reduce abuse. You can use the app without verifying a phone number.
- Contacts (optional): if you grant permission, we read phone numbers from your device address book to check which of your contacts already use DoneYet. We match these against verified users and do not store the contacts of people who are not DoneYet users.
- Groups & tasks: names, descriptions, cover images, task details (titles, notes, dates and times, recurrence, assignments, completion, locations, expenses, rewards), and related metadata.
- Itineraries & travel planning: activity order, dates and times, locations, travel-leg estimates, route choices, and information used to identify an obvious flight destination when that feature applies.
- Expenses & balances: descriptions, amounts, currencies, dates, payers, participants, split amounts, balances, and settlement records for group and direct expenses.
- Collaboration: chat messages, task comments, reactions, activity, and content visible to the applicable group or direct participants.
- Files & media: profile and group images, task and chat attachments, receipts, proof of completion, report evidence, and file metadata such as name, type, and size.
- Locations (optional): addresses, place identifiers, coordinates, and—only when you request it and grant permission—your current location. We do not require continuous background location tracking.
- DY Assist: messages you send to receive a response.
- Support: messages via Contact Support, including optional diagnostics you choose to include.
- Google Calendar (optional): if you connect one or more Google accounts, we retrieve the calendars you choose and read event details such as title, useful description, location, and start/end time so those events can appear in DoneYet’s calendar.
- Rewards (where enabled): payout preferences (such as a Venmo or PayPal handle), gift-card delivery details where applicable, and related details you provide for task rewards.
Information collected automatically
- Device & app: device type, OS version, app version, locale, and time zone.
- Logs: server and application logs for operation, debugging, and security.
- Push: device tokens for notifications (Apple Push Notification service, Firebase Cloud Messaging, coordinated via Expo where applicable).
- Usage: interactions needed for entitlements, feature limits, and product improvement.
- Local storage: session information, preferences, cached data, drafts, and queued changes stored by the app or browser to keep DoneYet responsive and support recovery when connectivity changes.
3. How we use information
- Provide accounts, groups, tasks, itineraries, chat, expenses, balances, settlements, rewards, invites, notifications, and collaboration;
- Help you find and invite people you already know (phone verification and contact-based discovery), which you can turn off in Account → Settings;
- Find places, geocode addresses, estimate itinerary travel, and optimize routes when you use location features;
- Operate DY Assist, Insights, receipt scanning, distribution helpers, and moderation on eligible plans;
- Display events from calendars you explicitly select when you enable the read-only Google Calendar integration;
- Maintain security, prevent abuse, and improve reliability; and
- Respond to support requests.
4. How we share information
With other users
Content you add to a group may be visible to its members according to product design and permissions. Direct tasks and expenses are visible to their applicable creator, assignee, and participants. Some shared records may remain visible in de-identified form if a participant later deletes an account.
Service providers
We use providers and services to perform limited functions on our behalf, including:
- Supabase: authentication, database, storage, and serverless functions;
- Apple and Google: sign-in and in-app subscription billing;
- Firebase (Google): phone-number verification by SMS when you choose to verify a number;
- RevenueCat: subscription and entitlement management;
- OpenAI: DY Assist, moderation, and certain classification or suggestion features;
- Resend: delivery of invitation and support emails;
- Google Maps Platform and Mapbox: place suggestions, geocoding, and routing; OpenStreetMap-based services may be used as a limited location fallback;
- Tremendous: eligible gift-card reward fulfillment where that option is offered; and
- Expo and push services: notification delivery.
Contacts and friend discovery
If you allow access to your device contacts, phone numbers from your address book are sent to our servers and matched against verified DoneYet users so we can show which contacts are already here. We use these numbers only for matching, do not retain contacts that do not match a DoneYet user, and do not share your contacts with other users or sell them. You can stop being discoverable this way from Account → Settings (“Find me on DoneYet”), and you can revoke contacts permission in your device settings.
Google Calendar integration
Google Calendar access is optional, read-only, and separate from signing in to DoneYet. Eligible users may connect multiple Google accounts. We store account and selected-calendar identifiers plus encrypted OAuth credentials so each connection can continue across devices. Event content is requested from Google when you view DoneYet’s calendar and is not stored as event records in DoneYet’s database. In-memory session caching may be used to display the calendar efficiently. DoneYet does not create, edit, or delete Google Calendar events and does not use Google Calendar data for advertising, AI training, or unrelated product features.
DoneYet requests only the Google Calendar read-only permissions needed to list your calendars and display events from calendars you select. Google Calendar requests are made through DoneYet’s authenticated server function and are scoped to the signed-in DoneYet user and the specific Google account connection. DoneYet personnel do not access Google Calendar event content except when you explicitly request support and consent to that access, when access is necessary to investigate a security incident, or when required by law.
If you choose Add to DoneYet for an event, selected event details are placed into a temporary task draft and become ordinary DoneYet task data only when you save the task. You can change selected calendars or disconnect an account at any time from Account → Settings → Integrations; disconnecting deletes DoneYet’s stored credentials for that connection and requests token revocation from Google. You may also revoke access in your Google Account settings.
DoneYet does not transfer, sell, or use Google Workspace API data for advertising, credit or lending decisions, data brokerage, or creating, developing, improving, or training generalized or non-personalized artificial-intelligence or machine-learning models. Google Calendar event content is not sent to DY Assist or other model providers.
DoneYet’s use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Legal and safety
We may disclose information to comply with law, enforce our Terms, investigate abuse, or protect users and the Service.
Business changes and your direction
Information may be transferred as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to applicable law and appropriate notice. We may also share information when you direct us to do so or give consent.
No sale of personal information
We do not sell your personal information. If that changes, we will update this policy and provide required notices.
5. AI and automated processing
DY Assist and related features may send your inputs and relevant context (such as a structured summary of your tasks) to model providers. Receipt scanning may process an image to suggest expense fields. Automated moderation may analyze text or images (for example, profile or cover photos). AI output can be imperfect. Do not treat it as professional advice.
6. Data retention
We retain information as long as needed to provide the Service and for legitimate purposes such as safety, fraud prevention, and legal compliance.
When you delete your account in the app, we delete or anonymize personal data tied to your account per our implementation, subject to backup, legal, and safety retention described on our delete account page. Content you contributed to a group or shared financial record (such as tasks, comments, expenses, and settlements) may remain with the relevant group or participants in de-identified form so shared history and balances remain usable.
DoneYet apps and websites may keep temporary caches, drafts, and queued changes on your device for speed and offline recovery. These may remain until they expire, you sign out, clear browser or app data, or uninstall the app, depending on the feature and platform.
For Google Calendar, DoneYet retains connection metadata, selected-calendar identifiers, and encrypted OAuth credentials only while the applicable Google account remains connected. Calendar event content is not retained as event records in DoneYet’s database or persistent application cache. Disconnecting a Google account deletes its stored OAuth credentials and requests revocation from Google. Details you expressly convert into a DoneYet task are retained as DoneYet task data under the ordinary retention rules above.
7. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, export, or object to certain processing. Manage much of your data in DoneYet (profile, phone verification, contact discoverability, calendar connections, notifications, and account deletion); for other requests, contact us below.
California (CCPA/CPRA): We do not sell your personal information and do not share it for cross-context behavioral advertising. California residents may request access or deletion and will not be discriminated against for exercising these rights.
EEA/UK (GDPR): We process personal data to perform our contract with you (providing the Service), based on your consent (for example, contacts access and optional features), and for legitimate interests such as security and abuse prevention. You may have rights to access, rectification, erasure, restriction, portability, and objection, and to lodge a complaint with your supervisory authority.
Do Not Track: We do not respond to browser “Do Not Track” signals.
8. Security and protection of Google user data
We use administrative and technical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. Data transmitted between DoneYet clients, DoneYet’s service infrastructure, and Google APIs is sent over HTTPS using transport-layer encryption.
Google OAuth access and refresh tokens are encrypted before database storage using AES-256-GCM with a new random initialization vector for each encryption operation. Authenticated additional data binds encrypted credentials to the applicable DoneYet user and Google Calendar connection. The encryption key is kept as a server-side secret separate from the database and is not included in DoneYet’s mobile or web clients. Connection metadata stored with our hosted database provider is also protected by encryption at rest. Credential tables are inaccessible to public, anonymous, and ordinary authenticated database clients and are accessed only by DoneYet’s server-side Calendar function.
Calendar API responses are marked not to be stored by intermediary caches. Google Calendar event content and calendar lists are excluded from DoneYet’s persistent application query cache; limited in-memory caching may be used during an active app session to display the feature and reduce unnecessary Google API requests. OAuth credentials and Calendar event content are not intentionally written to application logs.
DoneYet authenticates Calendar API requests, validates that each requested connection belongs to the signed-in user, limits OAuth permissions to read-only Calendar access, and uses short-lived, single-use, cryptographically random OAuth state values for browser authorization. Stored state is hashed, expires after a short period, and the browser flow uses PKCE to reduce authorization-code interception risk. Disconnecting removes stored credentials and requests token revocation from Google.
We review and update safeguards as the Service changes and take steps to investigate and contain suspected security incidents. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
9. Children’s privacy
The Service is not directed to children under 13, and we do not knowingly collect their personal information. Contact us if you believe we have done so.
10. International transfers
Information may be processed in the United States (including Texas) or where our providers operate, which may have different data protection laws than your country.
11. Changes
We may update this policy. Continued use after the “Last updated” date means acceptance unless law requires otherwise.
12. Contact
Privacy: [email protected]
Legal: [email protected]
Support: [email protected]