This policy explains how Primavera Tech LLC (“DoneYet”) handles information when you use the DoneYet app, doneyet.co pages, and related services (the “Service”).

1. Summary

2. Information we collect

Information you provide

Information collected automatically

3. How we use information

4. How we share information

With other users

Content you add to a group may be visible to its members according to product design and permissions. Direct tasks and expenses are visible to their applicable creator, assignee, and participants. Some shared records may remain visible in de-identified form if a participant later deletes an account.

Service providers

We use providers and services to perform limited functions on our behalf, including:

Contacts and friend discovery

If you allow access to your device contacts, phone numbers from your address book are sent to our servers and matched against verified DoneYet users so we can show which contacts are already here. We use these numbers only for matching, do not retain contacts that do not match a DoneYet user, and do not share your contacts with other users or sell them. You can stop being discoverable this way from Account → Settings (“Find me on DoneYet”), and you can revoke contacts permission in your device settings.

Google Calendar integration

Google Calendar access is optional, read-only, and separate from signing in to DoneYet. Eligible users may connect multiple Google accounts. We store account and selected-calendar identifiers plus encrypted OAuth credentials so each connection can continue across devices. Event content is requested from Google when you view DoneYet’s calendar and is not stored as event records in DoneYet’s database. In-memory session caching may be used to display the calendar efficiently. DoneYet does not create, edit, or delete Google Calendar events and does not use Google Calendar data for advertising, AI training, or unrelated product features.

DoneYet requests only the Google Calendar read-only permissions needed to list your calendars and display events from calendars you select. Google Calendar requests are made through DoneYet’s authenticated server function and are scoped to the signed-in DoneYet user and the specific Google account connection. DoneYet personnel do not access Google Calendar event content except when you explicitly request support and consent to that access, when access is necessary to investigate a security incident, or when required by law.

If you choose Add to DoneYet for an event, selected event details are placed into a temporary task draft and become ordinary DoneYet task data only when you save the task. You can change selected calendars or disconnect an account at any time from Account → Settings → Integrations; disconnecting deletes DoneYet’s stored credentials for that connection and requests token revocation from Google. You may also revoke access in your Google Account settings.

DoneYet does not transfer, sell, or use Google Workspace API data for advertising, credit or lending decisions, data brokerage, or creating, developing, improving, or training generalized or non-personalized artificial-intelligence or machine-learning models. Google Calendar event content is not sent to DY Assist or other model providers.

DoneYet’s use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Legal and safety

We may disclose information to comply with law, enforce our Terms, investigate abuse, or protect users and the Service.

Business changes and your direction

Information may be transferred as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to applicable law and appropriate notice. We may also share information when you direct us to do so or give consent.

No sale of personal information

We do not sell your personal information. If that changes, we will update this policy and provide required notices.

5. AI and automated processing

DY Assist and related features may send your inputs and relevant context (such as a structured summary of your tasks) to model providers. Receipt scanning may process an image to suggest expense fields. Automated moderation may analyze text or images (for example, profile or cover photos). AI output can be imperfect. Do not treat it as professional advice.

6. Data retention

We retain information as long as needed to provide the Service and for legitimate purposes such as safety, fraud prevention, and legal compliance.

When you delete your account in the app, we delete or anonymize personal data tied to your account per our implementation, subject to backup, legal, and safety retention described on our delete account page. Content you contributed to a group or shared financial record (such as tasks, comments, expenses, and settlements) may remain with the relevant group or participants in de-identified form so shared history and balances remain usable.

DoneYet apps and websites may keep temporary caches, drafts, and queued changes on your device for speed and offline recovery. These may remain until they expire, you sign out, clear browser or app data, or uninstall the app, depending on the feature and platform.

For Google Calendar, DoneYet retains connection metadata, selected-calendar identifiers, and encrypted OAuth credentials only while the applicable Google account remains connected. Calendar event content is not retained as event records in DoneYet’s database or persistent application cache. Disconnecting a Google account deletes its stored OAuth credentials and requests revocation from Google. Details you expressly convert into a DoneYet task are retained as DoneYet task data under the ordinary retention rules above.

7. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, export, or object to certain processing. Manage much of your data in DoneYet (profile, phone verification, contact discoverability, calendar connections, notifications, and account deletion); for other requests, contact us below.

California (CCPA/CPRA): We do not sell your personal information and do not share it for cross-context behavioral advertising. California residents may request access or deletion and will not be discriminated against for exercising these rights.

EEA/UK (GDPR): We process personal data to perform our contract with you (providing the Service), based on your consent (for example, contacts access and optional features), and for legitimate interests such as security and abuse prevention. You may have rights to access, rectification, erasure, restriction, portability, and objection, and to lodge a complaint with your supervisory authority.

Do Not Track: We do not respond to browser “Do Not Track” signals.

8. Security and protection of Google user data

We use administrative and technical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. Data transmitted between DoneYet clients, DoneYet’s service infrastructure, and Google APIs is sent over HTTPS using transport-layer encryption.

Google OAuth access and refresh tokens are encrypted before database storage using AES-256-GCM with a new random initialization vector for each encryption operation. Authenticated additional data binds encrypted credentials to the applicable DoneYet user and Google Calendar connection. The encryption key is kept as a server-side secret separate from the database and is not included in DoneYet’s mobile or web clients. Connection metadata stored with our hosted database provider is also protected by encryption at rest. Credential tables are inaccessible to public, anonymous, and ordinary authenticated database clients and are accessed only by DoneYet’s server-side Calendar function.

Calendar API responses are marked not to be stored by intermediary caches. Google Calendar event content and calendar lists are excluded from DoneYet’s persistent application query cache; limited in-memory caching may be used during an active app session to display the feature and reduce unnecessary Google API requests. OAuth credentials and Calendar event content are not intentionally written to application logs.

DoneYet authenticates Calendar API requests, validates that each requested connection belongs to the signed-in user, limits OAuth permissions to read-only Calendar access, and uses short-lived, single-use, cryptographically random OAuth state values for browser authorization. Stored state is hashed, expires after a short period, and the browser flow uses PKCE to reduce authorization-code interception risk. Disconnecting removes stored credentials and requests token revocation from Google.

We review and update safeguards as the Service changes and take steps to investigate and contain suspected security incidents. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

9. Children’s privacy

The Service is not directed to children under 13, and we do not knowingly collect their personal information. Contact us if you believe we have done so.

10. International transfers

Information may be processed in the United States (including Texas) or where our providers operate, which may have different data protection laws than your country.

11. Changes

We may update this policy. Continued use after the “Last updated” date means acceptance unless law requires otherwise.

12. Contact

Privacy: [email protected]
Legal: [email protected]
Support: [email protected]