Draft — beta. This policy is a draft and will be constantly updated during the Doops beta.

Privacy Policy

Last updated: 24 August 2026

1. Who we are

Doops is operated from Portugal by Will Prestes, a sole entrepreneur. Will Prestes is the data controller for the personal data described in this policy. You can reach us through the contact form on doops.app. This policy explains what we collect and why. It is a beta draft and will be expanded before general availability.

2. What we collect

  • Account data — your email address, display name and role, held via our authentication provider.
  • Chat data — the messages you send to a Doops and the responses generated for you.
  • Creator data — for creators, the YouTube channel you connect, the videos you select, their transcripts, and the persona settings you configure.
  • Usage data — message counts and token usage, used to enforce quotas and understand cost.
  • Technical data — standard server logs from our hosting provider.

3. Why we use it

To run the service, to generate Doops responses, to enforce usage limits, to keep the platform secure, to answer your support requests, and to improve Doops in aggregate. We do not use your data to train AI models.

4. Legal basis

We rely on the following legal bases to process your personal data under the GDPR:

  • Contract (Art. 6(1)(b)) — creating and running your account, generating Doops responses to your messages, and, for creators, connecting a channel and indexing the videos you select. This is the processing without which the service cannot be provided to you.
  • Legitimate interests (Art. 6(1)(f)) — keeping the platform secure, detecting and preventing abuse, enforcing usage limits, and understanding aggregate cost and usage so we can improve Doops. We balance these against your rights and use the minimum data needed.
  • Legal obligation (Art. 6(1)(c)) — where we must retain or disclose data to comply with law.

We do not currently rely on consent, because Doops does not run advertising, analytics or non-essential cookies. If that changes we will ask for consent first.

5. Cookies

Doops sets only strictly-necessary cookies: the session cookies set by our authentication provider (Supabase) to keep you signed in, and one small doops_role cookie that records your account role so pages load with the right permissions. It is HttpOnly and readable only by the server.

We run no analytics, no advertising and no third-party tracking cookies, and no cross-site tracking of any kind. Because these cookies are strictly necessary to deliver a service you asked for, they do not require consent. Clearing them signs you out. If we ever add non-essential cookies, we will ask for consent before setting them.

6. Who we share it with

We use a small set of processors to run Doops: our hosting and deployment provider, our database provider, our authentication provider, our email provider, and Google (YouTube Data API for channel and video data, and the Gemini API to generate responses). Your chat messages are sent to the model provider in order to produce an answer. We do not sell your data and do not share it for advertising.

7. International transfers

Some of the processors listed above are located outside the European Economic Area, including in the United States. Where that happens the transfer relies on an adequacy decision, or on the European Commission's Standard Contractual Clauses, together with the safeguards in each provider's data processing terms. Users can request more detail through the contact form.

8. YouTube data

Doops uses the YouTube Data API. When a creator connects a channel, we read channel and video metadata and fetch transcripts for the videos that creator selects. Creators can disconnect a channel or remove selected videos at any time, and can revoke our access from their Google account security settings.

9. How long we keep it

Account and chat data are kept while your account exists. Delete your account and we delete your account record, your conversations and, for creators, the indexed transcripts of your Doops. Backups and provider logs may retain copies for a short period afterwards. Beta data may be cleared when we leave beta.

10. Your rights

You have the right to access your data, to have it rectified or erased, to restrict its processing, to receive it in a portable, machine-readable format, and to object to processing we carry out on the basis of our legitimate interests. Make the request through the contact form on doops.app and we will action it.

Users in Portugal may lodge a complaint with the Comissão Nacional de Proteção de Dados (CNPD). Users elsewhere in the EEA may lodge a complaint with their local supervisory authority.

11. Children

Doops is not intended for anyone under 13, and we do not knowingly collect their data. If you believe a child has an account, tell us and we will remove it.

12. Security

Access is authenticated and data is encrypted in transit. No service is perfectly secure; do not put anything in a chat that you would not want stored.

13. Changes

We will update this policy as Doops develops, and change the date above when we do.

14. Contact

Questions about this policy can be raised through the contact form on doops.app.

Doops© 2026 Doops. All rights reserved.