Privacy
Privacy Policy
This draft explains the information dozzop uses, why it is needed, and the choices available to the owner. It is not legal advice or a claim of regulatory certification.
Draft effective and last updated July 28, 2026
Who operates dozzop
dozzop is a private personal-productivity and financial-organizing application. The legal person or entity responsible for operating it has not yet been verified for publication.
OWNER REVIEW REQUIRED: legal operating entity and any legally required public address.
Information dozzop handles
- Authentication and account information used to sign in and maintain the owner's session.
- Information entered directly, including notes, tasks, contacts, companies, Finance plans, imported Finance proposals, and related preferences.
- If the Plaid connection feature is enabled later, selected account metadata, institution information, partial account masks, account types, balances, currencies, transaction names or merchants, categories, amounts, dates, pending status, and synchronization state.
- Operational information needed for security, troubleshooting, audit history, and service reliability.
Connected financial information
Plaid is not currently enabled in Production. If enabled after separate review, dozzop intends to request the Transactions product for accounts the owner chooses to share. The current design requests up to 90 days of initial transaction history and then uses incremental synchronization. Updates can be delayed by the financial institution, Plaid, network availability, consent status, or dozzop's own scheduling.
Plaid Link handles the normal institution authentication experience. dozzop is not designed to receive the owner's bank password through that flow. Learn more in the Financial Data Disclosure.
Google connections
If you connect Google in Settings, dozzop requests access to the apps you select. Calendar access displays upcoming events. If you separately enable appointment creation, saving an appointment sends its title, times, time zone, location, and description to your chosen Google Calendar, where the event is stored. Gmail access displays inbox message headers and unread labels. Expanding a row retrieves that message's text for an inline preview. dozzop does not download attachments, load remote email images, send mail, or change messages, including their read status. Your Google email address identifies the connected account.
Google responses are used for these displays, are not stored in the application database, and are not sent to AI providers. The connection credential is encrypted in a browser cookie inaccessible to client JavaScript. Google pages and API responses are excluded from app cache storage. The connection lasts up to 30 days and clears on sign-out or when you disconnect it in Settings. You can revoke dozzop's grant across devices in your Google Account connections.
How information is used
- Provide the personal workspace and its requested features.
- Organize authored Finance information separately from observed account activity.
- Produce deterministic suggestions for the owner to review; observed transactions do not automatically change authored obligations or declare them paid.
- Protect, troubleshoot, and maintain the service.
Service providers and external services
Supabase provides authentication, database, and private storage services. Vercel hosts the application. Plaid would provide the financial connection flow only if separately enabled. Those providers process information under their own terms and privacy practices.
The current application code does not include a third-party behavioral-advertising or analytics SDK. Optional AI features elsewhere in dozzop are separately gated; connected-financial-data interpretation in M11 is deterministic and does not call an AI provider.
Security
dozzop uses access controls, owner-only Finance authorization, database row-level security, server-only credentials, and encrypted storage for Plaid access tokens when that feature is configured. Sensitive Finance responses are excluded from browser cache storage. No system can guarantee absolute security.
Retention, disconnect, and deletion
Authored information remains available until it is removed through supported product controls or an owner-verified deletion process. Disconnecting Plaid removes the remote Item, deletes the stored encrypted access credential, and stops future synchronization, while the current implementation retains normalized historical account and transaction records. Disconnecting is therefore different from deleting dozzop data.
Backup copies may remain until applicable backup-retention periods expire. A deletion request may also require limited retention when reasonably necessary for security, fraud prevention, dispute handling, or legal obligations. See Data Deletion for the draft process.
Sale, choices, and contact
The current implementation has no feature that sells connected financial information. A formal public no-sale commitment remains an owner and legal-review item before this draft can be treated as final.
The owner can choose whether to connect an institution, which accounts to share, whether to repair or disconnect a connection, and whether to confirm or reject suggested Finance relationships.
A verified public contact method has not yet been published. The Support page identifies this blocker and explains what never to include in a request.
Policy updates
Material changes should be dated and presented for owner and appropriate legal review before publication. Continued use terms and notice procedures remain subject to that review.