Privacy Policy
Effective August 11, 2026.
Donna is an AI executive-function partner that helps you follow through on what matters to you. This policy explains what information Donna collects, why, how it is stored, and the control you have over it. Donna is operated by GSD Labs LLC (“we,” “us”).
Information we collect
- Account information. When you sign in, our authentication provider (Clerk) gives us your name, email address, and a unique account identifier. In the app you can also set a preferred name and your working preferences, such as your time zone, your work hours, and when you want to hear from Donna.
- What you tell Donna. The outcomes you’re working toward, the tasks you keep, the notes and brain dumps you write, your messages, the documents you bring in, and the audio you record when you dictate instead of typing. Dictated audio is sent to our speech-to-text provider to be turned into text. We do not keep the recording.
- How your day is going. The working state you tell Donna about, such as how much time you have, how heavy the day feels, and the hours you want left alone.
- What Donna works out about you. To make the app personal, we keep a written profile of your goals, the people and projects you mention, and what has worked for you before. It is built from your own words and it lives in your account.
- Connected services. If you choose to connect a service (such as Google Calendar), we access the specific data described below to provide the feature you connected it for. We keep the names of the calendars you pick and a minimal copy of the events we read.
- Messages outside the app. If you set up a messaging channel, we store the handle you message from, which can be a phone number, along with the messages you send and the messages Donna sends you.
- Devices you get notifications on. If you turn on notifications, we store the push token or subscription for that device, the platform it runs on, and the browser or app version that registered it, so a notification can reach you.
- Feedback you send. What you write when you send feedback, and the screen you sent it from.
- Usage information. Which parts of the app you open and what you do in them, whether a notification reached you and whether you answered it, and how you first arrived at our website, such as the link or campaign that referred you.
- Diagnostic information. Crash reports, error reports, page-performance measurements, and records of whether background work such as a calendar sync succeeded or failed, including the error text when it failed.
- Before you have an account. If you join the waitlist, we store your email address, how you arrived (the referring page and any campaign tags), your browser’s user agent, and a one-way hash of your IP address that we keep to prevent abuse. We do not use that hash to determine your location.
Google user data
If you connect your Google Calendar, Donna requests two narrowly-scoped Google Calendar permissions, each tied to a specific feature:
- Your events (
https://www.googleapis.com/auth/calendar.events): read and write access to calendar events. This is why read-only access is not sufficient: Donna both reads your day and writes your focused work sessions back onto your calendar. - Your list of calendars (
https://www.googleapis.com/auth/calendar.calendarlist.readonly): read-only access to the names of the calendars you’re subscribed to, so you can choose which ones Donna reads from and writes to. We do not request access to share calendars, change their sharing settings, or delete entire calendars.
We use this access for exactly two things:
- Reading your day. We read your calendar events (their titles, times, and attendees) so Donna can show you the shape of your day and find realistic windows to focus.
- Writing back your work. We create and update events on your calendar: for the focused work sessions you schedule with Donna, and for edits or moves you make through the app.
How it’s stored. Your Google authorization token is held in encrypted storage by our authentication provider (Clerk). The calendar data we read is kept as a normalized, minimal copy in our database (Supabase) only so the app can render your day quickly. We do not copy your entire calendar history.
How long we keep it. We retain your token and the derived calendar data for as long as the connection is active. When you disconnect Google Calendar or delete your account, the token is revoked and the derived calendar data is deleted.
What we never do. We never sell your Google data. We never use it for advertising. We never use it to train generative AI or machine-learning models. We do not share it with third parties except the infrastructure providers needed to run the feature (listed below).
How we use your information
- To provide the features you use.
- To understand your goals and context over time so Donna adapts to you.
- To reach you on the channels and at the times you asked for.
- To find and fix crashes, errors, and slow pages.
- To keep the service secure, reliable, and working.
- To respond to you when you contact us.
To do any of that, your text and voice content is processed by the AI providers listed below, and a trace of those requests, including the text sent and returned, is recorded with our tracing provider so we can debug quality problems. It is used to generate Donna’s responses to you, not to train their models.
Who we share information with
We share data only with the service providers (“sub-processors”) we use to operate Donna, each limited to its purpose:
- OpenAI. Large-language-model processing for planning and understanding what you write, and speech-to-text for audio you dictate.
- Langfuse. Tracing of the AI requests Donna makes, which includes the text sent to and returned from the model, so we can debug and improve quality.
- Composio. Connections to third-party tools you choose to link.
- Clerk. Authentication and encrypted storage of your connected-account tokens.
- Supabase. Application database and file storage.
- Vercel. Application hosting and infrastructure, and page-performance measurement (Speed Insights).
- PostHog. Product analytics: which features you open and what you do in the app (United States).
- Sentry. Crash and error reporting for the website and the iOS app.
- Google Analytics. Pageview measurement.
We do not sell your personal information, and we do not use it for third-party advertising.
How long we keep your information
We keep your information for as long as your account is active. When you delete your account, we delete your personal data and revoke connected tokens, except where we are required to retain limited records by law.
There is one exception. If you unsubscribe from our emails, we keep your email address on a do-not-email list, with the date and how the unsubscribe reached us. That record is what stops us emailing you again, so we keep it rather than delete it. Nothing else is stored with it.
Security
We protect your data with encryption in transit and at rest, access controls, and reputable infrastructure providers. No system is perfectly secure, but we work to keep your information safe and to notify you if something material happens.
Your choices
- Disconnect a service. You can disconnect Google Calendar at any time from the app’s settings; this revokes our access and removes the derived calendar data.
- Access, export, or delete. You can request a copy of your data or ask us to delete your account by emailing privacy@meetdonna.xyz.
- Revoke Google access directly. You can also remove Donna’s access from your Google Account permissions.
Children
Donna is not directed to children under 13, and we do not knowingly collect their data.
Analytics, diagnostics, and cookies
We use PostHog as our product analytics provider. It sets cookies and uses your browser’s local storage to recognize your session, and it captures pageviews and product-usage events, such as the features you open and the actions you take. Once you sign in, we give PostHog your account identifier and email address, so what we see is tied to your account rather than to an anonymous visitor.
If session replay is enabled, PostHog may record a playback of how you move through the interface, to help us diagnose issues. We use this information to understand how the product is used and to make it better. We do not sell it.
We also use Google Analytics to count pageviews. We do not send it your account identifier.
We use Sentry for crash and error reporting, on the website and in the iOS app. A report carries the error and where in the code it happened. It is not tagged with your account, and we leave Sentry’s personal-data collection switched off. On our servers, the request body, cookies, and headers are removed before a report is sent.
We use Vercel Speed Insights to measure how quickly pages load for you.
None of this is used for advertising. We do not share it with data brokers, and we do not use it to follow you across other apps and websites.
Changes to this policy
We may update this policy as the product evolves. We’ll change the effective date above, and for material changes we’ll give you notice.
Contact
Questions about privacy or your data? Email privacy@meetdonna.xyz.
See also our Terms of Service.