Skip to content
DUVIS
DUVISPrivacy

DUVIS Privacy Policy

Privacy Policy

DUVIS processes only the personal information needed to connect purpose, goals, tasks, habits, time blocks, retros, notes, and AI reports in one self-management flow. This policy is organized so you can quickly see what we process, why we process it, and how you can exercise your rights.

Effective date

2026-06-17

Current policy

2026.06.17

Previous policies

No previous public policy

1. Information We Process and Why

The information we process depends on how you use DUVIS and which optional features you enable. Optional feature data is processed when you actively connect, request, upload, issue, or enable that feature.

CategoryPurposeInformationRetention
AccountCreate accounts, keep users signed in, verify emails, reset passwords, prevent abuseEmail address, display name, password hash, verification/reset tokens, login session dataUntil account deletion. Verification/reset tokens are deleted after expiry
Profile and settingsPersonalized screens, notifications, language settingsAvatar image, language setting, notification preference, mascot settingsUntil account deletion or user deletion/change
Growth dataGoals, tasks, habits, time, retros, notes, documents, reportsPurpose, core values, goals, milestones, tasks, habits and check-ins, time blocks, timer records, retros, daily notes, documents, mandalarts, weekly reportsUntil account deletion or user deletion
AI featuresAI coaching, planning, retro summaries, weekly reports, memory suggestionsCoaching conversations, messages, context needed for reports, memories and memory candidates, model/token usageUntil account deletion or conversation/memory deletion. Usage records are retained for billing and operations
Google integrationGoogle sign-in, read-only Google Calendar sync, busy-time displayGoogle identifier, connected email, granted scope, encrypted refresh token, event title and start/end timeUntil integration disconnection or account deletion
Security and operationsSecurity monitoring, incident response, access limits, MCP token managementIP address, sign-in/sign-up/verification attempts, email domain, hashed MCP access tokens and usage history, error logs and access logsDeleted after security or operational purpose is fulfilled, unless legal retention is required

Google Calendar, AI generation, avatar upload, MCP token issuance, and notifications are optional. Public pages remain available without enabling them, but the related feature may be limited.

2. Third-Party Sharing

DUVIS does not sell personal information. Data may be transferred to external services only where required by law or necessary for features the user chooses.

RecipientPurposeInformation and retention
AI model providers such as OpenAIAI coaching, summaries, reports, planning resultsUser requests, conversations, and context needed for generation. Subject to provider policy and contract scope
GoogleGoogle sign-in and read-only Google Calendar integrationGoogle account identifiers, Calendar API permissions, and information needed to retrieve events
Search tools such as TavilySearch-backed AI planning or information enrichmentSearch query and necessary context, only when the user runs the feature

3. Processors

Some processing is performed through infrastructure and operational tools. DUVIS limits processor use to what is needed to provide and operate the service.

ProcessorWorkNote
Infrastructure providers such as AWS and AmplifyApplication hosting, database, file storage, backupsService infrastructure
Email delivery servicesVerification, password reset, and notification emailsEmail address and delivery logs
Cloudflare TurnstilePrevent automated sign-up and sign-in attemptsSecurity check
SentryError monitoring and incident analysisConfigured to limit default personal data collection
SlackOperational alerts and sign-up notificationsUsed only when configured

4. Retention and Deletion

Personal information is deleted without undue delay after the purpose is fulfilled, the account is deleted, or consent is withdrawn. Data needed for legal obligations, disputes, security audits, or backup recovery may be retained separately for the necessary period.

CategoryDeletion triggerDeletion method
Account and user dataAccount deletion or user deletionDeleted from the database or irreversibly de-identified
Google Calendar integrationIntegration disconnection or account deletionStored connection tokens and synced data are deleted or disabled
Avatars and filesReplacement, deletion, or account deletionStorage objects are deleted. Cache or backups may retain copies for a limited period
Access and security logsAfter security and operational purposes are fulfilledDeleted or aggregated according to log retention policy

5. Cookies and Automatic Collection

DUVIS uses cookies and browser storage to maintain sign-in, language, and device-level UI preferences.

ItemPurposeHow to manage
Authentication cookieKeep users signed inStored as an HTTP-only cookie and expires on logout
Language cookieStore selected ko or en languageManaged by clearing browser cookies or changing language settings
Local storageDevice-level UI settings such as theme, sidebar state, time-planner tips, and desktop app tokenManaged by clearing browser storage or changing app settings

6. Your Rights

You may exercise privacy rights at any time. For requests that cannot be completed directly in the service, contact us by email.

  • Request access, correction, deletion, or suspension of processing
  • Withdraw consent, disconnect Google integrations, or change notification preferences
  • Revoke and reissue MCP access tokens
  • Request account deletion and deletion of service usage records
  • Exercise rights through a legal representative. We may request identity verification when necessary

7. Security Measures

DUVIS applies safeguards to protect personal information from loss, theft, leakage, falsification, alteration, or damage.

Technical measures

Password hashing, refresh token encryption, no plaintext MCP token storage, encrypted transmission

Administrative measures

Admin access limits, operational access control, security attempt logs, incident response

Physical and infrastructure measures

Cloud infrastructure access control, backup and storage permission management

8. Privacy Contact

Send requests for access, correction, deletion, suspension, withdrawal of consent, complaints, or remedies to the contact below.

CategoryContactScope
Privacy contactadmin@dododot.netPrivacy requests for DUVIS
Service operationsadmin@dododot.netAccount, billing, integration, and incident inquiries

9. Addendum

  • This Privacy Policy takes effect on June 17, 2026.
  • If this policy changes, we will disclose the effective date, changes, and reason on this page.
  • Material changes will be announced through the service, email, or another reasonable method.