Privacy Policy
We built Doodlik to be a calm, personal space for planning your day. That means the information you put into it — your calendar, your notes, your plans — is yours. This policy explains exactly what we collect, why we collect it, and how we keep it safe. We have written it in plain English because that is what a privacy policy should be.
This policy applies when you use the Doodlik web app (doodlik.com), our mobile application, or any other service we link to this notice.
If you have any questions, please email us at privacy@doodlik.com. We are happy to help.
At A Glance
Here is a quick summary. The full detail is in the sections below.
- We collect: your first name, email address, year of birth, calendar data, notebook content, approximate location (for weather), and basic device information.
- We do not sell your data. Ever.
- We do not use your data to train AI models. Your queries are processed to give you a response and nothing more.
- Your notebooks are private. We do not read them.
- You control calendar sharing. You choose who can see your schedule and how much detail they can see.
- No automated decisions are made about you. The AI assistant is a tool — it does not make decisions that affect your rights or life.
- You can delete your account at any time. We will remove your data within 30 days.
- We are based in the UK and registered with the ICO (ZC148938).
1. What Information Do We Collect?
In short: You give us some information when you sign up. We automatically collect some technical information when you use the app. We never collect what we do not need.
Information you give us
When you create a Doodlik account, you give us:
- Your first name
- Your email address
- Your year of birth (used for age verification — see section 12)
- A password (stored in encrypted form — we cannot read it)
When you use the app, you also create content that we store on your behalf:
- Calendar events and reminders you create
- Notes and entries in your notebooks
- Your preferences and app settings
- Queries you send to the AI assistant
If you use the shared calendar feature, you control what other users can see — either your full event details or your busy/free status only. You decide this per person.
Information we collect automatically
When you use Doodlik, we automatically collect some technical information to keep the service running smoothly:
- Your IP address
- Device type, operating system, and browser
- Pages and features you use, and when
- Error reports and crash data
We collect this for security, troubleshooting, and to understand how the app is being used so we can improve it. This information is not linked to your name or email unless we need to investigate a specific issue.
Location data (weather feature)
Doodlik includes a weather feature that shows you current conditions as part of your daily briefing. To do this, the app needs to know your approximate location. Here is exactly how that works:
- Browser GPS (preferred, with your permission). The app uses your browser’s built-in location feature, which asks you “Allow Doodlik to know your location?”. If you grant permission, your latitude and longitude are used to fetch your local weather. If you decline, GPS is not used.
- IP-based location (fallback only). If you decline the GPS prompt, or if GPS is unavailable or times out, the app estimates your location from your device’s public IP address using two services — ipwho.is and ipapi.co. This provides your approximate city or region, not a precise address. The IP fallback does not run if GPS permission is granted and GPS resolves successfully.
- Reverse geocoding (GPS path only). If GPS is used, your coordinates are sent to OpenStreetMap Nominatim to convert them into a readable place name (for example, “Manchester”) for display in the app.
Your location coordinates are sent directly from your browser to the weather and location services listed below. They are not stored on our servers. Location data is used only to fetch your weather and is not retained beyond the current session.
If you do not want any location data to be used, you can decline the browser GPS prompt and disable location access for Doodlik in your browser settings. The weather feature will not work without some form of location data.
Payment information (future subscriptions)
Doodlik is currently free. When we introduce paid subscriptions, payments will be processed by Stripe. We will not store your card number or billing details on our servers — Stripe handles all payment data directly. We will update this policy before subscriptions launch and notify you in advance.
Google API
If you connect Doodlik to Google (for example to sync your Google Calendar), our use of data received from Google APIs will comply with the Google API Services User Data Policy, including the Limited Use requirements.
2. Why Do We Collect It?
In short: We only collect information that helps us run the service for you.
- To create and manage your account. Your name, email, and year of birth let you sign in, verify your age, and keep your account secure.
- To deliver the service. We store your calendar events, notes, and settings so the app works as it should.
- To power shared calendars. When you choose to share your schedule, we process your calendar data to show the right level of detail to the people you have authorised.
- To run the AI assistant. When you ask the AI a question, we send your query and relevant context to our AI provider to generate a response.
- To show you local weather. We use your approximate location (from GPS if permitted, or your IP address as a fallback) to fetch current weather conditions for your daily briefing. Your location is not stored on our servers.
- To verify your age. We use your year of birth to ensure users under 13 cannot access the service, and to apply appropriate privacy defaults for users aged 13–17.
- To send you service emails. Things like password reset emails, important account notices, and service updates.
- To send marketing emails (only if you opt in). We will only send you promotional emails if you have explicitly agreed. You can unsubscribe at any time.
- To keep the service secure. We use technical data to detect fraud, prevent abuse, and fix problems.
- To improve Doodlik. Anonymised usage data helps us understand which features are useful and where we can do better.
3. What Is Our Legal Basis For Processing?
In short: UK GDPR requires us to have a legal reason to process your data. Here is ours, clearly mapped to what we do.
The table below sets out the legal basis for each type of processing we carry out.
| Data type | Purpose | Lawful basis |
|---|---|---|
| First name, email, year of birth | Account creation, age verification, login, and service delivery | Performance of a contract |
| Email address | Service communications (e.g. password reset, account notices) | Performance of a contract |
| Email address | Marketing emails (where you have opted in) | Consent |
| Year of birth | Age-gating to comply with the Children's Code and UK GDPR | Legal obligation |
| Calendar events and schedule | Providing the calendar and shared calendar features | Performance of a contract |
| Notebook content | Storing and displaying your personal notes within the app | Performance of a contract |
| AI assistant queries | Generating responses via the AI assistant feature | Performance of a contract |
| Location data (GPS, if permitted) | Fetching local weather for the daily briefing | Consent (via browser location prompt) |
| IP address (location fallback) | Estimating approximate location for weather when GPS is unavailable | Legitimate interests |
| Device and usage data | Security, analytics, and service improvement | Legitimate interests |
| Payment data (future) | Processing subscription payments via Stripe | Performance of a contract |
Data type
A note on legitimate interests
Where we rely on legitimate interests as our legal basis, our interest is in maintaining the security, stability, and improvement of the service. We have assessed that this interest is not overridden by your rights and freedoms, given the limited and non-intrusive nature of the data collected for this purpose. You have the right to object to processing carried out on this basis — see section 14.
In legal terms, we are the ‘data controller’ under UK GDPR for the personal information described in this notice. This means we determine how and why your data is processed. Where we use third-party providers (such as Supabase or OpenAI), they act as ‘data processors’ and are contractually bound to process your data only on our instructions.
4. Who Do We Share Your Data With?
In short: We do not sell your data. We share it only with companies that help us run the service, and only to the extent necessary.
- Supabase (database and authentication). Our application data and user accounts are stored in Supabase’s infrastructure, hosted in the EU. Supabase acts as a data processor on our behalf under a Data Processing Agreement.
- Netlify (web hosting). The Doodlik web app is hosted on Netlify. They may process technical request data (such as your IP address) as part of hosting the site.
- OpenAI (AI assistant). When you use the AI assistant, your query and relevant context is sent to OpenAI’s API to generate a response. OpenAI does not use API data to train its models. See section 7 for full detail.
- Stripe (future payments). When we introduce subscriptions, payment processing will be handled by Stripe. Stripe is PCI-DSS compliant and we will not receive or store your card details.
- Weather and location services. To provide the weather feature, your location coordinates or IP address are sent directly from your browser to: Open-Meteo (weather data), ipwho.is and ipapi.co (IP-based location estimation), and OpenStreetMap Nominatim (converting GPS coordinates to a place name). None of these services receive your name, email, or account information — only location data. Open-Meteo and OpenStreetMap Nominatim are open-source services. ipwho.is and ipapi.co are third-party lookup services.
- Other Doodlik users (only what you choose to share). When you share your calendar, other users see only the level of detail you have permitted — either your full schedule or your busy/free status. Your notebook content is never visible to other users.
- In a business transfer. If Doodlik is acquired or merges with another company, your data may be transferred as part of that transaction. We will notify you before this happens.
- When required by law. We may disclose your information if required to do so by law, court order, or to comply with a mandatory reporting obligation. See section 16.
We require all third-party processors to have appropriate security measures in place and to process your data only on our documented instructions. We do not allow them to use your data for their own purposes.
5. International Data Transfers
In short: Some of our third-party providers are based outside the UK. We make sure your data is protected wherever it goes.
Supabase, our database provider, hosts data within the EU. EU-hosted data benefits from the UK’s adequacy decision in respect of the EU, meaning no additional transfer safeguards are required for that data.
Netlify and OpenAI are US-based companies. When your data is processed by these providers, it may be transferred to and stored in the United States. We ensure these transfers are protected by the providers’ Standard Contractual Clauses (SCCs) as approved by the European Commission, supplemented by the UK Addendum issued by the ICO. These contractual arrangements require the recipients to protect your data to the same standard required under UK GDPR.
The weather and location services used by Doodlik (Open-Meteo, ipwho.is, ipapi.co, and OpenStreetMap Nominatim) receive only location coordinates or your IP address directly from your browser. They do not receive your name, email address, or any account information. Open-Meteo is a European open-source project. ipwho.is and ipapi.co may process IP addresses outside the UK; however, given that only an IP address is involved and no personal account data is shared, we consider this a low-risk transfer proportionate to the purpose of providing a weather feature.
When Stripe is introduced for payment processing, the same SCC and UK Addendum framework will apply. You can request a copy of the relevant transfer safeguards by emailing privacy@doodlik.com.
6. Cookies And Tracking
In short: We use a small number of cookies to keep the service working. We do not use cookies for advertising.
Cookies are small files stored in your browser. We use them for:
- Authentication. To keep you logged in between sessions.
- Preferences. To remember your settings.
- Analytics. To understand how the app is being used in aggregate, not tied to you individually.
We do not use advertising cookies. We do not use cookies to track you across other websites.
You can set your browser to refuse cookies, but doing so may prevent some features from working correctly. Full detail of every cookie we set, how long they last, and how to manage them is set out in our Cookie Notice, which is available on our website and linked in the site footer. We will obtain your consent before setting any non-essential cookies, as required by the UK Privacy and Electronic Communications Regulations (PECR).
7. Our Ai Assistant
In short: The AI assistant helps you plan and think. Your queries are processed to give you a response — nothing else.
- Your query is sent to OpenAI’s API. When you ask the assistant something, your message and relevant context (such as your upcoming events, where you have given permission) is sent to OpenAI to generate a response.
- OpenAI does not train on your data. Under OpenAI’s API terms, data submitted via the API is not used to train or improve OpenAI’s models. Your queries are processed to return a response and then discarded by OpenAI.
- We do not store your AI conversations permanently. AI query logs are retained for up to 90 days for troubleshooting and quality purposes, then deleted.
- No significant automated decisions are made about you. The AI assistant generates responses to your questions but does not make any automated decisions that produce legal or similarly significant effects on you. See section 13.
- Do not put sensitive information into the AI assistant. Please do not enter financial details, government ID numbers, health information, or other sensitive personal data. It is designed for planning and scheduling.
If we change our AI provider or if our provider’s data practices change in a way that affects you, we will update this policy and notify you.
8. The Weather Feature And Location Data
In short: The weather feature uses your location to show you local conditions. Your location is never stored on our servers and is not used for anything else.
Doodlik’s daily briefing includes your local weather. This requires knowing your approximate location. Here is a complete and transparent explanation of how that works.
How your location is determined
- Step 1 — Browser GPS (if you allow it). Your browser will ask “Allow Doodlik to know your location?”. If you grant permission, your latitude and longitude are obtained from your device’s GPS or network positioning. This is the most accurate method.
- Step 2 — IP address fallback (only if GPS is declined or unavailable). If you decline the GPS prompt, or if GPS times out or is unavailable on your device, the app estimates your location from your device’s public IP address. This gives an approximate city or region — not a precise address. Two services are used: ipwho.is (primary) and ipapi.co (backup). This step does not run if GPS is granted and resolves successfully.
- Step 3 — Place name lookup (GPS path only). If GPS is used, your coordinates are sent to OpenStreetMap Nominatim, which converts them into a readable place name (such as “Leeds”) for display in the app.
Who receives your location data
Your location data is sent directly from your browser to the following services. It never passes through our servers:
- Open-Meteo (open-meteo.com) — receives your coordinates to return weather data. European open-source project. No API key or account required.
- ipwho.is — receives your IP address to estimate your location. Used as primary IP lookup.
- ipapi.co — receives your IP address as a backup if ipwho.is is unavailable.
- OpenStreetMap Nominatim (nominatim.openstreetmap.org) — receives your GPS coordinates to return a place name. Open-source, non-commercial service.
None of these services receive your name, email address, account details, or any other personal information. They receive only location data — either coordinates or an IP address.
How long is your location stored?
We do not store your location on our servers at all. The location data travels directly from your browser to the weather services and back. It is used in the moment to fetch your weather and is not retained anywhere in your account.
Your choices
- You can decline the browser GPS prompt. The app will only fall back to IP-based location if GPS is declined or unavailable.
- You can disable location access for Doodlik entirely in your browser settings. The IP-based fallback will still run unless you also block the IP lookup services at a network level.
- If you do not want any location data used, the weather feature will not function.
9. Social Logins
In short: You can sign in with Google, Apple, or similar. We only use what we need.
- We will receive your name and email address from the provider.
- We will not request access to your contacts, social connections, or anything beyond what is needed to create your account.
- We use this information in the same way as if you had signed up directly with an email address.
We do not control how third-party providers collect or use your data. Please review their privacy policies if you want to understand their practices.
10. How Long Do We Keep Your Data?
In short: We keep your data for as long as you have an account with us. When you leave, we delete it promptly. The table below sets out specific retention periods.
| Data type | Retention period | Reason |
|---|---|---|
| Account data (name, email, year of birth) | Duration of account | Needed to provide the service |
| Calendar events and notebook content | Duration of account, then deleted within 30 days of account closure. If an account is deleted mid-period, AI query logs are also deleted at that point. | User-created content retained until no longer needed |
| AI assistant query logs | 90 days, then deleted | Short-term troubleshooting and quality assurance |
| Location data (GPS coordinates) | Not stored — used in-session only to fetch weather | Not retained on our servers |
| Server and access logs | 30 days, then deleted | Security monitoring and debugging |
| Backup data | Up to 60 days after deletion from active systems | Business continuity — isolated from active processing |
| Anonymised/aggregated analytics | Indefinitely | Cannot identify individuals; used for service improvement |
| Payment records (future) | 7 years | Legal obligation under UK tax and accounting law |
Data type
Where we are legally required to retain data for longer than the periods above (for example, for tax compliance), we will retain only the minimum necessary and will isolate it from any other processing.
11. How Do We Keep Your Data Safe?
In short: We use industry-standard security measures. No system is 100% secure, but we take this seriously.
- Encrypted storage. Your data is stored in Supabase, which uses encryption at rest and in transit.
- Secure passwords. Passwords are hashed and salted — we cannot see your password.
- Access controls. Only authorised personnel can access user data, and only where necessary.
- HTTPS everywhere. All data sent between your device and our servers is encrypted using HTTPS.
No system is 100% secure. If you believe your account has been compromised, please contact us immediately at privacy@doodlik.com.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of the breach, and will inform affected users without undue delay, as required by UK GDPR.
12. Children And The Age Appropriate Design Code
In short: Doodlik is for users aged 13 and over. We use your year of birth to verify this and apply stricter privacy defaults for younger users.
We take our obligations under the ICO’s Age Appropriate Design Code (Children’s Code) seriously. The Code applies to online services likely to be accessed by children under 18.
Age verification
We collect your year of birth at sign-up. Users whose year of birth indicates they are under 13 are blocked from creating an account. This is an active gate, not a passive checkbox — the app will not permit registration if the year of birth entered indicates the user is under 13.
We are aware that a user could enter an incorrect year of birth. We cannot guarantee forensic accuracy of age verification at this stage. However, by entering a false date of birth to circumvent the age gate, the user is in breach of our Terms and Conditions, and we reserve the right to close any account where we have reason to believe this has occurred.
Users aged 13 to 17
Where a user indicates they are between 13 and 17, we apply the following stricter privacy defaults by default:
- No marketing emails, unless the user actively opts in with a clear explanation
- Analytics data is not linked to their individual profile
- When the AI assistant is enabled, users aged 13–17 receive age-appropriate defaults. The assistant is instructed not to produce explicit or adult content, graphic violence, or content promoting harmful behaviour; not to discuss alcohol, drugs, gambling, or other age-restricted activities; and to avoid detailed discussion of self-harm, eating disorders, or similar topics, signposting to appropriate helplines instead. These are AI instructions, not a guarantee of perfect filtering.
- No data is shared with third parties for advertising purposes (this applies to all users, but is stated explicitly here)
These defaults are applied automatically and do not require the user to take any action.
If we discover an underage user
If we become aware that a user under 13 has created an account — whether through a report, our own monitoring, or any other means — we will deactivate the account and delete all associated data promptly. If you are a parent or guardian and believe your child has created a Doodlik account, please contact us at privacy@doodlik.com and we will treat it as a priority.
13. Automated Decision-Making And Profiling
In short: We do not make automated decisions about you that have legal or significant effects on your life.
Article 22 of UK GDPR gives you the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects on you.
Doodlik does not use automated decision-making of this kind. Specifically:
- The AI assistant generates responses to your queries but does not make decisions that affect your rights, finances, health, or access to services
- We do not use profiling to make decisions about you as an individual
- We do not use automated tools to assess, score, or categorise you in ways that have real-world consequences
If this changes in the future, we will update this policy and obtain your explicit consent before any such processing begins.
14. Your Rights
In short: You have real control over your data. Here is what you can do and how to do it.
Under UK GDPR, you have the following rights:
- Access. You can request a copy of the personal data we hold about you.
- Correction. You can ask us to correct any inaccurate data.
- Deletion. You can ask us to delete your personal data. You can also do this directly by deleting your account in app settings.
- Restriction. You can ask us to stop processing your data in certain circumstances.
- Portability. You can request a copy of your data in a machine-readable format. We will provide this in JSON or CSV format within one month of your request.
- Objection. You can object to processing carried out on the basis of legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds that override your interests.
- Withdraw consent. Where we rely on your consent (e.g. for marketing emails), you can withdraw it at any time without affecting the lawfulness of prior processing.
- Rights related to automated decision-making. As set out in section 13, we do not carry out significant automated decision-making. If this changes, you will have the right to request human review of any automated decision.
To exercise any of these rights, email us at privacy@doodlik.com. We will respond within one month, as required by UK GDPR. We may ask you to verify your identity before acting on your request.
If you are unhappy with how we have handled your data, you have the right to complain to the Information Commissioner’s Office (ICO):
- Website: https://ico.org.uk/make-a-complaint/
- Phone: 0303 123 1113
We would always prefer to resolve concerns directly, so please contact us first and we will do our best to help.
15. Do-Not-Track
Some browsers send a Do-Not-Track (DNT) signal to websites. There is currently no agreed standard for how websites should respond to DNT signals, so we do not currently act on them differently. If a standard is adopted that applies to us, we will update this policy accordingly.
16. Mandatory Disclosures To Authorities
In short: In certain serious circumstances, we are legally required to disclose data to law enforcement without notifying you first.
There are circumstances in which we are legally obligated to disclose personal data to law enforcement agencies, regulatory bodies, or other authorities without prior notice to you. These include:
- Where we receive a valid court order, warrant, or legal demand requiring disclosure
- Where we are required to report certain content to the National Crime Agency or other authorities — for example, where we discover or are notified of child sexual abuse material (CSAM), which triggers a mandatory referral obligation under UK law
- Where we believe disclosure is necessary to prevent an imminent threat to life or serious physical harm
In these circumstances, we may be prohibited by law from informing you that a disclosure has been made. Where we are not so prohibited, and where it is safe and practical to do so, we will notify you of any such disclosure.
17. Business Users And Data Processing
In short: If you use Doodlik for work purposes and share third-party data with us, you are responsible for having a lawful basis to do so.
Doodlik is primarily designed for personal use. However, if you use Doodlik in a business context — for example, to manage client meetings or share schedules with colleagues — and in doing so you upload or store personal data relating to third parties (such as clients or contacts), you are acting as a data controller in respect of that third-party data.
In those circumstances, you are responsible for:
- Ensuring you have a lawful basis under UK GDPR to process and share that third-party data with Doodlik
- Providing appropriate privacy notices to those individuals
- Ensuring the data is accurate and used only for lawful purposes
If you require a formal Data Processing Agreement (DPA) for your business use of Doodlik, please contact us at privacy@doodlik.com and we will provide one on request.
18. Updates To This Policy
In short: We will update this policy when things change. We will tell you if anything important changes.
We may update this Privacy Policy from time to time. If we make a material change — for example, if we introduce paid subscriptions, change our AI provider, or change how we use your data — we will notify you by email and update the ‘Last updated’ date at the top of this document.
For minor changes (such as clarifications or corrections), we will update the document without individual notification. We encourage you to check this page periodically.
19. Contact Us
In short: We are a small team and we genuinely want to hear from you.
If you have any questions about this policy, or about how we handle your data, please get in touch:
- General privacy enquiries and data subject requests: privacy@doodlik.com
- Data Protection Officer (registered contact): alexandra.gritsenko@doodlik.com
- Post: Doodlik, Data Protection Officer, 22 Hewett Street, London EC2A 3NL, United Kingdom
As a UK-based business, Alexandra Gritsenko is our appointed data controller representative. We are registered with the Information Commissioner’s Office (ICO) under registration number ZC148938.
20. How To Access, Update, Or Delete Your Data
The easiest way to manage your data is directly within the app. You can update your name and email in your account settings. To delete your account and all associated data, go to Settings → Account → Delete Account.
If you would like a full export of the data we hold about you (provided in JSON or CSV format), or if you need help with anything you cannot do in the app, contact us at privacy@doodlik.com and we will respond within one month.
See also: Privacy Policy · Terms and Conditions · Cookie Notice