Back to Home

Privacy Policy

Effective date: September 19, 2026. DoThat is a pre-release beta operated by DoThat AI Ltd (company number 17351077); beta data may be deleted at any time. Part I (sections 1–14) is for platform and website users; Part II (sections 15–18) is for people who chat with a Goblin.

The short version

In short: we are the controller of your account, billing and website data, and your processor for everything you and your people put into the platform. Your content is processed by AI models inside our own Google Cloud environment and is never used to train them. We host in the United States today and say so plainly. Contact us at privacy@dothat.com.

1. Pre-release beta — read this first


DoThat is a pre-release beta operated by DoThat AI Ltd, a company registered in England and Wales (company number 17351077, registered office: DNS House, 382 Kenton Road, Harrow, HA3 8DP). The Service is not yet live. While the beta notice is displayed, platform data — including your account, Goblins, Datasets, and conversations — may be deleted at any time as part of beta operations, without notice. Do not treat DoThat as durable storage. This policy has two parts: Part I (sections 1–14) is for people who use the platform and our website; Part II (sections 15–18) is for people who only chat with a Goblin — one someone else deployed, or the assistant on our own site.

2. When we are the controller, and when we are not


Two different things happen on DoThat and the law treats them differently. For the personal data we collect to run our own business — your account and billing contacts, how you use our website, the messages you send us — DoThat AI Ltd is the controller, and Part I of this policy is our notice to you about it. For the content our customers put into the platform — their prompts, Datasets, files, Goblin configurations and the conversations people have with their Goblins — the customer Organization is the controller and we act solely as its processor, on its instructions, under our Data Processing Addendum. We do not decide what goes into that content or what it is used for, and the customer is responsible for giving its own people and its own end users the privacy notice they are due. Where DoThat itself publishes a Goblin — the assistant on our own site — we are the controller of those conversations and Part II applies to them.

3. What we collect (platform users)


We believe in strict data minimisation and collect only what the Service needs: (i) account details via our authentication provider, WorkOS — your email, display name, and sign-in method; (ii) billing details via Stripe if you buy a plan — your plan, invoices, and payment status; your card details go directly to Stripe and never touch our systems; (iii) your content — prompts, instructions, Goblin configurations, and the documents you upload as Datasets; (iv) usage metering — Goblin Gold consumption, storage, and request counts per plan, which we need to run plan limits; and (v) any support or contact messages you send us. An account is needed to build and run Goblins, but not to chat with one: public and secret-link deployments, and the assistant on our own site, take no account at all.

4. Special category data


Special category data means information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data used to identify someone, health data, or data about sex life or sexual orientation. We do not ask for any of it to open or run an account, and you should not put it in the fields we collect as controller. Customer content is a different matter: it is written by our customers and the people who use their Goblins, so it may contain anything they choose to put in it, including special category data. We do not screen it, we do not decide what it may contain, and we do not delete it on our own initiative — the customer is the controller of it and is responsible for having a lawful basis and the Article 9 condition that goes with it. Our Data Processing Addendum records this.

5. Why we use your data, and our lawful bases


Where we are the controller we use your personal data to create and manage your account and provide the Service (to perform our contract with you, or to take steps before entering into it); to keep systems and data secure, prevent and detect abuse, and protect the Service (our legitimate interests, and our legal obligations); to send you service messages about changes to the Service, these policies, or your account (legitimate interests and legal obligations); to run and improve our business — support, quality, statistics about how the platform is used (legitimate interests); to comply with our accounting, tax and other legal obligations; to establish, exercise or defend legal claims (legitimate interests); to send marketing where you have agreed to it (consent); and, if we are ever involved in a merger, acquisition, asset sale or insolvency, to share what is necessary with the parties to it (legitimate interests), anonymised where we can. Where we rely on legitimate interests we balance them against your rights, and you can ask us for that assessment.

6. Infrastructure, AI processing & sub-processors


Data is hosted on Google Cloud (Cloud Firestore and Cloud Storage). Conversational requests and knowledge data are processed by AI models to generate responses, served through Google Cloud Vertex AI — Google's own Gemini models and partner models such as Anthropic's Claude, which Google hosts and runs inside our own Google Cloud environment under Google Cloud's terms rather than under a contract with the model's maker. Where a customer chooses a model served directly by Anthropic, the messages are sent to Anthropic under our agreement with Anthropic. Under those terms this data is not used to train foundation models, and we do not grant any AI provider the right to train models on your uploads, prompts, configurations, or conversations. We do not use your personal data, or the content of conversations, to train, fine-tune or improve any AI model — other than a customer's own Goblin, built on that customer's own data inside that customer's own account, at that customer's instruction. Prompts and outputs are automatically screened by Google Cloud's Model Armor safety tooling. Answers generated by AI may be inaccurate, and factual statements in them should be checked before you rely on them. We rely on a small set of sub-processors, each processing data only as needed: Google Cloud (hosting, storage, model inference, safety screening, and reCAPTCHA bot protection on our sign-in, sign-up, and contact forms), WorkOS (authentication and directory sync), Stripe (payments and billing administration), Postmark / ActiveCampaign (outbound transactional email, and receiving and parsing inbound email to a Goblin), Slack (only if your Organization connects the Slack channel), Meta / WhatsApp Business Platform (only if your Organization connects the WhatsApp channel), and Google Analytics (consent-gated website analytics). The full list — who they are, what they process, where, and the transfer safeguard for each — is on our Data Processing Addendum page, and customers get at least 30 days' notice before we add or change one.

7. Limited staff access — redacted and audited


A small number of authorised DoThat personnel can access customer content — including conversation logs between end users and Goblins — strictly for quality assurance, safety and abuse prevention, security investigations, debugging, and support. This access requires a specific, separately-granted permission (it is not a by-product of general administrative rights); shows conversations with personal identifiers redacted by default, with any fuller access held behind an additional, separately-granted permission; requires re-authentication at the point of access; and records every view in an audit log. We do not browse your content out of curiosity, we do not use it to train AI models, and we never sell or disclose it to outside parties.

8. Cookies and analytics


Two kinds of measurement run on the site. Google Analytics is consent-gated: it sets cookies only if you accept them in the cookie banner, and measures page navigation, session lengths, feature usage, and errors so we can fix and improve the Service; you can decline or withdraw consent at any time. Separately, a first-party, cookieless beacon sends anonymous events (such as page views) to our own backend using a random per-tab identifier that does not survive a page refresh; it sets no cookies, carries no durable identifier, and includes no email, account ID, or client-sent IP address. Neither mechanism ever includes the contents of your prompts, Datasets, or conversations. Separately from measurement, our sign-in, sign-up, and contact forms are protected by Google reCAPTCHA, which checks your browser for signs of automated abuse and sets its own Google cookies; this runs as a security measure to keep accounts and our contact channel safe, so it is not part of the analytics consent choice, and it never sees your content. Our Cookie Policy lists every cookie, including the one a Goblin's abuse guard sets, and how to change your choice.

9. Marketing


We may send you email about our services, such as promotions. Where you register a business account with us, or give us your business contact details in the course of a business relationship or an enquiry, we may send you that marketing on the basis of our legitimate interests in promoting our business — or, where the law requires it, on the basis of your consent, which we collect at the point you give us your details and never through our cookie banner. You can opt out at any time, by using the unsubscribe link in every marketing email we send or by emailing privacy@dothat.com, and we will not send you marketing after you do. Service messages about your account, your billing or changes to these policies are not marketing and you cannot unsubscribe from them while you hold an account. We will never sell your personal data, and we will never share it with another organisation for that organisation's own marketing; a service provider that sends marketing on our behalf may use your details only for that purpose.

10. Where your data is stored & international transfers


Our infrastructure is currently hosted on Google Cloud in the United States. If you are in the UK or EU, this means your personal data is transferred to and stored in the US — for every user, not as an exception. Where we transfer personal data to a country the UK government has not found adequate, we rely on appropriate safeguards under the UK GDPR: the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, or a provider's own adequacy certification where it holds one. UK or EU-resident hosting is not available today, and we will not claim otherwise; if that changes we will update this policy.

11. Retention — including beta deletion


The Service is in a pre-release beta and we have not yet fixed final retention periods; we will set them out here when it becomes generally available. During the beta, personal data we hold as controller is kept while your Organization uses the Service and for no longer than six years afterwards, and only for as long as we need it to meet our accounting and legal obligations or to establish, exercise or defend legal claims, after which it is deleted or anonymised. Customer content is different: it is kept on the customer's instructions, and when an agreement ends or an account is closed it is deleted within 30 days. Two beta exceptions apply to everything: platform data may be periodically deleted as part of beta operations, and may be deleted at any time without notice. Do not rely on the beta for data continuity — keep your own copies of anything important.

12. De-identified information and automated decisions


Where we have irreversibly de-identified personal data we hold as controller — so that no individual can be identified from it and it cannot be attributed back to a customer — we may use the result for analysis, to understand how the platform is used, and to improve it. That does not apply to personal data inside customer content, which we handle only under our agreements with the customer, and we do not use de-identified information to train AI models. Separately: we do not make decisions about you based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you. If that ever changed we would update this policy and tell you about your rights, including the right to ask for human review. A Goblin a customer builds may process people's data in ways that customer decides — that customer is the controller of it and responsible for those decisions.

13. Deleting your data & no selling


You can delete your Goblins, Datasets, Workspaces, entire Organization, or your account directly from your settings — Organization deletion shows exactly what will be removed before you confirm — and you can re-download the files you have uploaded. Deleting a Workspace withdraws everything under it and holds it recoverably for 30 days before permanent erasure, so an accidental deletion can be undone. For a copy of other personal data we hold about you, contact us and we will provide it within the timescales the law requires. Under no circumstances do we trade, lease, rent, or sell your personal details, prompts, conversation logs, or uploads. The only access beyond your Organization is the limited, redacted, audited staff access in section 7 and the sub-processors in section 6 who help us operate the Service.

14. Your rights, security & how to complain


Subject to applicable law (including the UK GDPR), you have the right to ask for a copy of your personal data, to have mistakes corrected, to have it deleted, to restrict or object to how we use it — including an absolute right to object to direct marketing — to receive it in a portable form, and to withdraw consent where we rely on it. You can action most of these from your settings, by emailing privacy@dothat.com, or through our Contact page; please tell us which right you want to exercise and give us enough to identify you. If the data you are asking about sits inside a customer's workspace, that customer is the controller and we will pass your request to them and help them answer it. We have appropriate security measures, limit access to those with a genuine business need, and have procedures for handling a suspected breach, including telling you and the regulator where the law requires it. If you are unhappy, please tell us first — and you also have the right to complain to the Information Commissioner (ico.org.uk, or 0303 123 1113). We may update this policy; when we make a significant change we will say so, and post the updated version with a new date.

15. Goblin end users — who is responsible for your data


This part applies to you if you chat with a Goblin deployed by a DoThat customer (the "publisher") — through a public page, a shared or secret link, or an email invitation — without being a member of the publisher's account. The publisher decides what their Goblin does, who can use it, and what happens to the resulting conversations, so for your chat content the publisher is the data controller and DoThat processes your data on the publisher's behalf. DoThat acts as a controller only for the narrow operational purposes we pursue for every conversation: security, abuse prevention, safety screening, and service integrity. Where the publisher is DoThat itself — the assistant on our own site — we are the controller of the whole conversation.

16. What a chat collects and how it is used


Depending on how the Goblin is shared, a chat may collect your messages and the Goblin's replies; session metadata (timestamps, message and token counts, session duration); and — only when the publisher invited you by email or you signed in — your email address and display name. Public and secret-link chats do not require an account. Your messages are processed by AI models running in our Google Cloud environment via Vertex AI — Google's own Gemini models or Anthropic's Claude models, depending on the model the Goblin uses — to generate answers and are screened by automated safety tooling. If you reach a Goblin through a messaging channel its publisher connected — such as Slack or WhatsApp — your messages also pass through that platform under its own terms. Conversations are stored and made available to the publisher, who may review them and use analytics — including AI-generated conversation summaries — to understand how their Goblin performs. Your conversations are not used to train our or our providers' AI models and are never sold. A small number of authorised DoThat staff can additionally view conversations under the redaction, permission, re-authentication, and audit controls in section 7. A publisher can also switch on a guard against abuse: if the safety screening refuses enough of your messages, that Goblin stops answering you with a short notice. To recognise you it may hold the conversation, a random identifier for your browser, your account if you are signed in, and — only if the publisher turned that option on — your IP address. These are kept in one record whose only purpose is that block, and that record is deleted when the block ends or somebody lifts it.

17. End-user retention & your rights


Your conversation is retained while the publisher keeps the Goblin and their account, under the publisher's own retention choices, and is removed when the publisher deletes the Goblin, the containing Workspace, or their Organization; during beta it may also be periodically deleted. Because the publisher controls your chat data, please direct requests to access, correct, or delete your conversations to the publisher first — they can act on their own data directly. If you cannot identify or reach the publisher, contact us through our Contact page or at privacy@dothat.com and we will help, including acting on our own systems where we are able to. If you are in the UK or EU you can also complain to your local supervisory authority.

18. If you chat with our own assistant


We publish an assistant on our own website, and we may publish others. When you chat with an assistant DoThat publishes, we are the controller of the personal data in that conversation and this policy is our notice to you about it; you do not need an account to use it. We collect the messages you send, the replies the assistant generates, any contact details you choose to give it, and technical data about the session — the time of use, and your device and browser type. We use that information to answer your questions, to keep the Service secure and prevent misuse, to understand how the assistant is used and improve it, and to follow up with you if you ask us to. Our lawful bases are our legitimate interests in running, securing and improving our business and our website, the performance of a contract with you or steps taken at your request, and consent where we ask for it. Please do not share special category data with the assistant. Replies are generated by AI and may be inaccurate: check any factual statement before you rely on it, and do not rely on it for legal, financial, medical or other regulated decisions. The terms shown to you before you chat, and our Website Terms and Conditions, apply to your use of the assistant. We keep the conversation logs of our own assistant for 12 months from the end of the conversation, unless we need to keep them for longer to deal with a query or a legal claim, after which we delete or anonymise them.

Questions about this page? Reach us through our Contact page.

Back to Home