(Legal)Privacy policy

Your data, our duty.

Updated October 7, 2026

This Privacy Policy describes how Donkit ("Company", "we", "us") collects, uses, and protects your personal information when you visit and use our websites and services, including our prompt-to-agent platform, the Donkit mobile apps, and the Donkit browser extension. "Donkit" means Donkit AI Ltd., the Israeli company that develops and operates the platform and is responsible for your data, together with its US affiliate Donkit AI Inc., which publishes the mobile apps and browser extension on Google Play, the Chrome Web Store, and the App Store. Donkit AI Inc. does not process your data separately; both entities are reached through the contact details at the end of this policy.

If you use the Donkit Browser Control browser extension, the Browser Extension Privacy Policy also applies. It is a standalone policy that supplements this one and describes what the extension collects, what it never touches, and how that data is protected.

This policy also covers the Donkit mobile apps for Android and iOS. The "Mobile Apps" section below explains which device permissions the apps request and what they transmit. To delete your account and the data associated with it, see our Delete Account page.

Our Services are designed for and offered to businesses and other organizations for commercial and professional use. They are not directed at consumers, and we do not knowingly process personal data of individuals acting outside of a business context. Where personal data is processed through our platform, this is generally done on behalf of our business customers.

This Privacy Policy is an integral part of our Terms of Service. By using our Services, you agree to the collection and use of information in accordance with this policy.

01

Our Role: Data Controller vs. Data Processor

To comply with global privacy frameworks (such as the GDPR, UK GDPR, emerging US state privacy laws, and the Israeli Privacy Protection Law), our legal responsibilities depend on the type of data being processed:

When Donkit is the Data Controller

Donkit AI Ltd. acts as the Data Controller for your direct relationship with us. This includes your account information, billing details, data collected through the mobile apps and browser extension, and data automatically collected when you navigate our website. Donkit AI Inc. publishes the apps and extension in the app stores on behalf of Donkit AI Ltd. and is not a separate controller of your data.

When Donkit is the Data Processor

When you use our platform to build agents, upload context files, submit prompts, configure integrations, or publish public agents, you are the Data Controller of that specific data. Donkit acts strictly as a Data Processor, handling this "Agent Data" solely on your behalf and according to your instructions.

02

Information We Collect

We collect information that you provide directly to us, as well as data collected automatically or generated through your use of our platform.

Information you provide directly to us

  • Name, email address, and contact information.
  • Account credentials and profile information.
  • Billing information (such as company name and billing address) used for invoicing. Payment card details are collected and processed directly by our payment processor; we do not receive or store your full payment card information and rely on payment processor's customer and transaction identifiers for billing and reconciliation purposes.
  • Information you provide when contacting us or using our support services.
  • Agent Data: Conversational data (prompts), documents, and contextual files you upload to instruct or manage your agents.
  • Integration Credentials: API keys, OAuth tokens, and passwords you provide to connect third-party tools to your agents.
  • Message feedback: ratings and optional comments you leave on an agent's replies.
  • Google user data: if you connect a Google account to an agent, the calendar events, spreadsheet and document contents, and Drive files that the agent accesses with your permission. See "Google Workspace Integration and Google User Data" below.

Information collected through the mobile apps

  • Photos, videos, and files you choose to attach to a conversation from your camera, photo library, or file storage. They are uploaded to your workspace and stored as message attachments.
  • Voice audio. In voice mode, microphone audio is streamed to our servers and forwarded to our speech provider (Microsoft Azure OpenAI real-time API) to be understood and answered. The raw audio is processed in real time and is not stored; the resulting transcript is saved as part of the conversation. On-device dictation uses the speech recognition service built into your device's operating system, which is governed by its provider's terms.
  • Device registration data: a per-installation device key generated by the app, your push notification token, device manufacturer and model, app version, and language/locale. We use these to pair the device with your account, deliver notifications, and let you see and revoke devices from your account settings.
  • Device attestation: at sign-up, the Android app obtains a Google Play Integrity verdict confirming that it is running as a genuine app on a genuine device. We use it in place of a captcha to prevent automated sign-ups; it is verified and then discarded.

Information we automatically collect

  • Log data (IP address, browser type, access times).
  • Device information.
  • Usage data and analytics, including product usage events recorded by our servers (for example sign-up, agent creation, and messages sent) that we forward to our analytics providers.
  • Cookies and similar tracking technologies.
  • Session recordings.
03

How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our Services.
  • Process transactions and send related information.
  • Send technical notices, updates, and support messages.
  • Respond to your comments, questions, and requests.
  • Monitor and analyze trends, usage, and activities.
  • Detect, prevent, and address technical issues and fraudulent activity.
  • Comply with legal obligations.

AI Model Training Policy

We respect your privacy and the confidentiality of your data. We do not use your personal information, prompts, conversational data, or uploaded context files to train or fine-tune our internal AI models unless you provide explicit, opt-in consent to do so. Your private data remains yours. This applies equally to data received from Google APIs, which we never use to develop, improve, or train generalized AI or machine-learning models.

04

Third-Party AI Providers & "Bring Your Own Key" (BYOK)

To power our prompt-to-agent platform, we utilize industry-leading third-party Artificial Intelligence providers (currently Microsoft, Google, and OpenAI) to process your prompts by default. Data sent to these default providers is transmitted securely via API and is subject to their enterprise data privacy standards, which prohibit using API data to train their foundational models.

Alternatively, if you utilize our Bring Your Own Key (BYOK) feature, you are solely responsible for the relationship, data sharing, and privacy agreements with your chosen AI provider.

05

Information Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

  • With Service Providers: Including the default third-party AI providers mentioned above, cloud hosting platforms, and payment processors who perform services on our behalf.
  • To Comply with the Law: To comply with legal obligations or respond to valid legal requests.
  • To Protect Rights: To protect our rights, privacy, safety, or property.
  • Business Transfers: In connection with a business transfer, merger, or acquisition.
  • With Your Consent: With your consent or at your direction.

Service providers we currently use

  • Cloud hosting: Microsoft Azure.
  • AI model providers: Microsoft (Azure OpenAI, including the real-time voice API), Google (Vertex AI), OpenAI, and the additional model providers listed in the platform's model catalogue when you select them for an agent.
  • Payments: Stripe.
  • Product analytics: Amplitude and Google Analytics 4.
  • Push notifications: Google Firebase Cloud Messaging (Android app).
  • Device attestation: Google Play Integrity API (Android app).
  • Transactional email: Resend.

These providers process data only on our instructions and under contractual data-protection terms. We do not sell your information to them, and we do not share it with them for their own purposes.

06

Data Security & Integration Credentials

We implement appropriate technical and organizational measures to protect your personal information. When you connect third-party integrations to your agents (e.g., email accounts, LLM providers, Telegram, or MCP servers), we employ stringent security measures to protect your credentials:

  • Encryption at Rest: All credentials are encrypted before being saved to our database using industry-standard symmetric encryption (AES-128-CBC with HMAC-SHA256 authentication).
  • No Plaintext Storage: We never store your credentials in plaintext; our databases utilize encrypted-only columns. Encryption keys are securely managed via environment variables and isolated by domain.
  • Minimal Exposure: Credentials are decrypted only in memory, at the moment your agent needs to interact with the third-party service, and decrypted values are never written to a database or to disk. Where a service issues short-lived access tokens in exchange for a stored credential (as Google does), those tokens are held in server memory only until they expire. Furthermore, our API responses will only ever surface masked versions of your credentials.

Note: While we use enterprise-grade security, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

07

Google Workspace Integration and Google User Data

Agents built on Donkit can optionally be connected to Google Calendar, Google Sheets, Google Docs, and Google Drive (the "Google Workspace integration"). This section describes what we ask Google for, how the data we receive from Google APIs ("Google user data") is used, stored, and shared, and how you can withdraw access. It applies alongside the rest of this policy.

The integration is off until the owner of an agent enables it in the agent's Integrations settings, where the owner chooses, for each of the four services, whether the agent gets no access, read-only access, or read-and-write access. A Google account is connected only through Google's own sign-in and consent screen, which lists exactly the permissions requested; you can decline, grant only some of them, and connect a different Google account from the one you sign in to Donkit with. Signing in to Donkit with Google is separate from this integration: sign-in uses only your basic profile (name, email address, and profile picture) and grants no access to your Google Workspace data. The integration does not request access to Gmail.

What we ask permission for

When you connect from an agent, the consent screen asks only for the services and access levels that agent is configured to use. When you add a Google account directly to your Connections library, it asks for the full set below, so that the account can later be used by any agent you attach it to without a second consent. The permissions that can be requested are:

PermissionWhat it lets the agent do
Basic account information (openid, email)See the email address of the Google account you connected, so that you and the agent owner can tell which account is in use. Requested with every connection.
Google Calendar — readList events from your calendar within a time window.
Google Calendar — read & writeIn addition, create events and update existing ones. Attendees listed on an event see it on their own calendars.
Google Sheets — readRead a range of cells from a spreadsheet that you or the agent owner point the agent at.
Google Sheets — read & writeIn addition, write values to a range, append rows, and create new spreadsheets.
Google Docs — readRead the title and body of a document that the agent is pointed at.
Google Docs — read & writeIn addition, create documents and append text to them.
Google Drive — files the agent created or you opened with itList and upload files in Google Drive. This permission (drive.file) is limited to files the agent created or that you opened with Donkit; the agent cannot see, search, or download any other file in your Drive.

In chat and in workflow steps, the access level set by the agent owner is enforced on our side before every call: an agent configured for read-only access to a service cannot write to it, even if your Google account granted more. If an agent later needs a permission you have not granted, you are asked again through Google's consent screen; permissions are never widened silently.

How Google user data is used

We use Google user data solely to provide the user-facing features of the agent you connected it to, at your or the agent owner's request:

  • In chat: when you ask an agent to do something that involves your calendar, spreadsheets, documents, or Drive files, the agent reads or writes the relevant data, and the result becomes part of that conversation.
  • In workflows: a workflow step can read from or write to the connected services, within the access levels set by the agent owner, when a run is started by you, on a schedule you set up, or by a webhook you configured.
  • When building an agent on a shared account: the owner's Google account can be read (never written to) by the Builder, so that it can inspect the spreadsheets and documents the owner names and configure the agent to use them.
  • In an agent's own application code: where an agent includes a custom application built on Donkit, that application's server-side code can obtain a short-lived access token for the connected account and call Google's APIs directly, within the permissions you granted.

We do not use Google user data for advertising, for profiling, to determine creditworthiness, or for any purpose unrelated to the agent you connected it to, and we do not use it to develop, improve, or train generalized AI or machine-learning models (see "AI Model Training Policy" above).

Who can act on a connected account

The agent owner chooses one of two connection modes, which you can see before you connect:

  • Each user connects their own account. Your Google account is used only for your own conversations with that agent and for workflow runs that act on your behalf. Other users of the agent cannot reach your data through it.
  • One shared account. The agent owner connects a single Google account that the agent uses for everyone who talks to it and for every workflow run. Anyone able to use that agent can therefore cause it to read from, or write to, the owner's calendar, spreadsheets, documents, and Drive files within the access levels the owner set. This is the owner's decision — Donkit shows the owner a warning when such an agent is shared or published — and the owner is the controller of the data processed this way.

A Google account you connect is kept in your Connections library and can be reused by other agents you attach it to, each within the services and levels its owner enabled. You can see at any time which agents use which account, and unlink or delete an account from the library.

How Google user data is stored and protected

  • Credentials. For each connected account we store an OAuth refresh token, the list of permissions you granted, and the account's email address. The refresh token is encrypted at rest as described under "Data Security & Integration Credentials" and is decrypted only in memory when the agent needs to act. Short-lived access tokens obtained from it are held in server memory until they expire (typically one hour) and are never written to a database or to disk.
  • Content. We do not copy your calendar, spreadsheets, documents, or Drive into a separate store of our own. Data the agent reads from Google is retained only where the agent's work is kept: in the conversation it was used in, in the records of the workflow run that processed it, and in any file the agent produces from it. These are Agent Data under this policy, controlled by you or by the agent owner, and are deleted when the conversation, run, agent, or account is deleted.
  • People. Our staff do not read Google user data, except with your consent, where it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or in aggregated, anonymised form for internal operations.

How Google user data is shared

To produce the agent's response, the content the agent reads from Google is sent to the AI model provider that powers the agent — one of the default providers listed under "Third-Party AI Providers" or, if the agent owner uses BYOK, the provider they chose — and is processed on our infrastructure provider's servers. These providers act as our processors (or, for BYOK, under the owner's own agreement with them) and are bound not to train their models on it. Google user data is not transferred to anyone else, except as described under "Information Sharing and Disclosure" (for example, to comply with the law), and it is never sold, never used to serve advertisements, and never shared with data brokers.

Retention and withdrawing access

  • Stored credentials are kept until you delete the account from your Connections library (Account → Connections on the web, Settings → Connections in the mobile app) or delete your Donkit account. When you delete a connection, we delete the stored token and ask Google to revoke the access grant. When you delete your Donkit account, every connection is deleted with it; Donkit may remain listed under your Google Account's third-party access until you remove it there.
  • You can also revoke Donkit's access at any time from your Google Account, under Security → Third-party apps & services (myaccount.google.com/permissions). Revocation takes effect immediately: the agent can no longer reach your account until you connect it again.
  • Withdrawing access does not by itself delete data the agent already retrieved into conversations or workflow runs; delete those as described under "Data Retention" and on our Delete Account page.

Limited Use disclosure

Donkit's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we only use Google user data to provide or improve the user-facing features described above; we do not transfer it to others except as necessary to provide those features, for security purposes, to comply with applicable law, or as part of a merger or acquisition with your explicit prior consent; we do not use or transfer it to serve advertisements; we do not allow humans to read it except as set out above; and we do not use it to develop, improve, or train generalized AI or machine-learning models.

08

Public Agents and End-Users

Our platform allows our business customers to "Publish" agents, making them accessible via a public URL with or without password protection.

If you interact with a public agent created by a Donkit business customer, please be aware that the customer who created and deployed that agent acts as the Data Controller. The Data Controller dictates the agent's purpose, configuration, and may have access to the conversation logs. Donkit processes these interactions strictly on behalf of the agent creator. We encourage end-users to verify the privacy practices of the organization hosting the public agent.

09

Mobile Apps

The Donkit mobile apps let you chat with your agents, attach media, talk to agents by voice, and receive notifications. They request the following device permissions, each only when you first use the related feature:

PermissionWhy the app asks for it
CameraTake a photo or video to attach to a conversation.
Photos and videosPick existing media from your library to attach to a conversation.
MicrophoneDictate a message, or hold a real-time voice conversation with an agent.
NotificationsTell you when an agent has replied, needs your input, or when a service event (credits running low, a failed workflow, a finished build) needs attention. Notification categories can be changed per device.
Network accessCommunicate with the Donkit platform over encrypted HTTPS and WSS connections.

The apps do not request access to your location, contacts, calendar, or the other apps installed on your device, and they contain no advertising SDKs. Adding a Google account from the app opens Google's own sign-in page; this is the Google Workspace integration described above, not a device permission, and the app itself does not read the calendar on your device. Purchases are not made inside the apps: your plan and credit balance are shown in the app, and any purchase is completed on our website through our payment processor.

Data you send through the apps is handled exactly as described elsewhere in this policy: conversations and attachments are Agent Data, your profile is account information, and both are protected by the same security measures. You can remove a device from your account at any time from the app or from the Devices page on the web; removing a device signs it out and erases its push token.

10

Data Retention

We retain your personal information for as long as your account is active and as necessary to fulfil the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. In particular:

  • Account and profile data is kept until you delete your account. On deletion, your name, email address, and password are anonymised so that the email address becomes available for a new sign-up, and your sign-in identities (Google, Microsoft, GitHub) and third-party connections are removed immediately.
  • Agents, conversations, attachments, and teams you own are deleted when you delete them or your account. Deleted agents and the data inside them are held in a recoverable state for up to 30 days and are then permanently purged from our systems.
  • Connected accounts and integration credentials, including the Google accounts in your Connections library, are kept until you delete the connection or your account. Deleting a Google connection also asks Google to revoke the access you granted; see "Google Workspace Integration and Google User Data" above.
  • Billing and usage records (invoices, credit purchases, and credit consumption) are retained after account deletion for as long as accounting, tax, and other legal obligations require, and are then deleted.
  • Server logs and security records are retained for a limited period for troubleshooting and fraud prevention and are then deleted or anonymised.
  • Analytics data held by our analytics providers is retained according to the retention settings of those services, in pseudonymous form.
11

Your Rights

Depending on your location (including under the GDPR, applicable US State Laws, and the Israeli Privacy Protection Law), you may have certain rights regarding your personal information, including:

  • The right to access your personal information.
  • The right to rectify inaccurate information.
  • The right to request the deletion of your information.
  • The right to object to or restrict the processing of your information.
  • The right to data portability.
  • The right to withdraw consent.

To exercise these rights, please contact us using the details below. Where a right relates to Agent Data processed on behalf of one of our business customers, we will refer you to that customer as the relevant Data Controller, or assist them in fulfilling your request in accordance with our Data Processing Agreement.

Deleting your account

You can delete your account yourself, without contacting us, from the web app (Account → General → Delete account) or from the mobile app (Profile → Delete account). The full steps, what is deleted, and what is kept are described on our Delete Account page. If you can no longer sign in, email [email protected] from the email address on the account.

12

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to track activity on our Services and hold certain information. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent.

13

Session Replay

We use session replay technology to record and reconstruct your interactions with our website and platform interface (such as mouse movements, clicks, scrolls, page navigation, and interactions with page elements). This helps us diagnose errors, reproduce bugs, and improve the usability and security of our Services. Sensitive input fields, including passwords, API keys, and Integration Credentials, and areas displaying Agent Data are masked or excluded from these recordings by default. Where required by applicable law, we rely on your consent or on our legitimate interest in maintaining and improving the Services.

15

Children's Privacy

Our Services are intended for businesses and are not directed at children. We do not knowingly collect personal information from individuals under the age of 18. If you become aware that a child has provided us with personal information, please contact us so we can take steps to remove that information.

16

International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. Our platform infrastructure and Agent Data are primarily hosted in the United States. Other categories of data — including data collected through website analytics and tracking technologies, and data processed by our third-party AI, payment, and infrastructure providers — may be processed in additional jurisdictions, including the European Economic Area, the United Kingdom, Israel, and other regions, depending on the service. By using our Services, you consent to the transfer of your information to our facilities and to the third parties with whom we share it as described in this policy.

17

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top of this policy. You are advised to review this Privacy Policy periodically for any changes.

18

Contact Us

If you have any questions about this Privacy Policy, please contact us:

  • Email: [email protected]
  • Phone: +972 (77) 360-9468
  • Operator: Donkit AI Ltd., Reg. No. 516981651, Derech Menachem Begin 158, Tel Aviv-Yafo, 6492109, Israel
  • App-store publisher: Donkit AI Inc., 850 New Burton Road, Suite 201, Dover, DE 19904, United States