Done · Legal
Privacy Policy
Last updated 2026-09-21
Done is a personal life-admin app: you capture notes, photos, and documents, and Done organizes them and helps you act on what matters. This policy describes what data Done collects, where it lives, who can see it, and how to get it back or have it deleted. “Done”, “we”, and “us” mean the operator of the Done service.
What Done collects
- What you capture. Notes, photos, and files (PDF, image, CSV) you add to your corpus, plus the AI-generated markdown record of each.
- Emails you forward to your personal Done address, if you use it — the sender, subject, and body become a capture.
- Account-level financial data from financial institutions only when you explicitly authorize a connection (e.g. Plaid). This may include account balances, transactions, and liability details for the accounts you connect.
- Your email address, used to sign you in and to send you messages about your account.
- Concerns and action threads you create inside the app, and the briefs and outcomes the AI derives from your corpus.
- A device push token, if you use the mobile app and allow notifications.
- Usage records — your plan, how many captures you've made, and the count and estimated cost of AI requests for your account, used to enforce plan limits.
- Standard request logs from the hosting platform (Vercel) and the database (Supabase), such as IP address, timestamp, and route hit. Used for operational monitoring and incident response; not used to profile you.
Why Done collects it
To organize your personal corpus and generate concrete, actionable briefs that reduce financial and life-admin friction. Your data powers your investigation. It is not sold, not used for advertising, and not shared with anyone other than the service providers listed below, which process it only to run Done.
Who can see your data
You — and no other Done user. Every account's data is kept separate: Postgres Row-Level Security restricts each row to the account that owns it, and each account's files are stored under that account's own private storage path. Automated jobs (such as the daily investigation) process your data on your behalf.
People who operate Done do not look at your data except where that is necessary to keep the service running, to investigate a security incident or a problem you report, or to comply with the law.
Third parties Done uses
Done runs on the service providers below. Each receives only what it needs to do its job:
- Vercel (hosting) — privacy policy. Runs the application code.
- Supabase (Postgres, file storage, auth) — privacy policy. Holds your corpus and account.
- Anthropic (Claude) (AI) — privacy policy. Receives the content of your captures, files, forwarded emails, and connected financial data; reads and classifies what you capture, finds what needs your attention, and powers chat and guided actions. Anthropic doesn't train its models on your data. Anthropic deletes API inputs and outputs within 30 days by default, except where it must keep them longer to enforce its usage policies or comply with the law. When the guided action agent researches something for you, Anthropic runs the web searches it needs.
- Voyage AI (AI) — privacy policy. Receives the content of your captures, files, forwarded emails, and connected financial data; indexes and ranks the text of your captures so Done can find what's relevant to a question or concern.
- Resend (inbound email, when you use your Done address) — privacy policy. Receives mail sent to your Done address and hands it to Done to file as a capture.
- Plaid (financial connector, when you opt in) — privacy policy. Plaid acts as the conduit between Done and your financial institution. You consent to Plaid's data sharing directly in the Plaid Link UI; your bank credentials are entered into Plaid and never reach Done's servers.
You agree to the AI processing described above when you start using Done, and you can withdraw by deleting your account.
Cookies and tracking
Done uses one category of cookie: an httpOnly secure session cookie set by Supabase Auth so that you stay signed in across requests. There is no analytics, no advertising tracker, no third-party embed, and no cross-site tracking pixel.
Security
Connection to Done is TLS 1.2 or higher in all paths. Data at rest is AES-256 encrypted on the Postgres volume (Supabase / AWS default). You sign in without a password — a one-time code or link sent to your email, or a WebAuthn passkey — so Done stores no password for you. The one exception is a demonstration account used by app-store reviewers, which signs in with a password that Supabase Auth keeps only as a salted hash. Administrative accounts for the infrastructure (Vercel, Supabase, GitHub) require multi-factor authentication. To report a security issue, email hello@quobo.co.
Retention and deletion
Different categories of data live for different lengths of time — for example, connector snapshots are superseded on every refresh, and dismissed briefs expire after 90 days. The full lifecycle and your deletion rights are in the Retention Policy.
You can delete your account yourself, at any time, from Settings → Delete account. This immediately and permanently erases your account and everything in it — every captured document, brief, concern, reminder, connected account, and stored file — disconnects your linked bank accounts at Plaid, and signs you out. It cannot be undone. You can also email hello@quobo.co if you need help.
Your rights
You can see, correct, or delete your data in the app at any time, and delete your whole account from Settings. For anything else — including a copy of your data, or a question about how it is processed — email the contact below. Depending on where you live (for example under the GDPR or CCPA), you may have further rights, such as to object to or restrict processing, or to complain to your data-protection authority. Done does not sell or share personal data for advertising, so there is nothing to opt out of.
Children
Done is not intended for and not directed at anyone under 13. If you believe a child has used Done, email hello@quobo.co and the account will be deleted.
Changes to this policy
Material changes are dated at the top of this page. Before any change that broadens what Done collects or who it shares data with takes effect for you, Done will ask you to review and accept it in the app.