privacy

dood listens to your meetings. that is the whole point of him. so here is exactly what he hears, what he keeps, who else touches it, and how to make it go away.

effective 2 october 2026. applies to meetdood.ai, the dood meeting bot, and the emails dood sends.

who we are

Doodldroppr is made by Chrissy Lim in Singapore. In this policy "we" means Doodldroppr and "dood" means the bot that joins your call. If you have a question about your data, write to dood@meetdood.ai.

the short version

what we collect

your account

your email address, to sign you in with a magic link and to send you murals. we set one cookie so you stay signed in for up to 90 days. we keep your plan, your metered hours, your nibs, and which outfit your cast is wearing.

your meetings

when you invite dood to a call he collects:

dood does not record or store video. the only video he produces is his own camera tile, which shows the doodles.

your calendar, if you connect it

calendar auto-join is optional. if you connect a Google account, dood reads your upcoming events so he can turn up to the ones with a meeting link. he reads event titles, times, attendees, and the meeting link. he reads only. he never creates, edits, or deletes events, and he never reads your email, files, or contacts.

we ask Google for two permissions: read-only access to calendar events, and your email address so we know which account you connected. the calendar sync itself runs through Recall.ai, the same company that puts dood in the call: we hand it the calendar token, it watches your calendar for events with a meeting link, and it tells dood when to turn up. you can disconnect at any time from your plan page or from your Google account settings. when you disconnect, we delete the stored calendar tokens and the events we fetched, and Recall.ai does the same.

our use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. we use calendar data only to schedule dood for your meetings. we do not use it for advertising, we do not sell it, and no human reads it except to fix a problem you ask us to look at, or where the law requires.

payments

payments are handled by Stripe. we never see or store your card number. we keep a record of what you bought, when, and your Stripe customer reference.

outfits

if you upload images to dress the cast, we keep the images and the outfit sheets dood makes from them, for as long as the outfit exists. delete the outfit and they go.

technical bits

our server keeps ordinary request logs for a short time to catch errors. the website has no advertising trackers.

what we do with it

we do not use your transcripts, doodles, or calendar data to train AI models, and the providers we use are on paid terms that do not allow them to either.

who else touches your data

dood is small. he leans on a few bigger companies to do the heavy lifting. each one only gets what it needs for its part of the job.

companywhat it doeswhat it gets
Recall.aiputs dood in the call, turns speech into text, and watches your calendar if you connected onethe meeting link, call audio while live, participant names, calendar token and events
Google (Gemini API)reads the transcript text and makes the doodles and the words dood saystranscript text, outfit images if you use them
Google (Calendar API)tells dood which meetings to join, if you connected a calendaryour calendar events
Stripetakes paymentsyour email and what you bought
Resendsends dood's emailsyour email address and the contents of the email
Renderhosts the app and stores your dataeverything above, on our server
Cloudflareruns our domain and keeps encrypted nightly backupsa backup of the database, kept 30 days

some of these companies are in the United States, so your data leaves Singapore and may leave your country. each of them is bound by a contract that limits what they can do with it.

sharing murals

you decide who sees a meeting page. it can be off, open to anyone with the link, or public. the people you email the mural to get the mural and the to-dos, not the transcript. transcripts, participant lists, and the log are visible only to the meeting owner. if you make a page public it can appear in search engines, so think before you do.

how long we keep it

your choices

if you are in the EU, UK, or another place with data protection law, you have the rights that law gives you, including to access, correct, delete, or object. use the same email address. if you are not happy with our answer you can complain to your local data protection authority. in Singapore that is the PDPC.

people in your meetings

dood hears everyone in the call, not just you. you are responsible for making sure the people in your meeting know dood is there and are fine with it, in the way your local law requires. dood always joins as a visible participant called "dood", never hidden. if someone in your meeting wants their words removed, delete the meeting or write to us.

children

doodldroppr is for work meetings and is not for anyone under 16. if you think a child has given us data, write to us and we will delete it.

security

everything travels over https. sign-in uses one-time magic links, not passwords. backups are encrypted. access to the server is limited to the people who run dood. no system is perfect, and if something goes wrong that affects you, we will tell you.

changes

if we change this policy in a way that matters, we will email you before it takes effect. the date at the top always tells you which version you are reading.

contact

dood@meetdood.ai. a person reads it.