who we are
Doodldroppr is made by Chrissy Lim in Singapore. In this policy "we" means Doodldroppr and "dood" means the bot that joins your call. If you have a question about your data, write to dood@meetdood.ai.
the short version
- dood turns speech into text, text into doodles, and doodles into a mural. he does not record video and we do not keep audio.
- we keep the transcript text, the doodles, and the mural so you can look at them later. you can delete them.
- we do not sell your data, show ads, or use your meetings to train AI models.
- other companies process parts of the job for us. they are listed below.
- dood joins a call as a visible participant called "dood". everyone in the call can see him. it is your job as the host to tell people he is there.
what we collect
your account
your email address, to sign you in with a magic link and to send you murals. we set one cookie so you stay signed in for up to 90 days. we keep your plan, your metered hours, your nibs, and which outfit your cast is wearing.
your meetings
when you invite dood to a call he collects:
- the meeting link and the time it started and ended.
- the names of participants as shown in the call, and when they joined and left.
- a live transcript of what is said, as text. the audio is converted to text as it happens. we never store audio, and Recall.ai deletes its copy once the transcript is made.
- the doodles dood makes, the mural he assembles, the to-dos he picks out, and a log of what happened in the call.
dood does not record or store video. the only video he produces is his own camera tile, which shows the doodles.
your calendar, if you connect it
calendar auto-join is optional. if you connect a Google account, dood reads your upcoming events so he can turn up to the ones with a meeting link. he reads event titles, times, attendees, and the meeting link. he reads only. he never creates, edits, or deletes events, and he never reads your email, files, or contacts.
we ask Google for two permissions: read-only access to calendar events, and your email address so we know which account you connected. the calendar sync itself runs through Recall.ai, the same company that puts dood in the call: we hand it the calendar token, it watches your calendar for events with a meeting link, and it tells dood when to turn up. you can disconnect at any time from your plan page or from your Google account settings. when you disconnect, we delete the stored calendar tokens and the events we fetched, and Recall.ai does the same.
our use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. we use calendar data only to schedule dood for your meetings. we do not use it for advertising, we do not sell it, and no human reads it except to fix a problem you ask us to look at, or where the law requires.
payments
payments are handled by Stripe. we never see or store your card number. we keep a record of what you bought, when, and your Stripe customer reference.
outfits
if you upload images to dress the cast, we keep the images and the outfit sheets dood makes from them, for as long as the outfit exists. delete the outfit and they go.
technical bits
our server keeps ordinary request logs for a short time to catch errors. the website has no advertising trackers.
what we do with it
- doodle your meeting live and build the mural afterwards.
- email the mural and the to-dos to you and, if you choose, to the people you name.
- send you a monthly letter from dood about your month, if you are on a paid plan.
- count your hours against your plan and your nibs.
- fix things when they break.
we do not use your transcripts, doodles, or calendar data to train AI models, and the providers we use are on paid terms that do not allow them to either.
who else touches your data
dood is small. he leans on a few bigger companies to do the heavy lifting. each one only gets what it needs for its part of the job.
| company | what it does | what it gets |
|---|---|---|
| Recall.ai | puts dood in the call, turns speech into text, and watches your calendar if you connected one | the meeting link, call audio while live, participant names, calendar token and events |
| Google (Gemini API) | reads the transcript text and makes the doodles and the words dood says | transcript text, outfit images if you use them |
| Google (Calendar API) | tells dood which meetings to join, if you connected a calendar | your calendar events |
| Stripe | takes payments | your email and what you bought |
| Resend | sends dood's emails | your email address and the contents of the email |
| Render | hosts the app and stores your data | everything above, on our server |
| Cloudflare | runs our domain and keeps encrypted nightly backups | a backup of the database, kept 30 days |
some of these companies are in the United States, so your data leaves Singapore and may leave your country. each of them is bound by a contract that limits what they can do with it.
sharing murals
you decide who sees a meeting page. it can be off, open to anyone with the link, or public. the people you email the mural to get the mural and the to-dos, not the transcript. transcripts, participant lists, and the log are visible only to the meeting owner. if you make a page public it can appear in search engines, so think before you do.
how long we keep it
- meetings, transcripts, doodles, and murals: at least 12 months on every plan, and up to as long as your account exists, or until you delete the meeting.
- calendar tokens and events: until you disconnect the calendar.
- backups: 30 days, then gone.
- sign-in cookie: 90 days.
- payment records: as long as tax law says, which is usually seven years.
your choices
- delete a meeting. open it and delete it. the transcript, doodles, and mural go with it.
- disconnect your calendar. from your plan page, or from your Google account's third-party access settings.
- delete your account. email dood@meetdood.ai from the address you signed up with. we delete your account and everything in it within 30 days, except payment records we must keep.
- get a copy. email the same address and we send you your data.
if you are in the EU, UK, or another place with data protection law, you have the rights that law gives you, including to access, correct, delete, or object. use the same email address. if you are not happy with our answer you can complain to your local data protection authority. in Singapore that is the PDPC.
people in your meetings
dood hears everyone in the call, not just you. you are responsible for making sure the people in your meeting know dood is there and are fine with it, in the way your local law requires. dood always joins as a visible participant called "dood", never hidden. if someone in your meeting wants their words removed, delete the meeting or write to us.
children
doodldroppr is for work meetings and is not for anyone under 16. if you think a child has given us data, write to us and we will delete it.
security
everything travels over https. sign-in uses one-time magic links, not passwords. backups are encrypted. access to the server is limited to the people who run dood. no system is perfect, and if something goes wrong that affects you, we will tell you.
changes
if we change this policy in a way that matters, we will email you before it takes effect. the date at the top always tells you which version you are reading.
contact
dood@meetdood.ai. a person reads it.