Privacy Policy
Last updated: August 20, 2026
This Privacy Policy explains how Dooit handles information for the landing page, waitlist, mobile app, optional cloud features, AI features such as receipt and statement scanning, analytics, and subscriptions.
1. Who we are
Dooit is a personal finance tracking app built for users in Malaysia, although people in other countries may also use it.
For privacy questions or requests, contact Dooit at hafizuddinshariff@gmail.com.
2. Waitlist and landing page information
When you join the Dooit waitlist, we collect the email address you submit, a source marker showing that the signup came from the landing page, and anti-spam information submitted with the form.
The waitlist form sends submissions to a Supabase Edge Function for processing and storage.
Our waitlist form uses Cloudflare Turnstile to help confirm that submissions are legitimate. Cloudflare may process verification tokens, browser signals, and similar technical information according to its own service terms and privacy practices.
3. App information you enter
By default, Dooit is local-first. Financial information you enter in the app, such as transactions, amounts, categories, budgets, accounts, notes, preferences, and saved receipt images, is stored on your device unless you choose to use a feature that sends or backs up that information.
Dooit currently relies on manual entry and user-uploaded receipts. We do not currently connect to banks or import bank transactions automatically.
If you contact us for support, we may collect your email address, message contents, and related troubleshooting information.
4. Optional Pro cloud backup and sync
If you purchase Pro, Dooit may offer optional cloud backup or sync. This is not enabled automatically. You must choose to turn it on.
When cloud backup or sync is enabled, selected financial data is stored in Supabase so it can be backed up or synced. This data is protected with technical and organizational safeguards, but it is not currently end-to-end encrypted.
Saved receipt images are included in cloud backup only if you separately opt in to backing up receipt images.
If you disable cloud backup or sync, Dooit is designed to delete the synced Supabase copy after you confirm that choice.
5. AI features and the third-party AI service we use
Dooit offers three optional features that use artificial intelligence: receipt scan, statement scan (multi-transaction extraction), and AI column mapping for file imports. Each one runs only when you deliberately start it. None of them runs in the background, and none of them reads your transactions, accounts, or files on its own.
The third-party AI service is Google Gemini, operated by Google LLC. Dooit's own server receives your request, forwards the content to the Gemini API, and returns the result to your device. No other AI provider receives your data.
Before anything is sent to Google Gemini for the first time, the app shows an in-app disclosure that names the data being sent and names Google Gemini as the recipient, and it sends nothing unless you agree. You can withdraw that permission at any time in Profile, Preferences, AI and data sharing. While it is off, all three AI features stay disabled and nothing is sent.
Receipt scan sends: the receipt image or PDF you selected and the text visible on it (which typically includes merchant, date, totals, line items, taxes and service charges); your category, account, and tag names so the result can be matched to them; your currency and country setting; and any correction prompt you type.
Statement scan sends: the statement image, PDF, or text you selected, including merchant names, dates, amounts, and any account or card labels printed on it; your category, account, and tag names; and your currency and country setting.
AI column mapping sends: the sheet names and column headers of the file you are importing, placeholders that describe each column instead of your real values (for example <amount>, <date>, <text:12>), and currency codes and transaction type labels found in the file. If you separately choose the improved detection option, a small sample of real rows from that file is sent as well, which can include merchant names, descriptions, dates, and amounts.
We collect this data only from what you hand to the feature: the image, PDF, text, or file you pick, plus the category, account, tag, currency, and country settings already stored in the app. We use it only to produce the extraction or mapping result you asked for, to show that result to you for review, and to run basic reliability and abuse-prevention checks on the scan service.
Dooit does not use your receipt, statement, or import content to train any Dooit model, and does not sell or rent it. Google processes it as our service provider to return the result. Under the Google Gemini API terms that apply to Dooit's paid API use, Google does not use content submitted through the API to train its models, and Google is bound by confidentiality, security, and data protection commitments comparable to those described in this policy. Google's own handling is also described in Google's privacy policy and Gemini API terms.
Uploaded files are kept only as long as needed to complete the scan and deliver the result. Extraction results are stored on your device; if Pro cloud backup is enabled they follow the backup rules in this policy. Receipt images may be saved on your device, and are backed up only if you opt in to receipt image backup.
6. Accounts and sign-in
If you create an account or enable cloud features, Dooit uses Supabase Auth to provide authentication and account management.
Dooit may support Apple Sign in and Google Sign-In. Depending on the provider and your settings, we may receive account identifiers such as your name, email address, or provider user ID.
You are able to delete your account and associated cloud data in the app. You may also contact us for help with privacy requests.
7. Support requests
When you submit an authenticated Support request, Dooit stores the ticket messages and any images you deliberately attach, associates them with your account, and records public lifecycle updates and private administrative audit events.
Support includes a limited diagnostic snapshot: app and build version, platform and operating system, device model, locale, timezone, account identifier, subscription state, and the source screen. It does not collect your finance records, receipt contents, passwords, authentication tokens, or app logs for this purpose.
Supabase provides database and private image storage for Support. Resend may process transactional staff email alerts, and Apple or Google notification services may process user push notifications. Support images are private and made available through short-lived authorized links.
Closed Support tickets and their messages, events, and attachments are normally retained for 24 months after closure. Account deletion schedules associated Support data for deletion within 30 days unless a narrow legal or billing hold applies. Support may permanently redact sensitive messages or images while preserving a non-sensitive record that redaction occurred.
If you cannot sign in, you may use the emergency support email shown in the app. Email sent through that fallback is not automatically added to the authenticated ticket system.
8. Purchases and subscriptions
Pro purchases are handled through Apple App Store or Google Play in-app purchases. Those stores process payment details under their own terms and privacy practices.
Dooit uses Adapty for subscription entitlement management. Adapty may process purchase receipts, product identifiers, subscription status, app user identifiers, and related subscription lifecycle information needed to unlock and manage Pro access.
Dooit does not need to receive your full payment card details when purchases are handled by Apple or Google.
9. Analytics and diagnostics
Dooit uses privacy-conscious analytics and diagnostics to understand reliability and improve the app.
We use PostHog for analytics events. We do not use PostHog session replay or screen recording.
We do not intentionally send transaction amounts, notes, receipt images, or financial record contents to PostHog for analytics.
You can opt out of analytics in the app.
10. Device permissions
Dooit may request camera or photo library access so you can capture or import receipts.
Dooit may request notification permission to send user-controlled reminders, budget alerts, and important account or service notices. Marketing push notifications are sent only with consent.
Dooit does not need access to your contacts. You can control app permissions through your device settings.
11. How we use information
We use information to operate Dooit, manage the waitlist, provide app features, maintain accounts, run the AI features described in section 5 (receipt scan, statement scan, and AI column mapping), manage subscriptions, respond to support requests, prevent spam and abuse, improve reliability, and communicate product updates where you have consented to receive them.
We may use aggregated or de-identified information to understand feature usage and improve Dooit.
12. Sharing information
We do not sell your personal information.
We may share information with service providers that help us operate Dooit, including Supabase, Cloudflare, Resend, Google Gemini, PostHog, Adapty, Apple, and Google. Google Gemini is the only third-party AI service Dooit uses, and it receives content only through the AI features described in section 5, after you agree in the app.
We share personal information with these providers only under contracts that require them to protect it with safeguards at least equivalent to those described in this policy, to use it only to provide their service to Dooit, and not to sell it or use it for their own unrelated purposes.
We may also share information when required by law, to protect Dooit and users, in connection with a business transfer, or with your consent.
13. Marketing communications
We send marketing or product update emails only with consent, such as when you join the waitlist or enable an in-app email preference.
Transactional messages, such as account, support, purchase, security, or service-related messages, may be sent when needed to provide Dooit.
14. Data retention
We keep waitlist emails until you unsubscribe, request deletion, or Dooit no longer needs the waitlist.
We keep account and cloud backup information while your account or cloud sync is active. If you delete your account or request deletion, we delete or anonymize associated information within a reasonable period unless we need to keep it for legal, security, fraud prevention, dispute resolution, or accounting reasons.
Local app data stored only on your device is controlled by you and may be removed by deleting it in the app or removing the app from your device, subject to your device backup settings.
15. Your choices and rights
You may choose not to join the waitlist, not to create an account, not to enable cloud backup, not to use the AI features, not to back up receipt images, or not to provide optional app information. Some features may not work without the information needed to provide them.
You can decline the in-app AI disclosure, or withdraw your agreement later in Profile, Preferences, AI and data sharing. Receipt scan, statement scan, and AI column mapping then stay off and send nothing to Google Gemini; you can still record and import transactions manually.
You may opt out of analytics in the app and manage camera, photo library, and notification permissions through your device settings.
You may contact us to request access, correction, or deletion of personal information, subject to applicable law and technical or legal limits.
16. Security
We use reasonable technical and organizational measures designed to protect information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
17. International processing
Dooit and its service providers may process information in Malaysia, the United States, the European Union, and other countries where they operate. Data protection laws may differ by location.
18. Children's privacy
Dooit is not intended for children under 13. If a higher minimum age applies in your country, you must meet that higher age requirement to use Dooit.
If you believe a child has provided personal information to Dooit, contact us so we can review and delete it where appropriate.
19. Changes to this policy
We may update this Privacy Policy from time to time. If changes are material, we will take reasonable steps to notify you, such as updating the date on this page or providing notice in the app.
20. Contact
For privacy questions or requests, contact Dooit at hafizuddinshariff@gmail.com.