Privacy Policy
DoneLayer (the "Service") respects your privacy. This policy explains what information the Service collects and how it is used.
Anonymous Accounts
On first launch, after you grant consent, the Service automatically creates an anonymous account to securely store and manage your data — even if you choose not to register an email address. Your article URLs and committed task data are linked to this anonymous account.
You can delete your anonymous account data at any time via "Delete Account" in Settings. Registering an email address migrates all your anonymous account data to the new account.
Information We Collect
Information you provide
- Email address: Collected only if you register with email. Used for authentication only. Not collected if you skip registration.
Information collected through your use of the Service
- Anonymous user ID: Auto-generated after first launch and consent. Linked to your email address upon registration.
- Article URL and body text: The body text of URLs you paste in the Input screen is sent to our server for AI task generation.
- Custom task text: When you use the custom task feature, text you type directly (up to 1,000 characters) is sent to our server for AI task generation. The raw input text is not stored server-side; only the AI-generated tasks you confirm are saved.
- Task data: Title, progress status, and source article information for tasks you commit.
- Usage data: For service improvement, we collect in-app operation events including: page views, button clicks, URL submissions, candidate fetches, task commits, status changes, deletions, Share Extension usage, registration/login/logout/account deletion, paywall views, purchase starts/completions/cancellations/errors, and purchase restores.
- Purchase information: If you purchase Pro, we record the Apple App Store transaction ID, product ID, purchase environment, and lifetime unlock timestamp (or expiration for the legacy monthly product). Payment details such as credit card numbers are managed by Apple; we do not access or store them.
- Knowledge domain classification data: Task titles are sent to the Gemini API for automatic domain classification (learning, career, health, etc.). Classification results are stored with your task data.
- Photo library access: When saving a weekly report card to your photo library, the Service requests add-only access to your iOS photo library. This access is used solely for the save operation; existing photos are never read or viewed.
How We Use Your Information
- Creating and managing your account
- Generating AI task candidates
- Syncing data between mobile and web
- Analyzing usage patterns
- Improving the Service
Third-Party Services
The Service uses the following third parties. Your information is not shared with anyone else.
| Service | Purpose | Data Sent |
|---|---|---|
| Supabase | Database & authentication (ap-northeast-1 region) | Anonymous user ID, email address (if registered), task data |
| Google Gemini API | AI task generation, domain classification, weekly report generation | Article URL and body text, custom task text, task titles (for domain classification), task title lists / completion counts / Action Rate stats (for weekly reports). Google's Privacy Policy (policies.google.com/privacy) applies. |
| Cloudflare Workers | API proxy & in-app event relay | Article URL and body text, custom task text, in-app operation events, anonymous measurement ID, logged-in user ID |
| Apple (App Store Server API) | Pro one-time purchase and legacy monthly Premium purchase verification | Transaction ID, product ID, purchase environment, and lifetime unlock timestamp or expiration. Apple's Privacy Policy (apple.com/legal/privacy) applies. |
| X (formerly Twitter) | Posting share cards to X (only when user taps "Post to X") | Post text (KPI metrics, hashtags, etc.). X's Privacy Policy (x.com/privacy) applies. |
| Google Analytics 4 | Usage analytics for the landing page, web app, and mobile app | Anonymous behavior data (page views, button clicks, URL submissions, candidate fetches, task commits, status changes, deletions, Share Extension usage, registration/login/logout/account deletion, etc.). Full article URLs, article body text, and task content are NOT sent. |
Custom Task Feature Notice
Text entered in the custom task field is sent to the Gemini API (Google) for AI task generation. Please do not enter the following types of content in the custom task field:
- Personal information of third parties (names, addresses, contact details, etc.)
- Confidential business information, internal documents, or information subject to an NDA
- Any other highly sensitive information that is not appropriate to send to an external AI service
Data Retention
Data is retained for the duration your account (anonymous or email-registered) remains active. Deleting your account removes all data including your anonymous user ID and email address.
Your Rights
Regardless of whether you registered an email address, you can delete your account and all associated data at any time via "Delete Account" in Settings.
Age Requirement
This Service is intended for users 13 years of age and older. Users under 13 are not permitted to use this Service.
Contact
For questions about this Privacy Policy, please reach out via X (formerly Twitter) @AI_PdM_Nullpo.