Privacy Policy
Updated August 2026 · Dolly Labs
This policy covers the OnDolly platform (`ondolly.com` / `ondolly.life`), operated by Xite Digital. OnDolly provides users a personal AI assistant. We respect your privacy and process personal data with confidentiality, explicit consent, and per-account isolation.
1. Information We Collect
Depending on your use of OnDolly (waitlist reservation, web chat, or messaging assistant), we collect:
- Account Data: Name, email address, chosen handle, and Google account authentication details.
- Calendar & Scheduling Data: We request read and write access to your Google Calendar to check your availability, resolve scheduling conflicts, and create or modify events on your behalf.
- Conversation & Assistant Data: Free-text messages, voice note transcripts, and task preferences.
- Self-Reported Wellness Data: If you choose to use wellness-guidance features, self-reported readings (such as blood pressure or blood glucose) and related notes you share. Provided only with your explicit opt-in.
- Inbound Email Briefs: Forwarded email headers, senders, and compact text snippets sent to your dedicated
<handle>@inbox.ondolly.comaddress.
2. Wellness Guidance & Consent
- OnDolly offers general wellness guidance, reminders, and nudges. It is not a medical device, medical service, or a substitute for professional medical advice — guidance is informational only.
- Self-reported wellness data is processed strictly with your explicit opt-in consent and can be withdrawn at any time by contacting us or closing your account.
- Google Calendar data is used solely for scheduling and reminders. It is never used for, or combined with, any wellness-guidance features.
3. Google API Services & Limited Use Policy
OnDolly requests access to your Google Calendar (a Sensitive scope) strictly to provide scheduling capabilities.
OnDolly's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We do not sell, rent, or lease your Google Calendar data to any third parties.
- We do not use your Google Calendar data for serving advertisements.
- We do not use or transfer your Google Calendar data to train, retrain, or fine-tune generalized AI or machine learning models. If calendar data is processed by an AI provider to fulfill a scheduling request, it is processed only for that request and not retained for model training.
- We only transfer Google Calendar data to sub-processors to the extent necessary to provide the scheduling features explicitly requested by the user, and under strict confidentiality agreements.
4. Sub-Processors & Data Transfer
We work with trusted infrastructure sub-processors under data protection agreements, limited to what each feature requires:
- Cloud hosting & database: reputable cloud infrastructure providers with per-account data isolation.
- AI processing: requests are routed through OpenRouter (commercial API tier) to established AI model providers — Anthropic (Claude), OpenAI (GPT), and Google (Gemini) — on their standard commercial API tiers. Under those API terms, the providers do not use API inputs or outputs to train or improve their models, and our routing configuration disables any optional data retention or training. No Google user data is ever used — in raw, aggregated, or derived form — to create, train, or improve any generalized AI/ML model, by us or by any provider we use.
- Email & messaging delivery: transactional email providers and messaging platforms (such as Telegram and WhatsApp) you choose to connect.
AI processing is per-request only: the minimum data needed to fulfill your specific request is sent, processed for that request, and not retained by the model provider for any secondary purpose. We additionally minimize what reaches AI providers — for example, saved contact phone numbers and email addresses are never included in AI prompts; only the contact's name is, with the actual details resolved inside our own systems.
5. Security & Data Protection Mechanisms
Sensitive data is protected by the following concrete mechanisms:
- Encryption in transit: all traffic uses TLS (HTTPS), including every call to Google APIs and sub-processors.
- Encryption at rest for credentials: Google OAuth refresh tokens are stored encrypted with authenticated encryption (AES-256-GCM, keys derived via scrypt). If the encryption key is unavailable, the system refuses to store tokens rather than falling back to plaintext.
- Per-account isolation at the database layer: PostgreSQL Row-Level Security enforces tenant isolation on every query, independent of application code — one user's data cannot be returned in another user's context.
- Least-privilege access: we request a single, narrow Google scope (
calendar.events) — no Gmail, Drive, or Contacts access. Internal APIs are gated by role-separated keys checked with constant-time comparison, and administrative access is restricted to a named-account allowlist. - Auditability: calendar changes made through OnDolly are recorded in an audit history (what changed, when, and whether it synced), and destructive actions require an explicit user confirmation step before execution.
6. Data Retention & Isolation
Your data is isolated per user account. Forwarded email briefs are stored in a rolling buffer (retained for 7 days by default) and automatically purged. Conversation history and memory remain accessible to you until account deletion is requested.
7. Your Rights & Data Deletion
In line with India's Digital Personal Data Protection (DPDP) Act, 2023 and other applicable data-protection laws, you have the right to access, export, correct, or request permanent deletion of your personal data stored by OnDolly. To exercise these rights or withdraw consent, email support@ondolly.com. Deletion requests are processed within 30 days.
8. Changes to this Policy
We may update this policy as new capabilities land. Material changes will be posted directly on this page with an updated revision date.
This is a plain-language summary for our launch reservation, not final legal terms. Questions? Email hello@ondolly.com.