Privacy Policy

This policy explains what DolessWork OS ("we", "us") collects, why, and what we never do with it. The short version: we store the business data you put into your workspace so the product works, we use trusted processors to run AI and voice features, and we don't sell data or run ad trackers.

1. What we collect

Account data: your email, workspace name, and a securely hashed password (we never store the password itself). Workspace data: the leads, orders, invoices, inventory, calls, bookings, tasks, and team invites you or your customers submit through your forms, phone number, and dashboard. Business profile: the optional onboarding answers (what your business does, goals, customer descriptions, weekly time sinks, common customer questions, and any standing rules you set for how we operate), used only to personalize Partner matching and AI assistance; every question is skippable and the answers are included in your data export. Prospect data:if you use the "what we'd automate" form or the ROI calculator, the details you type (including the hours you enter) are stored as a lead in our own workspace so we can reply.

Marketing email

If you unlock the ROI calculator's full results with your email, we send you that report plus a short follow-up series (a handful of emails at most, and it stops on its own). Every email has a one-click unsubscribe link, unsubscribing is immediate and permanent, and the series also stops the moment you create a workspace. We never buy lists or email anyone who didn't give us their address directly.

2. How we use it

Only to provide the Service: showing your workspace, scoring and routing leads, matching Partners, generating documents, and keeping the audit trail you see on the Compliance page. We don't sell your data, and we don't use your workspace content for advertising.

3. AI processing and subprocessors

Some features send relevant text to service providers to work: AI lead scoring and the assistant use a large-language-model provider (currently Anthropic); the Voice AI receptionist uses a voice-infrastructure provider (Vapi) to answer calls; transactional and follow-up email, including invoices and payment reminders you send from the Billing module, is delivered by an email provider (Resend). Hosting runs on Render. Each provider receives only what its feature needs.

4. Cookies

One cookie: an httpOnly session token that keeps you logged in. No analytics cookies, no tracking pixels, no third-party ad tech.

5. Retention, export, deletion

Workspace data is kept while your workspace is active. Admins can export a complete JSON copy from the Compliance page at any time. To delete your workspace and its data, ask via the contact form and we'll confirm completion by email.

6. Security

Passwords are bcrypt-hashed, sessions are signed httpOnly cookies, transport is HTTPS, and Partner/AI actions are recorded in your audit trail. No system is perfectly secure. If we learn of a breach affecting your data, we will notify affected workspaces without undue delay.

7. Your customers' data

When your customers submit forms or call your Voice AI line, you are the controller of that data and we process it on your instructions. Publish your own privacy notice where you collect it, and only point our intake endpoints at properties you control.

8. Changes and contact

Updates appear on this page with a new date. Questions or requests: the contact form reaches us directly.