Legal · Effective 9 September 2026

Privacy Policy

We do not see your work. Your documents, notes, files, and anything you create inside Donezo stay on your device. We hold your email, your plan membership, and your payment reference. That is it.

Sequence Theory · Commelinstraat 198, 1093 VD Amsterdam, Netherlands · KvK 72222204 · BTW NL002512044B49 · Supervisory authority: Autoriteit Persoonsgegevens (Dutch DPA)

The short version

We do not see your work. Your documents, notes, files, and anything you create inside Donezo stay on your device. We hold your email, your plan membership, and your payment reference. That is it.

If you use free apps without an account, we hold nothing about you at all.

1. Who controls your data

The data controller is Sequence Theory, a sole proprietorship registered at Commelinstraat 198, 1093 VD Amsterdam, Netherlands (KvK 72222204). Contact: omar@donezo.space.

2. What we collect and why

Free app users: Can, Docs, Grid and Make work entirely in your browser. There is no account to create. Your files and what you type stay on your device. The only thing that can leave is an anonymous event count, described under Signals below, and anything you choose to send us through the feedback panel.

Donezo Connected buyers:

DataWhy we hold itLegal basisRetention
Email addressConfirm your membership, send transactional messagesContract, GDPR Art. 6(1)(b)Duration of membership
Plan tierDetermine which features you can accessContract, GDPR Art. 6(1)(b)Duration of membership
Membership recordVerify your plan on your devicesContract, GDPR Art. 6(1)(b)Duration of membership
App settingsPreferences such as theme and workspace nameContract, GDPR Art. 6(1)(b)Duration of membership
Stripe customer IDLink membership to payment recordsLegal obligation, GDPR Art. 6(1)(c)7 years
Transaction recordsInvoicing and fiscal complianceLegal obligation, GDPR Art. 6(1)(c)7 years (Dutch AWR Art. 52)
Referral payout details: account holder name, IBAN, country, and the referrals attributed to youPay referral rewards you have earned, and keep the record the tax authority requiresContract, GDPR Art. 6(1)(b); legal obligation, Art. 6(1)(c) for the payout recordBank details: until paid out and for 12 months after your last payout, then deleted. Payout records: 7 years (Dutch AWR Art. 52)

Providing your email is a contractual requirement. Without it, we cannot confirm your membership. There is no obligation to provide it for free app use.

Referral payouts. Referral data is only collected if you take part in the referral programme and only when a reward is due. To pay you we ask for the name on the account and the IBAN, and we record the country for tax purposes. Bank details are entered by you inside Donezo, travel over an encrypted connection to Sequence Theory's payout record, and are used for nothing except the payout. We do not share them with anyone other than our own bank to execute the transfer. If a reward crosses a reporting threshold, Dutch tax law may require us to ask for further identification before paying; we will tell you what and why at that point.

Signals, not analytics. Donezo counts events, not people. When a locked Connected feature is reached or a checkout button is clicked, the app records one anonymous count for that feature in that app. No identifier, no IP address, no cookie and no device fingerprint is stored or sent with it, and nothing is kept on your device for this purpose. The counts tell us which features people reach for; they cannot be tied to a person. Because there is no identity in them, there is no cohort or retention analysis and no consent banner.

Feedback you send. The help panel in each app lets you send a mood and a short note. That is sent only when you press send, contains only what you typed plus the app name, and reaches Sequence Theory. Do not include information you would not want us to hold.

3. What we never collect

We never collect or process:

  • The contents of your vault: documents, notes, invoices, files, or any content you create in any Donezo app
  • Your API keys (stored encrypted locally in your vault, never transmitted to us)
  • Files you sync to your cloud provider
  • Data you send to an AI provider through Donezo's AI features
  • Keystrokes, input patterns, or typing behaviour
  • Device fingerprint or browser fingerprint
  • Behavioural tracking data
  • Cross-site tracking identifiers
  • Card numbers or bank details for purchases: payment goes through Stripe, which holds them, not us. The one exception is the IBAN you give us yourself to receive a referral payout (Section 2)

This is not only policy. It reflects the architecture. Donezo apps run in your browser and store data in your browser. There is no Donezo server that receives your content.

4. How your data flows

Donezo's architecture has three layers. The order matters. Sequence Theory is never in the chain.

1. Local browser

The vault is a synchronisation layer: it holds the references and state that let the apps find and connect the files you add or create in Donezo, not the documents and files themselves. Your files live in your browser's storage and, once you connect a folder, in that folder on your device. The vault is stored in your browser's localStorage and IndexedDB. These are browser-native storage mechanisms that operate entirely on your device. Donezo does not have access to these stores from outside your device. Local is the source of truth. Every app reads from and writes to your local vault first.

2. Google Drive

If you choose to connect Google Drive, your local vault is mirrored to a dedicated Donezo folder in your own Google Drive. Donezo never touches any other Drive folder. If your local data is lost, you restore from your Drive. If your Drive is unavailable, your local copy keeps working. The sync runs directly from your browser to your Drive. Sequence Theory does not act as an intermediary, and the file contents are encrypted in the browser before they leave (see Section 14).

3. Control Lab

Users access and manage their Donezo Drive folder across devices from Control Lab. Control Lab is the only place cross-device file management happens. It runs in your browser and reads from your own Drive folder using the OAuth scope you granted to Donezo. Sequence Theory does not have a copy of any file you manage in Control Lab.

Donezo never holds your vault content. We are not in the chain between your device, your Drive, and Control Lab. We cannot read your vault. We cannot recover it if you lose it. This is intentional.

Local device folder access

A Donezo app may request access to a folder on your device using the browser's File System API. This is a browser-native permission. You grant it through a standard browser prompt, not through any Donezo server. The connection is entirely local. Your file contents are never transmitted to Sequence Theory. You can revoke this permission in your browser settings at any time.

5. Cookies and local storage

Donezo does not set tracking cookies. What we do use is browser-native storage: localStorage, IndexedDB, and sessionStorage, described in Sections 4, 7 and 8. Under EU law, storing anything on your device falls under the same rules that govern cookies, regardless of which of these technologies is used. This section explains what that storage holds and why no consent banner sits in front of it.

Everything Donezo stores on your device falls into one of two categories:

  • Your own content and its state: your vault (Section 4), your session record after purchase (Section 6), your Google Drive connection token (Section 7), and the PWA cache that lets the apps run offline (Section 8).
  • A preference you set: theme and accent colour.

Under the EU's ePrivacy Directive, storage on a user's device does not require consent when it is strictly necessary to provide a service the user has explicitly requested. That is what every item above is: something Donezo cannot function without, or something you told it to remember. None of it is analytics, advertising, or tracking (see Signals in Section 2, and What we never collect in Section 3), so the narrow exemption applies and no banner is shown. Whether any of it later leaves your device is a separate question, answered in Section 4. It does not change the answer here: this section is only about whether something gets written to your device in the first place, which is what EU law regulates, regardless of where it goes afterward.

One item sits slightly apart: a short local log used to detect unauthorised copies of Donezo's code running on domains we do not control. It never leaves your device, holds no content of yours, and exists to protect the software, not to observe you.

app.donezo.space and donezo.space are the same product. The marketing site and the apps run on separate subdomains for technical reasons, so your browser may list them as separate storage origins. Both are operated by Sequence Theory under this one policy.

You can inspect or clear any of this yourself at any time through your browser's own settings (in Chrome, the site information icon in the address bar, then "Cookies and site data"). Clearing it removes your local vault along with everything else, so export first if you want to keep your work (Section 4).

6. Purchases, devices and sessions

Donezo has no accounts and no passwords. A purchase unlocks your plan on the device where you bought it: after payment, a verified record of your email and your plan is written to that browser, and the apps read it from there.

On a new device, or after clearing your browser, you re-validate by entering the email you bought with. That check goes to Sequence Theory's membership service, which confirms the plan and writes the record to the new device. As a backup route we can send a one-time link to your email; it expires after a single use. A plan can be active on three of your own devices, for example your phone, your laptop and your tablet, as stated in the Terms.

Your session lives in your browser's localStorage and persists until you clear your browser storage. Sequence Theory does not maintain server-side sessions and does not use tracking cookies.

7. Google Drive connection

If you choose to connect Google Drive, Donezo requests OAuth access using the drive.file scope only. This scope grants access exclusively to files and folders that Donezo itself created in your Drive, specifically the Donezo backup folder. It cannot read, write, or access any other file or folder on your Drive.

This scope is permanent. Donezo will not upgrade to broader Drive scopes. If a future feature would require broader access, the architecture is redesigned: the scope does not expand.

The OAuth token is stored in your browser's sessionStorage and is never transmitted to Sequence Theory. You can revoke Drive access at any time from your Google account settings at myaccount.google.com/permissions.

8. Progressive Web App (PWA)

Donezo apps can be installed as Progressive Web Apps. When installed, the browser caches the application shell and assets locally on your device. This cache enables offline use after first load.

The PWA cache contains app code and interface assets only. It does not include your vault content (which is stored in localStorage/IndexedDB separately). Installing or uninstalling the PWA has no effect on your vault data.

No additional data is transmitted to Sequence Theory as a result of PWA installation or offline use.

9. AI features

Donezo's AI features are bring-your-own-AI. You provide your own API key to your chosen AI provider (such as Anthropic or OpenAI). That key is stored encrypted in your local vault using AES-256. Sequence Theory never receives it.

When you run an AI task, your content travels directly from your browser to your chosen provider. Sequence Theory does not receive, proxy, or log the content of that exchange.

In accordance with EU AI Act Article 50, all AI-generated content in Donezo is clearly labelled as AI-generated. AI outputs are suggestions. Nothing is applied to your data without your explicit approval.

Sequence Theory does not make automated decisions about individuals using AI.

10. Third-party processors

We share data with the following processors. Each is bound by a Data Processing Agreement and may only process data on our instruction.

ProcessorPurposeCountry / RegionTransfer basis
Stripe, Inc.Payment processing, membership recordsUnited StatesEU Standard Contractual Clauses (Stripe DPA)
Cloudflare, Inc.Membership records, the membership service, web hostingUnited States, with data centres in the European UnionEU Standard Contractual Clauses (Cloudflare DPA)
Resend, Inc.Transactional email (membership confirmation)United StatesEU Standard Contractual Clauses + EU-U.S. Data Privacy Framework. DPA auto-executed on acceptance of Resend's Terms of Service.

Infrastructure providers:

Donezo's website and apps are served via Cloudflare. Cloudflare processes IP addresses and standard HTTP request metadata as part of web hosting. It does not access vault content or any content you create. Beyond the membership records named above, no personal data other than technical request metadata is processed by it.

Not Donezo processors

  • Your cloud provider (Google Drive, Dropbox, iCloud): data goes directly from your browser to your cloud. Donezo is not an intermediary. Your provider's privacy policy applies.
  • Your AI provider: you provide your own API key. Data goes directly from your browser to your provider. Donezo does not receive it.

11. International data transfers

Sequence Theory does not transfer your vault content internationally. We do not hold it.

For membership data held by our processors, any transfer outside the EEA is made under EU Standard Contractual Clauses approved by the European Commission.

12. Your rights under GDPR

RightWhat it means
Access (Art. 15)Request a copy of the data we hold about you
Rectification (Art. 16)Ask us to correct inaccurate data
Erasure (Art. 17)Ask us to delete your membership data. Transaction records required by fiscal law (7 years) cannot be deleted early. Vault content cannot be deleted because we do not hold it.
Portability (Art. 20)Receive your membership data in a machine-readable format
Restriction (Art. 18)Ask us to pause processing while a dispute is resolved
Withdraw consentIf we ever process data on the basis of consent (e.g. analytics), you may withdraw at any time without affecting prior lawful processing

To exercise any right: Email omar@donezo.space with the subject "Data Request." Include your name and the email address on your membership. We will respond within 30 days (GDPR Art. 12(3)).

13. Right to complain

Autoriteit Persoonsgegevens
PO Box 93374, 2509 AJ Den Haag, Netherlands
autoriteitpersoonsgegevens.nl · +31 (0)70 888 85 00

EU residents may also complain to their local supervisory authority.

14. Security

Membership data held by our processors is protected using industry-standard controls including encryption at rest and in transit.

How your vault is protected

  • Per-app namespaces. Each Donezo app owns its own vault namespace. An app can only read and write to its own namespace, not to the namespaces of other apps, unless you explicitly grant cross-app access on the Connected plan.
  • API keys are encrypted before storage. Any API keys you provide to bring-your-own-AI features are encrypted in your local vault using AES-256 before being written. Sequence Theory never receives them.
  • Connected plan vault encryption. On the Connected plan, your vault is encrypted at rest using AES-256 with a passphrase that you set. The passphrase never leaves your browser. Sequence Theory cannot decrypt your vault, even if compelled to.
  • Sealed files. When you seal a file on the Connected plan, a copy is encrypted in your browser with AES-GCM using a key derived from a generated passphrase or from the recipient's vault key. The key, the passphrase and the file do not reach Sequence Theory. There is no recovery route, and the original file is left unchanged. A record of what you sealed and for whom is kept on your device only.
  • Encrypted before leaving your device. When your vault syncs to Google Drive, it is encrypted in your browser before it leaves. The Drive copy is ciphertext from Donezo's point of view.

Recommended on your side

Full-disk encryption on your device, keeping your browser updated, and enabling vault PIN if using Donezo on a shared device.

15. Children

Donezo is not directed at users under 16. We do not knowingly collect data from anyone under 16. Contact omar@donezo.space if you believe this has occurred and we will delete it promptly.

16. Changes to this policy

Material changes will be notified by email (for members) with the effective date updated at donezo.space/privacy. The previous version will be archived for 12 months.

17. Contact

Sequence Theory
Commelinstraat 198, 1093 VD Amsterdam, Netherlands
omar@donezo.space

Last updated: 9 September 2026