Privacy Policy

Last updated: 28 September 2026

This Privacy Policy explains how Doneness collects, uses, stores, and shares personal data when you use our mobile app, websites, API, and related services.

About our names: the mobile app is currently available under the name Lodo.ai and is being renamed Doneness.ai. References in this policy to the “mobile app” mean the same iOS and Android app under either name. The Doneness API is our developer and organisation-facing API service.

1. Scope and who is responsible for your data

This policy applies to the Lodo.ai / Doneness.ai mobile app on iOS and Android, doneness.ai and related Doneness websites, the Doneness API, and associated support, notification, and developer services.

Doneness is responsible for personal data processed for its own purposes. If you use the services through an employer, facilities manager, school, club, customer, or other organisation, that organisation may decide why and how some work-related data is used. In that situation, Doneness may process the data on the organisation's instructions, and you should also read the organisation's privacy information.

2. Information we collect

Information you provide

  • Account and profile information: name, display name, email address, mobile number, profile and banner images, description, role, organisation or team, country, address, date of birth where requested, skills, languages, external work links, and notification preferences.
  • Work and app content: Lodos, job descriptions, locations, task instructions, applications, assignments, messages or notes, ratings and reviews, completion status, and related timestamps.
  • Evidence: photos, videos, location evidence, GPS route or track logs, capture time, notes, and associated task metadata that you choose or are required to submit for a Lodo.
  • Payment and payout information: transaction amounts, currency, status, and payment account references. Stripe processes card and payout-account details; we do not store complete payment-card numbers.
  • Developer and API information: organisation and developer details, API credentials, API requests and responses, integration metadata, webhook settings, and usage or quota information.
  • Website and communications information: details submitted through meeting, support, privacy, and account deletion forms, including your name, work email, company, role, message, selected product, and campaign referral parameters.

Information collected from your device or use of the services

  • Location: precise or approximate location when you grant permission and use nearby Lodos, maps, site check-in, location evidence, or GPS route tracking. A route may contain multiple location points and times.
  • Media and voice: camera or photo-library selections used for profile, Lodo, and evidence uploads, and microphone or speech-recognition input used to turn your voice into text. Speech recognition may be performed by your device's platform provider; the resulting text is handled like text you type into the app.
  • Device, usage, and diagnostics: IP address, device and app identifiers, operating system, browser or app version, language, session and feature usage, referring page or campaign, crash reports, performance data, error logs, and security or abuse-prevention signals.
  • Notifications: push-notification tokens and delivery or interaction information used to send app and work updates according to your settings.

Information from other sources

  • Basic account information from an identity provider you choose, such as Google, including your name, email address, profile image, and authentication identifier.
  • Assignment, team, site, and access information supplied by an organisation that invites or manages you.
  • Payment, payout, identity-verification, dispute, and transaction status from Stripe and other payment participants.
  • Information another app user submits about a shared Lodo, application, assignment, review, or evidence workflow.

3. Mobile permissions and your choices

The mobile app asks for a device permission when a feature needs it. Depending on your device and the features you use, this may include location, camera, photo library, microphone, speech recognition, and notifications.

  • Location supports nearby work, maps, site check-in, location evidence, and route or track-log evidence.
  • Camera and photo-library access lets you add profile, Lodo, and evidence images or videos.
  • Microphone and speech-recognition access supports optional voice input in forms.
  • Notification access lets us send assignment, evidence, review, account, and service updates.

You can refuse or withdraw a device permission in iOS or Android settings. The related feature may then be unavailable, but unrelated features should continue to work. You can also control available notification choices in the app and your device settings.

4. How we use information

  • Create and manage accounts, profiles, teams, permissions, and authentication.
  • Provide marketplace and organisation-managed work features, including discovery, assignments, task completion, evidence, review, notifications, ratings, payments, and payouts.
  • Generate task suggestions and assess evidence using Doneness and AI-assisted features.
  • Provide the Doneness API, developer access, documentation, webhooks, usage controls, support, and service communications.
  • Process meeting and support requests and manage customer or prospective-customer relationships.
  • Analyse use, diagnose crashes, maintain performance, improve the services, protect users, prevent fraud and abuse, and enforce rate limits and terms.
  • Comply with law, resolve disputes, and establish, exercise, or defend legal claims.

5. AI-assisted features and decision-making

Doneness uses AI-assisted systems to help structure task descriptions and checklists and to assess submitted evidence. Text, task context, images, and other evidence required for these features may be sent to Doneness systems and contracted AI service providers for processing.

An AI assessment may recommend an outcome such as done, not done, needs more evidence, or unclear. It does not make the final business decision: the Lister, customer, or authorised reviewer remains responsible for accepting or rejecting work. Contact us if you want to question an AI-supported outcome that materially affects you.

Do not submit personal data or media that you are not authorised to use. Organisations should configure evidence requirements so they collect only information necessary for the work.

6. Legal bases for processing (UK and EEA)

Depending on the context, we process personal data because it is necessary to perform a contract or take requested pre-contract steps; because we or another party have legitimate interests in operating, securing, improving, and supporting the services; to comply with legal obligations; or with consent where consent is required. Where an organisation controls the processing, its legal basis may differ and should be described in its own notice.

7. How information is shared

We share personal data only as needed for the purposes described in this policy, including with:

  • Other users and organisations: Listers, Doers, applicants, reviewers, team members, customers, and authorised administrators who need the information for a Lodo, assignment, review, or organisation-managed workflow.
  • Service providers: providers of cloud hosting, databases, file storage, authentication, maps, analytics, crash reporting, push notifications, email, AI processing, payments, payout onboarding, security, logging, and webhook delivery. These currently include Google and Firebase, Google Maps, OpenAI, Stripe, Resend and SendGrid, and infrastructure providers used by the Doneness API.
  • App platforms and identity providers: Apple, Google, and an identity provider you choose, where needed to distribute the app, provide platform features, or authenticate you.
  • Professional advisers and authorities: advisers, insurers, auditors, regulators, courts, law enforcement, or other parties where disclosure is required by law or necessary to protect rights, safety, and service integrity.
  • Business transaction recipients: a prospective buyer, investor, successor, or adviser in connection with a financing, reorganisation, merger, or sale, subject to appropriate confidentiality protections.

We require service providers that process data for us to protect it and use it only for the contracted service. We do not sell personal data, and we do not use personal data from the app or Google Sign-In for third-party targeted advertising.

8. Google user data and Google API Services

If you choose Google Sign-In, we access the basic Google account information you authorise, such as your name, email address, profile image, and authentication identifier. We use it to authenticate you, create or link your account, display your profile, secure the service, and provide features you request.

  • We do not sell Google user data.
  • We do not use Google user data for advertising.
  • We do not use Google user data to build profiles unrelated to the mobile app, Doneness API, security, or requested functionality.
  • We transfer Google user data only to service providers processing it for us, when you direct or expect the transfer, for security, or where required by law.
  • Human access is limited to authorised personnel who need it for support, security, legal compliance, or service operations.

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. You can disconnect Google access through your Google Account permissions. Disconnecting Google does not by itself delete your Doneness account; use the deletion process below if you also want the account and associated data removed.

9. Data retention

We retain personal data only for as long as needed for the purposes described in this policy. The period depends on the type of data, account or contract status, organisation instructions, legal and accounting requirements, dispute periods, and security needs.

  • Account, task, evidence, and API data is generally kept while the relevant account, Lodo, workspace, or customer relationship is active and for a reasonable period afterwards.
  • Meeting and support requests are kept as needed to respond and manage the resulting relationship.
  • Security and abuse-prevention logs are typically kept for up to 90 days, unless an incident or legal requirement requires longer.
  • Payment, tax, fraud-prevention, and compliance records may be kept for up to seven years or another period required by law.
  • After permanent deletion, residual copies may remain in encrypted backups until normal rotation, typically 30 to 90 days.

When data is no longer required, we delete it or irreversibly anonymise it.

10. Security

We use technical and organisational measures designed to protect personal data, including access controls, authentication, encrypted transmission, monitoring, logging, and managed secrets and keys. No service can guarantee absolute security, so please use a strong, unique password and report suspected account misuse promptly.

11. International data transfers

Doneness and its service providers may process data in countries other than the country where you live. Where required, we use recognised safeguards such as adequacy decisions, approved standard contractual clauses, and supplementary protections.

12. Your rights and privacy choices

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of your personal data; receive a portable copy; withdraw consent; or appeal a decision about a privacy request. Withdrawing consent does not affect earlier lawful processing.

You can update available profile and notification settings in the app, manage device permissions in iOS or Android settings, disconnect Google through your Google Account, and request account deletion below. To exercise another right, email [email protected]. We may need to verify your identity. You may also complain to your local data protection authority.

13. Children and supervised use

The services are not directed to children as independent consumers. A minor may use an organisation-managed or family-managed service only under the supervision and control of an authorised school, club, employer, parent, guardian, or other responsible adult and with any consent required by applicable law.

Organisations and responsible adults must provide appropriate notices, configure data collection proportionately, and obtain required permissions. If you believe a child's data was collected contrary to this policy or applicable law, contact us so we can investigate and delete or remediate it.

14. Website cookies and similar technologies

Our websites may use essential cookies or similar local technologies for security, sessions, preferences, and service operation. We also receive standard server logs and campaign parameters included in a meeting request. We do not use the website to serve third-party targeted advertising. If we introduce non-essential cookies where consent is required, we will provide an appropriate choice before using them.

15. Account and data deletion

Mobile app users (under either the Lodo.ai or Doneness.ai name) and Doneness API users can request deletion of their account and associated personal data without signing in:

Delete your account at doneness.ai/delete-account

Submit your account email and choose the mobile app, Doneness API, or both. If a matching account exists, we will email instructions to verify and confirm the request. After confirmation, the account is scheduled for permanent deletion rather than temporary deactivation. You may request restoration within 30 days; after that, deletion is permanent except for limited data we must retain for legal, payment, security, or fraud-prevention purposes.

Data deleted or anonymised includes, where applicable, account and profile information, tasks and Lodos, evidence, preferences, API keys, developer account details, and Google sign-in tokens. Limited legal records, payment records, security logs, anonymised data, and rotating backups may be retained as described in section 9.

16. Contact us

Doneness is the operator of the services covered by this policy. For privacy enquiries and rights requests, email [email protected].

If an organisation provides or manages your account, you may also contact its administrator or privacy contact.

17. Changes to this policy

We may update this policy when our services or legal obligations change. We will publish the latest version on this page and update the “Last updated” date. If a change materially affects how we use personal data, we will provide additional notice where required.