Legal
Privacy policy
This policy explains what DraftDo collects, how it is used, and the choices you have. It covers the DraftDo website and app at draftdo.io (“DraftDo”) and DraftDo Companion, our Chrome extension. DraftDo is operated by the DraftDo team; you can reach us at privacy@draftdo.io.
What DraftDo is
DraftDo turns an assignment you were given into a draft you can edit, approve, and finish in Google Docs. You upload or paste the assignment, DraftDo analyses it and builds an outline and a draft, and you review, edit, and approve the result. The extension moves assignment instructions from webpages into your account and writes your approved drafts into the editor you choose. Nothing is submitted anywhere on your behalf.
Information we process on the website
- Account information. Your email address, the name you enter, and a password. Sign-in and email verification use one-time codes sent to your address.
- Assignments you add. Pasted text and uploaded files (images and PDFs). Files are checked for type and stored in a private storage bucket under your account.
- Your work. Outlines, drafts, edits, approvals, and the preferences you set for new assignments.
- Subscription status. Your plan, its renewal date, the credits it includes, and the identifiers Stripe assigns to your subscription. We never see or store your full card number.
- Google Docs connection. If you connect Google, the email of the Google account you chose and the tokens Google issues for creating documents.
- Operational records. Server logs and error reports needed to run the service. They record identifiers and sizes, not the text of your assignments or drafts.
How we use it
To sign you in, keep your assignments and drafts attached to your account, build outlines and drafts when you ask for them, export a draft to Google Docs when you ask, run your subscription, answer your questions, and keep the service secure and working. We do not use your information for advertising and we do not sell it.
AI processing
Building an analysis, an outline, or a draft sends the relevant assignment content — the text you pasted, the images and PDFs you uploaded, and your instructions and edits — to OpenAI’s API for processing. This happens only when you ask DraftDo to analyse or draft. OpenAI processes that content under its API data usage policies. Instructions imported through the extension are not sent to OpenAI until you ask DraftDo to work on them.
Payments
Subscriptions are sold by DraftDo and processed by Stripe. Your card details are entered on Stripe’s checkout and handled under Stripe’s privacy policy; DraftDo receives the subscription status, plan, renewal dates, and Stripe’s identifiers so it can unlock your plan. DraftDo, not Google, is the seller of the subscription that the extension requires.
Google Docs export
Exporting to Google Docs asks Google for exactly three permissions: to know which Google account you connected (openid and your email address) and to create and edit only the documents DraftDo itself creates (the drive.file scope). DraftDo cannot see your other Drive files. The tokens Google issues are stored encrypted (AES-256-GCM) and are used only to create the destination document; the draft text is written into it by the extension on your computer, not sent to Google by our servers. You can disconnect Google at any time from Settings, which deletes the stored tokens. DraftDo’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
DraftDo Companion (Chrome extension)
This policy also covers DraftDo Companion, our Chrome extension, which moves assignment instructions from webpages into your DraftDo account and writes your approved drafts into webpage editors and Google Docs. Everything the extension does starts with an action you take in the extension; it never submits assignments or clicks buttons on a webpage for you. The extension works only with an active DraftDo subscription.
What the extension reads on webpages
- Selected text. When you choose “Capture selected text” in the popup, or “Send selection to DraftDo” in the right-click menu, the extension reads the text you highlighted on the current tab, and only that text. It does not read the rest of the page, password or other non-text fields, hidden fields, cookies, or your browsing history. The selection is held in the extension’s session storage for up to 10 minutes so you can review it, then discarded if you do not send it.
- Page title and site. When you capture a selection, the extension also records the tab’s title (proposed as the assignment title, which you can edit before sending) and the page address reduced to its site and path, which stays on your device so the popup can show where the selection came from. The address is never sent to DraftDo.
- Editor structure. When you choose “Start writing draft”, the extension checks the editor you last clicked in on the current tab: its type, whether it is editable and visible, whether it is empty, and where your cursor or selection is. It sends none of the editor’s text anywhere; on Google Docs it reads visible text as described below.
Once you use the writing workflow on a page, a small helper script from the extension stays on that page until you close or reload it. It only remembers which editor you clicked in and where your cursor is, so the destination survives the popup taking focus, and it sends no page text to DraftDo or anywhere else.
Google Docs
DraftDo Companion includes a helper script that Chrome loads automatically on Google Docs documents (addresses beginning with docs.google.com/document). Chrome may describe this as permission to read and change your data on docs.google.com. The script loads on every Google Docs document you open, whether or not you are using DraftDo, and does nothing until you choose “Start writing draft”. It then uses Google Docs’ own editing controls to confirm you can edit the document and reads the visible document text inside the page (roughly 20,000 characters) to note whether the document is empty. When you confirm, it writes your approved draft at your cursor, a character or two at a time, by handing the text to Google Docs the same way a paste does, and reads the visible text again just before, during, and after writing to confirm the text really landed. That text is compared locally, then discarded, and is never sent to DraftDo. You can pause, resume, or stop at any time; nothing is placed on your clipboard and no keystrokes are simulated. It may show a small notice in the corner of the document while you choose where writing should begin. Google Docs saves whatever is written under your Google account, exactly as if you had typed or pasted it. The extension does not use Google sign-in and requests no Google account permission. Google Sheets and Slides are not supported.
Signing in from the extension
You connect the extension through the browser’s built-in sign-in window, which opens the DraftDo website; the extension never sees your DraftDo password. When sign-in completes, DraftDo issues the extension two random tokens: a short-lived access token (valid for 15 minutes and renewed automatically) and a refresh token (valid for up to 30 days, replaced each time it is used). On your device the access token is kept in the browser’s session storage and the refresh token in the extension’s local storage; both are readable only by the extension, never by webpages. On our servers we store only a cryptographic hash (SHA-256) of each token, never the token itself, with the extension’s identifier and version and when the session was created, last used, and revoked. Tokens are sent only to draftdo.io over HTTPS and never placed in web addresses or logs. Sign-in, token-refresh, sign-out, and account-summary requests from the extension are rate-limited by IP address; the address is stored only as a request counter in a private table and is not linked to your account or content. Choosing “Disconnect” or “Clear all local extension data” revokes the session on our servers and deletes the tokens from your device. The server records of sessions and sign-ins (token hashes, the extension’s identifier and version, timestamps, and the import-request ids that prevent duplicates) are kept until your account is deleted; they contain no tokens and no content.
Account details and subscription status
After you connect, the extension fetches your display name and email address from DraftDo and keeps them in the browser’s session storage while you are connected, so the popup can show which account is connected and so a selection captured under one account is never sent to another. The extension also asks DraftDo whether your subscription is active — when the popup opens and roughly every five minutes in the background — and receives only whether it is active, the plan name, whether it is set to cancel, and when the current period ends. No payment details, prices, or billing identifiers are sent to or stored in the extension.
Importing assignment instructions
When you click “Send to DraftDo”, the extension sends the selected text you reviewed and the title you approved to DraftDo over HTTPS; the page address is not sent. DraftDo creates a new assignment in your account containing that text, with the title you approved. DraftDo keeps a small record that the import happened (your account id, a random request id, and the new assignment’s id) so a retried request cannot create a duplicate. Our server log records only the assignment id and the number of characters, never the text.
Using your approved drafts
The extension lists the assignments in your account (titles, status, and word counts) and, for an assignment whose draft you approved in DraftDo, retrieves the approved draft so you can preview it and write it into a webpage editor or Google Doc. Draft text is fetched only while you are connected and your subscription is active; it is held in memory while the popup is open, fetched again at the moment you confirm writing, and never saved on your device. During writing, the text is passed to the helper script in the page you chose, and the destination website or Google receives it exactly as if you had pasted it there. DraftDo receives nothing back from the destination page except, if you have turned diagnostics on, a success or failure event that contains no content.
Optional diagnostics from the extension
Diagnostics are off by default and stay off unless you turn them on in the extension’s “Privacy & data” page; acknowledging the extension’s privacy notice does not turn them on. When on, the extension sends DraftDo a short event when you sign in, start or complete an import, open a draft preview, or start, complete, or fail writing a draft. Each event contains only the event name, the extension version, a result, an error code, the kind of editor involved, and which part of the extension sent it. DraftDo stores each event with your account id, the extension session id, the extension id, and the time received. Events never contain assignment text, draft text, titles, page addresses, or your email address. We use them only to find and fix problems. There is currently no automatic deletion period for these events; they are removed when your account is deleted, and you can turn diagnostics off at any time.
What the extension stores on your device, and for how long
- Access token: session storage; until it expires (15 minutes) or is renewed; gone when the browser closes, on Disconnect, or on Clear all local data.
- Refresh token: extension local storage; until the session expires (30 days) or is revoked; removed on Disconnect or Clear all local data.
- Account name and email: session storage; while connected; gone when the browser closes, on Disconnect, or on Clear all local data.
- A selection you captured but have not yet sent, with the page title and the site it came from: session storage; up to 10 minutes; removed when sent, cleared, on Clear temporary data, or on Disconnect.
- A confirmed writing destination: session storage; up to 90 seconds; removed when writing starts, on Clear temporary data, or on Disconnect.
- One-time request ids that stop a draft being written or imported twice: session storage; up to 15 minutes; removed on Clear temporary data or Clear all local data.
- A pointer to the latest draft-writing run (request and assignment ids, your account email, the site and Google document id, the tab, counts, and final status, never the draft text): session storage; kept until the next run replaces it, on Clear all local data, or when the browser closes.
- Your privacy acknowledgement and diagnostics choice: extension local storage; until you Clear all local data.
- While you are signing in, a temporary sign-in verifier: session storage; discarded when sign-in finishes or fails, or after 10 minutes.
The extension’s “Privacy & data” page, available even when disconnected, offers three controls: Disconnect, Clear temporary data, and Clear all local extension data. None of these deletes assignments or drafts stored in your DraftDo account; you manage those from your Assignments page. Uninstalling the extension removes its local storage but does not revoke the server session until the refresh token expires, so disconnect first if you can.
How extension data is shared and protected
DraftDo Companion communicates only with draftdo.io, over HTTPS, and loads no code, fonts, or resources from anywhere else. It contains no advertising or analytics libraries. Information obtained through the extension is used only to provide and improve the extension’s features described here, and DraftDo’s use of it complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. We do not sell it, use it for advertising, or transfer it to third parties, except: to OpenAI when you later ask DraftDo to build an outline or draft from imported instructions; to the destination website or Google Docs when you choose to write a draft there; to the service providers that host DraftDo; or where required by law. People at DraftDo do not read your instructions or drafts except as needed to operate the service, investigate a problem you report, or comply with the law.
Service providers
DraftDo runs on Supabase (database, authentication, and file storage) and Vercel (hosting). OpenAI processes assignment content for analysis and drafting, Stripe processes payments, and Google provides the Docs export. Each provider processes data on our behalf under its own terms and security practices. We do not use analytics or advertising services on the website or in the extension.
Cookies
The website uses only the cookies needed to keep you signed in. There are no advertising or tracking cookies. The extension uses no cookies at all and sends none with its requests.
Retention and deletion
Assignments, uploaded files, and drafts stay in your account until you delete them from the Assignments page; deleting an assignment deletes its files and drafts. Extension sessions end when you disconnect or after 30 days without use; their server records are described under “Signing in from the extension” above. Subscription records are kept as long as needed for billing and legal obligations. Deleting your whole account from inside the app is not yet available; to request deletion of your account, of diagnostic events, or of any other data described here, email privacy@draftdo.io and we will confirm by email.
Security
Data travels over HTTPS. Extension tokens are stored on our servers only as hashes, Google tokens are encrypted at rest, uploaded files live in a private bucket, and every request for your assignments or drafts is checked on our servers against your session and subscription. No security certification is claimed.
Your choices and rights
You can review, edit, and delete assignments and drafts at any time, disconnect Google Docs from Settings, and disconnect the extension, clear its local data, or turn diagnostics off from its “Privacy & data” page. Depending on where you live, you may also have the right to access, correct, export, or delete your personal information, or to object to how it is used; write to privacy@draftdo.io to exercise those rights.
Children
DraftDo is not directed to children under 13, and we do not knowingly collect information from them. If you believe a child has created an account, contact us and we will delete it.
Changes to this policy
When we change this policy we update the date at the top of this page, and for material changes we tell you in the app or by email. The extension asks you to review its privacy notice again when that notice changes.
Contact
Questions about privacy, and requests about your data: privacy@draftdo.io.