Privacy policy
Last updated: September 30, 2026
This policy explains how didao ("we", "us", or "our") handles information when you use the didao Android app, visit didao.app, join our launch-news list, or contact us. For privacy questions or requests, email daodao+privacy@didao.app.
- AI assistance sends the text needed for your request to a model service when you invoke assistance. We do not send your writing on every keystroke.
- Learning history and saved expressions are stored on your device. Relevant saved expressions and style preferences can also be included in a requested AI task.
- didao does not use an AccessibilityService to read other apps' screens.
- Shared images are recognized on-device. Explicit image-based reply requests can send the image and recognized text to our AI provider.
- Sanitized crash reporting is on by default in release builds; you can disable it in Settings → Privacy.
- Optional product analytics is off by default. We do not sell personal information or use your writing for targeted advertising.
- You can request account deletion without the app, clear local learning data, and turn off optional collection.
1. Writing, AI assistance, and shared content
didao helps you complete, check, and understand language. When you invoke its keyboard or choose an AI action, the app may read the current selection, sentence, or bounded text around the cursor and send the information needed for that task to the configured AI service. Switching to didao can itself initiate assistance; there is not necessarily a separate submit button for every keyboard request. Password, sensitive, and unsupported fields are excluded by the app's field checks.
A request may include your draft or selected text, relevant nearby context, learner level, style settings, a custom style instruction, and a limited set of saved expressions that occur in the text. The AI service processes this input and produces suggestions or explanations. didao does not attach your entire learning database or all your conversations. Review suggestions before using them.
Content you choose to submit may contain personal or sensitive information about you or someone else. We process that content to provide the assistance you request; we do not require you to supply sensitive information. Avoid including information you do not want processed by an AI service.
You can share or select text using Android's sharing and text-selection controls. In the app's search input, clipboard text is read only when you choose Paste or an Android paste control. didao does not monitor the clipboard. Typing or pasting in that input does not itself send an AI request.
For shared screenshots or photos, didao uses Google's bundled ML Kit text recognition on the device. Requested explanations send selected recognized text and bounded nearby text. When you explicitly submit a reply request, your intent and corrected recognized text are sent, together with the image when the model supports vision. Images and unsaved screenshot-session content are held temporarily; choosing Save stores the selected learning item locally, not the surrounding conversation.
Release AI requests pass through our authenticated Supabase gateway to Google Gemini. We do not store prompts, images or model answers in the Supabase database or application logs. Content may remain temporarily in app memory and, where enabled, local learning history.
2. Conversation context and screen access
This release does not use an Android AccessibilityService to read other apps' screens or conversations. Received messages enter through your explicit share, selection or paste actions. The keyboard can receive bounded text from the active editor as described above. Normal screen-reader accessibility remains supported.
3. Local learning data and backups
Saved expressions, review progress, corrections, and learning history are stored in the app's local database. History entries can contain source text, answers, the sentence being worked on, alternatives, your chosen result, and the package name of the app where assistance was invoked. On a later return to the same editor, didao can record a correction to the recently inserted text in that local entry.
Turn off Keep my history to stop new history entries. This does not delete existing entries or stop expressions you explicitly save from being saved. Use Clear Memory to delete local history, saved phrases, review progress, and stored learning corrections.
Settings and style preferences are stored locally. Supabase sign-in does not synchronize your learning database. Local storage does not mean content can never leave the device: relevant expressions and preferences may be included in an AI request, and you may choose to export a backup.
Export creates a file in a location you select. It includes learning records and selected preferences, but excludes authentication sessions and model credentials. You control sharing and deletion of exported files; a storage service you choose may upload or back them up. didao's Android backup rules exclude its learning database, internal learning backups, dictionary files, authentication session, and model configuration from system backup and device transfer. Other app settings may be backed up according to Android and your device settings.
4. Accounts, purchases, and support
Sign-in: Google sign-in and Supabase Auth process your sign-in identity, email address, account identifiers, and profile information supplied by Google, such as your name or profile picture. didao stores an authentication session protected with Android Keystore. It does not receive your Google password or request your Google contacts or friends list.
Purchases: Google Play handles payment collection. RevenueCat manages purchase validation, subscription status, and entitlements using purchase records and an app user identifier. didao does not collect your payment-card number or security code. This purchase flow does not send your drafts or learning history to RevenueCat.
Support: If you email us or submit feedback, we receive the contact details and content you provide and use them to respond. The app's feedback action does not automatically attach your writing or learning history. Please omit unnecessary private content.
5. Analytics, permissions, and technical data
Crash reporting: Release builds enable sanitized Sentry crash reporting by default, independently of product analytics. Reports contain error types, sanitized code locations, event identifier/time, release and SDK metadata. Exception messages, user/request/context objects, breadcrumbs, tags, extras and attachments are removed. We disable replay, screenshots, tracing and profiling. Sentry receives the connection IP address. Turn off Settings → Privacy → Crash reporting to stop new reports and delete the local report queue; an in-flight transmission cannot be recalled.
Optional product analytics: If you enable Share product usage, PostHog receives an installation identifier, basic app/device metadata, and limited events such as opening a screen, requesting a feature, or saving a result. The app does not include drafts, prompts, answers, images, account details, or learning-history contents in those events. Session replay and automatic interaction recording are disabled. IP-based location enrichment is disabled, although the provider receives the connection IP address. Turn the setting off to stop future product analytics; contact us about previously received data.
ML Kit technical metrics: Google's ML Kit documentation states that input images and recognized text are processed on-device, while the SDK sends performance and usage metrics to Google and may contact Google for maintenance information. This SDK processing is separate from didao's optional PostHog analytics setting. See ML Kit terms and privacy.
Network services: Services used for AI, authentication, purchases, downloads, and hosting receive technical request information such as IP addresses, request times, and app or browser information needed to deliver and secure their services. didao does not intentionally include your writing, model responses, credentials, or clipboard contents in diagnostic logs.
Dictionary and audio: Dictionary searches run locally after the dictionary is available. Optional language packs are downloaded from public Supabase Storage without sending searches or learning history. Read-aloud uses installed offline voices for the selected supported language. Installing voice data is handled by the selected speech engine.
Permissions: Internet access supports online features. Notification permission supports review reminders, which you can disable in Android settings. Keyboard access supports the functions described above. didao does not request screen-reading accessibility access, GPS location, contacts, microphone, or camera access for these features. Selecting an image to share does not grant access to your entire photo library.
6. Website and launch-news email
The website is served through Cloudflare Pages. Cloudflare processes technical visitor information, including IP addresses, to serve and secure the site. See Cloudflare's privacy policy. Some website pages load Google Fonts, which sends ordinary font-request information to Google. This policy page uses system fonts and does not load analytics, remote fonts, or scripts.
The website stores your selected appearance locally in your browser. We do not use Google Analytics, advertising pixels, targeted advertising, or offer walls on the current site.
If you choose to join the launch-news list when signup is available, your email address is sent through our signup service to Resend to deliver a confirmation message. Confirming adds you to the launch-news list. Sending confirmation already involves provider processing; it is not a promise that nothing is stored before confirmation. This list is separate from app accounts and learning data. You can unsubscribe using the link in launch-news emails or email our privacy address, including if you receive an unwanted confirmation message.
The signup endpoint may process network information for security and rate limiting. We use the list for launch news, not unrelated advertising. We remove list membership when you unsubscribe and delete the launch list after its launch-news purpose is complete or on request, subject to necessary legal and abuse-prevention records.
7. Service providers and sharing
We use providers only for the functions described in this policy. Depending on the features you use, recipients include:
- Google Gemini via Supabase: receives text, contextual information and, for explicitly requested image tasks, images needed for language assistance. See Gemini API terms and Google's privacy policy.
- Sentry: sanitized default-on crash diagnostics, controllable in Settings. See Sentry's privacy policy.
- Google and Supabase: authentication; Google also provides Play billing and ML Kit. See Google's privacy policy and Supabase's privacy policy.
- RevenueCat: purchase and entitlement management. See RevenueCat's privacy policy.
- PostHog: optional product analytics. See PostHog's privacy policy.
- Cloudflare and Google Fonts: website hosting and website font delivery respectively. Supabase Storage delivers public language packs.
- Resend and the signup hosting service: launch-news confirmation and list delivery when you subscribe. The signup service is designed for Cloudflare hosting. See Resend's privacy policy and Cloudflare's privacy policy.
AI requests are not used by didao for advertising. Provider processing and retention depend on the service and applicable terms; we do not make a blanket promise of zero provider retention or that no provider ever uses data to improve its services.
We may also disclose information when necessary to comply with law, protect rights and security, or carry out a business transfer with appropriate protections. We do not sell personal information or share it for cross-context behavioral advertising.
8. Retention and security
- Local learning records: kept until you delete them with Clear Memory, clear the app's storage, or uninstall. Exported copies remain wherever you placed them.
- Account records: kept while your account is active, then deleted in response to your request, except records we must retain for legal, security, or fraud-prevention purposes.
- Service usage: Supabase stores account/request identifiers, times, broad activity categories, workload amounts, completion state and commerce event identifiers/types for usage limits and subscription enforcement. Scheduled cleanup removes usage metadata after 31 days and commerce events after 90 days. Deleting your Supabase account cascades through these records. RevenueCat associates entitlements with your Supabase account identifier; store providers determine trial eligibility.
- AI processing: request/response content may be held temporarily in app memory and optionally in local history. Remote retention is governed by the inference service's terms and configuration.
- Purchase, analytics, support, and hosting records: retained for the relevant service, support, security, or legal purpose. Provider records and backups may follow separate retention periods. Contact us to request deletion of data we control; there is no universal three-month deletion guarantee.
We use app-private storage, protected authentication sessions, and secure network services to reduce unauthorized access. No system is completely secure. Service providers may process data in countries other than yours. Where required, international transfers must use protections required by applicable law. Contact us for information about the safeguards applicable to your data.
9. Delete your didao account and data
Request deletion without the app
Email daodao+privacy@didao.app with the subject Delete my didao account. Send the request from your sign-in email address if possible and identify the didao account you want deleted. You do not need to reinstall the app. Do not send passwords, sign-in tokens, payment-card details, or private conversations. We may ask for the minimum additional information needed to verify ownership.
You may also request deletion from Settings → Account → Delete account. If that action fails or is unavailable, use the email route above. Account deletion removes your didao authentication account and associated account data we control, subject to any legal or security retention we explain to you. It does not delete your Google account.
Delete learning data on your phone
Account deletion and signing out do not erase local learning data. Use Settings → Data & privacy → Clear Memory to delete local learning records. To remove remaining app settings as well, clear didao's storage in Android settings or uninstall it. Delete exported backup files separately from the locations where you saved them. We cannot remotely erase those local or exported copies.
Subscriptions and other records
Deleting an account does not automatically cancel a Google Play subscription. Cancel it in Google Play's subscription settings. Google Play and payment providers may retain transaction records for billing and legal obligations. To request deletion of support, analytics, or launch-list data we control, contact the privacy address and specify your request. We will explain any data that must be retained and the reason.
10. Your rights, legal grounds, and contact
Where applicable, we process information to provide the services you request, with your consent for optional features and communications, for legitimate interests such as service security and responding to support requests, and to meet legal obligations. We do not use language suggestions to make decisions producing legal or similarly significant effects about you.
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal data, restrict or object to processing, withdraw consent, and appeal a decision about a privacy request. Exercising these rights will not result in unlawful discrimination. Withdrawing consent does not affect earlier lawful processing. You may complain to your local data-protection authority, including the UK Information Commissioner's Office where applicable.
We do not sell or share data for targeted advertising, so there is no advertising sale/sharing activity to opt out of. The current website does not change its behavior in response to browser Do Not Track signals. Optional app analytics is controlled by the in-app setting described above.
Send privacy requests or appeals to daodao+privacy@didao.app. For other support, email daodao+support@didao.app. We will consider requests under applicable law and may verify your identity before disclosing or deleting information.
We may update this policy when our practices change. The date at the top identifies the latest revision. Material changes will be communicated as required by applicable law.