Last updated: July 21, 2026
This Privacy Policy describes how doalt ("we", "us", "our") collects, uses, and protects your personal information when you use our service at doalt.io.
Account information: Email address and a cryptographically hashed password (bcrypt). We never store your password in plain text.
Task data: Task labels, due dates, completion status, and timestamps. This data is required for the core functionality of the Service.
Payment information: When you link a payment method, we store your Stripe customer identifier and the last four digits of your card number. Full card numbers, CVV codes, and expiration dates are never stored on our servers. All payment data is processed and stored by Stripe, Inc. in compliance with PCI DSS Level 1 requirements.
Timezone: Automatically detected from your browser to determine your local midnight for charge calculations.
Consent records: When you link a payment method, we log the timestamp, your user ID, and the consent text you agreed to, as required by payment card network rules.
Charge history: A ledger of charges made to your account, including dates, amounts, associated tasks, and the charity that received the donation.
We do not use analytics trackers, third-party cookies, advertising pixels, or social media integrations. We do not collect location data beyond timezone. We do not collect device fingerprints. We do not sell, rent, or trade your personal data to third parties.
We use your information solely to operate the Service: display your tasks, calculate penalties, process charges via Stripe at midnight, maintain your charge ledger, and communicate with you about your account (e.g., receipts, policy changes, support responses).
Stripe, Inc.: We share your email address and payment authorization with Stripe to process charges. Stripe's handling of your data is governed by Stripe's Privacy Policy.
We do not share your data with any other third parties unless required by law (e.g., valid court order, subpoena).
Passwords are hashed using bcrypt with a cost factor of 12. All network traffic is encrypted via TLS 1.2+. Payment processing is delegated entirely to Stripe (PCI DSS Level 1 certified). Database access is restricted to the application server only.
Your data is retained for as long as your account exists. When you delete your account or request deletion, all personal data — including tasks, ledger history, payment identifiers, and consent records — is permanently removed within 30 days. Stripe customer records are also deleted.
To request data deletion, use the account deletion option in Settings or email [email protected].
Depending on your jurisdiction, you may have the right to access, correct, delete, or port your personal data. To exercise these rights, contact us at [email protected]. We respond within 30 days.
The Service is not intended for users under 18 years of age. We do not knowingly collect data from minors.
We may update this Privacy Policy. Material changes will be communicated via email to the address on your account. The "Last updated" date at the top reflects the most recent revision.
For privacy-related inquiries: [email protected]