Skip to content
dotstrap

Privacy Policy

Last updated: 1 September 2026

This policy describes what Dotstrap actually does, in the same detail the system is built to. Where a limit exists we have named it, and where something is not built we have said so rather than letting a general sentence cover for it.

1. Who this applies to

Dotstrap gives you a permanent public address and an AI front desk that holds the first conversation with people who arrive there. This policy covers two kinds of person, and they are treated differently:

  • Owners — people with a Dotstrap account and a public page.
  • Visitors — people who read somebody's page, and who sign in with Google only if they want to start a conversation. Reading a public page requires no account and collects nothing about you.

Everyone with an account is both: the same account that receives requests can send them.

2. What we collect

Dotstrap has no sign-up form. You sign in with Google, and we never receive or store a password. We do not ask for, and do not store, a phone number. Your email address is a property of the Google account you signed in with — it is shown back to you, and is not collected as a separate field.

Beyond that, everything we hold is something you typed or something you were sent:

  • Your public page — name, photo, role, organisation, headline, bio, interests, links, and the opening line your front desk greets people with. All of this is published by you, on purpose.
  • Your private routing rules — the request types you want to receive and the qualification text under each. These are never shown to a visitor.
  • Your Intent Match declaration — one sentence, up to 600 characters, about what you are looking for. Never shown to anyone you match with.
  • Conversations — messages between a visitor, your front desk and you, plus the summary, category and priority the AI derives from them.
  • Requests — who you wrote to, when, and what happened, up to 600 characters per message.
  • Account state — your home region, your account status, and your rolling 24-hour allowance.
  • What you write to us — the category, the message and the screen you were on, when you send feedback or report a problem from inside the product.
  • What happened after a search — which profiles a search showed you and in what order, and whether you went on to write to somebody. Described in full in section 7.

3. How that data is classified, and what the classification decides

Every field in Dotstrap carries a data class, and the handling rules follow from the class rather than being decided again at each point in the code. Anything not explicitly classified is treated as the most restrictive class.

  • PUBLIC — what you chose to publish. May be cached and served anywhere.
  • PERSONAL — identifies a person. Does not leave its region, is never written to a global cache, and its values never appear in a log line.
  • SENSITIVE PERSONAL — conversations, inbox contents, your private routing rules and your intent. Region-bound, never logged, additionally encrypted at the application layer, and permitted into an AI prompt only where the rule for that field allows it.

The consequence worth stating plainly: your conversations and your private rules are not in our logs, and they are not in a shared cache.

4. Where it is stored, and why that does not move

Every account has a home region, fixed when the account is created. Personal and sensitive data is written in that region and stays there. Dotstrap is designed for three — India, the European Union and the United States — and encryption keys are scoped to a region, so a workload in one region cannot obtain the keys of another. That is enforced in the type system: the code cannot ask for a key without naming the region it is asking about.

One consequence is visible in the product rather than hidden: Intent Match does not match across regions. We would rather show you fewer people than move your declaration out of the region it was written in.

5. The pseudonym — what the person you write to actually receives

When you send a request, the region that stores the recipient’s mail does not receive your identity. It receives an opaque pseudonym. Your name and photo are resolved for display through a separate authorised call; they are not written into their records.

This is not a detail. It is the property that makes deletion work at all — see section 9 — and it is enforced at the boundary rather than remembered at each place that writes.

6. Artificial intelligence

Your front desk is a language model. It reads your public page, your private routing rules and the conversation in front of it, and it produces a category, a priority and a written summary. It decides what reaches you; it never decides for you.

We currently send prompts to two providers:

  • NVIDIA — integrate.api.nvidia.com
  • Sarvam AI — api.sarvam.ai

A request is routed only to a provider that satisfies the residency rule for the region the data belongs to. Where no eligible provider is available the feature degrades — the front desk falls back to a local extractor and says less — rather than sending the data somewhere it should not go. Degrading is the designed behaviour, not a failure state.

We do not sell your data, and we do not use your conversations, your routing rules or your intent to train models. Prompt content is not retained by Dotstrap beyond the conversation record described in section 8.

7. Cookies, storage, and the tracking we do not do

Dotstrap contains no analytics, no advertising, no tracking pixels and no third-party measurement of any kind. There is no tag manager, no product analytics SDK and no advertising identifier anywhere in the product. Nothing you do here is sent to another company to be measured, and we have nothing to sell to anyone who would want it.

We do measure one thing ourselves, and this is it. When a search shows you a set of profiles, we may record which profiles were shown, in what order, and the match score each one had at the time; and if you then write to one of them, we record that a request was created and which of you it was between. The owner’s reply or refusal is recorded as a result, never as a mark against the person who sent it. That is the whole list. We do it to find out whether the matching works at all — whether the people we rank highest are the people you actually write to — and for no other purpose.

These records are PERSONAL, stay in your region, are never shown to the other person, and are never used to rank, rate or score anybody. They are not on by default. If they are switched on, this section says so before the first one is written, and section 9 says exactly what happens to them when you delete your account.

One cookie keeps you signed in after Google hands you back. It is required for the product to function, and there is no version of Dotstrap without it.

Five values are stored in your own browser and are never sent to us: your theme, whether the sidebar is expanded, and three sets of marks recording which conversations you have already opened. The marks are keyed to your account, so one person’s read mail is never shown as read to the next person using the same browser. Clearing your browser storage clears all of it and costs you nothing but those preferences.

8. How long we keep things

Four clocks, and they measure different people’s silence:

  • 24 hours — an unfinished conversation stays resumable. A visitor who stops midway can come back and continue; after 24 hours the session ends and nothing is sent to anyone.
  • 15 days — a delivered request waits for the owner to react. If nothing happens it expires, the sender's slot frees up, and the record stays in both people's history.
  • 30 days — the grace period after you ask for deletion, during which you can change your mind.
  • Indefinitely — a conversation that became a real exchange between two people, and your Dotstrap address itself.

A conversation is a joint record. Once two people have spoken, it belongs to both of them, and one party cannot erase the other’s copy.

9. Deleting your account — precisely what happens

You can deactivate at any time, which takes your page down immediately, or request deletion, which starts a 30-day grace period you can cancel from inside the product. To everyone else the two states look identical — nobody is told which one you chose.

When the grace period elapses:

  • Deleted outright — your profile, your front desk configuration, your Intent Match declaration, your quota records, and the mapping between you and the pseudonyms other people hold.
  • Tombstoned — your public page becomes empty and your Dotstrap address is retired permanently. It is never reissued, so nobody can inherit an address people already associate with you.
  • Kept, anonymised — conversations you had with other people. We do not reach into somebody else's mail and delete it. Instead we destroy the pseudonym mapping, which makes you un-derivable from their records: their inbox falls back to showing an unresolved contact.
  • Kept — safety records about approaches to a destination. A record that exists to protect someone else has to outlive the account it constrains.
  • Deleted outright — everything you wrote to us. Feedback, problem reports and anything you sent from the Help screen go with the account, including a privacy complaint and an appeal written while suspended. There is no support-correspondence exception.
  • Deleted outright — the measurement records in section 7 that are yours: the searches you ran and what you did about them.
  • Changed, not deleted — the same records where somebody ELSE ran the search and you were one of the profiles shown. The row is theirs, so it stays, and your identifier is removed from it. We do not claim what remains is anonymous; we are telling you precisely what we did, which is delete the identifier.

The identity record is removed last, so a purge interrupted halfway leaves an inert account a later sweep can find and finish, rather than orphaned data nothing can locate.

10. Getting your data out

You can export from inside the product at any time. The file is generated and served to you directly — it is never written to storage, so there is no export sitting in a bucket waiting to be found. It contains your account state, your profile, your front desk configuration, your intent, your quota, and the metadata of up to 500 requests in each direction: who, when, the status, the category, the priority and the decision.

It deliberately excludes message bodies and transcripts. An export runs on one party’s authority, and a conversation has two parties in it. Handing you a file containing what somebody else wrote to you, on your say-so alone, would be a leak with a save dialog on the front.

It also contains what you wrote to us — every piece of feedback or problem report you sent from inside the product, with the category, the message in full, the screen you were on and the date. Those are your own words and there is no second party in them, so handing them back tells you something and tells nobody anything about anyone else.

One thing is held and is not in the file: the measurement records in section 7. Every one of them also names somebody else, so giving you the list of who you were shown would be a disclosure about them, on your say-so alone. The manifest below names it anyway, so you can see that we hold it. It is deleted with your account.

The export also carries a manifest naming every place your data is held and what happens to each on deletion — the same list section 9 describes, generated from the same source the deletion code uses, so the two cannot drift apart.

11. Your rights

Depending on where you live you may have rights to access, correct, export, restrict or erase your personal data, and to object to certain processing. Dotstrap is built so you can exercise the main ones yourself, immediately, without asking us: correction on your profile, export and erasure on the Data & privacy screen, and withdrawal from Intent Match with a single switch that keeps your declaration so nothing has to be retyped if you return.

For anything you cannot do yourself — including if you believe your account was suspended in error — use the Help screen inside the product. It reaches us with your account attached, which is the difference between an appeal we can act on and a message we cannot verify.

12. Children

Dotstrap is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, tell us through the Help screen and we will remove it.

13. Service providers

Dotstrap runs on infrastructure operated by others. Where they handle your data they do so on our instructions and under obligations to protect it:

  • Google — sign-in. Google authenticates you; we receive a verified identifier, a display name and a photo.
  • Google Cloud and Firebase — the databases holding your account, in the region your account belongs to.
  • Cloudflare — serving the site and running the application edge.
  • NVIDIA and Sarvam AI — language model inference, subject to the residency rule in section 6.

We do not sell personal information, and we do not share it with advertisers, data brokers or analytics companies, because we do not work with any.

14. Security

Data is encrypted in transit, and conversations and other sensitive fields are additionally encrypted at rest under keys scoped to their own region. Our security practices, and their current limits, are described on the Security page — including the things we have not built yet, which are named there rather than omitted.

15. Changes to this policy

If we change how Dotstrap handles your data we will change this page and move the date at the top. Where a change materially affects you we will tell you inside the product, rather than relying on you to re-read a page you have already read.

16. Contact

The Help screen inside Dotstrap reaches us with your account attached and is the fastest route for anything about your own data. For formal privacy correspondence, use the contact form on this site.