dooryard is a personal assistant service operated by Dan O'Brien and available at dooryard.io. This policy covers dooryard.io and its staging environment, and describes what data the service handles, why, and the promises we make about it. Questions and requests go to dan.obrien15@gmail.com.
Your account. When you sign in with Google, Microsoft or Apple we receive your name, email address, and (from Google) a one-time snapshot of your profile photo. We use these to create and label your account. We never receive or store your password.
If you sign in with Apple. Apple lets you hide your real address and hand us a forwarding one that ends in privaterelay.appleid.com. We treat it like any other address: it is how we label your account and how we can reach you, and mail sent to it reaches you through Apple. Apple also gives us your name only on the very first sign-in, so the name you type on Apple's screen is the one your account keeps. You can change it later in Settings, and you can stop the forwarding at any time from your Apple ID.
What you create. Your conversations with Otto, Board items, memories, people and facts, reflection reactions, and files you import are stored so the service can work for you. They belong to you and are isolated to your account.
Connections you link. If you connect an outside account (for example a calendar or mailbox), we store the access token for that connection encrypted at rest, with the encryption key held in a separate vault. You can disconnect at any time, which removes the connection. If you set an email watch ("tell me when this email arrives"), dooryard checks that mailbox for new message headers about once a minute and compares them against the rule you set; a matched message is read in full only to prepare what you asked for, and anything that would send an email still waits for your approval on a confirmation card. Cancelling the watch stops the checking.
Managing Outlook mail. If you connect an Outlook mailbox choosing "manage", dooryard can also mark a message as read, move a message to your Junk folder, or block a sender. Each of these is a change to your mailbox, so each one waits for your approval on a confirmation card before anything happens. "Block" creates a named inbox rule in your mailbox that moves future mail from that sender to Junk; you can see or remove that rule anytime in Outlook's own settings. A mailbox connected read-only cannot be changed by dooryard at all, and reconnecting read-only removes the manage permission.
Usage metering. We record counts and costs (for example how many requests you made and what they cost), never the content of what you said or wrote. Observability surfaces show numbers, not transcripts.
If you use Google sign-in or connect Google services, here is exactly what dooryard accesses and why:
Sign in with Google (your basic profile): your name, email address, and profile photo, used to create and label your account.
Google Calendar (if you connect it): dooryard reads your events to show you your day and answer your questions, and creates, edits, or deletes events only after you approve each change on a confirmation card.
Gmail (if you connect it): dooryard can send email for you. When you ask Otto to email someone, it composes a draft and shows you the exact recipient, subject, and body on a confirmation card; nothing is sent until you approve it. Connecting Gmail grants send permission only: dooryard does not request any Gmail read access and cannot list or read your inbox.
Google Drive (if you connect it): dooryard works only with files you create through dooryard or deliberately point it at. It cannot browse the rest of your Drive.
YouTube (if you connect it): dooryard reads your subscriptions to answer your questions about them. If you choose "Read + manage playlists" when connecting, Otto can also assemble a playlist for you: it drafts the playlist, shows the account, the title, and every video on a confirmation card, and creates it only after you approve. Playlists are always created private, on your own channel.
Google data is used only to provide these features to you. We do not use it for advertising, do not sell it, do not use it to train machine-learning models, and do not let humans read it except with your explicit consent, for security purposes, or where the law requires.
dooryard's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Your data is used to run the service for you: to remember what you tell Otto, to keep your Board, Daily, and Reflection current, and to act on your behalf when you approve an action. To generate replies, the content of a conversation is processed by the configured model provider (currently Microsoft Azure AI services under enterprise terms that prohibit training on your data).
We never train models on your data, never sell it, and never mine it for our own purposes. The only content that ever reaches the dooryard team is something you deliberately share into a group we are a member of, such as your Feedback group, and you can stop sharing at any time.
When you ask Otto about something current, it can search the web. The search terms it composes go to our search provider, Brave Search, so it can get results back. Your name, your account, and the rest of your conversation are not sent with them.
Otto can also read a web page in full, but only a page from those search results or a link you typed yourself. It cannot be talked into fetching an address you never gave it, which is what keeps a hostile web page from using that ability to send your information somewhere. Whatever it reads is treated as information to consider, never as instructions to follow, and Otto cites the links it used so you can check them.
Nothing you create is shared unless you share it. If you put an item into a group you belong to, the members of that group can see it. Your conversations with Otto are always private to you. We do not sell or rent data to anyone, and we disclose it to third parties only when the law requires.
dooryard is served over HTTPS. Connection tokens are encrypted at rest with keys held in a separate vault. Every person's data is isolated by per-account access rules enforced in the database itself. Any action that sends a message, spends money, or cannot be undone requires your explicit confirmation first.
Your data is kept while your account is active so the service can keep working for you. You can delete or retire content from within the app on the surfaces that hold it, and disconnect linked accounts at any time. To delete your account and its data entirely, email dan.obrien15@gmail.com and we will delete it and confirm when done.
dooryard accounts are for adults. The service is not directed at children under 13, and we do not knowingly collect their data.
If this policy changes, the changes will be posted here with a new effective date. Material changes will be announced in the app.