Privacy Policy
Last updated: June 21, 2026
This Privacy Policy describes how Plain Technologies Inc., doing business as donna.sh ("Donna," "we," "us," or "our") collects, uses, discloses, and protects information when you visit our website (donna.sh) or use our Services.
This policy covers two contexts: Website and marketing (information collected when you visit donna.sh) and Product (the Donna Platform) (Customer Data processed when you use Donna's AI agent platform). For enterprise customers, product data processing may be governed by a separate Data Processing Agreement ("DPA") — contact legal@donna.sh to request one.
1. Scope
This Privacy Policy applies to visitors to donna.sh and associated marketing pages, users who create Donna accounts, and authorized representatives of organizations using Donna.
It does not apply to third-party websites or Connected Services that Donna integrates with. Those services' own privacy policies govern how they handle your data within their systems.
2. Information We Collect
a. Information You Provide Directly
- Name, email address, and contact information
- Account credentials and authentication information
- Billing information (payment card details are processed and stored by Stripe — we do not store card numbers)
- Communications with us, including support requests, feedback, and sales inquiries
- Organization and team information
b. Information Collected Automatically
- IP address, device type, browser type, and operating system
- Usage data including pages viewed, features accessed, and timestamps
- Log and diagnostic data for security, reliability, and troubleshooting
c. Information from Third-Party Integrations
When you connect third-party services to Donna (such as email, calendar, or task applications), Donna accesses data from those services solely to perform Agentic Actions you configure. This may include email content and metadata, calendar events, task and project data, and other data accessible via the permissions you grant.
This data is processed as Customer Data under our Terms of Service. It is not used for advertising, not sold to third parties, and not used to train AI models.
d. Authentication
We use Clerk for user authentication. When you sign in via a third-party identity provider (such as Google), limited profile information (such as name and email) is shared under your agreement with that provider.
3. How We Use Information
We use information to:
- Provide, operate, maintain, and improve the Services
- Authenticate users and enforce access controls
- Execute Agentic Actions you configure
- Secure the Services and prevent fraud or abuse
- Monitor performance and reliability
- Send transactional and administrative communications (account alerts, security notices, billing receipts)
- Send marketing communications consistent with your preferences (you may opt out at any time)
- Comply with legal and regulatory obligations
We do not use your Customer Data to train AI models, sell your personal data, use your data for behavioral advertising or profiling, or share Customer Data with third parties except as described below.
4. Legal Bases for Processing (GDPR)
Where GDPR applies, we process personal data under the following legal bases:
| Legal Basis | When We Use It |
|---|---|
| Contractual necessity | To provide the Services you signed up for |
| Legitimate interests | To operate, secure, and improve the Services |
| Consent | For optional cookies and marketing communications |
| Legal obligation | Where required by applicable law |
5. How We Share Information
a. Service Providers
We work with vetted third-party providers that perform functions on our behalf. Key providers include:
| Provider | Purpose |
|---|---|
| Google Cloud | Cloud infrastructure and hosting |
| Clerk | User authentication and session management |
| Stripe | Payment processing and billing |
| Twilio | Voice and messaging (agentic phone/SMS features) |
| SendGrid | Transactional email delivery |
| Resend | Transactional email delivery |
All service providers are bound by data processing agreements and confidentiality obligations, may only process data as directed by Donna, and are periodically reviewed as part of our vendor management process.
b. Connected Services (At Your Direction)
When you configure agents to act within Connected Services, Donna passes data to those services only to the extent required to execute your instructions.
c. Legal Requirements
We may disclose information when required by law, regulation, court order, or valid legal process, or when necessary to protect the rights, property, or safety of Donna, our users, or others.
d. Business Transactions
In connection with a merger, acquisition, or asset sale, personal data may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Account and profile data | Duration of account + 30 days post-deletion |
| Customer Data (via integrations) | Duration of account + 30 days post-deletion |
| Billing and financial records | 7 years (legal and tax obligations) |
| Security and access logs | 90 days |
| Aggregated analytics | Up to 2 years |
You may request deletion of your account and associated data at any time by contacting privacy@donna.sh. We will process requests within 30 days except where legal obligations require longer retention.
7. Data Security
We implement security measures including encryption in transit (TLS 1.2+) and at rest, role-based access controls with least-privilege principles, security monitoring and incident detection, regular security reviews, and contractual security obligations for all service providers.
No system is completely secure. In the event of a data breach materially affecting your personal data, we will notify you as required by applicable law.
8. International Data Transfers
Donna is based in the United States. If you are located outside the US, your information may be transferred to and processed in the US, where data protection laws may differ. Where required by applicable law — including GDPR — we implement appropriate safeguards for international transfers, such as Standard Contractual Clauses approved by the European Commission.
9. Your Rights and Choices
| Right | What You Can Do |
|---|---|
| Access | Request a copy of personal data we hold about you |
| Correction | Request correction of inaccurate or incomplete data |
| Deletion | Request deletion of your personal data |
| Portability | Receive your data in a structured, commonly used format |
| Objection | Object to processing based on legitimate interests |
| Restriction | Request we limit processing in certain circumstances |
| Withdraw consent | Withdraw consent where processing is consent-based |
To exercise any of these rights, contact privacy@donna.sh. We will respond within 30 days.
California Residents (CCPA): You have the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale or sharing of personal information. We do not sell personal information.
European Residents (GDPR): If you are in the EEA, UK, or Switzerland, you have the right to lodge a complaint with your local supervisory authority.
10. Children's Privacy
The Services are not directed to children under 16 years of age. We do not knowingly collect personal data from children under 16. If we learn we have inadvertently collected such data, we will delete it promptly. Contact privacy@donna.sh if you believe we have collected data from a minor.
11. Changes to This Privacy Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or prominent notice within the Services at least 14 days before taking effect. The "Last updated" date at the top reflects the most recent revision.
12. Contact
Privacy questions, requests, or concerns: privacy@donna.sh
Enterprise DPA requests: legal@donna.sh