Donna

Privacy Policy

Last updated: June 21, 2026

This Privacy Policy describes how Plain Technologies Inc., doing business as donna.sh ("Donna," "we," "us," or "our") collects, uses, discloses, and protects information when you visit our website (donna.sh) or use our Services.

This policy covers two contexts: Website and marketing (information collected when you visit donna.sh) and Product (the Donna Platform) (Customer Data processed when you use Donna's AI agent platform). For enterprise customers, product data processing may be governed by a separate Data Processing Agreement ("DPA") — contact legal@donna.sh to request one.

1. Scope

This Privacy Policy applies to visitors to donna.sh and associated marketing pages, users who create Donna accounts, and authorized representatives of organizations using Donna.

It does not apply to third-party websites or Connected Services that Donna integrates with. Those services' own privacy policies govern how they handle your data within their systems.

2. Information We Collect

a. Information You Provide Directly

  • Name, email address, and contact information
  • Account credentials and authentication information
  • Billing information (payment card details are processed and stored by Stripe — we do not store card numbers)
  • Communications with us, including support requests, feedback, and sales inquiries
  • Organization and team information

b. Information Collected Automatically

  • IP address, device type, browser type, and operating system
  • Usage data including pages viewed, features accessed, and timestamps
  • Log and diagnostic data for security, reliability, and troubleshooting

c. Information from Third-Party Integrations

When you connect third-party services to Donna (such as email, calendar, or task applications), Donna accesses data from those services solely to perform Agentic Actions you configure. This may include email content and metadata, calendar events, task and project data, and other data accessible via the permissions you grant.

This data is processed as Customer Data under our Terms of Service. It is not used for advertising, not sold to third parties, and not used to train AI models.

d. Authentication

We use Clerk for user authentication. When you sign in via a third-party identity provider (such as Google), limited profile information (such as name and email) is shared under your agreement with that provider.

3. How We Use Information

We use information to:

  • Provide, operate, maintain, and improve the Services
  • Authenticate users and enforce access controls
  • Execute Agentic Actions you configure
  • Secure the Services and prevent fraud or abuse
  • Monitor performance and reliability
  • Send transactional and administrative communications (account alerts, security notices, billing receipts)
  • Send marketing communications consistent with your preferences (you may opt out at any time)
  • Comply with legal and regulatory obligations

We do not use your Customer Data to train AI models, sell your personal data, use your data for behavioral advertising or profiling, or share Customer Data with third parties except as described below.

4. Legal Bases for Processing (GDPR)

Where GDPR applies, we process personal data under the following legal bases:

Legal BasisWhen We Use It
Contractual necessityTo provide the Services you signed up for
Legitimate interestsTo operate, secure, and improve the Services
ConsentFor optional cookies and marketing communications
Legal obligationWhere required by applicable law

5. How We Share Information

a. Service Providers

We work with vetted third-party providers that perform functions on our behalf. Key providers include:

ProviderPurpose
Google CloudCloud infrastructure and hosting
ClerkUser authentication and session management
StripePayment processing and billing
TwilioVoice and messaging (agentic phone/SMS features)
SendGridTransactional email delivery
ResendTransactional email delivery

All service providers are bound by data processing agreements and confidentiality obligations, may only process data as directed by Donna, and are periodically reviewed as part of our vendor management process.

b. Connected Services (At Your Direction)

When you configure agents to act within Connected Services, Donna passes data to those services only to the extent required to execute your instructions.

c. Legal Requirements

We may disclose information when required by law, regulation, court order, or valid legal process, or when necessary to protect the rights, property, or safety of Donna, our users, or others.

d. Business Transactions

In connection with a merger, acquisition, or asset sale, personal data may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.

6. Data Retention

Data TypeRetention Period
Account and profile dataDuration of account + 30 days post-deletion
Customer Data (via integrations)Duration of account + 30 days post-deletion
Billing and financial records7 years (legal and tax obligations)
Security and access logs90 days
Aggregated analyticsUp to 2 years

You may request deletion of your account and associated data at any time by contacting privacy@donna.sh. We will process requests within 30 days except where legal obligations require longer retention.

7. Data Security

We implement security measures including encryption in transit (TLS 1.2+) and at rest, role-based access controls with least-privilege principles, security monitoring and incident detection, regular security reviews, and contractual security obligations for all service providers.

No system is completely secure. In the event of a data breach materially affecting your personal data, we will notify you as required by applicable law.

8. International Data Transfers

Donna is based in the United States. If you are located outside the US, your information may be transferred to and processed in the US, where data protection laws may differ. Where required by applicable law — including GDPR — we implement appropriate safeguards for international transfers, such as Standard Contractual Clauses approved by the European Commission.

9. Your Rights and Choices

RightWhat You Can Do
AccessRequest a copy of personal data we hold about you
CorrectionRequest correction of inaccurate or incomplete data
DeletionRequest deletion of your personal data
PortabilityReceive your data in a structured, commonly used format
ObjectionObject to processing based on legitimate interests
RestrictionRequest we limit processing in certain circumstances
Withdraw consentWithdraw consent where processing is consent-based

To exercise any of these rights, contact privacy@donna.sh. We will respond within 30 days.

California Residents (CCPA): You have the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale or sharing of personal information. We do not sell personal information.

European Residents (GDPR): If you are in the EEA, UK, or Switzerland, you have the right to lodge a complaint with your local supervisory authority.

10. Children's Privacy

The Services are not directed to children under 16 years of age. We do not knowingly collect personal data from children under 16. If we learn we have inadvertently collected such data, we will delete it promptly. Contact privacy@donna.sh if you believe we have collected data from a minor.

11. Changes to This Privacy Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email or prominent notice within the Services at least 14 days before taking effect. The "Last updated" date at the top reflects the most recent revision.

12. Contact

Privacy questions, requests, or concerns: privacy@donna.sh
Enterprise DPA requests: legal@donna.sh

Donna: The AI Executive Assistant That Gets Things Done