Legal · Data & Trust
Privacy Policy
Exactly what each Degird product touches, where that data lives, who else ever sees it, and the controls you hold — written product by product rather than as one vague promise.
The short version
A human-readable summary of what follows. It is a reading aid, not a term of the agreement — where this summary and the full clauses differ, the full clauses govern.
Section 1
Our Commitment & What This Covers
Most of our software never sends your data anywhere. This policy explains the parts that do, and why.
This Privacy Policy explains how Degird ("Degird", "we", "us"), a multi-product software studio and AI-powered digital agency operating from Dhaka, Bangladesh, collects, uses, shares, and protects personal data across every product and service we operate. Read it alongside our Terms of Service.
What this policy covers
- Our websites — degird.com, its documentation, blog, and support desk, and agency.degird.com.
- Desktop software — Tubeup for Windows and macOS.
- Hosted platforms — Dormefy (dormefy.com) and Revoye (revoye.degird.com, together with Revoye Desk and the Revoye browser extension), and Pulse and Caster on release.
- WordPress plugins — GuestDock, AuthDock, and SyncDock.
- Browser extensions — TabFold, ShotDock, Domain Checker, DeepCycle, Limiter, and SyncDock Client.
- Agency engagements, sales enquiries, newsletter subscriptions, and support conversations.
What it does not cover
- Third-party platforms our products connect to — YouTube, Google, WordPress.org, browser marketplaces, and payment processors — each of which has its own privacy policy that applies to your relationship with them.
- Websites you reach through links in our documentation, blog, or products.
- How a customer of ours handles data inside their own WordPress site, their own Dormefy tenant, or their own self-hosted deployment. There, they are the controller and we are at most their processor — see Section 2.
Section 2
Our Role: Controller or Processor
Sometimes we decide what happens to data and answer for it. More often, you do and we simply provide the tool.
Data-protection law distinguishes the party that decides why and how personal data is processed (the controller) from the party that processes it on the controller's instructions (the processor). Which one we are changes what you can ask of us, so it is worth being precise.
| Context | Our role | What that means for you |
|---|---|---|
| Our website, newsletter, support desk | Controller | We decide the purposes. Exercise your rights directly with us under Section 16. |
| Your Degird account & purchases | Controller | We hold your account and licence records and answer for them. |
| Dormefy tenant data (residents, meals, billing) | Processor | The institution operating the tenant is the controller. Residents should direct requests there; we assist the controller in responding. |
| Tubeup on your computer | Neither, in practice | Processing happens locally under your sole control. We never receive the content, so there is nothing for us to be controller of. |
| WordPress plugins on your site | Neither, in practice | The plugin runs inside your hosting. We have no access to your database, your users, or your posts. |
| Browser extensions | Neither, in practice | Data stays in your browser's local storage and is never transmitted to us. |
| Agency engagements | Processor, then controller | Processor for client data you give us to work with; controller for our own contract and billing records. |
Where we act as a processor, a Data Processing Agreement incorporating the EU Standard Contractual Clauses is available on request from hello@degird.com. We do not charge for one.
Section 3
What We Collect
Identity and billing details when you buy, technical basics when you visit, and whatever you choose to tell us in a support ticket.
Data you give us
| Category | Examples | When |
|---|---|---|
| Identity | Name, email address, company name, job role, country | Account creation, purchase, contact form, newsletter, careers application |
| Transaction | Order reference, licence key, plan and tier, purchase date, invoice records, billing country, last four digits and card brand | Purchase and renewal, via the merchant of record |
| Support | Ticket content, screenshots, log files, diagnostic output, and anything else you attach | When you contact support — you control what you send |
| Project | Briefs, brand assets, footage, credentials you choose to share, and feedback | Agency engagements |
| Recruitment | CV, portfolio links, cover letter, and interview notes | Careers applications |
Data collected automatically
| Category | Examples | Where |
|---|---|---|
| Technical | IP address, user agent, browser and OS version, screen size, referring URL, language | Website only |
| Usage | Pages viewed, time on page, navigation paths, scroll depth, clicks, and — through Microsoft Clarity — anonymised session replays and heatmaps | Website only |
| Licence validation | Licence key, a hashed device identifier, product version, OS platform, and activation timestamp | Paid desktop software, at activation and periodic checks |
| Delivery & security | Server logs, request timestamps, error traces, and rate-limit counters | Website and hosted platforms |
What we never collect
- Full payment card numbers. These go directly to PCI-DSS compliant processors and never reach Degird systems.
- Your browsing history. No Degird extension collects, transmits, or sells the pages you visit.
- Your video files or their content. Tubeup uploads directly from your machine to YouTube; the media never passes through us.
- Your WordPress database. Our plugins run inside your installation and send us nothing about your posts, users, or content.
- Special-category data. We do not seek health, biometric, genetic, racial, religious, political, or sexual-orientation data, and we ask you not to include it in support tickets.
- Data purchased from brokers. Every record we hold came from you or from your direct use of a product.
Section 4
What Each Product Touches
The whole portfolio in one table. If a product is not listed as sending something, it does not send it.
| Product | Where data lives | Leaves your device? | Sent to Degird |
|---|---|---|---|
| Tubeup | Your computer — videos, metadata, schedules, tokens | Only to YouTube (uploads) and Gemini (metadata text you request) | Licence validation only — details |
| Dormefy | Our hosted infrastructure, in your tenant | Hosted service by design | Tenant data, processed on the institution's instructions |
| GuestDock | Your WordPress database | No | Nothing |
| AuthDock | Your WordPress database | No | Nothing |
| SyncDock | Your WordPress database | Only to the client you authorise | Nothing |
| TabFold | Browser local storage | No | Nothing |
| Domain Checker | Browser local storage | Domain queries go to public RDAP/registrar endpoints | Nothing |
| DeepCycle | Browser local storage | No | Nothing |
| Limiter | Browser local storage | No | Nothing |
| SyncDock Client | Browser local storage | Only to the WordPress sites you connect | Nothing |
| ShotDock | Your device — captures are stitched in the browser | No | Nothing |
| Revoye | Split — provider sessions and chat history stay in your browser; your router config and API job history sit on Revoye's servers | API prompts and responses go to the Revoye router; provider logins never leave your browser | Account email, API key hashes, device public keys, routing configuration, and API job history |
| degird.com | Our servers and analytics providers | n/a | Technical and usage data — details |
Section 5
Website, Cookies & Analytics
Two analytics tools, a newsletter sheet, and an email relay. No advertising networks, no cross-site tracking, no data sales.
This section applies to degird.com and its subdomains only. None of it runs inside our desktop software, extensions, or plugins.
| Technology | Purpose | Type | Retention |
|---|---|---|---|
| Google Analytics 4 | Aggregate traffic measurement — which pages get read, where visitors arrive from | Analytics · first-party cookie | Up to 14 months |
| Microsoft Clarity | Anonymised session replay and heatmaps to diagnose confusing interfaces | Analytics · first-party cookie | Up to 13 months |
| Theme preference | Remembers your light/dark choice | Strictly necessary · localStorage | Until you clear it |
| Consent & campaign state | Remembers that you dismissed a banner so we do not show it again | Strictly necessary · localStorage | Up to 12 months |
| Freemius, Inc. | Checkout overlay, fraud prevention, and licence delivery | Strictly necessary · loaded only at checkout | Per Freemius' policy |
What we deliberately do not run
- No advertising pixels, retargeting tags, or ad-network cookies.
- No cross-site tracking, data brokers, or identity-resolution services.
- No sale or sharing of personal data for behavioural advertising, in the sense those terms carry under the CCPA/CPRA.
- Web fonts are self-hosted and served from our own origin, so reading a page makes no request to a font CDN.
Your controls
Block or delete cookies in your browser settings. Strictly-necessary storage is limited to your theme choice and dismissed banners; blocking it costs you nothing but those preferences.
Opt out of Google Analytics with the Google Analytics opt-out browser add-on.
Opt out of Microsoft Clarity by enabling Global Privacy Control or your browser's Do Not Track signal, both of which we honour, or by blocking `clarity.ms`.
Ask us to erase the analytics data associated with you at hello@degird.com. Providing your Clarity or GA identifier makes this faster, but is not required.
Forms and mailing list
Contact, support, and enquiry forms send their contents to us by email over an authenticated SMTP relay. We hold the resulting correspondence in our mailbox.
Newsletter subscriptions record your email address, the date, and the source page in a private Google Sheet accessed by a restricted service account. We use it to send product news, and for nothing else.
Every marketing email carries a one-click unsubscribe link, and unsubscribing is honoured immediately. Transactional messages — licence delivery, receipts, security notices, and end-of-life warnings — are not marketing and continue regardless, because you need them.
Forms are rate-limited by IP and email address to stop abuse. Those counters hold an IP address transiently and are not used for profiling.
Section 6
Tubeup: Local Processing, Google & YouTube
Your videos never touch our servers. Tubeup talks to YouTube and to Gemini from your machine, using your own credentials.
Tubeup is a desktop application. It runs on your computer, stores its data on your computer, and uploads directly from your computer to YouTube. Degird operates no intermediary server in that path.
What stays on your machine
- Video files, thumbnails, and every other media asset.
- Titles, descriptions, tags, hashtags, and dynamic description templates.
- Upload queues, schedules, channel configurations, and publishing history.
- Google OAuth tokens and any YouTube API key you supply, held in your operating system's local application storage.
- Analytics you pull back from YouTube for your own channels.
Google and YouTube data
Tubeup's API mode uses YouTube API Services. By using it you are also bound by the YouTube Terms of Service, and Google's handling of your data is governed by the Google Privacy Policy.
Authorisation uses Google OAuth. You sign in to Google directly — Tubeup never sees or stores your Google password. The resulting access and refresh tokens are stored locally on your device only.
Tubeup requests the narrowest scopes that its features need: uploading and managing videos on channels you authorise, and reading analytics for those channels. It does not request access to your Gmail, Drive, Contacts, Photos, or any other Google service.
API data retrieved from YouTube — channel lists, video statuses, analytics figures — is stored locally so the interface can display it, and is refreshed from YouTube rather than accumulated by us.
You can revoke Tubeup's access to your Google account at any time at myaccount.google.com/permissions. Revocation is immediate and takes effect regardless of anything stored locally.
To delete locally stored Google data, sign out of the channel inside Tubeup or uninstall the application and remove its application-data folder. Because the data is local, deletion is entirely under your control.
AI metadata generation
When you ask Tubeup to generate metadata, it sends only the text needed for that request — such as a working title, filename, topic, or description you provide — to Google Gemini, and returns the suggestion to your machine.
Video files are never sent to the AI provider. Only text you have chosen to submit leaves your device, and only when you trigger generation.
Neither Degird nor the provider uses your prompts or outputs to train models. See Section 17.
If you would rather nothing left the machine at all, simply do not use the AI features — every other function of Tubeup works without them.
Licence validation
Tubeup contacts the licence service operated by our merchant of record to validate activation and entitlement. That exchange carries the licence key, a hashed device identifier, the product version, and the OS platform.
It does not carry your video files, metadata, channel names, Google tokens, or any content. Its only purpose is confirming that the seat you are using is one you paid for.
Section 7
WordPress Plugins
GuestDock, AuthDock, and SyncDock run entirely inside your hosting. We receive nothing from them.
Our WordPress plugins execute within your own WordPress installation, on hosting you choose and control. They write to your database and read from it. They do not transmit site data, user data, post content, or analytics to Degird.
GuestDock stores guest submissions, contributor details, and editorial state in your database. Those contributors are your data subjects and you are their controller; Degird is not involved in that processing.
AuthDock stores authentication events, failed-login records, lockout state, and IP addresses in your database for security purposes. IP addresses are personal data in many jurisdictions, so configure retention to match your own policy — the plugin gives you that control precisely so the decision stays yours.
SyncDock stores API credentials and publishing logs in your database. Content flows between your site and whichever client you authorise. Degird operates no relay in that path and holds no copy.
Plugin updates are delivered through the WordPress.org directory. Update checks are made by your WordPress installation to WordPress.org, under WordPress.org's own privacy policy, not to us.
Because we hold no data from these plugins, a data-subject request about a WordPress site must go to the site's operator. We will help that operator technically, but we cannot answer for data we have never had.
Section 8
Browser Extensions
Local storage, minimal permissions, and no browsing history — which is why they are free without being paid for with your data.
Every Degird browser extension follows the same rule: data stays in your browser. Nothing is transmitted to Degird servers, and no extension monetises your attention or your history.
| Extension | What it stores locally | Network activity |
|---|---|---|
| TabFold | Tab groups, saved sessions, suspension rules, exported URL lists | None |
| Domain Checker | Your query lists, results, and CSV exports | Queries public RDAP and registrar endpoints to check availability |
| DeepCycle | Focus sessions, timer settings, blocklists, streaks and stats | None |
| Limiter | Per-site daily limits and today's elapsed time | None |
| SyncDock Client | Site connections, credentials, drafts, and publishing queue | Connects only to the WordPress sites you configure |
| ShotDock | Your capture format and save preferences | None — screenshots are captured, stitched, and saved on your device |
Extensions request only the permissions their stated features require. Where an extension needs host access to function on a page, that access is used for the feature and nothing else — not for reading, logging, or transmitting page content.
No Degird extension collects browsing history, keystrokes, form contents, or page text, and none sells or shares data with anyone. This is also a condition of remaining listed under Chrome Web Store user-data policies, against which our listings are auditable.
Domain Checker queries public domain-registration data. Those lookups reveal to the queried endpoint which domains you are checking, in the same way any WHOIS or RDAP lookup does. They do not identify you to Degird, because they do not pass through us.
Uninstalling an extension removes its local data. Where you want a clean slate without uninstalling, each extension offers a reset in its own settings.
Where you sign in to a browser profile with sync enabled, your browser vendor may sync extension storage across your devices under its own policy. That is your browser's behaviour, not ours, and you control it in your browser settings.
Section 9
Dormefy & Hosted Platforms
Institutions manage real people's records here. They decide; we process on their instructions and nothing more.
Dormefy is a hosted platform used by dormitories, hostels, universities, and mess committees to manage rooms, residents, meal schedules, and billing. The institution operating a tenant is the controller; Degird is its processor.
A tenant may contain resident names, contact details, room assignments, guardian contacts, meal records, attendance, and payment history. That data is entered and governed by the institution, and we process it only to run the service and only on the institution's documented instructions.
Degird does not sell tenant data, does not use it for marketing, does not use it to train AI models, and does not share it between tenants. Tenants are logically isolated from one another.
Residents and guardians: direct access, correction, and deletion requests to the institution that operates your dormitory's account. They hold the relationship and the authority. If you cannot reach them, contact us and we will do our best to route your request to the right person.
Institutions: a Data Processing Agreement with the EU Standard Contractual Clauses, a current subprocessor list, and a security overview are available on request from hello@degird.com.
We notify a controller without undue delay, and in any event within 72 hours of becoming aware of a personal-data breach affecting their tenant, with the information needed for their own regulatory notifications.
On termination, tenant data is available for export for 30 days and is then deleted per Section 14.
Pulse and Caster will be added to this section with their actual data behaviour before they become generally available.
Section 10
Agency Clients & Project Data
Assets and credentials you hand us for a project are used for that project, then returned or destroyed.
During an agency engagement you may give us brand assets, footage, copy, analytics access, staging credentials, or datasets. We use them solely to deliver the agreed scope.
Credentials you share are stored in access-controlled systems, limited to the team members working on your engagement, and revoked or rotated at project close. We will always tell you when we no longer need access.
Where project materials contain personal data — customer lists, testimonial footage, user research — you are the controller and we act as your processor under a DPA available on request.
We retain project files for 12 months after delivery so we can support handover and reissue deliverables, then delete them unless you ask us to keep them longer or a retainer is ongoing.
Portfolio use is governed by Terms §19. Where an engagement is under NDA, or where you simply ask us not to, nothing about it is published — including in this context.
Contract, invoice, and tax records are kept for the statutory period under Section 14, as controller, regardless of project deletion.
Section 11
How & Why We Use Data
Every purpose, with the lawful basis it rests on — the test a regulator actually applies.
| Purpose | Data used | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Deliver licences and run hosted products | Identity, transaction, licence validation | Performance of a contract |
| Process payments and prevent fraud | Transaction, billing country, device signals | Contract; legitimate interests in preventing fraud |
| Provide support and answer enquiries | Identity, support content, diagnostics | Contract; legitimate interests in serving users |
| Send transactional messages — receipts, security notices, end-of-life warnings | Identity, transaction | Contract; legal obligation |
| Send product news and marketing | Email address, subscription source | Consent — withdrawable at any time |
| Improve products and diagnose usability problems | Aggregate usage, session replay, error traces | Legitimate interests in improving our products |
| Secure our systems and enforce licences | Technical, licence validation, server logs | Legitimate interests in security and protecting our IP |
| Meet accounting, tax, and legal obligations | Transaction, identity | Legal obligation |
| Defend or bring legal claims | Whatever is relevant to the claim | Legitimate interests in establishing and defending claims |
| Recruitment | Application materials | Steps prior to entering a contract; consent |
Where we rely on legitimate interests, we have balanced that interest against your rights and concluded it does not override them. You may object at any time under Section 16, and we will stop unless we have compelling grounds we can articulate to you. Our balancing assessment is available on request from hello@degird.com.
Section 12
Who We Share Data With
A short, named list of service providers. No advertisers, no brokers, no sales — ever.
Degird does not sell your personal data, and does not share it for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA. We have never done so and we have no plans to. The complete list of processors we rely on is below.
| Provider | What it does | Data it receives |
|---|---|---|
| Freemius, Inc. | Merchant of record — checkout, payment, tax, invoicing, licensing | Name, email, billing country, transaction and licence records |
| Payment processors (via Freemius) | Card authorisation and settlement, PCI-DSS compliant | Payment details — never passed to Degird |
| Google (Analytics, Gemini, Sheets, Fonts API build-time) | Website analytics; AI metadata generation in Tubeup; newsletter list storage | Aggregate usage; prompt text you submit; subscriber email addresses |
| Microsoft Clarity | Anonymised session replay and heatmaps on our website | Masked interaction data, technical data |
| Hosting & CDN providers | Serving our website and hosted platforms | Technical data, request logs, and hosted content at rest |
| Email delivery (SMTP relay) | Sending transactional and support email | Email address, message content |
Other disclosures
Legal requirements. We may disclose data where compelled by a valid legal process. We check that a demand is valid and proportionate, we disclose only the minimum required, and we notify you unless legally prohibited from doing so.
Rights protection. We may disclose data where necessary to investigate suspected fraud, licence circumvention, or a threat to the safety or rights of any person — the enforcement route described in Terms §12.
Corporate transaction. If Degird is involved in a merger, acquisition, or asset sale, data may transfer as part of it. You will be notified before your data becomes subject to a materially different policy, and this policy continues to apply until then.
With your direction. Where you connect a Degird product to a third-party service, data flows to that service because you asked it to, under that service's own policy.
Section 13
International Data Transfers
We operate from Bangladesh and use global infrastructure. Transfers are covered by Standard Contractual Clauses.
Degird operates from Dhaka, Bangladesh, and our providers operate infrastructure in several regions. Personal data may therefore be processed outside your country, including outside the EEA and the UK.
Bangladesh has not received an adequacy decision from the European Commission or the UK government. Where we transfer personal data from the EEA, the UK, or Switzerland, we rely on the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914) and the UK International Data Transfer Addendum, supplemented where needed by additional technical and organisational measures.
We carry out transfer impact assessments where required, and apply encryption in transit and at rest, access controls, and data minimisation so that the volume of personal data crossing borders is as small as the service allows.
Where a customer requires data residency in a specific region, contact us before purchase — we will tell you honestly whether we can meet it rather than after the fact.
A copy of the transfer mechanism relevant to your data is available from hello@degird.com.
Section 14
How Long We Keep Data
Each category has a stated period. Nothing is kept indefinitely just because storage is cheap.
| Data | Retained for | Why |
|---|---|---|
| Account & licence records | Life of the account, then 24 months | Support reactivation, warranty and licence disputes |
| Transaction & invoice records | 7 years from the transaction | Statutory accounting and tax obligations |
| Support correspondence | 24 months from resolution | Recurring-issue context and quality review |
| Newsletter subscription | Until you unsubscribe, then 12 months | Proof that consent was withdrawn and honoured |
| Website analytics | 14 months (GA4) · 13 months (Clarity) | Year-over-year comparison, then automatic expiry |
| Server & security logs | 90 days, longer where an investigation is open | Security, abuse investigation, incident response |
| Hosted tenant data | Life of subscription + 30-day export window | Continuity of service and clean offboarding |
| Agency project files | 12 months after delivery | Handover support and deliverable reissue |
| Recruitment applications | 12 months, or longer with your consent | Future openings |
When a retention period ends, data is deleted or irreversibly anonymised. Anonymised, aggregate statistics that can no longer identify anyone may be kept indefinitely — those are no longer personal data. Backups follow their own rolling cycle and are overwritten within 90 days, so a deletion request is reflected in live systems immediately and in backups as the cycle turns.
Section 15
How We Protect Data
Encryption, least privilege, and an architecture that avoids holding what it does not need.
In transit: all connections to our websites, hosted platforms, and APIs use TLS 1.2 or higher, with modern cipher suites and HSTS.
At rest: hosted data is encrypted with AES-256 or equivalent, and secrets and credentials are held in dedicated secret storage rather than in code or configuration files.
Access control: least privilege throughout. Production access is limited to the people who need it for a stated role, protected by multi-factor authentication, and reviewed periodically.
Isolation: hosted tenants are logically separated. Development and staging environments do not use production personal data.
Minimisation by architecture: the strongest control we have is not collecting data in the first place. Local processing in Tubeup, in-browser storage in extensions, and in-database storage in WordPress plugins mean most of our products create no central store to attack.
Monitoring: systems are monitored for anomalous access, rate-limit abuse, and error patterns, with alerting to on-call staff.
Dependencies: third-party libraries are tracked and patched, and we accept vulnerability reports under the safe harbour in Terms §25.
Breach response: where a personal-data breach is likely to result in risk to your rights, we notify the relevant supervisory authority within 72 hours of becoming aware, and notify affected individuals without undue delay where the risk is high. We tell you what happened, what we did, and what you should do.
Honesty about limits: no system is perfectly secure. We do not claim certifications we do not hold, and we do not describe controls we have not implemented. Where you need a specific compliance artefact, ask and we will tell you plainly whether we have it.
Section 16
Your Rights & How to Use Them
Access, correct, delete, port, object — free of charge, within 30 days, wherever you live.
We extend the following rights to everyone, not only to residents of regions whose law compels them. Drawing a privacy line at a border makes for a worse product.
| Right | What you can ask for |
|---|---|
| Access | A copy of the personal data we hold about you, and an explanation of how we use it. |
| Rectification | Correction of inaccurate or incomplete data. |
| Erasure | Deletion of your data, subject to records we must keep by law. |
| Restriction | That we pause processing while a dispute about accuracy or legitimate interests is resolved. |
| Portability | Your data in a structured, commonly used, machine-readable format, or transmitted to another provider where technically feasible. |
| Objection | That we stop processing based on legitimate interests, or stop direct marketing — the latter is absolute and honoured immediately. |
| Withdraw consent | Withdrawal of any consent you gave, without affecting processing already carried out. |
| Non-discrimination | Equal service and pricing after exercising any right. We do not degrade an account for making a request. |
How to exercise them
Email hello@degird.com describing what you want. There is no form to fill in and no fee.
We verify identity proportionately — usually by confirming you control the email address on the account. For a broad request we may ask for more, and we will explain why.
We respond within 30 days. Where a request is genuinely complex we may extend by a further 60 days, and we will tell you within the first 30 that we are doing so, and why.
An authorised agent may act for you with written authorisation, subject to the same verification.
Where we hold your data as a processor — Dormefy tenants, agency project files — we will route your request to the controller and support them in answering it, because they hold the authority to decide.
Regional specifics
- EEA / UK (GDPR & UK GDPR): all rights above apply, plus the right to lodge a complaint with your supervisory authority — see Section 20.
- California (CCPA/CPRA): rights to know, delete, correct, and opt out. We do not sell or share personal information for cross-context behavioural advertising, and we do not process it for targeted advertising, so there is no opt-out to operate — but we honour Global Privacy Control signals regardless.
- Other US states (Virginia, Colorado, Connecticut, Utah, Texas and comparable laws): equivalent access, correction, deletion, portability, and opt-out rights, with an appeal route if we decline a request.
- Canada (PIPEDA): access and correction rights, and a complaint route to the Office of the Privacy Commissioner.
- Brazil (LGPD), Australia (Privacy Act), and comparable regimes: we honour equivalent rights on the same terms.
- Bangladesh: as our home jurisdiction, we comply with applicable local law on data and electronic transactions, and apply the standards above as our operating baseline.
Section 17
AI Features & Model Training
We do not train models on your data, and we configure providers so they cannot either.
Where a feature calls a third-party model provider — Google Gemini for Tubeup metadata today — we use API configurations under which submitted data is not retained for provider model training. That is a condition of our using a provider, not an assumption we make about them.
Only the text needed for the specific request is transmitted. Video files, media, credentials, and unrelated project data are never sent to an AI provider.
AI features are opt-in by action: nothing is sent until you trigger generation. Products remain fully functional if you never use them.
Providers may retain prompts briefly for abuse monitoring under their own policies. We link those policies in Terms §17 so you can read the actual terms rather than our summary of them.
We do not build behavioural profiles of you, and we do not use AI to make decisions about your account.
This is reciprocal with Terms §13, where we reserve our own content against AI training. We ask for that protection, so we extend it.
Section 18
Children's Privacy
Our products are not for children. Where an institution manages minors' records, the institution holds the consent.
Degird products are intended for adults and for professional use. You must be at least 16 years old — or the minimum digital-consent age in your country, if higher — to create an account or buy a licence in your own name.
We do not knowingly collect personal data from children. If we learn we have, we delete it promptly.
Dormefy may contain records of residents who are minors, entered by the institution operating the tenant. That institution is the controller and is responsible for the lawful basis, parental or guardian consent where required, and the notices given to residents and guardians. Degird processes those records only on the institution's instructions and never for its own purposes.
If you believe a child has provided us with personal data, contact hello@degird.com and we will investigate and delete it.
Section 19
Changes to This Policy
Material changes get 30 days' notice. New products get documented before they ship, not after.
We update this policy when we launch products, change providers, or improve our practices. The version and effective date at the top of this page always identify the operative revision.
For material changes — a new category of data, a new purpose, a new processor, or a reduction in your controls — we give at least 30 days' notice before they take effect, and notify account holders by email or in-product notice.
Clarifications, corrections, and structural edits take effect on publication.
New products are documented here before general availability, so this policy describes what ships rather than catching up with it.
We will never apply a materially different use to data already collected without a fresh lawful basis, which for consent-based processing means asking you again.
Previous versions are available on request. If a change is one you cannot accept, exercise your rights under Section 16 — including deletion.
Section 20
Contact & Complaints
Ask us first — we answer properly. If we get it wrong, here is the escalation route.
Data controller: Degird, a multi-product software studio and AI-powered digital agency operating from Dhaka, Bangladesh.
| Reason for contact | Where to write |
|---|---|
| Privacy questions and rights requests | hello@degird.com |
| Data Processing Agreement or subprocessor list | hello@degird.com |
| Security vulnerability reports | hello@degird.com |
| Legal notices and copyright | hello@degird.com |
| Product support | degird.com/support |
If you are not satisfied
Tell us first. Most complaints come from a gap in explanation rather than a gap in practice, and we would rather fix it directly and quickly.
EEA residents may lodge a complaint with the supervisory authority in their country of residence, workplace, or the place of the alleged infringement. UK residents may complain to the Information Commissioner's Office at ico.org.uk.
Canadian residents may complain to the Office of the Privacy Commissioner of Canada. Australian residents may complain to the OAIC. US state residents may contact their state Attorney General.
You retain every right to a judicial remedy, and nothing in this policy or in our Terms of Service limits it.
Questions about this document?
Write to us and we'll answer in plain language. If your message concerns a specific clause, quote its number — every clause on this page is individually addressable.