Legal
Privacy
Last updated · 2 October 2026
Short version: we store what you need to use Draftly (your account, your current draft and the proposals you share), we don't sell anything to anyone, and Google Analytics is the one third-party script running on the site. The detail below is checkable against what the product actually stores.
What this covers
This describes what Draftly collects when you use Draftly, and what your clients' browsers record when they open a proposal you sent them. It covers the Draftly website and app, and nothing else.
What is never stored
We never see or store your card details. Upgrading to a paid plan takes you to a checkout page hosted by Dodo Payments — your card goes to them, not to us. What comes back to our servers is a confirmation that you paid, and which plan and billing cycle you bought.
We don't use advertising trackers or sell data to anyone. We do use Google Analytics to see aggregate usage — see Cookies below for what that means.
Your account
We store:
- your email address;
- if you sign in with Google, the name and profile picture Google returns — used only to show who is signed in;
- the profile you fill in on the settings page: business name, your name, services, payment terms and standard terms. This is stored so it follows you to another device, and it is sent to the AI provider with each proposal so your own terms are reproduced instead of invented.
- the proposal you're currently working on: the brief you wrote, the generated proposal and your edits. It is saved as you edit, both in your browser and to your account, so you can pick it up on another device. Only one draft is kept; it is replaced when you start a new one and cleared when you share or discard it.
- if you're on a paid plan, which plan and billing cycle you bought and how many proposals you've used against it — not your card details, which Dodo holds.
Shared proposals
When you create a share link we store the proposal's contents, the link's token, when it was created, and — if you asked for alerts — the email address to notify.
The token is the only thing protecting a shared proposal. Anyone holding the link can read it, so treat it like a password and delete the proposal if the link gets somewhere it shouldn't.
What your client's visit records
Opening a shared proposal records the time it was opened, the heading of the section your client scrolled furthest to, and how long they spent on each section and whether they scrolled back to one after leaving it. Nothing identifies them: no name, no email, no IP address, no cookie, no device or browser details, and no way to tell one visitor from another. Two people opening the same link are two timestamps and nothing more.
We still do not record the order sections were read in, a scroll-by-scroll trace, or anything that would let one visit be tied to another — a sender needs to know whether a proposal is being read, how far, and which parts held their client's attention, and that is where it stops. Your own previews are excluded entirely.
Accepting a proposal records more. When your client clicks accept, we store the name and email they type, their IP address, their browser user-agent, and the time — because the point of that record is to evidence who agreed to what. It is written once and cannot be edited afterwards.
If your client leaves a comment, we store their name, their message, and the email address they optionally provide. The email is used only to notify you and to send them your reply; it is never shown in the thread and never returned to the browser.
You are the one asking your client to open that link, which under GDPR makes you the controller of their data and us your processor. Telling them what accepting records is your responsibility — this page is here so you can point them at it.
What the AI provider sees
Writing or revising a proposal sends your brief and your saved profile to Google (Gemini). That is the only way the text can be written, and Google is the only model provider Draftly sends it to.
Send only what you would be comfortable sharing with a third party. Their handling of that data is governed by their own terms, and we don't control it.
Who processes data for us
- Supabase — authentication and database.
- Google — writing and revising proposals, through Gemini.
- Resend — sign-in codes and notification emails.
- Dodo Payments — checkout and billing for paid plans. They are the merchant of record, which means your card details go to them, not us.
- Vercel — hosting and request logs.
- Google Analytics — aggregate usage across the site. See Cookies below.
These providers process data on our behalf and may hold it outside your country. We don't sell data to anyone, and there is no advertising network involved.
How long it's kept
Your in-progress draft is kept until you share it, discard it or start a new one.
Shared proposals are kept until you delete them. Deleting one removes it and its comments, and the link stops working immediately.
Account data is kept while your account exists. Ask us to close it and we'll delete your account, your profile, your saved draft and your shared proposals.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to how it's used. Email hello@godraftly.com and we'll action it. If your client wants their acceptance record removed, contact us and we'll handle it with you — bear in mind deleting it also removes the evidence of their agreement.
Children
Draftly is a tool for professional work and isn't intended for anyone under 16. We don't knowingly collect data from children.
Changes
If what we collect changes, this page changes with it and the date at the top moves. Material changes will be notified by email or in the product before they take effect.
Contact
Email hello@godraftly.com.
Questions about this page? Get in touch.