Legal
Privacy
Last updated · 14 September 2026
Short version: a proposal you haven't shared never leaves your browser, we don't sell anything to anyone, and Google Analytics is the one third-party script running on the site. The detail below is checkable against what the product actually stores.
What this covers
This describes what Draftly collects when you use Draftly, and what your clients' browsers record when they open a proposal you sent them. It covers the Draftly website and app, and nothing else.
What is never stored
A proposal you haven't shared never reaches our database. Writing one sends your brief to the AI provider and returns the result; the draft and your edits are held in your own browser. Nothing is written to our servers until you create a share link for it.
We never see or store your card details. Upgrading to a paid plan takes you to a checkout page hosted by Dodo Payments — your card goes to them, not to us. What comes back to our servers is a confirmation that you paid, and which plan and billing cycle you bought.
We don't use advertising trackers or sell data to anyone. We do use Google Analytics to see aggregate usage — see Cookies below for what that means.
Your account
We store:
- your email address;
- if you sign in with Google, the name and profile picture Google returns — used only to show who is signed in;
- the profile you fill in on the settings page: business name, your name, services, payment terms and standard terms. This is stored so it follows you to another device, and it is sent to the AI provider with each proposal so your own terms are reproduced instead of invented.
- if you're on a paid plan, which plan and billing cycle you bought and how many proposals you've used against it — not your card details, which Dodo holds.
Shared proposals
When you create a share link we store the proposal's contents, the link's token, when it was created, and — if you asked for alerts — the email address to notify.
The token is the only thing protecting a shared proposal. Anyone holding the link can read it, so treat it like a password and delete the proposal if the link gets somewhere it shouldn't.
What your client's visit records
Opening a shared proposal records the time it was opened, and the heading of the section your client scrolled furthest to. Nothing identifies them: no name, no email, no IP address, no cookie, no device or browser details, and no way to tell one visitor from another. Two people opening the same link are two timestamps and nothing more.
We deliberately do not record how long anyone spent, what order they read in, or anything else about their behaviour — a sender needs to know whether a proposal is being read and roughly how far, and that is where it stops. Your own previews are excluded entirely.
Accepting a proposal records more. When your client clicks accept, we store the name and email they type, their IP address, their browser user-agent, and the time — because the point of that record is to evidence who agreed to what. It is written once and cannot be edited afterwards.
If your client leaves a comment, we store their name, their message, and the email address they optionally provide. The email is used only to notify you and to send them your reply; it is never shown in the thread and never returned to the browser.
You are the one asking your client to open that link, which under GDPR makes you the controller of their data and us your processor. Telling them what accepting records is your responsibility — this page is here so you can point them at it.
What the AI provider sees
Writing or revising a proposal sends your brief and your saved profile to whichever provider is configured — Google (Gemini) or Anthropic (Claude). That is the only way the text can be written.
Send only what you would be comfortable sharing with a third party. Their handling of that data is governed by their own terms, and we don't control it.
Who processes data for us
- Supabase — authentication and database.
- Google or Anthropic — writing and revising proposals.
- Resend — sign-in codes and notification emails.
- Dodo Payments — checkout and billing for paid plans. They are the merchant of record, which means your card details go to them, not us.
- Vercel — hosting and request logs.
- Google Analytics — aggregate usage across the site. See Cookies below.
These providers process data on our behalf and may hold it outside your country. We don't sell data to anyone, and there is no advertising network involved.
How long it's kept
Shared proposals are kept until you delete them. Deleting one removes it and its comments, and the link stops working immediately.
Account data is kept while your account exists. Ask us to close it and we'll delete your account, your profile and your shared proposals.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to how it's used. Email hello@godraftly.comand we'll action it. If your client wants their acceptance record removed, contact us and we'll handle it with you — bear in mind deleting it also removes the evidence of their agreement.
Children
Draftly is a tool for professional work and isn't intended for anyone under 16. We don't knowingly collect data from children.
Changes
If what we collect changes, this page changes with it and the date at the top moves. Material changes will be notified by email or in the product before they take effect.
Contact
Email hello@godraftly.com.
Questions about this page? Get in touch.