Privacy Policy
DYO OS is a behavioral execution platform operated by DYO Technologies, Inc., a Delaware corporation based in Newark, New Jersey, USA. This policy covers joindyo.com and dyohq.com. Effective October 8, 2026. Questions: robin@dyohq.com.
Who can use DYO
DYO is intended for users 16 years of age or older.
What we collect
- Name and email address when you create an account
- Responses to the behavioral archetype assessment
- Task descriptions, goals, and sprint context you enter into the platform
- Emotional state inputs you self-report at the start of a session
- Mission completion status, constraint outcomes, streak data, and behavioral pattern detection results
- Calendar availability signals (only when you connect Google Calendar)
- Google Calendar events and Gmail draft/send capability, only when you authorize those connections
- Active browser tab URL and page title — read by the DYO Chrome extension only when active and only when you interact with it
- Anonymized Google Analytics usage data on the joindyo.com marketing website only (not inside the DYO platform)
What we do not collect
- Payment card numbers or financial account details (handled directly by Stripe, PCI-compliant)
- Government ID numbers or social security numbers
- Passwords in plaintext
- Full page content from your browser or browsing history
How we use your information
To generate behavioral missions calibrated to how you work, detect execution patterns and intervene at the moment friction occurs, sync connected calendar and email accounts per your permissions, improve pattern detection, send transactional emails (via Resend), and respond to support requests. We do not use your information for advertising, sell it, or share it outside the subprocessors listed below.
Subprocessors
- Vercel — application hosting (application traffic)
- Supabase — database and authentication (account and behavioral data)
- Google (Gemini) — mission generation (anonymized task context)
- Anthropic (Claude) — complex reasoning (anonymized task context)
- Composio — Google Calendar and Gmail integration delivery (OAuth tokens, calendar and email data per your permission)
- Stripe — payment processing (PCI-compliant)
- Resend — transactional email (your email address)
- Google Analytics — website analytics on joindyo.com only (anonymized browsing behavior)
All subprocessors are US-based or process data in US data centers. By using DYO, you acknowledge this transfer.
Data retention
Active accounts: data is retained while your account is active. Account deletion: personally identifiable information is deleted within 30 days of request; anonymized aggregate behavioral data may be retained. Inactive accounts (12+ months) are flagged for deactivation with notice first.
Your rights
You may have rights to access, correct, or delete your personal data — email robin@dyohq.com and we respond within 30 days. California residents: DYO does not sell or share personal information as defined under the CPRA. International users: data is processed in the United States under US data protection standards.
Security
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Production data access is limited to founding engineers on a need-to-know basis. OAuth integrations use minimal scope.
Cookies
Authentication cookies keep you logged in (functional, required). Google Analytics cookies exist on the joindyo.com marketing website only; opt out via the Google Analytics Opt-out Browser Add-on.
Children
DYO is not directed at children under 16 and does not knowingly collect their data. Contact robin@dyohq.com to report and delete an under-16 account.
Changes & contact
We may update this policy; material changes are emailed to active users. Contact: DYO Technologies, Inc., robin@dyohq.com, joindyo.com. © 2026 DYO Technologies, Inc.