Privacy Policy
Last updated: 28 September 2026
The short version: we collect what we need to run Donvi and nothing else. We don't sell your data or show you ads, and we don't use tracking or analytics cookies. We don't use your content to train AI models. Your content goes to AI model providers and cloud computers only so your agents can do the work you asked for. You can ask us to see or delete your data at any time.
This policy explains what personal data we process when you use Donvi (the "Service"), why we do it, who we share it with, and what rights you have. We have tried to write it in plain language. If anything is unclear, email us at jonas@neuston.io.
1. Who we are
Donvi is provided by Neuston AB, a company registered in Sweden ("Neuston", "we", "us"). Neuston AB is the data controller for the personal data described in this policy, unless section 3 says otherwise.
Contact: jonas@neuston.io
2. What data we collect
Data you give us
- Account details: your name, email address and password. We store passwords only as a secure hash, never in plain text. If you sign in with Google, we receive your name, email address and profile picture from Google.
- Organization details: the organizations (workspaces) you create or join, their names, and your role in them (owner, admin or member).
- Your content: the messages and instructions you send to agents, the files you upload, the skills and scheduled tasks you create, and everything agents produce for you (replies, files, code, reports).
- Messages to us: anything you send us when you contact us or ask for early access.
Data from services you connect
You can choose to connect other services so agents can work with them. We only access these services when you connect them, and only within the permissions you grant:
- Gmail (read-only): agents can search and read your emails and attachments when a task needs it.
- Google Calendar: agents can read your calendars and read, create and change events.
- GitHub: agents can access the repositories you grant our GitHub App access to.
We store the access tokens for these connections in encrypted form. You can disconnect a service at any time in Donvi or in that service's own settings.
Data collected automatically
- Sign-in and security data: the IP address and browser/device information (user agent) linked to each signed-in session. We use this to keep your account secure.
- Usage and billing data: which AI models and cloud computers your agents used, how much (for example number of tokens and computer time), the cost, and your organization's credit balance and purchases.
- Activity logs: technical records of what agents did in a session, such as which tools they ran and which actions you approved or denied. We need these to run the Service, show you what happened and fix problems.
- Notification data: if you turn on push notifications, we store the technical address your browser gives us for sending them.
3. Your organization and its members
Donvi is built for teams. When you work inside an organization, other people can see some of your data:
- Sessions you share with your organization are visible to all of its members. Private sessions are visible only to you.
- Skills, scheduled tasks and connected repositories that belong to the organization are shared with its members.
- Owners and admins manage the organization, including its members and credit balance.
If you use Donvi on behalf of a company, that company may be the controller of the business data you process in Donvi. In that case we process it on the company's behalf and follow its instructions. Please contact your organization's administrator with questions about how it uses Donvi.
4. How we use your data and why
Under the EU General Data Protection Regulation (GDPR) we must have a legal basis for each use of your data. Here is what we do and why:
- To provide the Service: create your account, run your agents, show you your sessions, bill usage and send the notifications you asked for. Legal basis: performance of our contract with you.
- To keep Donvi secure: prevent fraud and abuse, protect accounts and investigate problems. Legal basis: our legitimate interest in a secure service.
- To improve Donvi: understand how the Service performs, for example error rates and costs, so we can fix and improve it. Legal basis: our legitimate interest in developing our product.
- To communicate with you: answer your questions and tell you about important changes to the Service or these terms. Legal basis: contract and legitimate interest.
- To follow the law: for example, keeping accounting records. Legal basis: legal obligation.
- Connected services and push notifications: only when you choose to turn them on. Legal basis: your consent, which you can withdraw at any time.
We do not:
- sell your personal data;
- use your data for advertising;
- use your content to train AI models;
- make decisions about you based only on automated processing that have legal or similarly significant effects on you.
5. How AI processing works
When an agent works on a task, we send the relevant content (your instructions, the conversation so far, and any files or data the agent is using) to the AI model you picked. The model provider uses it to generate a response. Model providers may keep data for a limited time under their own policies, for example to prevent abuse.
Each session also gets its own cloud computer, where the agent can run programs, browse the web and work on files. The computer is deleted when you delete the session.
AI output can be wrong. Agents act on your instructions, and we ask for your approval before agents take certain actions in external systems.
6. Google user data
Donvi's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. In particular:
- We only use Gmail and Google Calendar data to carry out the tasks you ask agents to do.
- We never use it for advertising and never sell it.
- We never use it to train or improve general AI or machine learning models.
- No person at Neuston reads it unless you ask us to (for example for support), it is needed for security, or the law requires it.
7. Who we share data with
We share personal data only with service providers who help us run Donvi. They may use it only to provide their services to us:
- Hetzner Online GmbH (Germany): hosts our servers and database.
- Daytona (USA): runs the cloud computers your agents use.
- OpenRouter (USA) and the AI model providers it routes to (for example Anthropic, OpenAI and Fireworks AI): generate AI responses.
- Payment providers: process payments when you buy credits. We do not store your full card details.
- Browser push services (for example Google, Mozilla or Apple, depending on your browser): deliver push notifications if you turn them on.
- Map tile providers (OpenStreetMap and Esri): when an agent shows you a map, your browser loads map images directly from them, which shares your IP address with them.
When you connect Google, GitHub or Wint, data is exchanged with those services at your request. Their own privacy policies apply to the data they hold.
We may also share data if the law requires it, to protect our rights or the safety of others, or as part of a merger or sale of our business. If that happens, this policy continues to protect your data.
8. Transfers outside the EU
Some of our service providers are in the United States or other countries outside the EU/EEA. When we transfer data there, we use the safeguards the GDPR requires. These include the EU–US Data Privacy Framework, where the provider is certified, and the European Commission's Standard Contractual Clauses. You can contact us for more details.
9. How long we keep data
- Account and organization data: for as long as your account exists. When you ask us to delete your account, we delete it within 30 days.
- Sessions and their content: until you delete them. Deleting a session also deletes its cloud computer and the files on it.
- Connected-service tokens: until you disconnect the service or delete your account.
- Sign-in sessions and push subscriptions: until you sign out or they expire.
- Billing and accounting records: for seven years, as Swedish accounting law requires.
Deleted data may remain in backups for a short time until they are overwritten.
10. Cookies and local storage
We only use what Donvi needs to work. We have no advertising or analytics cookies, so we don't show a cookie banner.
- Sign-in cookies keep you signed in and protect against certain attacks.
- Local storage in your browser remembers your display preferences, such as theme and font.
11. How we protect your data
We use encryption in transit (HTTPS), encrypt stored access tokens for connected services, give each session its own isolated cloud computer, and check on every request that you can only access data from organizations you belong to. No system is perfectly secure. If a data breach affects you, we will notify you and the authorities as the law requires.
12. Your rights
Under the GDPR you have the right to:
- access your data and get a copy of it;
- correct data that is wrong;
- delete your data ("right to be forgotten");
- restrict or object to certain processing, including processing based on our legitimate interests;
- data portability: receive your data in a machine-readable format;
- withdraw consent at any time, for example by disconnecting a service or turning off notifications.
To use any of these rights, email jonas@neuston.io. We will reply within one month. You also have the right to complain to the Swedish data protection authority, Integritetsskyddsmyndigheten (IMY), or to the authority where you live. We would appreciate the chance to help you first.
13. Children
Donvi is a professional tool and is not meant for anyone under 18. We do not knowingly collect data from children.
14. Changes to this policy
We may update this policy as Donvi changes. We will change the "Last updated" date above, and if the changes are significant we will tell you by email or in the app before they take effect.
See also our Terms of Service.