Privacy Policy
Last updated and effective: 2026-07-29
Domi exists to carry your household's mental load — and that only works if you can trust it completely with your family's information. So our promise is simple: your data stays yours. Each household lives in its own isolated space. Domi never sells, shares, or rents your information without your consent, and never lets AI providers train their models on it. And you can switch on encryption at rest for your household, right from Settings — built on 256-bit encryption that even future quantum computers are not expected to break. This policy explains, in plain language, what we collect, where it lives, and the rights you have over it — wherever you live.
Who we are
Domi is built and operated by Gailleur Labs, based in Quebec, Canada. JF Gailleur is Domi's designated Privacy Officer — the person responsible for how your personal information is protected. You can reach the Privacy Officer directly at hello@domiapp.ai.
What we collect, and why
We collect only what the service needs to work for you:
- Account information. Your email address, and the household name you choose during onboarding — so you can sign in and we can reach you.
- Information you give Domi. Documents, photos, and structured data you provide about your household, vehicles, residences, appliances, members, and obligations — and, if you choose to connect them, emails and calendar items from accounts you link. This is the household memory the whole product is built on: organizing your records, extracting facts, and predicting what needs to happen next.
- Usage telemetry. AI-call costs, error logs, and audit-log entries for your account's changes — so we can run the service reliably and you can see what happened in your account.
- Support messages. If you write to support in-app, the Domi support team reads those messages and attachments (that's the point); they are stored with your household data and deleted with it.
- Sign-in cookies. A session cookie (essential for staying signed in) and a sign-in challenge cookie. We do not set tracking cookies.
We use this data solely to provide the service. Domi routes each kind of task to the AI model best suited for it — Anthropic, OpenAI, or Cohere (see the sub-processor list below) — chosen by us per task, not configurable per account. We never sell or share your data without your consent — if we ever propose something that involves a third party (say, a better rate on an insurance you already hold), we will ask you first, every time. We do not train AI models on your data (and our providers are bound not to), and today the only third parties that touch it are the sub-processors listed below, strictly to run the service.
Your consent
By creating an account, you consent to the processing described in this policy. Anything beyond the core service is a separate, explicit choice: connecting an email or calendar account always asks you first, and each connection can be disconnected at any time in Settings. You can withdraw your consent entirely, at any time, by deleting your account (see "Your rights" below).
Where your data lives, and how it's protected
Your data is stored with our infrastructure providers in the United States: application compute on Vercel (US East, us-east-2), the database on Neon (AWS us-east-2), files on Cloudflare R2 (ENAM, Eastern North America), and email delivery via Resend (us-east-1). AI calls transit US-based provider APIs under no-training terms and zero-data-retention arrangements. Before relying on these providers, we assessed the transfer as Quebec law requires; the protection travels with the data rather than depending on geography:
- Contracts: every provider is bound by a data-processing agreement or equivalent terms covering your data. For readers in the European Union and the United Kingdom: transfers to the United States are protected by contractual safeguards, including the European Commission's Standard Contractual Clauses incorporated in our providers' data-processing agreements.
- Encryption: sensitive fields (document filenames, chat message bodies, OAuth tokens) are always encrypted with operator-managed keys. When you enable Encryption at rest in Settings, your household gets its own encryption key (wrapped by an operator-held master key) covering entity details, document contents, and search-index text as well — 256-bit symmetric encryption, the kind even future quantum computers are not expected to break.
- Isolation: Postgres row-level security enforces that no household can read another household's rows — at the database level, not just the application level.
- Accountability: every change in your account is logged to an INSERT-only audit log with the actor, the action, and a timestamp — and you can protect sign-in with two-factor authentication and review your active sessions in Settings.
Sub-processors
We share data with the following sub-processors strictly to operate the service:
- Vercel — application hosting; functions run in the US East region (Cleveland,
us-east-2), encrypted in transit. Vercel is a US-incorporated company. - Neon — Postgres database (AWS
us-east-2, US East / Ohio; no Canada region is available on the provider). - Cloudflare R2 — object storage for uploaded files (ENAM, Eastern North America region).
- Anthropic — default LLM provider for chat, document extraction, and plan generation.
- OpenAI — used to transcribe and interpret uploaded documents (for example, complex or copy-protected PDFs). Document content sent to OpenAI is not retained by OpenAI (zero-retention / logging disabled) and is never used to train OpenAI models.
- Cohere — generates the embeddings used to search your documents (and reranks search results). Document text and your search queries are sent to Cohere; they are not used to train Cohere models.
- Resend — transactional email delivery (magic-link sign-in, account notifications); hosted in the US (
us-east-1, North Virginia). - Sentry — error and performance telemetry (no message content sent).
- Google Cloud Pub/Sub — the channel Gmail uses to notify Domi of new emails (only used if you connect Gmail).
- Google (Sign-In) — if you use "Continue with Google", your Google identity (email, profile basics) transits Google during login. Google never receives household data through sign-in.
We will update this list before relying on a new sub-processor. Authentication is fully in-house — no third-party identity service ever holds your credentials — and built on Auth.js, the widely used open-source authentication framework for Next.js, following its established best practices, with sign-in via Google or a secure email link.
Google user data (Limited Use)
If you connect a Google account, Domi's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Gmail and Google Calendar data is read only to provide user-facing household features (extracting bills, renewals, appointments, and mirroring calendar events), is never used for advertising, is never sold, and is never transferred to third parties except sub-processors listed above as required to provide those features. Humans do not read this data except with your explicit consent (e.g. a support request you initiate), for security purposes, or to comply with law. Google data is not used to train generalized AI or machine-learning models.
Apple iCloud data
If you connect an iCloud account, Domi uses an app-specific password you create (revocable at any time at appleid.apple.com) to read your iCloud Mail and Calendar — Domi never sends email or writes to your calendar. The password is stored encrypted, and the same commitments as above apply: your iCloud data is read only to provide household features, is never used for advertising, is never sold, and never reaches third parties beyond the sub-processors listed above.
Microsoft account data
If you connect a Microsoft account (Outlook / Microsoft 365), Domi requests read-only permissions (Mail.Read, Calendars.Read) — it cannot send email or modify your calendar, and you can revoke access at any time at account.live.com. The same commitments apply: your Microsoft data is read only to provide household features, is never used for advertising, is never sold, and never reaches third parties beyond the sub-processors listed above.
How long we keep your data
Domi is your household's memory, so your data is kept while your account is active — nothing expires while you use the service. When you close your account, everything is kept for 30 days (in case you change your mind), then permanently deleted — including documents, uploaded files, and your login. Copies held in backup and write-protected storage are removed as those systems' own retention windows lapse. Audit-log entries are retained for at least 12 months for security investigations and are deleted with your account.
Your rights
Wherever you live — anywhere in Canada, the United States (including California), the European Union, or the United Kingdom — we extend the same core rights to everyone:
- Access — see the personal information Domi holds about you (most of it is directly visible in the app).
- Correction — fix anything that's wrong, directly in the app, on any record.
- Deletion — delete your account and all its data yourself, no email or support request needed: open Settings → Delete account & data. Deletion is recorded immediately, kept on file for 30 days in case of mistake, then carried out permanently and automatically.
- A copy of your data (portability) — ask us and we will provide your data in a structured, commonly used format.
- Withdrawal of consent — disconnect any connected account at any time in Settings, or withdraw entirely by deleting your account.
- Restriction and objection — ask us to limit how your data is used, or object to a particular use, and we will honor it or explain why we can't. Sensitive details (like health information) are only ever used to provide the service you asked for — never for advertising or profiling. These rights apply wherever you live, including in the European Union.
For access, correction, or data-copy requests, write to hello@domiapp.ai or use in-app support; we respond within 30 days. In Canada, Domi's handling of personal information is governed federally by PIPEDA and provincially by Quebec's Law 25 — the strictest of the Canadian regimes and the baseline Domi is built to — as well as the Alberta and British Columbia PIPAs where they apply.
Questions or complaints
If anything about your privacy worries you, we'd like to hear it first — write to hello@domiapp.ai or open an in-app support ticket, and the Privacy Officer will answer. If you're not satisfied with our response, you may complain to your local privacy regulator — for example, the Commission d'accès à l'information (CAI) in Quebec, the Office of the Privacy Commissioner of Canada (OPC) federally and in provinces under PIPEDA, the Office of the Information and Privacy Commissioner (OIPC) of Alberta or British Columbia, the Information Commissioner's Office (ICO) in the United Kingdom, the Commission nationale de l'informatique et des libertés (CNIL) in France, or the California Privacy Protection Agency (CPPA) in California.
If something ever goes wrong
If a security incident ever put your information at risk, we would tell you promptly and plainly — what happened, what was involved, and what we did about it — and notify the authorities as the law requires.
Children and family members
Domi accounts are held by adults. A parent or guardian manages the household and adds younger members themselves — those records belong to the family's own space and are used only to serve the household. Domi is not directed at children and does not knowingly collect personal information directly from a child: members under 14 (the age of digital consent in Quebec; 13 applies in the United States and the United Kingdom, and 15 in France) are added by their parents and do not hold their own login.
Automated features
Domi suggests and predicts — it never decides for you. Predicted tasks and extracted facts are always labeled as such, anything that changes your household's records waits for a person to confirm it, and nothing legally significant is ever decided about you automatically. You can dial predictions down, exclude specific ones, or turn them off in Settings.
Changes to this Policy
We may update this Policy as the service evolves. Material changes will be communicated by email to the address on file at least 14 days before they take effect. This version is effective 2026-07-27.