Privacy Policy.
Doza Assist is local-first by design. Your footage, transcripts, and projects stay on your machine. We collect only what we need to run the website and process your purchase.
The app does not phone home with your media. Transcription, search, AI analysis, and exports all happen on your Mac. No footage, transcripts, or project files are uploaded to Doza Visuals servers.
The website collects the basics. We log anonymized site analytics, store your email if you contact us or sign up for product news, and pass payment information through our processor when you buy.
We don't sell or share your data. No advertising trackers, no third-party data brokers, no selling of email lists.
Optional bring-your-own-key AI features are at your own risk. If you choose to connect a third-party AI provider with your own API key, content you send leaves your Mac and is governed by that provider's terms, not ours. Details in section 03.
01Who We Are
This policy is published by Doza Visuals LLC ("Doza Visuals," "we," "us," or "our"), a Massachusetts limited liability company. It covers personal data we collect through doza.ai and the Doza Assist desktop application (collectively, the "Service").
For privacy-related questions or requests, email [email protected].
02What the App Does Not Collect
Because this is the most important thing to understand about Doza Assist, we put it first.
- The app does not upload your video, audio, transcripts, or project files to any Doza Visuals server
- The app does not send your prompts, AI conversations, or story outputs back to us
- The app does not run analytics on how you use it, what files you open, or what you ask the assistant
- The app works offline. Turn off your network connection and it still transcribes, analyzes, and exports
The only network activity the app initiates by default is a periodic license check to confirm your purchase is valid. That request transmits an anonymized license key and the application version. It does not include identifying information about your projects or content.
03Optional: Bring Your Own AI Provider
Doza Assist is local-first by default. Transcription, AI analysis, and story generation run on your Mac using the bundled local model stack. No content is sent to any remote AI service unless you explicitly enable it.
Some features may let you connect a third-party AI provider (for example, OpenAI, Anthropic, Google, or another service) using an API key you supply. These bring-your-own-key (BYOK) features are off by default and you control whether to enable them in the app's settings.
When you enable a BYOK connection and choose to send content to a third-party provider, the following is outside our control:
- Content you send (transcript excerpts, prompts, queries, file contents) leaves your Mac and is transmitted directly to that provider's servers
- The provider's terms of service, privacy policy, and data retention practices govern how that content is handled, stored, logged, and potentially used to train their models
- Some providers retain content for extended periods, share it with subprocessors, or use it for product improvement unless you explicitly opt out in their settings
Before enabling BYOK, review the terms and privacy policy of the provider you select. Doza Visuals has no visibility into or responsibility for how third-party providers handle content you choose to send them. You can disable BYOK at any time in the app's settings, after which the app reverts to local-only processing.
Your API keys are stored locally on your Mac in the macOS Keychain. They are not transmitted to Doza Visuals, and we never see your prompts, the provider's responses, or any content you exchange with them.
04What We Collect Through the Website
Information you give us
- Email address when you contact us, sign up for product updates, or request support
- Name and any details you share in support emails or inquiry forms
- Billing information when you purchase a license. Payment card data is collected and processed by our payment processor, Paddle, and is not stored on our servers
Information we collect automatically
- Site analytics: pages viewed, referring source, approximate country, device category, and browser type. We use this to understand which content is useful and where to focus improvements
- Server logs: IP address, timestamp, and request URL for the standard short retention period that comes with hosted infrastructure
We do not use third-party advertising trackers, social media pixels, or session replay tools on doza.ai.
05Cookies
We use a small number of cookies and similar technologies, limited to:
- Essential cookies required for the site and checkout to function
- A privacy-respecting analytics cookie that records anonymized session data
We do not use cookies for cross-site tracking or behavioral advertising.
06How We Use the Information
We use the personal data we collect to:
- Deliver, support, and improve the Service
- Process purchases, license keys, renewals, and refunds
- Respond to your questions, feedback, and support requests
- Send important account, billing, and product notices
- Send occasional product updates if you have opted in to receive them
- Protect against fraud, abuse, and security threats
- Meet our legal and tax obligations
07Third-Party Services We Rely On
To operate the Service, we share limited data with a small number of trusted service providers, each bound by their own terms and privacy commitments:
- Paddle (Paddle.com Market Limited) acts as the merchant of record for purchases through doza.ai. Paddle collects payment details, billing address, and tax information to process your purchase. Their privacy notice describes how they handle that data
- Netlify hosts the doza.ai website and processes standard server logs
- Email infrastructure providers transmit transactional messages such as receipts, license keys, and support replies
We do not sell personal data to third parties and we do not allow third parties to use your data for their own marketing.
08Legal Bases for Processing
Where the EU or UK General Data Protection Regulation applies, we process personal data on the following legal bases:
- Contract: to deliver the Service you purchased
- Legitimate interests: to operate the website, prevent fraud, and improve the Service
- Consent: for optional marketing emails, withdrawable at any time
- Legal obligation: to meet tax, accounting, and other regulatory requirements
09Your Rights
Depending on where you live, you may have the following rights with respect to your personal data:
- Access a copy of the data we hold about you
- Correct inaccurate or incomplete data
- Delete data we hold about you
- Restrict or object to certain processing
- Receive your data in a portable format
- Withdraw consent for marketing communications
- Lodge a complaint with your local data protection authority
To exercise any of these rights, email [email protected]. We respond within 30 days. California residents have additional rights under the CCPA, including the right to opt out of the sale of personal information. We do not sell personal information.
10Data Retention
We keep personal data only as long as we need it for the purposes described above or as required by law. Order and tax records are retained for the period required by U.S. and EU tax authorities, typically seven years. Support emails are retained for two years from the last interaction. Marketing email subscriptions are retained until you unsubscribe.
11Children
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided personal data to us, please contact [email protected] and we will delete it.
12International Transfers
Doza Visuals is based in the United States. If you are located outside the U.S., your personal data may be transferred to and processed in the U.S. and in other countries where our service providers operate. Where required, we rely on Standard Contractual Clauses or other approved transfer mechanisms.
13Security
We use reasonable administrative, technical, and physical safeguards to protect personal data, including encryption in transit, access controls, and least-privilege practices for the small set of systems that touch customer data. No system is perfectly secure, and we cannot guarantee absolute protection.
14Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will post the revised policy at this URL and update the "Last updated" date above. For substantial changes, we will notify subscribers by email.
For privacy and data requests, or anything else, write to [email protected]. Every message reaches Chris directly.
15Data Controller
Doza Visuals LLC
North Easton, Massachusetts, United States
[email protected]