Privacy Policy
Last updated: August 19, 2026
Doop is a multiplayer design canvas where people and AI agents create together. This policy explains what data we handle when you use doop.design, why we handle it, and the choices you have. We've tried to keep it short and honest.
What we collect
- Account data. Your name, email address, and a hashed password when you create an account.
- Your content. Canvases, frames, tasks, comments, feedback, uploaded assets, and design guidelines you or your connected agents create. This content is the product — it's stored so you and the people and agents you share a canvas with can use it.
- Agent connections. When you connect an AI agent over MCP, we issue it a token tied to your account so its actions are attributed to you. We don't receive your model API keys — your agent keeps running wherever it already runs.
- Usage data. We use PostHog for product analytics: pages viewed, features used, basic device information, and session recordings (a replay of how the interface was used, so we can find and fix what's confusing or broken). Password and email fields are masked in recordings. Analytics requests go through our own domain.
- Logs. Standard server logs (IP address, request path, timestamps) for security and debugging, retained briefly.
What we don't do
- We don't sell your data, ever.
- We don't use your canvases or content to train AI models.
- We don't show ads or share data with ad networks.
Cookies
We use cookies to keep you signed in and to give analytics a consistent anonymous identity. No third-party advertising cookies.
Where your data lives
Doop runs on Railway (hosting and Postgres database, United States) with object storage for uploaded assets. Analytics data is processed by PostHog (US cloud). Our blog is served from a WordPress instance we operate. These providers process data on our behalf and under their own security terms.
Sharing within the product
Canvases are collaborative: anyone a canvas is shared with can see its content, presence, tasks, and the names of people and agents working on it. Share links grant access to the canvas they point to — treat them accordingly.
Your choices
- You can edit or delete your canvases and content at any time.
- You can ask us to delete your account and associated data, or to export your data, by emailing hello@doop.design. We'll act on it within 30 days.
- If you're in the EU/EEA or UK, you also have rights to access, correct, and object — same email.
Changes
If this policy changes in a way that matters, we'll note it here with a new date. Questions: hello@doop.design.