Your privacy is important to us. This policy explains how we collect, use, and protect your information when you use asktodo.ai and its AI productivity tools, resume builder, and email outreach platform.
Last updated: May 18, 2026 | Effective Date: May 18, 2026
Service Provider: asktodo.ai
Operating jurisdiction: Karnataka, India
Website: https://asktodo.ai
Contact / Data Protection inquiries: hi@asktodo.ai
asktodo.ai provides AI-powered productivity tools, a resume builder, and a self-service email outreach platform. We are based in India and do not actively target the European Economic Area, but EU/EEA residents who choose to use the service retain the data-protection rights described in this policy.
Authentication is provided by Supabase Auth. When you register, we collect:
user_data_storage to personalize the dashboardSubscriptions and credit purchases are processed by Razorpay (which exposes multiple payment methods including cards, UPI, net-banking, and PayPal). We log:
We do not store raw card numbers, CVV, or full bank account details — those remain with Razorpay.
The authenticated dashboard runs only first-party server-side telemetry — no Google Analytics, no third-party trackers. We record:
This telemetry is operational — it is what powers your usage history, credit accounting, security monitoring, and platform reliability. It is not shared with any third party.
When you use any of our AI tools (we operate over thirty), the prompts you submit and the responses you receive are stored in a centralized history table so you can review past generations and so we can accurately bill credits. Inputs and outputs are tied to your user ID and stored encrypted at rest.
resume-exports and resume-imagesbackground-removal buckettool-files bucketemail-outreach bucketavatars bucketBuckets are private by default with row-level security restricting access to the owning user; only avatars, blog images, and resume templates are publicly readable.
If you use the email outreach platform, you may connect a Gmail account (via OAuth) or any custom SMTP server. We store:
What we do not do: We do not read your inbox. We do not access mail you have already received. The OAuth scope we request is the minimum needed to send messages on your behalf. (We do not currently support Microsoft Outlook integration.)
When you use the email outreach platform you may upload CSV files or paste contact lists containing third-party personal data (names, email addresses, company, role, custom fields).
Our role: asktodo.ai acts strictly as a Data Processor in respect of your uploaded contact lists. You are the Data Controller.
What this means:
Sending: All campaign emails are dispatched directly through the Gmail OAuth account or custom SMTP server you connect. We do not relay messages through any third-party Email Service Provider (ESP) on your behalf.
You warrant that you have a lawful basis to process every contact you upload (consent, contract, or legitimate interest) and that you will honor unsubscribe requests promptly. The legal responsibility for the contact data itself rests with you as the controller — see our Terms of Service.
We process your personal data on the following legal grounds (GDPR Article 6, DPDP Section 7, equivalents in other jurisdictions):
When you submit a prompt to any AI tool, the request is sent to Groq, a high-speed inference provider that runs open-source language models on our behalf. Groq processes the input, returns a response, and we relay it back to you.
Our absolute commitment:
Inputs and outputs are stored in your private history (Section 2.4) so you can revisit past generations. You can delete any history item at any time.
We retain your data only as long as needed for the purposes above:
You can delete your account from Dashboard → Settings → Delete Account. You will be asked to type DELETE MY ACCOUNT to confirm.
On deletion, the platform performs the following automatically:
Irreversibility: Account deletion is permanent. After 30 days the residual backup window also expires and the data is non-recoverable. We cannot restore a deleted account.
To minimize the personal data we retain, we reserve the right to delete accounts that remain inactive for 24 or more consecutive months. Before any deletion we will:
If you reside in the EU/EEA or UK, you have these rights regardless of where we operate:
Request a copy of the personal data we hold about you.
Correct inaccurate or incomplete personal data.
Delete your personal data — available directly via Dashboard → Settings → Delete Account, or by emailing us.
Limit how we process your data in specific situations.
Receive your data in a machine-readable format (JSON export of history, resumes, contacts).
Object to processing based on legitimate interests or for direct marketing purposes.
Withdraw consent for any processing that relies on consent, including cookie tracking (via the cookie banner) and marketing emails.
To exercise any of the above:
Email hi@asktodo.ai
Response time: within 30 days. Free of charge for the first request per calendar year.
California residents have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
Do Not Sell or Share My Personal Information:
asktodo.ai does not sell personal information for monetary value. We also do not “share” personal information for cross-context behavioral advertising in the CPRA sense. To submit a verifiable opt-out request anyway, email hi@asktodo.ai with the subject line “Do Not Sell or Share — CCPA Request”.
If you are a Data Principal under the Digital Personal Data Protection Act, 2023 (India), you have the right to:
To exercise these rights or raise a grievance, email hi@asktodo.ai.
Open and click tracking can be disabled per campaign in the campaign builder. As the sender you are responsible for disclosing tracking to recipients where the law requires it (e.g. some EU jurisdictions).
The dashboard sets only essential cookies (Supabase session tokens, CSRF). It does not load Google Analytics, AdSense, or any third-party tracking script. Internal usage telemetry is server-side (see Section 2.3) and not based on cookies.
The marketing site (asktodo.ai) loads Google Analytics 4 and Google AdSense under Google Consent Mode v2. By default, before you make a choice on the cookie banner:
If you click Accept All, all categories switch to granted. If you click Reject All (or dismiss the banner via the X button), the deny state is persisted, and any pre-existing Google cookies (_ga, _gid, _gat, _gcl_au, NID, IDE, __gads, __gpi) are proactively scrubbed.
To be explicit: ads are visible to all visitors regardless of consent choice. AdSense is loaded unconditionally because it is a core revenue stream. The cookie choice controls only whether ads are personalized (granted) or non-personalized (denied). Showing ads without consent is permitted worldwide; only tracking-based personalization requires consent.
For the full mechanism see our Cookie Policy.
asktodo.ai relies on the following processors to provide the service. Each is bound by its own data-processing agreement and security commitments:
| Subprocessor | Purpose | Data accessed |
|---|---|---|
| Supabase | Database, authentication, file storage, edge functions | All account data, all uploaded files, all telemetry |
| Razorpay | Payment processing & subscription billing (includes PayPal, cards, UPI, net-banking as payment methods) | Name, email, billing address, payment details |
| Groq | AI inference for all generation tools and chat | Prompts you submit + the responses generated. Not used for training. |
| Google (Gmail API) | OAuth send-only access when you connect a Gmail account | Send-scope token. We do not read your inbox. |
| Google (Analytics + AdSense) | Marketing-site analytics and advertising | Cookie-gated. Dashboard pages are excluded. |
| Your own SMTP server (optional) | Direct campaign delivery via your SMTP credentials | You configure and control this directly |
Material changes to the subprocessor list will be reflected on this page with at least 14 days' advance notice for paying customers.
asktodo.ai's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice this means we use Gmail OAuth data only to:
We do not transfer Gmail data to third parties, we do not use it for advertising, we do not allow humans to read it (except with your explicit consent for support or as required by law), and we do not use it for any purpose unrelated to providing the outreach feature.
We protect your information with the following measures:
In the event of a breach affecting your personal data we will notify you and the relevant supervisory authorities without undue delay and, where required by GDPR, within 72 hours of becoming aware of it.
asktodo.ai operates from India. Our cloud infrastructure (Supabase) hosts data in multiple regions including the United States and the European Union, depending on the project region and edge-function execution location.
For data transferred from the EU/EEA or UK to a third country, we rely on the European Commission's Standard Contractual Clauses (SCCs) as our transfer mechanism, plus any supplementary technical measures (encryption in transit and at rest) needed to maintain an equivalent level of protection.
For data transferred under India's DPDP Act, transfers are made to jurisdictions not restricted by the Central Government.
We may publish or share aggregated, anonymous statistics about how the platform is used overall — for example, “asktodo.ai users generated 2 million pieces of content last month” or “the average resume takes 14 minutes to draft.” This data is irreversibly stripped of anything that could identify an individual user.
We will never publish individual prompts, outputs, contact lists, resume content, or any other personally identifiable data without explicit written consent from the user.
We will only feature your logo, name, quote, screenshots, or any other identifying information in our marketing material (website, social media, sales decks, advertising) with your explicit prior written consent. You can withdraw that consent at any time by emailing hi@asktodo.ai, and we will remove the material from active channels within a reasonable period.
asktodo.ai is intended for users 18 years of age or older. We do not knowingly collect personal data from anyone under 18. If we learn that we have collected data from someone under 18, we will delete it promptly. Parents and guardians who believe their child has provided us data should contact hi@asktodo.ai.
We may update this Privacy Policy from time to time. When we do, we will:
For any privacy question, data-request, grievance, or to exercise any right above, please contact us:
Contact email:
Response time: within 30 days.
Operating jurisdiction: Karnataka, India.
Supervisory authority (EU/EEA): You may also lodge a complaint with your local data-protection authority.
Supervisory authority (India): Data Protection Board of India once constituted under the DPDP Act, 2023.