Privacy
Plain language, deliberately. Last updated 29 July 2026.
This policy covers the BooDoo web app at boodoo.ai, the BooDoo Android app, and the BooDoo iOS app. It explains what personal data we handle, why, and what you can make us do about it.
Who is responsible for your data
BooDoo is operated by two companies, and which one is the data fiduciary for your information depends on how you use it:
- The Android app, installed from Google Play — DesignNicely Technologies Private Limited
- The iOS app, installed from the App Store — CodeNicely Software Services LLP
- The web app at boodoo.ai — CodeNicely Software Services LLP
The two companies run one service on one set of systems and apply this single policy. Where one processes data on the other's behalf, it does so under a written arrangement and on the same terms you are reading here. Registered addresses and grievance contacts for both are at the end of this page.
What we collect
Only what the service needs to run, and nothing collected "just in case".
Your account
Your name, email address, a hashed password (we never store the password itself), and the country you pick when you sign up. If you sign in on more than one device we keep the session tokens that keep you signed in.
What you build
Your descriptions and messages to the builder, the code of the apps it writes for you, and the data those apps store. Each project gets its own database with its own credentials, isolated from every other project.
Photos and files you attach
When you attach a photo or a document as a brief — a menu, a price list, a logo — we store it and send it to our AI provider so it can be used in your app. The Android and iOS apps ask for access to a specific picture you choose through the system picker; neither reads your photo library.
Your voice, if you use the microphone
On the website and in the mobile apps, you can describe an app by speaking instead of typing. The microphone is on only while you have started speaking and is switched off the moment you stop; it is never listening in the background, and there is no microphone at all until you tap one. While you speak, the sound goes through BooDoo to ElevenLabs, who turn it into words. We do not keep the recording — it passes through and is never saved on our side. ElevenLabs does keep what it transcribes, under its own privacy policy. The words appear in the box for you to read and change; nothing is ever sent automatically, and typing always works instead.
On Android and iPhone, if speaking this way is unavailable — no signal, say — the app falls back to your own phone's speech recognition, which on most Android phones is Google's and converts the sound to text under Google's policy.
Billing
The billing name, address, state and optional GSTIN you give us so we can issue a tax invoice, and a record of what you bought and when. Card, UPI and netbanking details go to Razorpay directly — we never see or store them.
Operational and device data
Logs of requests, builds and errors, what each AI turn consumed, and the app version, operating system version and language of the device you use. IP addresses appear in security and rate-limiting logs. We use a coarse country lookup on your IP to guess your currency and region; it never resolves to a street or a city.
Notifications
If — and only if — you agree when we ask, we keep a notification address for that device, along with the language it reported and how far its clock is from UTC. The address comes from Google’s Firebase Cloud Messaging, which delivers the notification; the language decides which one of ours you get, and the clock offset is what stops us sending anything overnight. We use them for one thing: telling you about your own apps. We never use them to advertise, and we never give them to anyone. Signing out of a device deletes its address, and you can switch any kind of notification off at any time in your account settings.
What we do not collect
- Precise location. The apps never ask for it and cannot read it.
- Your contacts, calendar, call logs, SMS, or your photo library as a whole.
- Health, biometric, or financial-account data.
- Adverts inside BooDoo. There are none, on any screen, in any app.
- Automatic crash reports. We do not collect these. If that changes, this page changes first and the Play Data Safety declaration changes with it.
Why we use it, and on what basis
Under the Digital Personal Data Protection Act, 2023 we process your personal data with your consent, given when you create an account and use the service, and for the legitimate uses the Act allows — chiefly performing the service you asked for and meeting a legal obligation.
- To build what you asked for. Your descriptions and code go to our AI provider. That is the product, not a side effect of it.
- To run and secure the service — hosting your apps, keeping you signed in, rate-limiting abuse, investigating incidents.
- To bill you and issue the tax invoice the law requires.
- To talk to you — password resets, verification, build notifications, and support replies.
- To make the product better, using aggregate figures about how features are used.
- To find out which adverts are worth paying for. We advertise on Google and Meta, and this tells us which advert brought someone here and whether it was money well spent. On the website that means the pages you looked at before signing in. In the Android app it also means the advertising ID your phone carries, which is how an app install can be matched to the advert that led to it — the iPhone app reads no such thing. In Europe and the UK we ask you first and nothing happens unless you say yes. Everywhere else you can say no at any time, in the app’s account screen, and both stop immediately. This is the only thing on this page you can switch off and keep using BooDoo exactly as before.
We do not sell your personal data, and we do not use your projects to train AI models. What you build, what you write to it, and what your app stores are never used for advertising and are never sent to an advertising company. The measurement described above covers how you found us and what you paid — never what you made.
Who else touches it
A short list of processors, each doing one job under a contract that limits them to that job:
| Who | For what | Where |
|---|---|---|
| Anthropic | The AI that reads your description and writes your appYour prompts, your project's code, and any file you attach | United States |
| Razorpay | PaymentsYour billing name and address; card and UPI details go to them directly and never reach us | India |
| Mailgun | Account and notification emailYour email address and the contents of the mail we send you | European Union |
| DigitalOcean and Microsoft Azure | Hosting for the platform and for the apps you publishEverything the service stores, at rest | India and Singapore |
| Pexels | Stock photography the builder places into apps it makesThe search words derived from your description — never your account details | Germany |
| ElevenLabs | Turning speech into text when you use the microphoneThe audio recorded while you are speaking, and the text it becomes — we relay it and never store it; they keep it under their own policy | United States |
| Google (Analytics and Ads) | Measuring which adverts bring people here, and how the website and the Android app are used. Only where you have agreed, or where the law does not require us to askPages you visited, the advert you arrived from, how you used the Android app, the advertising ID that phone carries, and — when you buy — the value of the purchase and a scrambled form of your email that only Google can match | United States |
| Meta | Measuring which adverts bring people here, and which adverts lead to an app install. Only where you have agreed, or where the law does not require us to askPages you visited before signing in, the advert you arrived from, the fact that the Android app was opened and the advertising ID that phone carries, and — when you buy — the value of the purchase and a scrambled form of your email | United States |
The last two are different from the rest, and it would be misleading to list them without saying so. Everyone above them works only on our instructions. Google and Meta also use what they receive for their own purposes, under their own terms, which is what an advertising company does — so they are not simply working for us in the way the others are. They only receive anything at all where you have agreed, or in countries where the law does not require us to ask, and never from inside your workspace.
Our staff can access a workspace to operate the service or investigate an abuse report, and every such access is logged. We also disclose data where the law requires it — a valid court order or a lawful request from an authority.
Some of these providers are outside India, so your data is transferred abroad to the extent needed to deliver the service. We only use countries the Indian government has not restricted for this purpose, and we require contractual protection equivalent to this policy.
How long we keep it
- Your account, projects and their data: for as long as your account exists, and then deleted when you delete it.
- An app you have put away stays recoverable until you choose to delete it forever, which is irreversible and says so.
- Operational logs: up to 12 months, then discarded.
- Invoices and payment records: eight years. Indian tax law requires us to keep them, so these survive account deletion. Nothing else does.
How we protect it
Everything travels over TLS. Passwords are hashed, never stored. API keys and secrets you give a project are encrypted at rest and shown back to you masked. Every project's database and operating-system user is separate from every other project's, and generated code is executed in a confined sandbox rather than on the platform's own account. If a breach affects your data we will notify you and the Data Protection Board as the law requires.
Your rights
Under the DPDP Act you can, at any time:
- Get a copy of the personal data we hold about you and a summary of how it is processed.
- Correct or complete anything inaccurate — most of it you can edit yourself in your account.
- Erase it. See deleting your account.
- Withdraw consent, as easily as you gave it. Withdrawing it generally means closing your account, because the service cannot run without the data it runs on.
- Nominate someone to exercise these rights for you if you die or become incapacitated — write to us and we will record it.
- Complain to our Grievance Officer, and after that to the Data Protection Board of India.
Write to privacy@boodoo.ai and we will act within 30 days. We may ask you to confirm who you are first — that check protects you, not us.
Deleting your account
You can delete your account and its data from inside the app — Account → Delete account — or from the web. Full instructions, and what survives, are on the account deletion page. You will be asked to delete or hand over your apps first, because deleting an account with live apps would take someone else's working website down without warning.
Children
BooDoo is for people aged 18 and over. We do not knowingly collect data from children, and we do not direct the service at them. If you believe a child has created an account, tell us and we will delete it.
Cookies
Some cookies keep you signed in and remember how you like the workspace set up. Those are what makes the site work, so they are always on and there is nothing to agree to.
If you arrive on a referral link — from a college, an event, or someone who shared one — we remember the code for 30 days so the credits it promises reach your account when you sign up. It holds that code and nothing else, it is never sent to anyone outside BooDoo, and it goes when your account does.
The rest are for measuring adverts, and they are the ones you get a say over. They record which advert you arrived from and which pages you looked at, so we can tell which adverts are worth paying for. Google and Meta can recognise the same browser on other sites they measure. In Europe and the UK we ask before setting any of them, and nothing is set until you say yes. Elsewhere they are on by default and the banner is available if you want to turn them off.
None of them load inside your workspace — the pages where you build and where your own information is on screen carry no advertising cookies at all, whatever you have agreed to. The mobile apps use no cookies; they hold your session token in the device's encrypted storage.
Grievance Officer
Under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDP Act, each operating company names an officer for complaints. We acknowledge within 24 hours and resolve within 15 days.
DesignNicely Technologies Private Limited
PENDING — awaiting founder input
grievance@boodoo.ai
PENDING — awaiting founder input
PENDING — awaiting founder input
CIN: PENDING — awaiting founder input
CodeNicely Software Services LLP
PENDING — awaiting founder input
grievance@boodoo.ai
+91 8109109457
2nd Floor, House, 106/3, Avanti Vihar Rd
Geetanjali Nagar, Sector - 3, Shankar Nagar
Raipur, Chhattisgarh 492004
LLPIN: PENDING — awaiting founder input
Changes to this policy
When we change something that matters we will update the date at the top and, for a material change, tell you by email before it takes effect.
Reaching us
General: hello@boodoo.ai · Privacy: privacy@boodoo.ai · Security: security@boodoo.ai · Postal addresses on the contact page.