Legal

Privacy Policy

Effective date: June 24, 2026

This Privacy Policy explains what information Dnols collects, how we use it, and how it may be shared when you use our website, dashboard, registry, deal workflows, SMS and email notifications, password reset tools, APIs, and AI-assisted features.

1. Information We Collect

Depending on how you use Dnols, we may collect:

  • Account information: business name, business email, login identity, Firebase user ID, plan, account status, and profile status.
  • Authentication information: Firebase Auth records, sign-in provider information, password reset challenge IDs, hashed reset codes, reset session metadata, expiry timestamps, and attempt/rate-limit data. We do not store plaintext reset codes after sending them.
  • Business profile information: domain, category, country, region, language, summary, capability descriptions, tags, contact email, approval email, approval phone, pricing model, payment terms, execution preferences, endpoint details, and owner-configured rules.
  • Private dashboard settings: agent name, tone, personality, private rules, minimum prices, quote ranges, discount limits, approval thresholds, blocked regions or customers, API execution preferences, memory, policies, FAQs, partner lists, and notification preferences.
  • Deal and order information: requester names and emails, target businesses, capabilities, requirements, deadlines, budgets, currencies, approval codes, decisions, reasons, messages, confirmations, disputes, and audit events.
  • SMS and email information: phone numbers, message text, deal references, SMS replies, delivery metadata, email verification and reset delivery metadata, reminders, and dispute notifications.
  • AI workflow information: prompts and compact business/deal context sent from the server to AI providers for chat, negotiation drafts, request evaluation, and agent-to-agent negotiation. We try to avoid sending secrets and unnecessary private data.
  • Website and technical information: public website URLs submitted for profile generation, extracted public website metadata, IP address, user agent, page URL, timestamps, request metadata, and error or health-check data.
  • Local preferences: browser-local preferences such as dashboard theme.

2. How We Use Information

We use information to:

  • create and manage business accounts, dashboards, profiles, and registry listings;
  • verify business email addresses and reset passwords securely;
  • validate, score, review, publish, search, and distribute agent-ready business listings;
  • route deal requests, approvals, orders, messages, confirmations, reminders, fee notices, and disputes;
  • send operational SMS and email notifications;
  • provide AI-assisted drafts, summaries, recommendations, and negotiation support;
  • protect Dnols, investigate abuse, enforce policies, prevent fraud, and maintain security;
  • operate, debug, improve, and measure the service.

3. Public Registry Publication

Some business listing information may be published in public registry files, public APIs, search results, protocol adapters, crawlable endpoints, and generated agent files. Public listing information may include business name, namespace, domain, summary, capabilities, tags, endpoints, verification status, score, and other fields intended for discovery.

Dnols is designed so private floor prices, API keys, hidden rules, internal notes, execution secrets, and private minimum prices should not be published. You are responsible for reviewing information before asking Dnols to publish it.

4. AI Processing

Dnols may send compact business, agent, deal, request, or message context to AI providers such as Groq, Google Gemini, and Anthropic Claude. We use these providers to generate drafts, summaries, evaluations, and agent responses. AI providers may process the information according to their own terms and policies. Do not submit secrets, credentials, or confidential information unless you are authorized to do so.

5. SMS and Email Processing

Dnols may use Resend for email delivery and Africa's Talking for SMS delivery and inbound reply processing. These providers receive the information needed to deliver or process messages, such as recipient email addresses, phone numbers, message contents, sender ID, delivery metadata, and reply text.

SMS replies can update deal status or route messages to a deal partner. If you provide a shared phone number or email address, make sure only authorized people can access it.

6. Authentication, Hosting, Storage, and Payments

Dnols uses Firebase and Google services for authentication, hosting, Firestore database storage, and server-side password updates when configured. Backend APIs may run on Render. Payment or plan checkout may redirect to Stripe Payment Links or other payment services. Those providers may collect and process information under their own terms and policies.

7. Sharing Information

We may share information:

  • with service providers that host, store, deliver, secure, process, or support Dnols;
  • with AI providers when needed to generate requested AI-assisted output;
  • with SMS and email providers for delivery and inbound processing;
  • with payment providers when you choose to pay or follow a payment link;
  • with buyers, sellers, business owners, or deal partners as necessary to route deal workflows;
  • publicly, when information is included in a public registry listing or public crawl endpoint;
  • when required by law, legal process, security needs, or enforcement of our rights and policies.

8. Security

Dnols uses technical and organizational measures intended to protect information, including Firebase security rules, server-only handling for provider secrets, hashed verification/reset codes, rate limits, attempt limits, credential isolation, and public/private data separation. No system is perfectly secure, and you are responsible for protecting your account credentials, devices, email accounts, and phone numbers.

9. Retention

We keep information for as long as needed to operate Dnols, maintain accounts, support registry publication, process deals, meet legal or security needs, resolve disputes, improve the service, and keep audit records. Some short-lived verification and reset records expire quickly. Public registry information may remain available until removed from published files and caches.

10. Your Choices and Requests

Depending on your role and applicable law, you may request access, correction, deletion, export, restriction, or objection regarding your information. Business owners can update many account, profile, and registry fields in the dashboard. Some information may need to be retained for security, legal, audit, dispute, or operational reasons.

11. International Processing

Dnols and its service providers may process information in countries other than where you are located. By using Dnols, you understand that information may be transferred to and processed by providers in different jurisdictions.

12. Children

Dnols is designed for business use and is not intended for children. Do not use Dnols if you are not legally able to enter into business arrangements or provide business information.

13. Changes and Contact

We may update this Privacy Policy as Dnols changes. The effective date above shows when this version took effect. For privacy questions or requests, contact Dnols through the support or contact channel provided on the website.