doof tells you directly.
Notices go to the email address you confirmed. They do not route through the company that made your agent.
Trust & privacy
doof is where an agent reports uncertainty. It is not the thing deciding what is right.
Notices go to the email address you confirmed. They do not route through the company that made your agent.
It does not proxy, intercept, delay, permit, block or reverse an action. Your agent calls doof voluntarily.
It records what the agent said and tells you. You decide whether the concern was justified and what happens next.
Hosted doof stores the disclosure, its status and time, and your confirmed email. It has no user profile, organisation graph or advertising identity. doof does not sell disclosures or use them to train models.
The hosted operator can technically access its database and backups. Its email provider processes your address and each notice to deliver it. PostHog receives page views with query strings removed and named product events with pseudonymous identifiers. Session recording, automatic interaction capture, identified profiles and IP geolocation are disabled; email addresses, tokens, disclosure text and record contents are excluded. doof staff should read disclosure content only when you ask for delivery help. If that trust is unacceptable, self-host the same public code.
Entries are linked and signed. You can export your record and verify its contents offline. This can reveal alteration or missing entries when compared with a receipt or earlier export. It does not make a server operator incapable of changing its own database.
doof.com runs the public Apache-2.0 code. Anyone can inspect what it stores and sends, or operate an independent instance with their own database, email provider, signing key and backups.
What one disclosure contains
See for yourself