Privacy Policy
Last updated: September 2, 2026
Who we are
Dorima is operated by Adam Kofod, an individual in California, United States ("Dorima," "we," or "us"). Contact: privacy@dorima.app.
This policy covers Dorima's application, waitlist, invitations, and related services.
Information we collect
Depending on how you use Dorima, we collect:
- Account and pre-account information, including your email address, authentication records, waitlist submission, invitation, and invitation-redemption records.
- Content you provide, including journal entries, tasks, habits, projects, chats, calendar information, files, and information you choose to add to About me, such as facts about where you live or work, your family, and your preferences.
- Integration information, including authorization tokens and data from services you connect, such as Google Calendar.
- Derived information, including summaries, patterns, advisor notes, embeddings used for search, and limited automated distress classifications.
- Operational information, including consent and acceptance events, AI-usage and cost records, performance timing, error reports, and security logs.
Journal content and attached files may contain sensitive information. Please submit only information you want Dorima to process as described here.
How we use information
We use information to:
- provide and secure Dorima;
- display, organize, search, and summarize your content;
- provide AI-assisted features you enable;
- synchronize connected services;
- send account and service messages;
- diagnose errors and prevent misuse; and
- maintain records of your choices and acceptance of our terms.
Dorima does not sell personal data or use advertising trackers or product-analytics platforms. Dorima does collect limited first-party performance and error telemetry.
AI processing
Dorima asks for a separate affirmative choice before processing your content with AI. You may pause AI processing in Settings. While processing is paused, AI-dependent features will be unavailable, but pausing does not itself delete stored data.
When AI processing is on, Dorima may use relevant About me information in responses and other AI features for your account.
Dorima uses:
- Anthropic to generate replies, summaries, patterns, and other AI-assisted output. Relevant journal content, tasks, goals, calendar information, relationship context, chat history, documents, profile details you provide (such as your name and pronouns), your approximate location if you share it, and records Dorima has derived from your content (summaries, patterns, and notes) may be sent to Anthropic. When chat needs current information, Dorima may run a web search through Anthropic. The model composes the search query from your conversation, and Dorima instructs it to leave names, journal text and identifying details out of it. Results appear in chat with their sources.
- OpenAI only to create search embeddings. Dorima sends text from captures, the user side of chats, Dorima-generated advisor notes, and short Dorima-generated search queries, labels, and questions derived from that content. Dorima's model-feedback, evaluation/fine-tuning, and input/output sharing settings are disabled.
AI output may be incomplete or wrong and should not be treated as medical, legal, financial, or other professional advice.
Distress classification
Dorima may apply an automated distress classification to some newly captured text and chat turns. It is not applied to every record and may miss or misidentify distress.
A positive classification can make a capture confirmation quieter and prevent a cross-advisor feature from running for that entry. It does not notify a person, trigger human review, create an alert or escalation, contact emergency services, or initiate crisis intervention. Do not rely on Dorima for emergency assistance.
Dorima is a tool for reflecting on your life, not a replacement for professional mental health care. If you're in crisis, please reach out to 988.
Removing and editing journal entries
When you remove a journal entry, it disappears from your journal and Dorima stops using it in future search, summaries, and AI processing. The stored entry is not permanently erased.
Journal edits are recorded as corrections rather than overwriting the original stored event. Permanent deletion of an individual journal entry is not currently available.
Service providers
Dorima uses service providers only as needed to operate the service:
- Supabase for database storage, file storage, and authentication;
- Vercel to run the application;
- Cloudflare to run background processing;
- Anthropic and OpenAI for the AI processing described above;
- Google for Calendar integration when connected;
- Open-Meteo provides weather information when you choose to share your approximate location. It receives approximate coordinates for that purpose.
- Sentry for error reporting and operational logs; and
- Resend for account and service email.
These providers process information under their own contractual and legal obligations.
Security
Dorima encrypts designated content, file, and authorization-token fields before storage and uses encrypted connections in transit. Some metadata and operational fields are not encrypted at the application layer.
Dorima enforces account isolation at the database: authenticated application requests are scoped to a single account.
Dorima controls the encryption keys. Adam, as Dorima's operator, and Dorima's running systems can technically decrypt content when necessary to operate the service. Dorima is not end-to-end encrypted or designed so that operator access is cryptographically impossible.
No security system can guarantee absolute protection.
Retention and deletion
We retain account information and content while your account remains active, subject to the following:
- Removed journal entries remain in the primary database until account deletion.
- Account deletion removes account-scoped database records and uploaded files.
- Separate pre-account records—such as waitlist, invitation, and invitation-redemption records—are not currently removed automatically with an account. Contact privacy@dorima.app about those records.
- Deleted database records may remain in rolling daily backups for up to seven days. Uploaded storage objects are not included in those database backups.
- When your trial ends, your account moves to Dorima Free. Your account and stored information are not deleted automatically. You may still export the data included in Dorima's export tool or delete your account.
- Anthropic normally retains API inputs and outputs for up to 30 days after receipt or generation. Zero Data Retention is not enabled. Anthropic may retain information longer when required by law or necessary to enforce its usage rules.
- OpenAI may retain embedding inputs in abuse-monitoring logs for up to 30 days under its default controls. It does not retain application state for the embeddings endpoint. Dorima's voluntary data-sharing controls are disabled.
- Vercel runtime logs are retained for one day under Dorima's current plan. Build logs are retained with deployments indefinitely but currently contain no user content.
- Retention periods for Sentry and Resend have not yet been verified, so Dorima does not promise a specific deletion deadline for provider-held records in those systems.
- After account deletion, Dorima retains a minimal record of your acceptance of the Terms and acknowledgment of this policy. That record is currently retained indefinitely and contains a keyed identifier, acceptance time, checkbox wording, and document versions and hashes, but no journal content.
Your choices
You may:
- view and correct information through Dorima's interfaces;
- remove journal entries from ordinary use, subject to the storage limitation above;
- download the information included in Dorima's export tool;
- pause AI processing;
- disconnect integrations; and
- delete your account in Settings.
The export tool is not currently represented as a complete copy of every operational or pre-account record.
For other privacy requests, contact privacy@dorima.app.
Location and eligibility
Dorima is operated from the United States and is offered only to United States residents. This does not mean all processing occurs only in the United States.
Dorima's OpenAI project uses Global residency and its inference location is not pinned. OpenAI and other providers may process information in the United States or other locations where they operate.
Children
Dorima is not intended for anyone under 18. If you believe a person under 18 has created an account or provided personal information to Dorima, contact privacy@dorima.app.
Changes
We may update this policy as Dorima changes. We will provide notice of material changes through the application or by email. Where a new affirmative acknowledgment is appropriate, we will request one rather than relying solely on continued use.