Privacy Policy

Last updated October 7, 2026

Dozif helps agencies and freelancers find business websites by the technology they run on. This policy explains what personal data we handle, why, and the choices you have. It covers two groups of people: our users, who sign up and use Dozif, and people connected to the websites we list, whose business contact details appear on those websites.

Data about our users

When you create an account and use Dozif, we keep:

  • Account details: your name, email address and password (stored only as a secure hash by our authentication provider). If you sign in with Google, we receive your name and email from Google.
  • What you save: lead lists, statuses and notes, saved searches, bulk lookups, and the websites you ask us to analyze.
  • Billing: your plan and subscription status. Card details are handled by Stripe and never reach our servers.
  • Usage: counts we need for plan limits, such as export rows and daily analyses.
  • Messages: anything you send through the contact form.
  • AI features: the details you enter to write an outreach email, and the drafts produced.
  • Connected apps: if you connect ChatGPT, Claude or another assistant, which app it is and when it was last used.

We use this to run your account, provide the features you use, take payments, answer you, keep the service secure and improve it. We don't sell your data, and we don't use it for advertising.

Data about listed websites

Dozif visits publicly available business websites and records what they are built with, their niche and country, and signs of problems such as an outdated footer or broken links. Where a business publishes contact details on its own website (an email address, phone number, postal address or social profile), we record those too.

We only collect what the business itself has made public on its website. We don't buy data, guess email addresses or look for personal profiles. We process this data on the basis of legitimate interests: helping businesses that offer web services find companies that may need them. Our users are responsible for contacting businesses lawfully, as our Terms require.

If you own a listed website and want it removed, use our removal form. We hide the site from search, profiles and exports and confirm by email.

Services we use

We rely on these providers to run Dozif. Each one only gets what it needs for its job:

  • Supabase: database, sign-in and file storage.
  • Vercel: hosting, plus privacy-friendly analytics and performance measurement that don't use cookies.
  • Stripe: payments and invoices.
  • Anthropic: writes AI outreach emails when you ask for one. It receives facts about the website and the sender details you enter.
  • Cloudflare Turnstile: checks that sign-ups and sign-ins come from people, not bots.
  • Email delivery provider: sends account emails, alerts and replies.
  • Google: sign-in with Google (if you choose it), and Google PageSpeed for website speed tests, which receives website addresses only.

Some of these providers process data outside your country. Where that happens, we rely on the safeguards they offer, such as Standard Contractual Clauses.

Cookies and local storage

We don't use advertising or tracking cookies. We use:

  • Sign-in cookies that keep you logged in.
  • A preference cookie that remembers whether you collapsed the sidebar.
  • Your browser's local storage for small conveniences: theme, table layout, a dismissed checklist and the sender details for AI emails. This stays on your device.

The security check on sign-up and sign-in is run by Cloudflare and may set its own technical cookie for that purpose.

How long we keep data

We keep your account data while your account exists. You can delete your account at any time from Account in the app: this removes your account, lists, notes, saved searches and connected apps straight away, and cancels any subscription. Copies in backups are overwritten in the normal course of things. Stripe keeps invoices as long as accounting rules require.

Data about listed websites stays while the website is public and relevant, and is removed when its owner asks.

Your rights

Depending on where you live (for example under the GDPR in the EU and UK, or the CCPA in California), you can ask to access the personal data we hold about you, correct it, delete it, object to or restrict how we use it, or receive a copy. You can also complain to your local data protection authority.

To use any of these rights, contact us or, for a listed website, use the removal form. We may need to confirm it's really you before we act.

Security

Data travels over encrypted connections, passwords are never stored in plain text, and access to our systems is limited to what each part needs. No system is perfectly secure, but we work to protect your data and fix problems quickly.

Children

Dozif is a business tool and isn't meant for anyone under 16. We don't knowingly collect data from children.

Changes to this policy

If we change this policy, we'll update the date at the top. For important changes, we'll tell signed-in users by email or in the app.

Questions about this page? Contact us.