Legal
Privacy Policy
Effective 26 July 2026
Doestep is the verification layer for AI knowledge, operated by Intellopia (“Doestep,” “we,” “us”), based in Asaba, Delta State, Nigeria. This policy explains what we collect, why, and what we never do with it. It’s written to be read, not to hide behind, in keeping with the fact that trust is the entire product.
1. Sign in with GitHub, we never store passwords
Doestep uses GitHub OAuth for authentication. You sign in with GitHub, and GitHub confirms your identity to us. We never see, receive, or store your GitHub password. To keep you signed in, we store an OAuth token issued by GitHub and a session record in our database. You can revoke Doestep’s access at any time from your GitHub account settings.
2. What we collect
- Public GitHub profile data: your name, username/handle (GitHub login), and avatar image URL.
- Your email address, if your GitHub profile makes one available to us at sign-in. We use it only to identify your account and, where relevant, to contact you about your account.
- Content you create: the playbooks you publish (including every field of each frozen version: title, summary, target models, stack, inputs, expected output, cost estimate, and your golden example) and the reproduction reports you file (result, the model version you ran, and any optional note or failed-step detail you add).
- Your Doestepper profile: your public handle, optional bio, and the date you joined.
- Basic technical data needed to operate the service, such as session records and standard server logs.
3. What we do not do
- We do not access, read, clone, or write to your GitHub repositories. We request public profile information only. Our OAuth token is used to confirm who you are, never to reach your code.
- We do not run ads, and we never sell or rent your personal data to third parties. This is a permanent commitment, not a current setting: ads poison trust, and trust is the product.
- We do not build advertising profiles or share your data with data brokers.
4. How we use your information
We use your information to create and display your public Doestepper profile; attribute the playbooks you publish and the reports you file; compute freshness badges and reputation from your reproduction history (these are derived from your report log, never sold or exposed as raw personal data); operate, secure, and debug the service; and contact you about your account when necessary.
5. What is public by design
Doestep is a public record of what works. Your handle, avatar, published playbooks, and the reproduction reports you file are publicly visible, and that visibility is what makes verification meaningful. Please don’t put anything private into a playbook, a golden example, or a report note. Your email address is not shown publicly.
6. Where your data is stored, and international transfer
Your data is stored in a PostgreSQL database hosted by Neon, and the application is hosted on Vercel. Both are third-party infrastructure providers that process data on our behalf under their own security and privacy terms. We operate from Nigeria, and these providers process data in the United States and other regions, so by using Doestep you understand your data will be transferred and processed internationally.
7. Cookies and sessions
We use a small number of strictly necessary cookies to keep you signed in and to remember your light/dark theme preference. We do not use advertising or cross-site tracking cookies.
8. Data retention and deletion
You can request deletion of your account and personal data at any time by emailing us (see Contact). When you do, we delete or anonymize your profile data (name, email, avatar, bio, handle) and revoke your sessions.
One honest exception, by design: reproduction reports are append-only public evidence, and other people’s badges depend on them. Rather than erasing reports, which would silently rewrite the verification record others relied on, we dissociate them from your identity (anonymize authorship) while preserving the underlying result. If you need a specific report fully removed (for example, because it contains information that shouldn’t have been posted), tell us and we’ll handle it directly.
9. Your rights
Subject to Nigerian data-protection law (including the Nigeria Data Protection Act) and any other law that applies to you, you may have rights to access, correct, export, or delete your personal data, or to object to certain processing. To exercise any of these, contact us and we’ll respond within a reasonable timeframe.
10. Children
Doestep is not directed to children under 16, and we don’t knowingly collect their data.
11. Changes to this policy
If we make material changes, we’ll update the effective date above and, where appropriate, notify signed-in users. Continuing to use Doestep after a change means you accept the updated policy.
12. Contact
Questions about privacy or a deletion request? Email support@doestep.com.
See also our Terms of Service.