Privacy Policy

Last updated 3 August 2026

This policy explains what personal data Doers Movement handles, why, and what your rights are. It covers two very different groups of people, and the distinction matters: our customers (founders and their teams who use the product), and the prospects our customers research (people in the lead lists customers bring in).

1. Who is responsible

Doers Movement operates the Service. For customer account data we are the data controller. For prospect data that a customer uploads or asks us to research, the customer is the controller and we act as their processor, handling that data only on their instructions.

Contact for any privacy question: george.calcea@cubeo.ai.

2. Data we hold about customers

  • Account data — name, email address, password hash, team membership and role, and two-factor settings if you enable them.
  • Workspace content — your ICP and persona definitions, the problems and solutions you describe, notes, and everything else you create in the product.
  • Billing data — subscription and payment status. Card details are handled by Stripe and never reach our servers.
  • Usage and technical data — log entries, IP address, browser type, error reports and feature usage, used to run and debug the Service.

Legal basis: performance of our contract with you for account, workspace and billing data; our legitimate interest in a secure, working product for technical and usage data.

3. Data we process about prospects

When you bring a lead list into the Service, or ask the agent to research a company or contact, we process business-context personal data about those people: name, job title, employer, professional profile URLs, business email address, publicly available posts and company information, and the qualification verdicts and message drafts our AI produces about them.

We process this only to deliver the Service to the customer who brought the data in. We do not build our own marketing database from it, we do not sell it, and we do not share it between customers. The customer is responsible for having a lawful basis (typically legitimate interest for B2B outreach) and for meeting their own transparency obligations toward those prospects.

4. AI processing

Qualification, research summaries and message drafting are performed by large language models. To do that we send the relevant parts of your workspace content and prospect records to AI providers acting as our subprocessors. We use providers under terms that prohibit training their models on data we send. AI output is stored alongside the record it relates to, including the reasoning behind each verdict, so that you can audit it.

5. Subprocessors

We rely on a small set of vendors to run the Service:

  • Cloud hosting and databases — our infrastructure provider, hosted in the EU.
  • AI model providers — for qualification, research and message drafting.
  • Data enrichment and web research — email verification, web scraping and search providers used to gather publicly available company and contact information.
  • Payments — Stripe, for subscriptions and invoicing.
  • Email delivery and product communications — for transactional and product emails.
  • Error monitoring and analytics — to detect and fix faults, and to understand product usage.

We will provide the current named list of subprocessors on request, and to customers with a data processing agreement in place we will give notice of changes to it.

6. International transfers

We host in the EU. Some subprocessors, particularly AI providers, may process data outside the EEA. Where that happens we rely on the EU Standard Contractual Clauses or an adequacy decision.

7. Retention

We keep workspace and prospect data for as long as your account is active. After you close your account we keep it for up to 30 days so it can be restored or exported, then delete it, except where we must keep records longer for accounting or legal reasons (invoices, typically for the statutory period). Backups roll off on their own cycle within 90 days. You can delete individual records at any time from inside the product.

8. Security

Data is encrypted in transit and at rest. Access is scoped per team, so one customer's workspace is not reachable from another's. Internal access to production data is limited to the people who need it to operate the Service, credentials and API keys are stored encrypted, and two-factor authentication is available on all accounts. No system is perfectly secure; if a breach affects your data we will notify you and the relevant supervisory authority as the GDPR requires.

9. Your rights

If you are in the EEA or the UK you can ask us to give you a copy of your data, correct it, delete it, restrict or object to its processing, or provide it in a portable format. Write to george.calcea@cubeo.ai and we will respond within one month.

If you are a prospect who has been contacted by one of our customers and you want your data corrected or removed, contact that customer directly, since they control it. If you contact us instead, we will pass your request to them and help them act on it. You also have the right to complain to your national data protection authority.

10. Cookies

We use cookies that are strictly necessary to keep you logged in and to protect forms against cross-site request forgery. Where analytics are enabled we use them to understand aggregate product usage. We do not run advertising or cross-site tracking cookies.

11. Changes

We will update this policy as the product changes. Material changes are announced to account holders by email or in the product before they take effect, and the date at the top of this page always reflects the current version.