Privacy Policy
Last updated: October 7, 2026
This policy explains how Dojito ("we", "us") handles information on dojito.com and in the software we operate, including Dojito Autopilot, our internal tool that publishes our own content to our own YouTube channels and X account.
1. Information we collect
- Information you send us, such as your name, email address, and message when you use our inquiry form or email us.
- Basic technical data (for example IP address, browser type, and pages visited) that our hosting and security provider, Cloudflare, processes to deliver and protect the site.
- Data from connected accounts. When an account owner authorizes Dojito Autopilot with Google (YouTube) or X, we receive OAuth access and refresh tokens and the account information those services return, such as the channel or account ID and name.
2. How we use information
- To reply to inquiries and provide the services you ask for.
- To upload and manage videos, metadata, and posts on channels and accounts that the account owner has authorized.
- To keep the site and our systems secure and working.
We do not sell personal information, and we do not use it for advertising.
3. Google user data
Dojito Autopilot's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We request YouTube scopes only to upload videos and manage metadata on channels the account owner has authorized.
- We do not use Google user data to train AI or machine-learning models, and we do not share it with third parties except as needed to provide this feature, to comply with law, or with the owner's consent.
- OAuth tokens are stored only on our own servers, with restricted access.
- Our use of YouTube is also subject to the YouTube Terms of Service and the Google Privacy Policy.
- You can revoke access at any time at myaccount.google.com/permissions.
4. X (Twitter) data
We use the X API only to publish and manage posts on our own X account. Tokens are stored on our own servers. Access can be revoked under Settings → Security and account access → Apps and sessions on X.
5. Sharing
We share information only with service providers that help us run our business, such as hosting (Cloudflare), email delivery, and payment processing (for example Lemon Squeezy, which acts as merchant of record for purchases). We also share information when the law requires it.
6. Retention and deletion
We keep inquiry emails for as long as we need them to respond and keep business records. We keep OAuth tokens until access is revoked or no longer needed. To ask us to access or delete your information, email djkim@dojito.com.
7. Security
We use reasonable technical and organizational measures to protect information, including encrypted connections (HTTPS) and restricted access to credentials.
8. Children
Our services are not directed to children under 13, and we do not knowingly collect their personal information.
9. Changes
If we update this policy, we will change the date at the top of this page.
10. Contact
Dojito · Toronto, Canada · djkim@dojito.com