Privacy & Terms

Privacy policy

Draoi stores what it needs to run your account and your decks: your email, your projects/decks/cards (including the content your agent writes), your review history, and a log of the actions your agent takes through MCP (so you can see what it changed and why).

We don't run any first-party AI — the agent that authors your cards is your own (Claude, Codex, or whatever you connect), operating over the Model Context Protocol against your account. We don't sell your data or share it with third parties beyond what's required to run the service (e.g. sending you email for password resets).

Passwords are hashed (bcrypt); API and pairing tokens are stored hashed, never in plaintext.

Your data (GDPR)

If you're in the EU (or anywhere else — we apply this to everyone), you have the right to export and delete your data at any time.

We keep review-log data only as long as your account exists; deleting your account removes it along with everything else.

Terms of service

Draoi is provided as-is, without warranty. You're responsible for the AI agent you connect and the content it authors on your behalf — review what it creates before you rely on it to study.

Don't use draoi to store or generate unlawful content. We may suspend accounts that abuse the service (e.g. hammering the MCP endpoint past its rate limits).

These terms may change as the product evolves; material changes will be reflected on this page.