Privacy

This draft covers the public letsdao.org website, an early-access request, and emails sent to the team. It is not the Privacy Policy for the Lets mobile app.

Document status

Not in effect. Last updated: August 27, 2026. Version: privacy-draft-2026-08-27-v5. This working draft is pending technical verification and legal review. The closed beta is already running, so a separate mobile-app policy remains a required gate before the next expansion of the test.

Who is responsible for data

Igor Olegovich Ufimtsev is identified as the controller for data connected with the public site and incoming emails. Requests can be sent to privacy@letsdao.org. LetsDAO is not a separate legal entity or independent data controller. The mobile-app operator must be confirmed separately before the closed beta expands.

What the site does not collect

The site has no registration, account area, newsletter, advertising pixels, session replay, or optional analytics. Its only public form is for early-access requests; contact and partner messages still use email.

Early-access request

The form asks for an email address and one choice: friends, family, a team or community, or exploring on your own first. The site also processes the page language and address, consent, submission metadata, and anti-abuse signals. The request is delivered through Resend to the team's Yandex 360 mailbox. We use this information only to review the request, contact the person about an invitation, and protect the form from abuse.

When you email us

The team receives the sender's email address, name in the message, message text, and delivery metadata. Email is processed through Yandex 360 only to read and answer the message and protect the email channel from abuse. It is not used for advertising, profiling, newsletters, or automatic beta selection.

Technical delivery data

Vercel and network providers may process an IP address, request time, page address, user-agent, and technical logs needed to deliver and protect the site. The exact fields, retention periods, and processing regions must be confirmed with the providers before this policy is approved.

Cookies and analytics

Optional analytics, advertising cookies, marketing pixels, A/B testing, and session replay are disabled. The early-access page uses Cloudflare Turnstile, which checks browser signals needed to protect the form but does not receive the contents of its fields. The Cookies page records the details.

Your requests

You can ask what data arrived with your email or request correction or deletion at privacy@letsdao.org. Whether a request can be fulfilled and the response time depend on applicable law and mandatory retention; counsel must approve the final process.

The mobile app is outside this draft

This document does not cover app accounts, profiles, posts, stories, messages, notifications, reports, backups, or account deletion. The closed beta is already running, so a separate app policy must be prepared and reviewed before the next invitation wave.

What still needs confirmation

Before approval, the team must confirm the legal basis, retention periods for email and logs, provider agreements, international transfers, and Russian Federal Law No. 152-FZ requirements, including Russian-citizen data localization and any RKN notice requirement. Age limits and the request-response process must also be defined.