Privacy Policy
Effective Date: July 1, 2026
This Privacy Policy explains how Thanks Donna, LLC, a Florida limited liability company ("Donna," "we," "us," or "our"), collects, uses, shares, and protects information in connection with the Donna website, applications, and email-screening services (the "Service").
Donna's Service involves two kinds of people: account holders, who connect one or more email accounts ("Connected Accounts") to Donna, and senders, who are trying to reach an account holder and may be asked to pay a priority fee to do so. This policy covers both.
1. Information We Collect
From account holders:
- Account information, such as your name and email address;
- Access to your Connected Account(s), which allows us to read the sender and message metadata (such as sender address, subject line, and timestamp) needed to screen incoming mail;
- The screening rules and approvals you configure;
- Identity-verification information required to receive payouts (such as legal name, date of birth, and government-identifier or tax information), which is collected and verified by our third-party payment processor to comply with financial regulations;
- Payout and banking details, if you receive priority-fee payouts;
- Usage data and device/log information.
From senders:
- The sender address, subject line, timestamp, and content of messages you send to an account holder, which we process to screen the message and, where a fee is required and paid, to deliver it;
- If an account holder requires a priority fee and you choose to pay it: your confirmation that you are at least 18 years old, your acceptance of these Terms and this Policy, and payment information processed by our third-party payment processor to complete the payment.
Scope of access for provider-authorized accounts. For accounts connected through a provider's authorization process (such as Gmail or Outlook), the scope of access is defined by the permissions that provider grants, which may be broader than the metadata-only access used for direct mail screening. We use such access only to operate the screening features you enable.
Message content and storage. To screen incoming mail, Donna reads only the message envelope and header information — details such as the sender's address, subject line, and timestamp — and does not scan or process the body of your messages on our servers. While a message is held at the gate awaiting the account holder's decision, the message is kept encrypted at rest (AES-256) and is permanently deleted the moment it is released to the inbox or the hold expires. The only circumstance in which a message is retained beyond that is when you enable a feature that requires keeping it (for example, saving mail); in that case the message is stored encrypted at rest under an isolated, Donna-held key. Because Donna holds that key, this retention path is not end-to-end encrypted, and we are technically able to access retained content where necessary to operate the feature, respond to your requests, or comply with law.
Google API Services Limited Use. Donna's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
2. How We Use Information
We use information to:
- Operate the email screening and priority-fee features of the Service;
- Charge and process payments from senders who choose to pay a priority fee, and process payouts to account holders;
- Communicate with you about your account, transactions, and security;
- Detect and prevent fraud, spam, and abuse of the priority-fee mechanism;
- Improve, modify, and develop the Service, including by analyzing aggregated, statistical metrics about how messages are delivered and engaged with (such as opens and reads); and
- Comply with legal, tax, and financial-regulatory obligations (for example, identity verification and reporting related to payouts).
Engagement information. We do not give senders read receipts, and we do not report back to a sender whether their delivered message was opened, read, or answered. We measure message activity such as deliveries, opens, and reads only on an aggregated, statistical basis, which we use to operate, secure, improve, and modify the Service. We do not track individual message opens or reads except to the extent that activity contributes to these aggregated metrics, and we do not sell this information.
We do not sell your personal information, and we do not use the content of your email to serve you advertising.
3. How We Share Information
- Between senders and account holders. When a sender pays a priority fee, we share the information necessary to deliver their message and identify them to the account holder (such as name and email address).
- Service providers. We share information with vendors who help us operate the Service, including payment processors, cloud hosting providers, and email infrastructure providers, under confidentiality and data protection obligations.
- Your email provider. Donna interacts with your Connected Account(s) through your email provider's mail routing or API. Where access is granted through a provider's authorization process, that provider defines the scope of the permissions involved, as described in Section 1. We do not control, and are not responsible for, that provider's own data practices.
- Legal reasons. We may disclose information if required by law or legal process, or to protect the rights, safety, or property of Donna, our users, or others.
- Business transfers. If Donna is involved in a merger, acquisition, or asset sale, information may be transferred as part of that transaction, subject to this Policy or a policy offering equivalent protections.
4. Your Choices and Controls
Account holders can, at any time:
- Adjust or disable screening rules for any Connected Account;
- Review and approve or deny specific senders;
- Revoke Donna's access to any Connected Account, through the Service or your email provider's permissions settings;
- Request deletion of your account and associated data, subject to Section 6.
Senders can request access to, correction of, or deletion of the personal information they submitted when contacting an account holder, subject to our legitimate need to retain transaction and fraud-prevention records.
5. Legal Rights
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have rights under the GDPR, including rights to access, correct, delete, restrict, or object to processing of your personal information, and to lodge a complaint with your local data protection authority.
If you are a California resident, you have rights under the CCPA/CPRA, including the right to know, delete, and opt out of certain sharing. We do not sell or share personal information for cross-context behavioral advertising.
To exercise these rights, contact us at Legal@ThanksDonna.com.
6. Data Retention
We retain account and transaction information for as long as needed to operate the Service, resolve disputes, and meet legal, tax, and fraud-prevention obligations. A message held for the account holder's review is stored, encrypted, only while it awaits their decision, and is permanently deleted once it is released or the hold expires. If you enable a feature that retains a message (such as saving mail), we keep that message, encrypted, until you delete it or close your account, subject to any retention we are legally required to maintain. When you disconnect a Connected Account or delete your account, we delete or anonymize personal information that we are not otherwise required to retain.
7. Data Security
We use administrative, technical, and physical safeguards designed to protect your information, including encryption of data in transit, encryption of any stored message content at rest under access-restricted keys, restricted access to Connected Account data, and regular security review. No system is completely secure, and we cannot guarantee absolute protection.
8. International Data Transfers
We may process and store information in countries other than your own. Where we transfer personal information internationally, we use appropriate safeguards, such as standard contractual clauses, consistent with applicable law.
9. Children's Privacy
The Service is intended for adults and is not directed to children. You must be at least 18 years old to use the Service, and we do not knowingly collect personal information from children.
10. Cookies and Similar Technologies
We use cookies and similar technologies to operate the Service and understand usage patterns. You can control cookies through your browser settings, though some features may not function properly without them.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting the updated policy with a new effective date, or through other reasonable means, such as email or an in-Service notice.
12. Contact Us
Questions about this Privacy Policy, or requests to exercise your privacy rights, can be sent to Legal@ThanksDonna.com or:
Thanks Donna, LLC4604 49th St N #5310
St. Petersburg, FL 33709