Privacy Policy
Effective date: 29 August 2026
Last updated: 29 August 2026
This Privacy Policy explains how Todayq Technologies Private Limited (“Todayq,” “we,” “us,” or “our”) collects, uses, shares, and stores personal information when you use Directly (directly.work, app.directly.work, audits, dashboards, bots, and related services).
Registered office: WeWork Forum, DLF Cybercity, Gurugram, 122002, India.
Contact: team@directly.work
Directly is built for founders and companies. We do not sell personal information.
This page is written to match the current product. Have counsel review it before you treat it as final, especially if you expand into the EU or run ads that trigger extra US state rules.
1. Who this covers
This Policy applies to:
visitors to the marketing site
people who run an X audit
founders and workspace members who use the AI Agent or managed service
people who message our Slack or Telegram bots after a workspace connects them
operator and specialist applicants and contractors (additional contract terms may also apply)
It does not apply to X itself. X’s own policy covers what X stores when you use X.
2. Information we collect
2.1 You give us
name, work email, company, role, timezone
LinkedIn or other login identity if you use that signup path
billing name, tax details, and payment confirmation from our processor (we do not store full card numbers)
onboarding answers (space, opinions, product description, voice preferences, pillars, strategy)
knowledge-base files and URLs (docs, Notion/Google links, changelogs, FAQs)
dumps, notes, images, and voice-related instructions sent in web chat, Slack, or Telegram
Telegram handle or Slack workspace IDs if you connect a bot
support emails and call content, if a call is recorded with disclosed consent
2.2 From X, after you authorize access
If you only run an audit, we pull public profile and post data. No OAuth is required.
If you connect X OAuth and/or Delegate access, we may receive, depending on the scopes you approve:
profile identifiers, handle, bio, follower counts, and public metrics
posts, replies, quote tweets, and media you author or that we are allowed to read
engagement metrics on those posts
the ability to create, edit, or delete content
Direct Messages and DM metadata, only if you grant DM scope
tokens needed to keep that access working until you revoke it
We ask only for the scopes required to run the product path you chose. Managed posting uses X Delegate where possible. OAuth is used for authorized read/write/delete/DM features and better tracking.
2.3 We generate
voice profiles, style overrides, content pillars, held positions
drafts, three-angle options, skip reasons, and review decisions
activity logs (posted, replied, skipped, flagged)
space summaries and monitoring matches
credit ledger and invoice records
customer-intent flags (“this reply looks like a buyer — you should answer”)
2.4 Automatically
device, browser, IP address, approximate location, pages viewed, and referrer
cookies and similar tech on the site and app
server and security logs
2.5 From public or connected sites you point us at
If you give us a website URL, we may crawl pages to extract product positioning for onboarding, audits, or the knowledge base.
3. How we use information
We use personal information to:
run audits and show you an X snapshot
create and operate workspaces, agents, and managed engagements
draft and publish content you authorize
learn and update voice only as described in the product (hard voice changes wait for your confirmation)
monitor accounts and search terms you subscribe to
detect likely customer interest and route that to you instead of auto-replying
take payment, issue credits, and prevent fraud
log work so you can see what ran
message you in-app, by email, Slack, or Telegram about the Service
secure the Service, debug, and prevent abuse
comply with law and enforce our Terms
We may use aggregated or de-identified data to improve playbooks and models. We do not use your private dumps to advertise third-party products.
4. Legal bases (where a basis is required)
For users protected by regimes that require a legal basis, we rely on:
contract - to provide the Service you asked for
legitimate interests - security, product improvement on de-identified patterns, limited marketing to existing leads
consent - cookies that need it, call recording, optional marketing emails, extra X scopes such as DMs
legal obligation - tax, accounting, and lawful requests
Under India’s Digital Personal Data Protection Act, 2023, we process personal data for the specified purposes above, with your consent where required, or for uses the Act otherwise allows.
5. How we share information
We share personal information only as needed:
Operators and specialists working your managed engagement, who can see the account materials required to do the work
Vendors that host or process data for us, under contract. That set can include cloud hosting, X platform APIs, model providers used to draft and classify text, crawl providers, Slack, Telegram, call/video providers, email, analytics, and payment processors
Group companies and professional advisers bound to confidentiality
Authorities when required by law or to protect rights, safety, or the Service
A buyer if Todayq is involved in a merger, financing, or sale, subject to this Policy’s standards
We do not sell personal information and we do not share it for cross-context behavioral advertising as those terms are commonly used in US state privacy laws.
Other people on X will see whatever is published on your public X account. That is the point of the product. Public posts are public.
6. DMs and sensitive inbound messages
If DM scope is connected, inbound messages may include personal data about third parties (customers, candidates, journalists). We use that data only to provide the inbox / flagging features and to keep a support record.
The agent is instructed not to auto-handle messages that look like genuine buying intent. Those are surfaced to you. You remain responsible for how you respond.
Do not use Directly to store payment card numbers, government IDs, or health records in dumps or the knowledge base.
7. Cookies
We use:
essential cookies for login and security
preference cookies for the dashboard
analytics cookies to understand site use
You can block non-essential cookies in your browser. The marketing site and app may not work fully without essential cookies.
8. Retention
We keep information only as long as needed for the purposes above.
Typical windows (unless a longer period is required by law or a dispute):
audit pulls of public posts: short cache (about 7 days) unless you continue into onboarding
active workspace data: for the life of the account plus a wind-down period
billing and tax records: as required under Indian law (generally 8 years for certain books)
OAuth tokens: until you revoke access or the engagement ends
call recordings: for the engagement and a limited period after, for quality and disputes
server logs: a shorter operational window unless needed for security
You can ask us to delete a workspace. We will delete or de-identify personal data we no longer need, except records we must keep.
9. Security
We use administrative, technical, and organizational measures appropriate to the risk: access controls, encrypted transit, least-privilege operator access, and revocation when an engagement ends.
No internet service is perfectly secure. Protect your inbox and your X access. Revoke Directly in X’s settings if you stop using us.
10. International processing
Directly is based in India. Vendors and model providers may process data in the United States, India, or other countries. If you access the Service from outside India, you understand your information may be processed in India and in those vendor locations.
Where a transfer law requires safeguards, we use appropriate contracts or other permitted mechanisms with vendors.
11. Your rights
Depending on where you live, you may have the right to:
access the personal data we hold about you
correct it
withdraw consent where processing is consent-based (that will not undo processing already done)
delete data we no longer need
nominate someone to exercise rights in limited cases under Indian law
complain to the Data Protection Board of India, or to another regulator that has power over us
To make a request, email team@directly.work from the address on the account. We may need to verify you. We will not honor a request that would expose another customer’s workspace or an operator’s private data.
California and similar US state residents: we do not sell or share personal information as those statutes define those terms. You may still email us to ask what categories we collected and from where.
12. Children
The Service is for adults running companies or professional accounts. We do not knowingly collect data from children under 18. If you believe we have, email team@directly.work and we will delete it.
13. Third-party links and platforms
The site may link to X, Slack, Telegram, payment pages, or other sites. Their privacy terms govern those properties.
14. Changes
We will update this Policy when the product or the law changes. The “Last updated” date will change. Material changes will be posted on the site or sent to the account email.
15. Contact
Privacy and data requests:
Todayq Technologies Private Limited
WeWork Forum, DLF Cybercity, Gurugram, 122002, India
team@directly.work
If you are an operator or applicant, the same address applies.