Privacy Policy

Effective date: 29 August 2026
Last updated: 29 August 2026

This Privacy Policy explains how Todayq Technologies Private Limited (“Todayq,” “we,” “us,” or “our”) collects, uses, shares, and stores personal information when you use Directly (directly.work, app.directly.work, audits, dashboards, bots, and related services).

Registered office: WeWork Forum, DLF Cybercity, Gurugram, 122002, India.
Contact: team@directly.work

Directly is built for founders and companies. We do not sell personal information.

This page is written to match the current product. Have counsel review it before you treat it as final, especially if you expand into the EU or run ads that trigger extra US state rules.

1. Who this covers

This Policy applies to:

  • visitors to the marketing site

  • people who run an X audit

  • founders and workspace members who use the AI Agent or managed service

  • people who message our Slack or Telegram bots after a workspace connects them

  • operator and specialist applicants and contractors (additional contract terms may also apply)

It does not apply to X itself. X’s own policy covers what X stores when you use X.

2. Information we collect

2.1 You give us

  • name, work email, company, role, timezone

  • LinkedIn or other login identity if you use that signup path

  • billing name, tax details, and payment confirmation from our processor (we do not store full card numbers)

  • onboarding answers (space, opinions, product description, voice preferences, pillars, strategy)

  • knowledge-base files and URLs (docs, Notion/Google links, changelogs, FAQs)

  • dumps, notes, images, and voice-related instructions sent in web chat, Slack, or Telegram

  • Telegram handle or Slack workspace IDs if you connect a bot

  • support emails and call content, if a call is recorded with disclosed consent

2.2 From X, after you authorize access

If you only run an audit, we pull public profile and post data. No OAuth is required.

If you connect X OAuth and/or Delegate access, we may receive, depending on the scopes you approve:

  • profile identifiers, handle, bio, follower counts, and public metrics

  • posts, replies, quote tweets, and media you author or that we are allowed to read

  • engagement metrics on those posts

  • the ability to create, edit, or delete content

  • Direct Messages and DM metadata, only if you grant DM scope

  • tokens needed to keep that access working until you revoke it

We ask only for the scopes required to run the product path you chose. Managed posting uses X Delegate where possible. OAuth is used for authorized read/write/delete/DM features and better tracking.

2.3 We generate

  • voice profiles, style overrides, content pillars, held positions

  • drafts, three-angle options, skip reasons, and review decisions

  • activity logs (posted, replied, skipped, flagged)

  • space summaries and monitoring matches

  • credit ledger and invoice records

  • customer-intent flags (“this reply looks like a buyer — you should answer”)

2.4 Automatically

  • device, browser, IP address, approximate location, pages viewed, and referrer

  • cookies and similar tech on the site and app

  • server and security logs

2.5 From public or connected sites you point us at

If you give us a website URL, we may crawl pages to extract product positioning for onboarding, audits, or the knowledge base.

3. How we use information

We use personal information to:

  • run audits and show you an X snapshot

  • create and operate workspaces, agents, and managed engagements

  • draft and publish content you authorize

  • learn and update voice only as described in the product (hard voice changes wait for your confirmation)

  • monitor accounts and search terms you subscribe to

  • detect likely customer interest and route that to you instead of auto-replying

  • take payment, issue credits, and prevent fraud

  • log work so you can see what ran

  • message you in-app, by email, Slack, or Telegram about the Service

  • secure the Service, debug, and prevent abuse

  • comply with law and enforce our Terms

We may use aggregated or de-identified data to improve playbooks and models. We do not use your private dumps to advertise third-party products.

4. Legal bases (where a basis is required)

For users protected by regimes that require a legal basis, we rely on:

  • contract - to provide the Service you asked for

  • legitimate interests - security, product improvement on de-identified patterns, limited marketing to existing leads

  • consent - cookies that need it, call recording, optional marketing emails, extra X scopes such as DMs

  • legal obligation - tax, accounting, and lawful requests

Under India’s Digital Personal Data Protection Act, 2023, we process personal data for the specified purposes above, with your consent where required, or for uses the Act otherwise allows.

5. How we share information

We share personal information only as needed:

  • Operators and specialists working your managed engagement, who can see the account materials required to do the work

  • Vendors that host or process data for us, under contract. That set can include cloud hosting, X platform APIs, model providers used to draft and classify text, crawl providers, Slack, Telegram, call/video providers, email, analytics, and payment processors

  • Group companies and professional advisers bound to confidentiality

  • Authorities when required by law or to protect rights, safety, or the Service

  • A buyer if Todayq is involved in a merger, financing, or sale, subject to this Policy’s standards

We do not sell personal information and we do not share it for cross-context behavioral advertising as those terms are commonly used in US state privacy laws.

Other people on X will see whatever is published on your public X account. That is the point of the product. Public posts are public.

6. DMs and sensitive inbound messages

If DM scope is connected, inbound messages may include personal data about third parties (customers, candidates, journalists). We use that data only to provide the inbox / flagging features and to keep a support record.

The agent is instructed not to auto-handle messages that look like genuine buying intent. Those are surfaced to you. You remain responsible for how you respond.

Do not use Directly to store payment card numbers, government IDs, or health records in dumps or the knowledge base.

7. Cookies

We use:

  • essential cookies for login and security

  • preference cookies for the dashboard

  • analytics cookies to understand site use

You can block non-essential cookies in your browser. The marketing site and app may not work fully without essential cookies.

8. Retention

We keep information only as long as needed for the purposes above.

Typical windows (unless a longer period is required by law or a dispute):

  • audit pulls of public posts: short cache (about 7 days) unless you continue into onboarding

  • active workspace data: for the life of the account plus a wind-down period

  • billing and tax records: as required under Indian law (generally 8 years for certain books)

  • OAuth tokens: until you revoke access or the engagement ends

  • call recordings: for the engagement and a limited period after, for quality and disputes

  • server logs: a shorter operational window unless needed for security

You can ask us to delete a workspace. We will delete or de-identify personal data we no longer need, except records we must keep.

9. Security

We use administrative, technical, and organizational measures appropriate to the risk: access controls, encrypted transit, least-privilege operator access, and revocation when an engagement ends.

No internet service is perfectly secure. Protect your inbox and your X access. Revoke Directly in X’s settings if you stop using us.

10. International processing

Directly is based in India. Vendors and model providers may process data in the United States, India, or other countries. If you access the Service from outside India, you understand your information may be processed in India and in those vendor locations.

Where a transfer law requires safeguards, we use appropriate contracts or other permitted mechanisms with vendors.

11. Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you

  • correct it

  • withdraw consent where processing is consent-based (that will not undo processing already done)

  • delete data we no longer need

  • nominate someone to exercise rights in limited cases under Indian law

  • complain to the Data Protection Board of India, or to another regulator that has power over us

To make a request, email team@directly.work from the address on the account. We may need to verify you. We will not honor a request that would expose another customer’s workspace or an operator’s private data.

California and similar US state residents: we do not sell or share personal information as those statutes define those terms. You may still email us to ask what categories we collected and from where.

12. Children

The Service is for adults running companies or professional accounts. We do not knowingly collect data from children under 18. If you believe we have, email team@directly.work and we will delete it.

13. Third-party links and platforms

The site may link to X, Slack, Telegram, payment pages, or other sites. Their privacy terms govern those properties.

14. Changes

We will update this Policy when the product or the law changes. The “Last updated” date will change. Material changes will be posted on the site or sent to the account email.

15. Contact

Privacy and data requests:
Todayq Technologies Private Limited
WeWork Forum, DLF Cybercity, Gurugram, 122002, India
team@directly.work

If you are an operator or applicant, the same address applies.