Introduction
This Privacy Policy explains how IllDoItApp (“IllDoItApp,” “we,” “us,” or “our”), operated by IK Labs, LLC, collects, uses, stores, shares, and otherwise processes personal data.
It applies when you use our mobile applications, website, admin interfaces, customer support channels, and related services (collectively, the “Services”).
IllDoItApp is currently offered in the United States and is not directed to residents of other countries. Service availability may still vary by state, city, or task category.
This Privacy Policy applies to users who create accounts, browse or create tasks, apply for tasks, communicate through the platform, upload media, receive payments, interact with support, or otherwise use the Services.
If you do not agree with this Privacy Policy, you should not use the Services.
1. Who we are
IllDoItApp is operated by IK Labs, LLC.
Operator of the Service:
IK Labs, LLC
Registered address:
131 Continental Dr, Suite 305
Newark, DE 19713, USA
Jurisdiction:
Delaware, United States
Contact email:
Website:
https://illdoitapp.com
If you have questions regarding this Privacy Policy or how your data is processed, you may contact us using the email above.
2. What personal data we collect
We collect information in several categories.
2.1 Account and profile information
When you register or maintain an account, we may collect information such as:
- name
- surname
- email address
- password
- user role (for example customer or provider)
- locale or language preference
- avatar
- phone number
- biography or profile text
- account status
- email verification status
We may also maintain profile-related information such as:
- rating
- rating count
- profile image gallery URLs
On mobile devices, registration flows currently collect name, surname, email, password, role, and locale. Avatar and biography may be added later through profile management flows.
Users may also later update:
- avatar
- biography
- password
- profile images
A Customer may also provide a contact name and phone number for a task. The phone number is stored as a private task field. It is not displayed to Providers or other marketplace users, but may be viewed by the Customer who supplied it and by authorized IllDoItApp moderators or administrators when reasonably necessary for support, safety, moderation, or dispute handling.
2.2 Location information
We process both exact and approximate location information to operate the marketplace, protect the privacy of task locations before approval, verify certain task events, and investigate disputes.
Task and device location fields may include:
- exact latitude and longitude selected or supplied by a Customer
- street address, city, state or region, postal code, and country
- building and access details such as entrance, floor, intercom, or apartment
- a stable approximate marketplace latitude and longitude
- device latitude, longitude, and accuracy submitted during an enabled verification flow
- derived geographic information, time zone, and service-area information
For an OPEN task, the marketplace displays a stable approximate point generated approximately 400 to 500 meters from the exact task coordinates, together with a general city or region label where available. Exact coordinates, the street address, postal code, building information, contact details, and access instructions are removed from that marketplace response. The approximate point is normally generated once and remains stable unless the Customer changes the exact task location.
When a Provider is selected and the task is PAYMENT_PENDING, that Provider still receives only the approximate location. After payment succeeds and the task reachesAPPROVED, the selected Provider may receive the exact coordinates, address, postal code, building information, and access instructions needed to perform the task. Exact location may remain available to that Provider through later task, completion, cancellation, and dispute states as reasonably necessary. Sensitive access instructions may be removed from terminal task history. Providers do not receive the task contact phone number.
Other Providers and marketplace users do not receive the exact task address through the task API. Authorized administrators and moderators may access exact location, access details, and the private task contact number when needed for support, moderation, safety, fraud prevention, or dispute review.
The 400-to-500-meter offset is approximate for product display purposes. It does not make location data anonymous, does not guarantee that a task or user cannot be inferred, and may still be treated as precise or sensitive geolocation under some U.S. privacy laws or platform rules.
We use location information for:
- task placement and map discovery
- matching tasks to service areas and location preferences
- revealing the exact task location to an authorized selected Provider
- task start, proximity, cancellation, and completion verification
- safety, fraud prevention, support, and dispute investigation
Our mobile apps request foreground or “while using the app” location access when needed for an enabled feature. We do not currently request continuous background location access. You may deny or revoke device permission, although some location-dependent features may not work.
2.3 Media and uploaded content
We process media that you choose to upload, including:
- avatars
- profile images
- task images
- report attachments
- dispute attachments
- chat images
- AI support screenshots or attachments, where available
- audio messages
Media files are stored in external storage infrastructure (such as Cloudflare R2). Our backend stores references (URLs) to these files rather than storing raw media files in standard database fields.
Mobile apps may request access to:
- camera
- photo library
- microphone
These permissions are used only to support features such as uploading images or recording audio messages.
2.4 Messages, chat, and task communication
We process content sent through task-related communication channels, including:
- text messages
- structured task request payloads
- read states
- proposed rewards
- schedule information
- image URLs
- audio URLs
These messages may be stored as part of task communication records or chat threads between customers and providers.
2.5 Reviews and ratings
We process ratings and review comments associated with completed tasks.
Reviews may include:
- task identifier
- reviewer identifier
- reviewee identifier
- rating value
- review text
- creation timestamp
Aggregated rating values may be displayed on user profiles.
2.6 Payments and payout information
Payments within IllDoItApp are processed through Stripe.
Our systems may store operational payment information such as:
- payment intent identifiers
- charge identifiers
- transfer identifiers
- refund identifiers
- currency
- payment amount
- payout metadata
IllDoItApp does not store full credit card numbers or CVV information. Payment card data is handled directly by Stripe.
2.7 Device, technical, and diagnostic information
We may collect technical information associated with the use of the Services, including:
- push notification tokens
- device or application context used in support or report flows
- operating system information
- locale
- timezone
- network type
- event timestamps
The backend may also process limited technical signals such as:
- IP address
- user agent
These may be used for security, logging, rate limiting, or fraud prevention purposes.
Mobile applications may store limited session information locally in order to keep users logged in and enable push notification delivery.
2.8 Account deletion and support-related information
If you request account deletion, we may collect:
- deletion request information
- optional reason text
- internal administrative notes associated with deletion workflows
Support or report submissions may also include message text, attachments, and device context information used for troubleshooting or moderation.
2.9 AI support and AI-assisted task creation
If you use AI-powered support features, we may process information related to your support request, including:
- support questions and messages you send to AI support
- AI support conversation history
- suggested actions shown to you
- feedback about AI support responses, if feedback features are available
- screenshots, images, or attachments you choose to submit through AI support, where available
- limited account, technical, or platform context needed to respond to your request
For example, if you ask about Stripe Connect onboarding, we may use limited Stripe connection status information available in our systems to help explain your current onboarding state.
Users should not include passwords, full bank account numbers, full payment card numbers, Social Security numbers, tax documents, government ID images, or other highly sensitive information in AI support.
If you use AI-assisted task creation, we may process the text or voice input you provide, conversation transcripts, task draft fields, location and address details, contact name and phone number, schedule, reward, category, and images you choose to submit. OpenAI is the only generative AI provider currently used by IllDoItApp and may process this information to interpret your request, create or update a draft, or provide realtime voice interactions.
Google Cloud Vision may process uploaded photos for recognition, labels, text or barcode detection, and safety analysis. Where enabled, OpenAI may also process task images to evaluate relevance or assist moderation. AI output may be inaccurate; you must review and confirm the draft before publishing it.
Our OpenAI API account is configured so that we do not authorize content submitted through our API use to be used to train OpenAI's models. OpenAI and Google may still process and retain limited data under their applicable service terms for providing and securing their services.
2.10 Authentication artifacts
To support secure authentication workflows, we may store:
- hashed refresh tokens
- hashed email verification tokens
- hashed magic-link tokens
Raw tokens are not stored directly.
2.11 Website waitlist and marketing information
If you join the website waitlist, we may collect:
- email address
- country, state or region, and city
- intended user type and task-category interests
- optional free-text category information
- language or locale
- marketing consent and its associated record
- the page source and UTM campaign parameters contained in the page URL
We use this information to prioritize launch areas, understand category demand, measure campaign performance, prevent abuse, and send launch or early-access emails you requested. You may unsubscribe at any time using the link in an email or by contacting us.
3. How we collect personal data
We collect personal data:
- directly from you when you register, edit your profile, create tasks, apply for tasks, communicate in chats, upload media, open disputes, submit reports, use AI features, join the waitlist, or request deletion;
- automatically when you use the Services (for example push token registration or technical logs);
- from third-party service providers involved in payments, push delivery, maps, geocoding, media hosting, or email delivery;
- from other users interacting with you through the marketplace.
4. How we use personal data
We use personal data for the following purposes:
- To operate the marketplace
This includes account creation, profile display, task posting, task applications, messaging, disputes, reviews, payments, payouts, and customer support.
- To authenticate users and secure accounts
Including password authentication, email verification, refresh token management, and security monitoring.
- To process payments and payouts
This includes interactions with Stripe and maintaining transaction records.
- To enable location-based functionality
Including map display, task discovery, cancellation verification, and fraud prevention.
- To support communication features
Including chat, attachments, reports, and task-related messaging.
- To send service notifications
Including push notifications about tasks, messages, disputes, and payments.
- To improve and troubleshoot the Services
Including diagnostic data associated with support requests and operational logs.
- To comply with legal obligations and prevent abuse
Including fraud prevention, dispute resolution, security monitoring, and regulatory compliance.
- To provide AI-powered features
This includes using AI support messages, relevant conversation history, approved platform documentation, submitted task-creation input and draft fields, images, and limited account or technical context to generate support responses, create task drafts, analyze task images, suggest next steps, and troubleshoot platform workflows.
- To administer the waitlist and requested marketing
This includes prioritizing launch areas, measuring campaign sources, understanding category demand, sending launch and early-access emails with consent, and maintaining unsubscribe records.
5. United States scope and sensitive information
The Services are currently directed to users in the United States. We process personal information as needed to provide the Services you request, carry out transactions, protect users and the platform, comply with law, and for the other purposes described in this Policy.
Exact or legally defined precise geolocation, account credentials, and certain financial information may be considered sensitive personal information under applicable state law. We use sensitive information only for permitted operational purposes such as providing a requested task, processing payment, authenticating users, protecting safety, preventing fraud, and resolving disputes. We do not use sensitive personal information to infer characteristics about users for advertising.
Device permissions for location, camera, photos, microphone, and notifications are controlled through your device. Marketing emails are sent based on your consent, and you may withdraw that consent at any time.
7. Public and user-visible content
The Services enable interactions between users.
Certain information such as messages and attachments may be shared between users involved in a task to facilitate communication and task completion.
- profile information
- task descriptions
- messages and attachments
- reviews and ratings
For OPEN tasks, the location visible to marketplace users is the stable approximate point described in Section 2.2. For PAYMENT_PENDING tasks, the selected Provider still receives only that approximate point. The selected Provider may receive the exact location and access details after successful payment and APPROVED status. The private task contact phone number is not disclosed to Providers at any task status.
Users must avoid placing exact addresses, phone numbers, apartment numbers, access codes, or other sensitive information in task titles, descriptions, images, profile fields, or other content that may be visible before approval.
8. Push notifications and communications
We may send service-related notifications including:
- task updates
- messages
- payment events
- dispute notifications
- account updates
You can disable notifications in your device settings, although this may limit certain features.
9. Payments and financial data
Payments on IllDoItApp are handled by Stripe.
IllDoItApp stores only operational transaction data necessary to administer the platform. Payment card data is processed directly by Stripe.
10. Data retention
We retain personal data for as long as reasonably necessary to:
- provide the Services
- maintain platform security
- comply with legal obligations
- resolve disputes
- enforce platform rules
Some records related to tasks, payments, disputes, or reviews may be retained even after account deletion for legal or operational reasons.
Retention depends on the type of information and why we process it:
- account and profile information is generally retained while the account is active and then deleted or de-identified subject to exceptions;
- task, exact and approximate location, access, message, review, payment, dispute, moderation, and audit records may be retained for transaction history, safety, fraud prevention, tax, accounting, legal claims, and enforcement;
- waitlist and marketing information is retained until you unsubscribe, request deletion, or it is no longer reasonably needed, with suppression records retained to honor opt-outs;
- security logs and authentication records are retained for periods reasonably necessary to protect the Services;
- backups may retain information until overwritten through the normal backup cycle.
AI support conversations are subject to an automated retention process configured around a limited operational retention period. AI task-draft sessions, AI audit records, and submitted materials are retained only as long as reasonably necessary for task creation, troubleshooting, abuse prevention, security, and audit purposes, then deleted or de-identified when no longer needed. Legal holds, disputes, fraud investigations, and backup cycles may extend otherwise applicable periods.
11. Account deletion
Users may request account deletion through the application.
When deletion is executed:
- personal profile information may be removed or anonymized
- the account is deactivated
- certain historical records (tasks, payments, disputes, reviews) may remain retained for legal or operational purposes.
Deletion may be delayed if unresolved tasks, payments, or disputes exist.
Account deletion does not automatically unsubscribe or delete a separate website waitlist entry. You may unsubscribe through an email link or request deletion of waitlist information at [email protected].
12. Security
We implement reasonable technical and organizational measures to protect personal data.
However, no internet-based system can be guaranteed to be completely secure. Users are responsible for protecting their account credentials.
13. International transfers
Although the Services are currently directed to the United States, service providers may process information in the United States or other countries where they operate. Those locations may have data-protection rules different from those in your state.
14. U.S. state privacy rights
Depending on your state and whether an applicable law covers our processing, you may have rights to:
- confirm whether we process your personal information and access it
- correct inaccurate personal information
- delete personal information, subject to legal exceptions
- obtain a portable copy of certain information
- obtain a list or categories of third parties to which personal information was disclosed, where required
- opt out of sale, targeted advertising, or certain profiling
- limit certain uses or disclosures of sensitive personal information
- withdraw consent where processing is based on consent
- appeal a denial of a privacy request
We do not currently sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or engage in profiling that produces legal or similarly significant effects. If those practices change, we will update this Policy and provide any required opt-out method.
Submit a request to [email protected] and describe the right you wish to exercise. We may ask for information reasonably necessary to verify your identity and authority. An authorized agent may submit a request where state law permits, subject to verification. To appeal a denial, reply to our decision with the subject “Privacy Appeal.” We will respond within the period required by applicable law. We will not discriminate against you for exercising a privacy right.
14A. California Privacy Rights
In the preceding 12 months, we may have collected the following California categories of personal information, as described more fully above:
- identifiers and customer-record information
- commercial and transaction information
- internet, application, and network activity
- exact, approximate, and derived geolocation information
- audio, visual, and electronic information
- professional or task-related information
- inferences drawn to operate, secure, or improve the Services
- sensitive personal information, including account credentials, precise geolocation, and certain financial information
We collect these categories from you, your device, other marketplace users, and the service providers described above. We use and disclose them for the business and commercial purposes described in Sections 4 and 6. Recipient categories include operational service providers, authorized task participants, professional advisers, government or legal recipients where required, and transaction counterparties in a business transfer.
We have not sold personal information, shared it for cross-context behavioral advertising, or knowingly sold or shared personal information of consumers under 16 in the preceding 12 months. California residents may request to know, access, correct, or delete personal information and may exercise any applicable right to limit use of sensitive personal information using the request method above.
15. Children’s privacy
IllDoItApp is not intended for users under 18 years of age. We do not knowingly collect personal data from children under this age.
16. Third-party services
Our Services use third-party providers including Stripe, Cloudflare, SendGrid, Firebase Cloud Messaging, Apple Push Notification Service, Google Maps, Google Cloud Vision, and OpenAI. Their processing is also governed by their applicable terms and privacy policies.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When updates occur, the “Last updated” date will be revised. If a change materially expands how we use previously collected personal information, we will provide additional notice and obtain consent where required by applicable law.
18. Contact
If you have questions regarding this Privacy Policy, please contact:
IllDoItApp
Email: [email protected]
Website: https://illdoitapp.com