Privacy Policy

Last updated: 24 May 2026 · Effective: 24 May 2026

Available in বাংলা

Dolil AI (“we”, “us”, “our”, or “the Platform”) is an AI-powered legal document generator and online lawyer consultation service operated for users in Bangladesh. This Privacy Policy explains what personal data we collect, how we use it, with whom we share it, and the rights you have. By using www.dolilai.com you agree to the practices described here.

1. Information we collect

We collect the following categories of information when you use the Platform:

  • Account data — name, email address, hashed password, profile picture (if provided), authentication provider (Google, etc.).
  • Document content — the form fields you fill in (parties' names, addresses, amounts, dates) and the documents you generate.
  • Identity data when explicitly entered — NID number, date of birth, parents' names (only when you include them in a document you generate; we never request NID for account creation).
  • Consultation data — bookings you make with lawyers, payment status, video session metadata (we do not record video calls).
  • Payment data — order IDs, transaction reference numbers, plan tier, and payment status. Full card or wallet credentials are handled by bKash and Nagad and never stored on our servers.
  • Technical data — IP address (hashed for analytics), browser, operating system, device type, approximate country/region/city derived from your IP.
  • Usage data — pages visited, features used, anonymous visitor ID stored in a cookie (dolil_visitor_id), conversion events such as “document generated” or “consultation booked”.
  • Communications — emails or messages you send us through support channels.

2. How we use your information

  • To provide the document generation service and process your form inputs into legally compliant drafts.
  • To facilitate lawyer consultations and process the related payments.
  • To manage your account, plan subscription, and document quota.
  • To send transactional emails (account verification, password reset, booking confirmation, payment receipt).
  • To improve the Platform — measure which templates and features are used, identify usability problems, monitor performance.
  • To prevent fraud and abuse, enforce our Terms of Service, and comply with legal obligations.
  • With your separate consent, to send product updates or marketing communications (you can opt out at any time).

4. NID and other sensitive data

We treat NID (National ID) numbers and similarly sensitive identifiers with extra care:

  • We never require an NID to create an account.
  • NIDs you enter into documents are stored only as part of the document you generated; they are encrypted at rest in our database.
  • We do not display NIDs in admin interfaces in full — only the last 4 digits.
  • We do not share NID data with third parties except where strictly required by law.
  • You can request deletion of any document containing your NID at any time from your dashboard.

5. Payments (bKash, Nagad)

Payments for paid plans and lawyer consultations are processed by third-party gateways:

We receive only the transaction reference, amount, status, and order ID from these gateways. We do not receive or store your bKash/Nagad PIN, wallet balance, or KYC details.

6. AI processing of your inputs

When you generate a document or use the AI Writer, your form inputs and prompts are sent to large language model providers we use as sub-processors:

  • Anthropic (Claude) — see Anthropic Privacy Policy. We use API access under Anthropic's data-processing terms; inputs are not used to train their models.
  • OpenAI — see OpenAI Privacy Policy. We use API access under OpenAI's data-processing terms; inputs are not used to train their models.

We do not send your NID, payment data, or account password to AI providers. We send only the document field values you choose to include.

7. When we share your data

We share personal data only in the following circumstances:

  • With the lawyer you book — your name and the topic of consultation, so they can prepare. The video session itself is end-to-end between you and the lawyer.
  • With sub-processors — hosting (Vercel), database (Neon PostgreSQL), email delivery, AI providers (Anthropic, OpenAI), payment gateways (bKash, Nagad), video infrastructure (Jitsi), analytics (Google Analytics, anonymous).
  • When required by law — in response to a valid court order, subpoena, or government request under Bangladeshi law.
  • To protect rights — to investigate fraud, prevent harm, or enforce our Terms of Service.
  • With your explicit consent — for any other purpose, we will ask you first.

We do not sell your personal data to anyone.

8. Data retention

  • Account data — retained for as long as your account is active. Deleted within 30 days after account closure.
  • Documents you generate — retained in your account indefinitely until you delete them. After account closure, deleted within 30 days.
  • Consultation records — retained for 7 years for tax and audit purposes (Income Tax Ordinance 1984 compliance).
  • Anonymous analytics events — automatically purged after 90 days.
  • Server logs — retained for up to 30 days for security and debugging.
  • Backups — encrypted database backups may persist up to 35 days before rotation.

9. Security

  • All data is transmitted over HTTPS/TLS 1.3.
  • Passwords are hashed with bcrypt; we cannot read your password.
  • NIDs and other sensitive fields are encrypted at rest.
  • Database access is restricted to authenticated services using role-based controls.
  • IPs used for analytics are SHA-256 hashed; we do not store raw IP addresses long-term.
  • We follow OWASP-aligned development practices including parameterized queries (Prisma), CSRF protections, rate limiting, and input validation (Zod).

No system is perfectly secure. If you believe your account has been compromised, contact us immediately at support@dolilai.com.

10. Your rights

Under the draft Personal Data Protection Act of Bangladesh and applicable international frameworks (GDPR, CCPA where relevant), you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate data through your profile or by contacting us.
  • Erasure — delete your account and associated data (subject to legal retention obligations).
  • Restriction — request that we limit processing in certain situations.
  • Portability — download your generated documents in PDF/DOCX format at any time.
  • Objection — opt out of marketing communications or non-essential analytics.
  • Withdraw consent — at any time, where processing is based on consent.
  • Complain — lodge a complaint with the appropriate data protection authority.

To exercise any of these rights, email support@dolilai.com from the address registered to your account. We will respond within 30 days.

11. Cookies and tracking

We use a small number of essential and analytics cookies:

  • dolil_visitor_id — anonymous visitor identifier for analytics and rate limiting (1-year expiry, HttpOnly).
  • dolil-ai-lang — your language preference (bn or en).
  • next-auth.session-token — session authentication when logged in.
  • Google Analytics 4 cookies — anonymous traffic measurement; you can opt out via the Google Analytics opt-out browser extension.

We do not use third-party advertising cookies. We do not run cross-site behavioral advertising trackers.

12. International data transfers

Our infrastructure providers (Vercel, Neon, Anthropic, OpenAI, Google Analytics) operate servers in the United States and the European Union. When you use the Platform, your data may be transferred to and processed in these regions. These providers are contractually bound to protect your data to standards equivalent to or higher than those required by Bangladeshi law.

13. Children

The Platform is not intended for children under the age of 18. Drafting legal documents and entering into contracts is a function reserved for adults under Bangladeshi law. We do not knowingly collect personal data from minors. If you believe a minor has created an account, please contact us so we can delete the account.

14. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced via email and a prominent banner on the Platform at least 14 days before they take effect. The “Last updated” date at the top of this page always reflects the current version.

15. Contact us

For privacy questions, data requests, or complaints, contact:


This Privacy Policy is provided in good faith and reflects current practices. For specific legal questions about your rights under Bangladeshi data protection law, consult a qualified Bangladeshi advocate.