DOB Desk — Privacy Policy
Last updated September 4, 2026
DOB Desk is a product of MoLabs LLC (“DOB Desk,” “we,” “us”). This policy explains what we collect through the DOB Desk website at dobdesk.com and its DOB NOW autofill browser extension, how we use it, and who we share it with. Questions: support@dobdesk.com.
Who this is for
DOB Desk is a professional tool for New York City filing representatives, expediters, licensed design professionals, and authorized firm staff. It is not directed to children, and we do not knowingly collect data from anyone under 18.
Software only — no professional services. MoLabs LLC and dobdesk.com provide software, not engineering, architectural, or expediting services, and assume no professional liability for any DOB NOW filing prepared or auto-filled with the Service. The extension never fills Statements & Signatures, legal attestations, or professional/owner signature boxes; those remain the responsible party's own statements and electronic signatures. Reviewing and submitting every filing is solely the responsibility of the responsible filer and licensed professional. See the Terms of Service.
What we collect
- Account information. Your email address, and — if you sign in with Google — the basic profile (name, email, profile picture) Google shares when you choose that sign-in method. We use this only to create and authenticate your account. We never receive your Google password, and we request no access to your Gmail, Drive, or contacts.
- Filing and project data you enter. The property addresses, work types, scope descriptions, cost figures, and related details you type into DOB Desk to prepare a DOB NOW filing. This is your working data, used to generate your prep package and stored so you can return to your projects.
- Plan sets you upload (Plan Check). If you use the optional Plan Check feature, you upload a plan-set PDF for an AI code pre-review. The file is stored briefly in encrypted storage, sent to the provider you approve for that run (Anthropic by default; OpenAI and Google only after a separate multi-provider choice) to generate the review, and deleted promptly after the review completes. These documents may contain project or third-party information — you are responsible for having the right to upload them.
- Payment information. If you subscribe, payment is processed by Stripe. We receive your subscription status and billing period from Stripe — we never see or store your full card number.
- Improvement telemetry (explicit opt-in). The browser extension can send “field reports” — the labels of DOB NOW form fields and whether the extension matched them, never the values you typed — plus DOB-displayed filing status and fee amounts, and, when you save a filing, whether you changed what the extension typed (compared on your own computer and sent as a yes/no verdict per field — the values themselves, both ours and yours, never leave your machine). This improves autofill accuracy for everyone and is controlled by an opt-in toggle and a short-lived, account-bound extension session. See the extension privacy policy for detail.
- Support correspondence. Emails you send to support@dobdesk.com and feedback you submit in the app.
How we use it
- To provide the service: prepare your filings, autofill DOB NOW, decode objections, track permits, and manage your account.
- To process your subscription and issue your ZoneIQ license.
- To improve the product — chiefly the accuracy of DOB NOW field matching and the shared objection knowledge base.
- To contact you about your account, filings, and support requests.
We do not sell your data, and we do not use it for advertising.
Service providers we share data with
We use a small set of vendors strictly to operate DOB Desk. Each receives only what it needs:
- Supabase — database and authentication (your account and project data).
- Stripe — subscription payments.
- Vercel — website and application hosting.
- Resend — transactional and support email.
- Google — only if you choose “Sign in with Google,” for authentication.
- Anthropic, OpenAI, and Google — only when configured for and disclosed before an AI feature run (e.g. drafting a scope, decoding an unmatched objection, or running Plan Check). For most features only the text of the request is sent; for Plan Check, the plan-set PDF you upload may be sent to the provider(s) you consent to for that run so the model can review it. Provider handling is governed by the applicable provider terms and account configuration.
- NYC Open Data / NYC Planning — public city data lookups (address, BIN, PLUTO, permits). These are queries of public records; we send the address or BIN you look up.
- PostHog — product analytics and session replay, used to find where the site is confusing or broken (e.g. clicks that go nowhere, pages people abandon). Sessions are pseudonymous — we do not link recordings to your name or email. Form inputs are always masked, and on the filing tools all on-page text is masked, so recordings show where you clicked but never your filing data, addresses, or project details.
- Vercel Web Analytics — anonymous page-view counts. No cookie, and no identifier that follows you between sites.
- Google Analytics — page-view and traffic-source measurement (which pages are visited, and whether you arrived from a search, a link, or an ad). We send the page address, not your filing data. Google sets its own cookies and is able to associate this activity with its other services; if you would rather it did not, Google publishes an opt-out at tools.google.com/dlpage/gaoptout, and any tracker-blocking extension will also stop it.
Cookies and sessions
We use a login session (stored by your browser) to keep you signed in, a first-party analytics cookie (PostHog) so repeat visits count as one visitor, and Google Analytics cookies for the same purpose. We do not use advertising cookies and we do not sell or share your data with advertisers — but Google Analytics is a third-party service, so its cookies are set by Google and are subject to Google’s own privacy policy.
Data retention and your choices
We keep your account and project data while your account is active. Plan-set PDFs uploaded to Plan Check are deleted promptly after the review is generated and are not retained. We retain only operational metadata such as provider, page count, byte size, and deletion outcome. You can request a copy or deletion of your data, or close your account, at any time by emailing support@dobdesk.com. Some records (e.g. billing history) may be retained as required for legal and accounting purposes.
Security
Data is encrypted in transit (HTTPS) and stored with our providers' encryption at rest. Access is limited to what's needed to run the service. No system is perfectly secure, but we work to protect your information.
Changes
We may update this policy; material changes will be reflected by the “last updated” date above.
Contact
MoLabs LLC · support@dobdesk.com