Dit is a minimal presence signaling app. You send a dit to say "I'm here" and receive a dah back meaning "received". No messages, no text, no media. Just presence. This policy explains what we collect, why, and how we protect it.
Privacy by design. Dit collects the minimum data necessary. We don't read your messages — because there are none. We don't track your location. We don't serve ads. We don't sell data.
Dit is a mobile application for iOS and Android that lets you exchange minimal presence signals with your contacts. The two signal types are:
Dit is not a messaging app. There is no text, no images, no voice, no video. The only information exchanged is the fact that a signal was sent and whether it was acknowledged.
We collect only what is necessary to make Dit work.
| Data | Details |
|---|---|
| Account | Email address and name when you register. Username you choose during setup. Optional: bio (max 140 characters) and profile picture URL. |
| Social login | If you sign in via Google, Facebook, or Microsoft, we receive your name, email, and profile picture from that provider. Nothing else. |
| Contacts | The list of Dit users you choose to save, plus any private nicknames you assign. We never access your device's address book. |
| Dits & dahs | Timestamps of signals sent and received, their status (pending, acknowledged, expired, ignored), and TTL duration. No message content exists. |
| Presence | Whether you are currently online and your last-seen timestamp. Visible only to your contacts according to your privacy settings. |
| Push tokens | A device identifier issued by Apple (APNs) or Google (FCM) to deliver notifications. Used exclusively for Dit notifications. Deleted on logout. |
| Server logs | IP address, device type, operating system. For security and debugging only. Maximum retention: 30 days. |
We do not use your data for advertising, profiling, analytics beyond basic service operation, or any purpose other than running Dit. We do not sell, rent, or trade your data to anyone.
We share your data only in these limited cases:
When you send a dit, the recipient sees that a signal was sent and its timestamp. They do not see any other account information unless your privacy settings allow it. Your name and bio visibility are independently controlled by you.
We use cloud services to operate Dit. These providers process data on our behalf under data processing agreements and cannot use your data for their own purposes:
If we receive a legally valid request from a law enforcement authority, we may be required to disclose data. We will notify you if legally permitted.
Dit gives you granular control over your privacy from Settings → Privacy in the app.
You control who can see your name and bio independently. Each field has three options:
Your username and profile picture are always visible. Username is required for others to find you, and the profile picture has an initials fallback.
You can block any user at any time. Blocking is completely silent — the blocked user is never notified in any way. When you block someone:
Blocking permanently deletes all signal history between you and the blocked user. This cannot be undone, even if you later unblock them.
Dit is designed so that if someone picks up your phone, they see minimal information. There are no message previews, no text content, no media. The timeline view shows only abstract visual indicators (dots and threads) representing that signals were exchanged.
Dit sends push notifications in two cases:
Notifications include custom sounds inspired by Morse code: two short tones (··) for a dit (the letter "I" in Morse — meaning "me"), and two short plus one long tone (··—) for a dah (the letter "U" in Morse — meaning "you").
You can reply with a dah directly from the notification without opening the app.
If you are logged in on multiple devices, notifications are delivered to all of them. When you read or dismiss a notification on one device, it is dismissed on all others automatically. Logging out of a device immediately deletes all push tokens for that device — no further notifications are sent to it.
| Data | Retention |
|---|---|
| Dits & dahs | Automatically deleted 90 days after creation. |
| Account data | Retained until you delete your account. |
| Push tokens | Deleted immediately on logout or when the provider reports the token as invalid. |
| Server logs | Retained for 30 days, then permanently deleted. |
| Block records | Retained until you unblock the user. |
| Session cookies | Expire after 30 days or on explicit logout. |
You can, at any time:
If you are in the European Union, European Economic Area, or the United Kingdom, you also have the right to lodge a complaint with your local data protection authority.
No system is 100% secure. We take reasonable precautions, but cannot guarantee absolute security. If you discover a vulnerability, report it to security@ditapp.net.
Dit is not directed at children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has created an account, contact us at privacy@ditapp.net and we will delete it promptly.
Dit uses a single httpOnly session cookie to maintain your login session. This cookie:
Dit does not use analytics cookies, advertising cookies, tracking pixels, or any form of cross-site tracking.
We may update this policy as Dit evolves. If we make material changes, we will notify you via the app or by email at least 14 days before the changes take effect. The "last updated" date at the top reflects the current version.
For any privacy-related questions, data access requests, or concerns:
We respond within 5 business days.
05 · Social sign-in
If you sign in with Google, Facebook, or Microsoft, we receive only your name, email address, and profile picture (if available). We do not receive access to your social media posts, friends lists, contacts on those platforms, or any other data.
The data we receive is governed by each provider's privacy policy: Google, Meta, Microsoft.
You can also sign in with email and a one-time passcode (OTP) delivered to your inbox, without involving any social provider.