Privacy Policy

last updated: july 2025 · version 2.0

Dit is a minimal presence signaling app. You send a dit to say "I'm here" and receive a dah back meaning "received". No messages, no text, no media. Just presence. This policy explains what we collect, why, and how we protect it.

Privacy by design. Dit collects the minimum data necessary. We don't read your messages — because there are none. We don't track your location. We don't serve ads. We don't sell data.

contents
  1. What is Dit
  2. Data we collect
  3. How we use it
  4. Data sharing
  5. Social sign-in
  6. Privacy controls
  7. Notifications
  8. Data retention
  9. Your rights
  10. Security
  11. Children
  12. Cookies & sessions
  13. Changes

01 · What is Dit

Dit is a mobile application for iOS and Android that lets you exchange minimal presence signals with your contacts. The two signal types are:

Dit is not a messaging app. There is no text, no images, no voice, no video. The only information exchanged is the fact that a signal was sent and whether it was acknowledged.

· — · · —

02 · Data we collect

We collect only what is necessary to make Dit work.

DataDetails
AccountEmail address and name when you register. Username you choose during setup. Optional: bio (max 140 characters) and profile picture URL.
Social loginIf you sign in via Google, Facebook, or Microsoft, we receive your name, email, and profile picture from that provider. Nothing else.
ContactsThe list of Dit users you choose to save, plus any private nicknames you assign. We never access your device's address book.
Dits & dahsTimestamps of signals sent and received, their status (pending, acknowledged, expired, ignored), and TTL duration. No message content exists.
PresenceWhether you are currently online and your last-seen timestamp. Visible only to your contacts according to your privacy settings.
Push tokensA device identifier issued by Apple (APNs) or Google (FCM) to deliver notifications. Used exclusively for Dit notifications. Deleted on logout.
Server logsIP address, device type, operating system. For security and debugging only. Maximum retention: 30 days.

What we do NOT collect

03 · How we use your data

We do not use your data for advertising, profiling, analytics beyond basic service operation, or any purpose other than running Dit. We do not sell, rent, or trade your data to anyone.

04 · Data sharing

We share your data only in these limited cases:

With your contacts

When you send a dit, the recipient sees that a signal was sent and its timestamp. They do not see any other account information unless your privacy settings allow it. Your name and bio visibility are independently controlled by you.

With infrastructure providers

We use cloud services to operate Dit. These providers process data on our behalf under data processing agreements and cannot use your data for their own purposes:

When required by law

If we receive a legally valid request from a law enforcement authority, we may be required to disclose data. We will notify you if legally permitted.

05 · Social sign-in

If you sign in with Google, Facebook, or Microsoft, we receive only your name, email address, and profile picture (if available). We do not receive access to your social media posts, friends lists, contacts on those platforms, or any other data.

The data we receive is governed by each provider's privacy policy: Google, Meta, Microsoft.

You can also sign in with email and a one-time passcode (OTP) delivered to your inbox, without involving any social provider.

— · · —

06 · Your privacy controls

Dit gives you granular control over your privacy from Settings → Privacy in the app.

Profile visibility

You control who can see your name and bio independently. Each field has three options:

Your username and profile picture are always visible. Username is required for others to find you, and the profile picture has an initials fallback.

User blocking

You can block any user at any time. Blocking is completely silent — the blocked user is never notified in any way. When you block someone:

!

Blocking permanently deletes all signal history between you and the blocked user. This cannot be undone, even if you later unblock them.

Confidential by design

Dit is designed so that if someone picks up your phone, they see minimal information. There are no message previews, no text content, no media. The timeline view shows only abstract visual indicators (dots and threads) representing that signals were exchanged.

07 · Notifications

Dit sends push notifications in two cases:

Notifications include custom sounds inspired by Morse code: two short tones (··) for a dit (the letter "I" in Morse — meaning "me"), and two short plus one long tone (··—) for a dah (the letter "U" in Morse — meaning "you").

You can reply with a dah directly from the notification without opening the app.

Multi-device

If you are logged in on multiple devices, notifications are delivered to all of them. When you read or dismiss a notification on one device, it is dismissed on all others automatically. Logging out of a device immediately deletes all push tokens for that device — no further notifications are sent to it.

08 · Data retention

DataRetention
Dits & dahsAutomatically deleted 90 days after creation.
Account dataRetained until you delete your account.
Push tokensDeleted immediately on logout or when the provider reports the token as invalid.
Server logsRetained for 30 days, then permanently deleted.
Block recordsRetained until you unblock the user.
Session cookiesExpire after 30 days or on explicit logout.

09 · Your rights

You can, at any time:

If you are in the European Union, European Economic Area, or the United Kingdom, you also have the right to lodge a complaint with your local data protection authority.

10 · Security

No system is 100% secure. We take reasonable precautions, but cannot guarantee absolute security. If you discover a vulnerability, report it to security@ditapp.net.

11 · Children

Dit is not directed at children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has created an account, contact us at privacy@ditapp.net and we will delete it promptly.

12 · Cookies & sessions

Dit uses a single httpOnly session cookie to maintain your login session. This cookie:

Dit does not use analytics cookies, advertising cookies, tracking pixels, or any form of cross-site tracking.

13 · Changes to this policy

We may update this policy as Dit evolves. If we make material changes, we will notify you via the app or by email at least 14 days before the changes take effect. The "last updated" date at the top reflects the current version.

· · · — — —

Contact

For any privacy-related questions, data access requests, or concerns:

privacy@ditapp.net

We respond within 5 business days.