dit← back

Privacy Policy

version 3.0 · last updated 28 July 2026 · effective 11 August 2026

Dit is a minimal presence signalling app. You send a dit to say “I’m here” and receive a dah back meaning “received”. No messages, no text, no media. Just presence. This policy explains what we collect, on what legal basis, who it reaches, and how long we keep it.

✓ privacy by design

Dit collects the minimum data necessary. We don’t read your messages — because there are none. We don’t track your location. We don’t serve ads. We don’t sell or share your personal information, as those terms are defined under California law.

01Who is responsible for your data

Dit is a free personal project, not a business. There is no company behind it, no advertising, no in-app purchases, no paid tier and no monetisation of any kind.

The data controller — the person who decides why and how your data is processed — is Marius Trica, acting as a private individual, reachable at [email protected].

Because Dit is run by one person and processes very little data, we are not required to appoint a Data Protection Officer: requests are handled directly by the controller. If you need a postal address — to serve a formal notice, or because a supervisory authority has asked you for one — request it at the address above and it will be provided.

02What is Dit

Dit is a mobile application for iOS and Android that lets you exchange minimal presence signals with your contacts. The two signal types are:

Dit is not a messaging app. There is no text, no images, no voice, no video. The only information exchanged is the fact that a signal was sent and whether it was acknowledged.

03Data we collect

We collect only what is necessary to make Dit work.

DataDetails
AccountEmail address and name when you register. Username you choose during setup (3–24 characters). Optional: bio (max 140 characters) and profile picture.
CredentialsIf you register with a password, we store only a cryptographic hash of it, never the password itself. If you use a one-time passcode, the code is valid for 10 minutes and is not retained after use.
Social loginIf you sign in via Google, Facebook, Microsoft or Apple, we receive your name, email address and profile picture URL from that provider. Nothing else. Profile pictures are referenced by URL — we do not copy or host the image.
ContactsThe list of Dit users you choose to save, plus any private nicknames you assign. We never access your device’s address book, and Dit never requests that permission.
Dits & dahsSender, recipient, timestamps of signals sent and received, their status (pending, acknowledged, expired, ignored) and TTL duration. No message content exists.
PresenceWhether you are currently connected. This is held in memory by the real-time service for the duration of your connection and is not written to the database. Dit does not record or display a “last seen” timestamp.
Push tokensA device identifier issued by Apple (APNs) or Google (FCM) to deliver notifications. Used exclusively for Dit notifications. Deleted on logout.
Server logsIP address, device type, operating system, request metadata. For security, abuse prevention and debugging only. Retention: 30 days.

What we do not collect

The Dit mobile app contains no analytics or crash-reporting SDK of any kind.

04How we use your data

We do not use your data for advertising, profiling or behavioural analytics. We do not sell, rent or trade your data to anyone.

05Legal bases for processing

If you are in the European Union, the European Economic Area or the United Kingdom, we must have a legal basis under Article 6 GDPR for every purpose. These are ours:

PurposeLegal basis
Creating and running your account; delivering dits and dahs; storing your contacts and privacy settingsPerformance of a contract — Art. 6(1)(b). Without this data the service cannot be provided to you.
Push notifications and expiry remindersConsent — Art. 6(1)(a), given through your device’s notification permission prompt. Withdrawable at any time in system settings, with no effect on the rest of the service.
Server logs, rate limiting, abuse prevention, security monitoringLegitimate interests — Art. 6(1)(f): keeping the service available and protecting users from abuse. We balanced this against your rights and limited retention to 30 days to keep the impact minimal.
Transactional email (verification codes, password reset)Performance of a contract — Art. 6(1)(b).
Responding to legal requests; retaining records where the law requires itLegal obligation — Art. 6(1)(c).

Where we rely on legitimate interests, you have the right to object — see Your rights. Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

06Data sharing

We share your data only in these limited cases.

With your contacts

When you send a dit, the recipient sees that a signal was sent and its timestamp. They do not see any other account information unless your privacy settings allow it. Your name and bio visibility are controlled independently by you.

With infrastructure providers

We use the following providers to operate Dit. Each processes data on our behalf as a processor under Article 28 GDPR, bound by a data processing agreement, and cannot use your data for its own purposes:

ProviderPurposeData reached
DigitalOcean, LLCServer hosting. Dit’s database, cache and application services all run on infrastructure rented from DigitalOcean; we operate them ourselves.All service data, at rest and in processing.
Google (Firebase Cloud Messaging)Push notification delivery for Android and iOS.Push token and notification payload (signal type only — no content).
Apple (APNs)Push notification delivery on iOS.Push token and notification payload.
Brevo (Sendinblue SAS)Transactional email: verification codes, password resets.Email address and message content.

We do not use third-party analytics, advertising networks, data brokers or customer-tracking tools of any kind.

When required by law

If we receive a legally valid request from a competent authority, we may be required to disclose data. We assess every request for validity and disclose only what is strictly necessary. We will notify you unless legally prohibited from doing so.

Business transfers

If Dit is ever transferred to another entity through a merger, acquisition or asset sale, your data would move with it. We would notify you beforehand and you would be able to delete your account before any transfer takes effect.

07International data transfers

Dit’s servers are located in DATACENTRE REGION. Where that region is inside the EEA, your service data does not leave the EEA in normal operation.

Some of our processors are established in the United States, or may route data there. For those transfers we rely on the safeguards below, as required by Chapter V GDPR:

You can request a copy of the safeguards applying to any transfer by writing to [email protected].

08Social sign-in

If you sign in with Google, Facebook, Microsoft or Apple, we receive only your name, email address and profile picture URL where available. We do not receive access to your posts, friend lists, contacts on those platforms, or any other data, and we never post anything on your behalf.

The data we receive is governed by each provider’s own privacy policy: Google, Meta, Microsoft, Apple.

You can also sign in with an email address and a one-time passcode delivered to your inbox, without involving any social provider.

09Your privacy controls

Dit gives you granular control over your privacy from Settings → Privacy.

Profile visibility

You control who can see your name and your bio independently. Each field has three options:

Your username and profile picture are always visible: the username is what lets others find you, and the picture falls back to your initials if you haven’t set one.

User blocking

You can block any user at any time. Blocking is completely silent — the blocked user is never notified. When you block someone:

! irreversible

Blocking permanently deletes all signal history between you and the blocked user, for both of you. This cannot be undone, even if you later unblock them.

Confidential by design

Dit is designed so that if someone picks up your phone, they see very little. There are no message previews, no text content, no media. The timeline shows only abstract visual indicators representing that signals were exchanged.

10Notifications

Dit sends push notifications in two cases:

Notifications carry custom sounds inspired by Morse code: two short tones (··) for a dit — the letter “I”, meaning “me” — and two short plus one long (··—) for a dah — the letter “U”, meaning “you”. You can reply with a dah directly from the notification without opening the app.

Notification payloads contain the sender’s display name and the signal type. They never contain message content, because none exists.

Multi-device

If you are logged in on several devices, notifications reach all of them. Reading or dismissing a notification on one device dismisses it on the others. Logging out of a device immediately deletes that device’s push tokens, and nothing further is sent to it.

You can withdraw notification consent at any time in your device’s system settings. Dit keeps working; you simply stop receiving alerts.

11Data retention

DataRetention
Dits & dahsA signal stops being actionable when its TTL expires (1, 6 or 24 hours) and is marked expired. The record is retained for RETENTION PERIOD after creation and then deleted, so that your timeline history stays available. Deleted immediately and permanently if either party blocks the other.
Account dataRetained until you delete your account.
Deleted accountsErased from live systems the moment you confirm — see Delete your data.
BackupsDatabase snapshots are kept for 14 days on a rolling basis. Data from a deleted account may persist in a backup for up to 14 days after erasure, after which it is overwritten. Backups are only ever restored wholesale after an incident, never queried to retrieve an individual record.
Push tokensDeleted immediately on logout, or when the provider reports the token invalid.
Server logs30 days, then permanently deleted.
One-time passcodesValid for 10 minutes; not retained after use or expiry.
Block recordsRetained until you unblock the user — the record is what enforces the block.
SessionsExpire 30 days after issue, or immediately on logout.

12Your rights

Under the GDPR and UK GDPR you have the following rights. You can exercise all of them by writing to [email protected], and several directly in the app:

We answer requests within one month, as required by Article 12(3) GDPR. If a request is complex we may extend by up to two further months and will tell you why within the first month. Exercising these rights is free; we may charge a reasonable fee only for manifestly unfounded or excessive repeat requests. We may ask you to confirm your identity before acting, to make sure we don’t disclose your data to someone else.

13US state privacy rights

If you are a resident of California, or of another US state with a comprehensive privacy law (including Virginia, Colorado, Connecticut, Utah and Texas), you have additional rights. Dit is a free personal project and almost certainly falls below the revenue and volume thresholds that make those laws binding — we grant these rights anyway, and will honour them as if the laws applied.

In the twelve months preceding the date of this policy, we collected the following categories of personal information under the CCPA/CPRA: identifiers (email address, username, name, IP address, device identifiers) and internet or network activity (server logs). We collect these for the business purposes described above, from you directly and from the social sign-in provider you choose.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA/CPRA. We have never done so, including with respect to minors under 16. We do not use or disclose sensitive personal information for purposes requiring a right to limit.

You have the right to:

Submit requests to [email protected]. We respond within 45 days, extendable once by a further 45 days where permitted. You may use an authorised agent; we will ask for proof of authorisation. We honour Global Privacy Control signals where they apply.

14Security

No system is completely secure. We take reasonable and proportionate technical and organisational measures under Article 32 GDPR, but we cannot guarantee absolute security. If you discover a vulnerability, please report it to [email protected]. We will acknowledge your report and will not pursue legal action against good-faith security research.

15Breach notification

If a personal data breach occurs, we will notify the competent supervisory authority within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to your rights and freedoms (Article 33 GDPR).

Where a breach is likely to result in a *high* risk to you, we will also notify you directly and without undue delay, describing what happened, what data was involved, what we are doing about it, and what you can do to protect yourself (Article 34 GDPR).

16Automated decisions and profiling

Dit does not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR. There is no profiling, no scoring, no ranking algorithm and no recommendation engine. Signals are delivered in the order they are sent.

17Children

Dit is not directed at children. You must be at least 16 to use Dit in the European Union and the United Kingdom, unless the Member State where you live has set a lower age of digital consent — the age is 14 in Italy, and Member States may set it anywhere between 13 and 16 under Article 8 GDPR. Outside the EU and UK the minimum age is 13.

We do not knowingly collect personal data from anyone below the applicable age. We do not ask for a date of birth, so we cannot verify age proactively; we rely on the age ratings declared on the App Store and Google Play and act on reports.

If you believe a child below the applicable age has created an account, write to [email protected] and we will verify and delete it promptly, together with any data collected. See also our Safety standards.

18Cookies & sessions

The Dit app and API use a single session cookie to keep you logged in. This cookie:

Dit uses no advertising cookies, no tracking pixels and no cross-site tracking.

This website

CONFIRM OR REMOVE — if this site uses privacy-friendly, cookieless audience measurement, describe it here: what is measured, that no cookie is set, that no cross-site profile is built, and the legal basis (legitimate interest). If the site sets no measurement of any kind, replace this paragraph with a plain statement to that effect.

19Changes to this policy

We may update this policy as Dit evolves. If we make material changes, we will notify you in the app or by email at least 14 days before they take effect, so you can review them or delete your account first. Where a change requires your consent, we will ask for it rather than assume it.

The version number and dates at the top of this page always reflect the current text. Continuing to use Dit after changes take effect means you accept the updated policy.

20Contact

For any privacy question, data access request, or concern:

[email protected]

We acknowledge messages within 5 business days and complete requests within the statutory deadlines set out above.