Privacy Policy
version 3.0 · last updated 28 July 2026 · effective 11 August 2026
Dit is a minimal presence signalling app. You send a dit to say “I’m here” and receive a dah back meaning “received”. No messages, no text, no media. Just presence. This policy explains what we collect, on what legal basis, who it reaches, and how long we keep it.
✓ privacy by design
Dit collects the minimum data necessary. We don’t read your messages — because there are none. We don’t track your location. We don’t serve ads. We don’t sell or share your personal information, as those terms are defined under California law.
01Who is responsible for your data
Dit is a free personal project, not a business. There is no company behind it, no advertising, no in-app purchases, no paid tier and no monetisation of any kind.
The data controller — the person who decides why and how your data is processed — is Marius Trica, acting as a private individual, reachable at [email protected].
Because Dit is run by one person and processes very little data, we are not required to appoint a Data Protection Officer: requests are handled directly by the controller. If you need a postal address — to serve a formal notice, or because a supervisory authority has asked you for one — request it at the address above and it will be provided.
02What is Dit
Dit is a mobile application for iOS and Android that lets you exchange minimal presence signals with your contacts. The two signal types are:
- Dit (·) — a brief signal you send to let someone know you’re thinking of them. Each dit has a time-to-live of 1 hour, 6 hours or 24 hours, after which it stops being actionable and is marked as expired.
- Dah (—) — an acknowledgement sent back when you receive a dit. It means “received” or “I’m here too”.
Dit is not a messaging app. There is no text, no images, no voice, no video. The only information exchanged is the fact that a signal was sent and whether it was acknowledged.
03Data we collect
We collect only what is necessary to make Dit work.
| Data | Details |
|---|---|
| Account | Email address and name when you register. Username you choose during setup (3–24 characters). Optional: bio (max 140 characters) and profile picture. |
| Credentials | If you register with a password, we store only a cryptographic hash of it, never the password itself. If you use a one-time passcode, the code is valid for 10 minutes and is not retained after use. |
| Social login | If you sign in via Google, Facebook, Microsoft or Apple, we receive your name, email address and profile picture URL from that provider. Nothing else. Profile pictures are referenced by URL — we do not copy or host the image. |
| Contacts | The list of Dit users you choose to save, plus any private nicknames you assign. We never access your device’s address book, and Dit never requests that permission. |
| Dits & dahs | Sender, recipient, timestamps of signals sent and received, their status (pending, acknowledged, expired, ignored) and TTL duration. No message content exists. |
| Presence | Whether you are currently connected. This is held in memory by the real-time service for the duration of your connection and is not written to the database. Dit does not record or display a “last seen” timestamp. |
| Push tokens | A device identifier issued by Apple (APNs) or Google (FCM) to deliver notifications. Used exclusively for Dit notifications. Deleted on logout. |
| Server logs | IP address, device type, operating system, request metadata. For security, abuse prevention and debugging only. Retention: 30 days. |
What we do not collect
- Message content — Dit has none.
- Location data, in any form, including approximate or IP-derived location.
- Your device’s contact list or address book.
- Microphone, camera or sensor data.
- Advertising identifiers (IDFA / GAID) or tracking pixels.
- Browsing history or cross-app usage analytics.
- Financial or payment information — Dit is free and has no in-app purchases.
- Special category data under Article 9 GDPR (health, biometrics, beliefs, and so on).
The Dit mobile app contains no analytics or crash-reporting SDK of any kind.
04How we use your data
- To create and manage your Dit account.
- To deliver dits and dahs between you and your contacts in real time.
- To send push notifications when you receive a dit or a dah while the app is closed.
- To send scheduled reminders for pending dits before they expire, so signals aren’t missed.
- To show your online status to contacts you have approved.
- To enforce your privacy settings (profile visibility, user blocking).
- To secure the service, prevent abuse and debug faults.
- To comply with legal obligations where they apply to us.
We do not use your data for advertising, profiling or behavioural analytics. We do not sell, rent or trade your data to anyone.
05Legal bases for processing
If you are in the European Union, the European Economic Area or the United Kingdom, we must have a legal basis under Article 6 GDPR for every purpose. These are ours:
| Purpose | Legal basis |
|---|---|
| Creating and running your account; delivering dits and dahs; storing your contacts and privacy settings | Performance of a contract — Art. 6(1)(b). Without this data the service cannot be provided to you. |
| Push notifications and expiry reminders | Consent — Art. 6(1)(a), given through your device’s notification permission prompt. Withdrawable at any time in system settings, with no effect on the rest of the service. |
| Server logs, rate limiting, abuse prevention, security monitoring | Legitimate interests — Art. 6(1)(f): keeping the service available and protecting users from abuse. We balanced this against your rights and limited retention to 30 days to keep the impact minimal. |
| Transactional email (verification codes, password reset) | Performance of a contract — Art. 6(1)(b). |
| Responding to legal requests; retaining records where the law requires it | Legal obligation — Art. 6(1)(c). |
Where we rely on legitimate interests, you have the right to object — see Your rights. Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
07International data transfers
Dit’s servers are located in DATACENTRE REGION. Where that region is inside the EEA, your service data does not leave the EEA in normal operation.
Some of our processors are established in the United States, or may route data there. For those transfers we rely on the safeguards below, as required by Chapter V GDPR:
- Google LLC and Apple Inc. — the EU–US Data Privacy Framework adequacy decision, supplemented by Standard Contractual Clauses.
- DigitalOcean, LLC — Standard Contractual Clauses incorporated into its Data Processing Agreement.
- Brevo — established in France; data processed within the EU.
You can request a copy of the safeguards applying to any transfer by writing to [email protected].
09Your privacy controls
Dit gives you granular control over your privacy from Settings → Privacy.
Profile visibility
You control who can see your name and your bio independently. Each field has three options:
- Everyone — any Dit user can see it (default).
- My contacts — only users you have saved as contacts.
- Nobody — hidden from everyone except you.
Your username and profile picture are always visible: the username is what lets others find you, and the picture falls back to your initials if you haven’t set one.
User blocking
You can block any user at any time. Blocking is completely silent — the blocked user is never notified. When you block someone:
- All dits between you and that person are permanently deleted in both directions.
- All contact records between you are deleted in both directions.
- The blocked user can no longer find you in search, send you dits, or see your profile.
- They cannot distinguish being blocked from you having deleted your account.
- You can unblock at any time, but deleted data cannot be recovered.
! irreversible
Blocking permanently deletes all signal history between you and the blocked user, for both of you. This cannot be undone, even if you later unblock them.
Confidential by design
Dit is designed so that if someone picks up your phone, they see very little. There are no message previews, no text content, no media. The timeline shows only abstract visual indicators representing that signals were exchanged.
10Notifications
Dit sends push notifications in two cases:
- When you receive a dit — an immediate notification plus optional reminders before it expires.
- When your dit receives a dah — a single notification confirming acknowledgement.
Notifications carry custom sounds inspired by Morse code: two short tones (··) for a dit — the letter “I”, meaning “me” — and two short plus one long (··—) for a dah — the letter “U”, meaning “you”. You can reply with a dah directly from the notification without opening the app.
Notification payloads contain the sender’s display name and the signal type. They never contain message content, because none exists.
Multi-device
If you are logged in on several devices, notifications reach all of them. Reading or dismissing a notification on one device dismisses it on the others. Logging out of a device immediately deletes that device’s push tokens, and nothing further is sent to it.
You can withdraw notification consent at any time in your device’s system settings. Dit keeps working; you simply stop receiving alerts.
11Data retention
| Data | Retention |
|---|---|
| Dits & dahs | A signal stops being actionable when its TTL expires (1, 6 or 24 hours) and is marked expired. The record is retained for RETENTION PERIOD after creation and then deleted, so that your timeline history stays available. Deleted immediately and permanently if either party blocks the other. |
| Account data | Retained until you delete your account. |
| Deleted accounts | Erased from live systems the moment you confirm — see Delete your data. |
| Backups | Database snapshots are kept for 14 days on a rolling basis. Data from a deleted account may persist in a backup for up to 14 days after erasure, after which it is overwritten. Backups are only ever restored wholesale after an incident, never queried to retrieve an individual record. |
| Push tokens | Deleted immediately on logout, or when the provider reports the token invalid. |
| Server logs | 30 days, then permanently deleted. |
| One-time passcodes | Valid for 10 minutes; not retained after use or expiry. |
| Block records | Retained until you unblock the user — the record is what enforces the block. |
| Sessions | Expire 30 days after issue, or immediately on logout. |
12Your rights
Under the GDPR and UK GDPR you have the following rights. You can exercise all of them by writing to [email protected], and several directly in the app:
- Access — obtain confirmation of what we hold about you and a copy of it.
- Rectification — correct inaccurate data, from
Settings → Account. - Erasure — delete your account and associated data. See Delete your data.
- Restriction — ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
- Objection — object to processing based on legitimate interests. We will stop unless we can show compelling grounds that override your interests.
- Portability — receive your data in a structured, commonly used, machine-readable format (JSON), or have it sent directly to another controller where technically feasible.
- Withdraw consent — for notifications, from your device’s system settings, at any time.
- Complain — lodge a complaint with your local supervisory authority. In Italy that is the Garante per la protezione dei dati personali; in the UK, the ICO. You may also complain to the authority where you live or work.
We answer requests within one month, as required by Article 12(3) GDPR. If a request is complex we may extend by up to two further months and will tell you why within the first month. Exercising these rights is free; we may charge a reasonable fee only for manifestly unfounded or excessive repeat requests. We may ask you to confirm your identity before acting, to make sure we don’t disclose your data to someone else.
13US state privacy rights
If you are a resident of California, or of another US state with a comprehensive privacy law (including Virginia, Colorado, Connecticut, Utah and Texas), you have additional rights. Dit is a free personal project and almost certainly falls below the revenue and volume thresholds that make those laws binding — we grant these rights anyway, and will honour them as if the laws applied.
In the twelve months preceding the date of this policy, we collected the following categories of personal information under the CCPA/CPRA: identifiers (email address, username, name, IP address, device identifiers) and internet or network activity (server logs). We collect these for the business purposes described above, from you directly and from the social sign-in provider you choose.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA/CPRA. We have never done so, including with respect to minors under 16. We do not use or disclose sensitive personal information for purposes requiring a right to limit.
You have the right to:
- Know what personal information we collect, use and disclose.
- Delete personal information we hold about you.
- Correct inaccurate personal information.
- Opt out of sale or sharing — not applicable, since we do neither.
- Not be discriminated against for exercising any of these rights. Dit is free, has a single tier, and your privacy choices never change the service you receive.
Submit requests to [email protected]. We respond within 45 days, extendable once by a further 45 days where permitted. You may use an authorised agent; we will ask for proof of authorisation. We honour Global Privacy Control signals where they apply.
14Security
- All data in transit is encrypted with TLS, with certificates renewed automatically.
- Passwords are never stored in plain text. They are stored only as salted cryptographic hashes produced by a memory-hard key derivation function.
- Sessions use
httpOnly,securecookies with a 30-day maximum lifetime; the cookie holds an opaque identifier, never personal data. - Real-time WebSocket connections are authenticated with separate short-lived tokens valid for 15 minutes, issued by the API and validated independently by the real-time service.
- Push notification tokens are cleaned up automatically on logout and whenever a provider reports a token as expired or invalid.
- Database backups run nightly and are retained on a 14-day rolling window.
- We apply the principle of least privilege to all internal systems and keep administrative access limited to the controller.
No system is completely secure. We take reasonable and proportionate technical and organisational measures under Article 32 GDPR, but we cannot guarantee absolute security. If you discover a vulnerability, please report it to [email protected]. We will acknowledge your report and will not pursue legal action against good-faith security research.
15Breach notification
If a personal data breach occurs, we will notify the competent supervisory authority within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to your rights and freedoms (Article 33 GDPR).
Where a breach is likely to result in a *high* risk to you, we will also notify you directly and without undue delay, describing what happened, what data was involved, what we are doing about it, and what you can do to protect yourself (Article 34 GDPR).
16Automated decisions and profiling
Dit does not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR. There is no profiling, no scoring, no ranking algorithm and no recommendation engine. Signals are delivered in the order they are sent.
17Children
Dit is not directed at children. You must be at least 16 to use Dit in the European Union and the United Kingdom, unless the Member State where you live has set a lower age of digital consent — the age is 14 in Italy, and Member States may set it anywhere between 13 and 16 under Article 8 GDPR. Outside the EU and UK the minimum age is 13.
We do not knowingly collect personal data from anyone below the applicable age. We do not ask for a date of birth, so we cannot verify age proactively; we rely on the age ratings declared on the App Store and Google Play and act on reports.
If you believe a child below the applicable age has created an account, write to [email protected] and we will verify and delete it promptly, together with any data collected. See also our Safety standards.
19Changes to this policy
We may update this policy as Dit evolves. If we make material changes, we will notify you in the app or by email at least 14 days before they take effect, so you can review them or delete your account first. Where a change requires your consent, we will ask for it rather than assume it.
The version number and dates at the top of this page always reflect the current text. Continuing to use Dit after changes take effect means you accept the updated policy.
20Contact
For any privacy question, data access request, or concern:
We acknowledge messages within 5 business days and complete requests within the statutory deadlines set out above.
08Social sign-in
If you sign in with Google, Facebook, Microsoft or Apple, we receive only your name, email address and profile picture URL where available. We do not receive access to your posts, friend lists, contacts on those platforms, or any other data, and we never post anything on your behalf.
The data we receive is governed by each provider’s own privacy policy: Google, Meta, Microsoft, Apple.
You can also sign in with an email address and a one-time passcode delivered to your inbox, without involving any social provider.