Privacy
Privacy Policy summary
Last updated: 2026-07-20 · v2.9
The one-line version
You can use dadokim without signing up. Free text is optional, dadokim stores neither the original nor its hash, and you choose whether to enable app analytics during first run.
What we collect
- Anonymous ID: a UUID used only in the app or on functional web routes such as gifts and account tools. SEO, legal, and FAQ pages do not issue an identity cookie. Account linking is optional.
- Free text · safety level: processed for card generation and safe routing after separate consent. dadokim stores neither the original nor its hash; the safety level stays with the card. If a defined special-category or crisis pattern is detected, that dynamic text is not sent to the overseas LLM model and a local safety or fallback path is used.
- Required operational events: minimal authentication, purchase, gift, push-state, and report records needed for functionality and security. Never your line or card text.
- Web/API diagnostics: Sentry processes errors and a 10% sample of production server/edge traces. Request and user objects, free text, and dynamic route or span values are removed or normalized before transmission; no native Android crash SDK or Session Replay is used.
- Optional analytics events: app screen-use, card-generation-flow, and purchase-flow data only after you opt in. Withdrawal deletes previously collected optional analytics events.
- Gift-message reports: a limited message snapshot, reason, and action record kept for up to 90 days, then deleted or de-identified.
- Device and security information: anonymous ID, request-limit keys, and device or OS information derived from the user-agent. Identifying fields are cleared within 1 year.
- Push information: token, locale, timezone, and delivery preferences only after notifications are enabled. Disabled rows are kept up to 90 days and long-inactive tokens up to 180 days.
- Email: optional, for sign-in, recovery, and receipts. Never required for free use.
- Google account information: when you choose Google sign-in, the token's user ID, email, and profile name are processed for authentication. We do not store the raw token or profile name.
- Payment info: Apple handles iOS purchases, Google Play handles Android purchases, and RevenueCat manages app purchase history. Web checkout is not currently offered; only past web-transaction records may remain for the applicable retention period. Your card number never reaches our servers.
- Apple refund consumption information: only after separate optional consent, we send Apple the consent flag, delivery status, consumption percentage, whether a free sample or functionality information was provided before purchase, and our refund preference. Declining does not restrict purchases or refund requests.
What we don’t collect
- A member profile that directly asks for and stores your name or phone number (a Google token's profile name is processed during authentication but not stored)
- Storage of your original free text or its hash in dadokim's database
- Precise GPS location
- Third-party ad pixels (no Meta, Google, or TikTok pixels)
How long we keep it
- Anonymous ID: 1 year when inactive · optional app events: up to 1 year
- Safety Router (crisis detection) logs: 90 days
- Free text sent to the overseas LLM model: up to 30 days under its API policy, subject to policy-enforcement or legal exceptions
- Sentry active web/API diagnostic events: 30 days · production backups: 90 days
- Payment and withdrawal records: up to 5 years · consumer complaint and dispute records: at least 3 years within that 5-year ceiling
- Post-purchase surveys: up to 1 year
- Email: deleted on request, except minimum information in legally retained transaction records for up to 5 years
Your rights
- Delete your account and records in Me > Account in the app
- Decline sensitive free text or withdraw app analytics consent
- Decline or withdraw consent for Apple refund consumption information
- Report a gift message, block its sender, or change message visibility
- Request a copy of your data
- Unsubscribe from emails anytime
Requests: privacy@dadokim.com
Third parties
- Supabase (database · US · EU): data storage · SOC 2 certified
- Vercel (hosting · US): page serving
- Apple · Google Play · RevenueCat (app purchases · US): purchase processing and history. Apple receives refund consumption information only after separate optional consent; rights for data held by Apple can be exercised at privacy.apple.com.
- Google (sign-in and Android FCM · US and other processing regions): optional account authentication and opt-in push delivery
- Expo (push relay · US): opt-in notification delivery
- Sentry (web/API diagnostics · United States): error monitoring and a 10% sample of production server/edge traces
- Polar Software, Inc. (past web payments · US · Merchant of Record): existing transaction-record management
- Overseas LLM model provider: card generation from separately consented free text (detected contact and financial identifiers masked · defined special-category or crisis patterns blocked from transmission · dadokim stores no original or hash · retention exceptions and legally required recipient details are in the full Privacy Policy)
We don’t share your data with ad or marketing companies.
This is the user-friendly summary. The full version lives in our privacy policy.