Draft — not yet in force
Privacy policy
This draft says what Duongöndro stores, where, and why. It has not been reviewed by a lawyer and does not apply until it is published without this banner.
Controller: [CONTROLLER NAME AND ADDRESS]. Contact: [CONTACT EMAIL].
What is end-to-end encrypted
These are sealed on your device before they are uploaded. The server stores them and cannot read them:
- practice sessions, including the day, the duration and your notes
- counts, rounds and totals
- targets
- imported streak seeds
The keys that open them stay on your devices. The server never receives a plaintext count or a key, and signing in does not give it one.
What the server stores in plain form
- your account, and the Apple or Google sign-in linked to it
- your display name and avatar
- your friendships
- the invite tree: who invited whom
- your streaks, only for practices where you chose to publish them, with a signature
- the public keys of your devices
- push notification tokens
- when you upload, and how large each sealed blob is
The last item is a real limit. Upload times and sizes can suggest when you practise, even for a private streak.
Cover photos for practices never leave your phone.
Religious belief and consent
Being a member of a Buddhist practice app says something about your religious belief. Under Article 9 of the GDPR that is special-category data. We ask for your explicit consent before you create an account. You can withdraw it at any time by deleting your account, which takes effect immediately.
There is no member directory. Only friends you have accepted can see your name.
Hosting, analytics and third parties
- The server is hosted in the EU. [HOSTING PROVIDER AND REGION, TO CONFIRM]
- No analytics, no advertising, no trackers, no crash-reporting service.
- This website uses no third-party fonts or scripts and makes no requests to other sites. Invite codes in link fragments are read in your browser and are not sent to us.
- Push notifications go through Apple or Google, which is how push works on those platforms. The text of a notification is built on your device.
Your rights: export and deletion
Both are done inside the app, with no email needed.
- Access and portability (Articles 15 and 20): Settings › Your data › Export gives you a ZIP of machine-readable JSON, with your sessions decrypted on your phone.
- Erasure (Article 17): Settings › Your data › Delete everything removes your account and everything linked to it from the server in one step, and then from your phone. The invite tree keeps an anonymous placeholder with no name, so that other people's “invited by” stays consistent.
You can also contact us at [CONTACT EMAIL], and you can complain to your data protection authority.
Backups and logs
Encrypted database backups are kept for 30 days [TO CONFIRM]. A deleted account disappears from backups as they expire, and a restore re-applies deletions. Server logs never contain your content and are kept for at most the same period.
Changes
This draft will change before it comes into force. The history is public in the source repository.