1. Who we are & how to contact us
This policy explains how DeSpy (“DeSpy”, “we”, “us”) handles personal data collected through our website at despy.app. DeSpy is the data controller responsible for the personal data described here.
- Controller: Global Digital Forensics, Inc., PO Box 431, Crystal Beach, FL 34681-0431
- Privacy / data-protection contact: privacy@despy.app
- General enquiries: hello@despy.app
For any privacy question or to exercise your rights, email privacy@despy.app. See also our Terms and our Cookies & Storage page.
2. Summary of our commitments
In plain terms:
- We never sell or share your personal data, and we do not disclose it to data brokers or advertisers.
- We set no cookies at all — no session cookie, no consent cookie, no tracking cookie.
- We run no analytics, no advertising, no third-party scripts, and no device fingerprinting. Our Content-Security-Policy blocks third-party code from loading on every page.
- We collect personal data only when you choose to give it to us — primarily by applying to the beta.
3. What personal data we collect
3a. What you give us (the beta application form)
When you apply to the DeSpy beta, we collect the following fields:
- Full name (required)
- Email address (required)
- Organization (optional)
- Platforms you want to test — one or both of iOS / Android
- Country (optional, 2-letter code)
- Reason for applying (required free text)
- Marketing opt-in (optional) — whether you agree to receive occasional product email
- Two required consent confirmations — that you have read the privacy notice and that you accept the beta terms
We record the privacy-notice and beta-terms version strings in effect when you submit (currently 2026-07-15), so we have a record of exactly what you agreed to.
3b. What is collected automatically
When you submit the form (or, later, download a build), our server records a small amount of technical data for security and abuse prevention:
- A salted, one-way hash of your IP address —
SHA-256(ip + secret salt). Your raw IP address is never stored. - Your browser user-agent string.
- A submission timestamp and an application status.
We do not collect analytics, tracking data, device fingerprints, or any behavioural profile. We do not collect your device model, OS version, phone number, or how you heard about us.
3c. Newsletter subscriptions (the homepage box)
Submitting the homepage “Join the privacy movement” box sends your email address to our server together with the same anti-abuse technical data as above (salted IP hash, user-agent) and the consent version in effect. The address is encrypted at rest; nothing is subscribed until you click the confirmation link we email you; an unconfirmed signup is deleted automatically when its confirmation window lapses; and every newsletter carries a one-click unsubscribe that blanks the sealed address. Our newsletters contain no tracking pixels and no click tracking.
3d. Bug reports
If you submit a bug report (from this site or from the app), we store the report content you write, an optional contact email (encrypted at rest, opened only to reply to you), any attachments you include (re-encoded to strip location and other metadata), and the same anti-abuse technical data as above. This is also disclosed at the point of collection on the report form, and bug-report contact details are covered by the same self-service erasure as beta applications.
3e. Corrections and disputes about our research
Every page in our research databases carries a “Think something here is wrong?” form. Submitting it stores the message you write, which page it came from, and the date (day only). We store no IP address and no user-agent for these — unlike every other form on this site. The contact email is optional: leave it blank and your correction is genuinely anonymous. If you do give one, it is encrypted at rest and opened only to answer you.
That address exists to answer one correction, so it expires on its own: it is erased 30 days after we mark the matter resolved, or 180 days after you sent it if it is still open — whichever comes first. You do not have to ask. It is also covered by the same self-service erasure as everything else, and erasing it leaves your correction in place, anonymously — we would rather fix the page than lose the reason to.
4. Why we process it & our legal basis
Under the GDPR (Article 6), each purpose rests on a specific legal basis:
| Purpose | Data used | Legal basis |
|---|---|---|
| Evaluating your beta application | Name, email, organization, platforms, country, reason, consent records | Consent — Art. 6(1)(a) |
| Sending optional marketing / product email | Email (only if you opted in) | Consent — Art. 6(1)(a) |
| Administering beta access after approval (download links, tester communications) | Email, application record, tokenized download data | Contract / pre-contract — Art. 6(1)(b) |
| Security, abuse prevention, and rate limiting | Salted IP hash, user-agent, timestamps | Legitimate interest — Art. 6(1)(f) |
Where we rely on consent, you may withdraw it at any time (see Your rights); withdrawing does not affect the lawfulness of processing before withdrawal.
5. Approved-tester download data
If your application is approved, we mint a per-tester tokenized download link. To protect that link:
- The token is stored only as a SHA-256 hash — never in plain form.
- The link expires 14 days after it is issued and allows at most 5 downloads.
- Each download is logged with a salted IP hash, user-agent, and timestamp. No raw IP address is recorded.
These logs exist to keep the private beta builds from being redistributed and to detect abuse.
6. How long we keep it
- Denied or inactive applications: deleted no later than 12 months after submission.
- Approved-tester records: kept for the duration of the beta program and deleted within 90 days of the program’s end.
- Newsletter subscriptions (the homepage box): an unconfirmed signup that is never confirmed is deleted automatically after its confirmation window lapses; a confirmed subscription is kept until you unsubscribe, at which point the sealed address is blanked.
- Contact emails on research corrections: erased 30 days after the matter is marked resolved, or 180 days after submission if it is still open — whichever comes first. The correction itself stays, without the address.
What erasure leaves behind
When you request removal, we erase your entire application row — including the salted IP hash and user-agent stored inside it. All we retain afterwards is a minimal anonymous suppression record (email blanked, status set to “erased”, and an anonymization timestamp). It contains no personal data and exists only as proof that your request was fulfilled.
7. Your rights & how to exercise them
Depending on where you live, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your data (“right to be forgotten”)
- Restrict processing
- Object to processing based on legitimate interest
- Portability — receive your data in a portable format
- Withdraw consent at any time
- Lodge a complaint with a supervisory authority
How to exercise them
- Self-service data removal. Use the data-removal form, enter any address you have given us, and we email a confirmation link to that address. Confirming erases every record we hold under it — beta application, bug-report and research-correction contacts, and newsletter subscription — and revokes any active download links.
- Email us. For any right, write to privacy@despy.app.
Identity verification: for self-service removal, we send a confirmation link to the email address on file before anything is erased, so only the account owner can trigger deletion.
Response time: we respond within 30 days. You will never be treated differently for exercising your rights.
8. California privacy rights (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect and how we use it (set out in this policy)
- Delete the personal information we hold about you
- Correct inaccurate personal information
- Opt out of the sale or sharing of your personal information — there is nothing to opt out of, because we do not sell or share personal information
- Non-discrimination — we will not discriminate against you for exercising any of these rights
To make a request, use the data-removal form or email privacy@despy.app.
9. Who else can access it
Sub-processors
We keep external processors to the absolute minimum:
- Infrastructure / hosting: the site and its data run on a Linode (Akamai) virtual server. This is our infrastructure sub-processor.
- Email delivery: Twilio SendGrid (SendGrid, Inc., a Twilio company) relays the email DeSpy sends — account confirmations, beta-program mail, data-request replies and the newsletter. SendGrid processes the recipient address and message content for the purpose of delivering that message. It is not used for advertising or profiling, and DeSpy sends it no other personal data. You can always use privacy@despy.app as an alternative channel for data requests.
- No advertising, analytics, or data-broker processors — ever.
Law enforcement
We disclose personal data to authorities only when compelled by valid legal process, and only to the extent required.
10. International transfers
Our hosting infrastructure may be located outside your region. Where personal data is transferred internationally, we rely on appropriate safeguards — such as the EU Standard Contractual Clauses (SCCs) — to protect it.
11. How we secure it
We apply strong technical protections across the site:
- HTTPS everywhere, with HSTS (2-year
max-age,includeSubDomains). - A Content-Security-Policy on every page that permits scripts and styles from our own origin only — no third-party code can load. The only third-party content permitted is images and, on pages that embed them, the YouTube/Vimeo video players.
X-Content-Type-Options: nosniffandReferrer-Policy: strict-origin-when-cross-origin.- A Permissions-Policy disabling geolocation, microphone, and camera.
- IP addresses are pseudonymized via a salted one-way hash; download tokens are stored only as hashes.
- Data at rest lives in a server-side SQLite database on a hardened, access-controlled server; administrative access requires multi-factor authentication.
For plain-language answers to common security questions — encryption, backups, hosting location, access controls, and audits — see our Data Security & Privacy FAQ.
12. Children
DeSpy is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact privacy@despy.app and we will delete it.
13. Cookies & browser storage
We set no cookies. The only data stored in your browser is one localStorage key:
despy_consent_v1— your consent record: the policy version, the decision timestamp, a Global Privacy Control flag, and your category choices (necessary: true,functional: true|false). This is strictly necessary and is written when you make a choice in the cookie banner.
The email you type into the homepage “Join the privacy movement” box is not stored in your browser — submitting it sends the address to our server to start a double-opt-in newsletter subscription. Nothing is subscribed until you click the confirmation link we email you, the stored address is encrypted at rest, and every newsletter carries a working unsubscribe. The full detail is in section 3.
We detect and honor Global Privacy Control (GPC): if GPC is present and you have not made a choice, the functional category defaults off. For full detail, see our Cookies & Storage page.
14. Changes & consent versioning
Our privacy notice and beta terms carry version strings (currently 2026-07-15), which we record against each application at submission. The cookie consent record stores the policy version you agreed to. If we make material changes, we bump the version and re-prompt you for consent where required.
This document is labelled Version 2026-07-15, last reviewed 2026-07-31.