The short version. We never sell or share your personal data, and we do not use it for advertising. We set no cookies and run no analytics, trackers, fingerprinting, or third-party scripts; the only thing stored in your browser is one localStorage key remembering your privacy choices. The homepage email box starts a double-opt-in newsletter signup — it does send your address to our server, where it is encrypted at rest and never shared. If you have ever given us an email address — a beta application, a bug report, a correction to our research, or the newsletter — you can erase all of it yourself at any time via the data-removal form, or by emailing privacy@despy.app.

1. Who we are & how to contact us

This policy explains how DeSpy (“DeSpy”, “we”, “us”) handles personal data collected through our website at despy.app. DeSpy is the data controller responsible for the personal data described here.

For any privacy question or to exercise your rights, email privacy@despy.app. See also our Terms and our Cookies & Storage page.

2. Summary of our commitments

In plain terms:

3. What personal data we collect

3a. What you give us (the beta application form)

When you apply to the DeSpy beta, we collect the following fields:

We record the privacy-notice and beta-terms version strings in effect when you submit (currently 2026-07-15), so we have a record of exactly what you agreed to.

3b. What is collected automatically

When you submit the form (or, later, download a build), our server records a small amount of technical data for security and abuse prevention:

We do not collect analytics, tracking data, device fingerprints, or any behavioural profile. We do not collect your device model, OS version, phone number, or how you heard about us.

3c. Newsletter subscriptions (the homepage box)

Submitting the homepage “Join the privacy movement” box sends your email address to our server together with the same anti-abuse technical data as above (salted IP hash, user-agent) and the consent version in effect. The address is encrypted at rest; nothing is subscribed until you click the confirmation link we email you; an unconfirmed signup is deleted automatically when its confirmation window lapses; and every newsletter carries a one-click unsubscribe that blanks the sealed address. Our newsletters contain no tracking pixels and no click tracking.

3d. Bug reports

If you submit a bug report (from this site or from the app), we store the report content you write, an optional contact email (encrypted at rest, opened only to reply to you), any attachments you include (re-encoded to strip location and other metadata), and the same anti-abuse technical data as above. This is also disclosed at the point of collection on the report form, and bug-report contact details are covered by the same self-service erasure as beta applications.

3e. Corrections and disputes about our research

Every page in our research databases carries a “Think something here is wrong?” form. Submitting it stores the message you write, which page it came from, and the date (day only). We store no IP address and no user-agent for these — unlike every other form on this site. The contact email is optional: leave it blank and your correction is genuinely anonymous. If you do give one, it is encrypted at rest and opened only to answer you.

That address exists to answer one correction, so it expires on its own: it is erased 30 days after we mark the matter resolved, or 180 days after you sent it if it is still open — whichever comes first. You do not have to ask. It is also covered by the same self-service erasure as everything else, and erasing it leaves your correction in place, anonymously — we would rather fix the page than lose the reason to.

4. Why we process it & our legal basis

Under the GDPR (Article 6), each purpose rests on a specific legal basis:

Where we rely on consent, you may withdraw it at any time (see Your rights); withdrawing does not affect the lawfulness of processing before withdrawal.

5. Approved-tester download data

If your application is approved, we mint a per-tester tokenized download link. To protect that link:

These logs exist to keep the private beta builds from being redistributed and to detect abuse.

6. How long we keep it

What erasure leaves behind

When you request removal, we erase your entire application row — including the salted IP hash and user-agent stored inside it. All we retain afterwards is a minimal anonymous suppression record (email blanked, status set to “erased”, and an anonymization timestamp). It contains no personal data and exists only as proof that your request was fulfilled.

7. Your rights & how to exercise them

Depending on where you live, you have the right to:

How to exercise them

  1. Self-service data removal. Use the data-removal form, enter any address you have given us, and we email a confirmation link to that address. Confirming erases every record we hold under it — beta application, bug-report and research-correction contacts, and newsletter subscription — and revokes any active download links.
  2. Email us. For any right, write to privacy@despy.app.

Identity verification: for self-service removal, we send a confirmation link to the email address on file before anything is erased, so only the account owner can trigger deletion.

Response time: we respond within 30 days. You will never be treated differently for exercising your rights.

8. California privacy rights (CCPA/CPRA)

If you are a California resident, you have the right to:

To make a request, use the data-removal form or email privacy@despy.app.

9. Who else can access it

Sub-processors

We keep external processors to the absolute minimum:

Law enforcement

We disclose personal data to authorities only when compelled by valid legal process, and only to the extent required.

10. International transfers

Our hosting infrastructure may be located outside your region. Where personal data is transferred internationally, we rely on appropriate safeguards — such as the EU Standard Contractual Clauses (SCCs) — to protect it.

11. How we secure it

We apply strong technical protections across the site:

For plain-language answers to common security questions — encryption, backups, hosting location, access controls, and audits — see our Data Security & Privacy FAQ.

12. Children

DeSpy is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact privacy@despy.app and we will delete it.

13. Cookies & browser storage

We set no cookies. The only data stored in your browser is one localStorage key:

The email you type into the homepage “Join the privacy movement” box is not stored in your browser — submitting it sends the address to our server to start a double-opt-in newsletter subscription. Nothing is subscribed until you click the confirmation link we email you, the stored address is encrypted at rest, and every newsletter carries a working unsubscribe. The full detail is in section 3.

We detect and honor Global Privacy Control (GPC): if GPC is present and you have not made a choice, the functional category defaults off. For full detail, see our Cookies & Storage page.

14. Changes & consent versioning

Our privacy notice and beta terms carry version strings (currently 2026-07-15), which we record against each application at submission. The cookie consent record stores the policy version you agreed to. If we make material changes, we bump the version and re-prompt you for consent where required.

This document is labelled Version 2026-07-15, last reviewed 2026-07-31.