Privacy policy
Effective date: 19 June 2026
This policy describes how Zupersoft ApS ("we", "us"),
based in Denmark, processes personal data in the Dangdi mobile and web
application ("Dangdi" or "the service"). It is written to comply with the
EU General Data Protection Regulation (GDPR) and applies globally.
1. Who we are
Data controller: Zupersoft ApS, a company registered in
Denmark. You can reach us at privacy@dangdi.io for any
privacy-related request.
2. What we collect
Account data
- Email address (required for all account types)
- Password, stored salted and hashed with bcrypt (never in plain text)
- Optional username, display name, profile photo, biography
- Optional profile attributes: hometown, current city, languages, occupation, university, birth year
- Optional approximate location (latitude and longitude), if you choose to share it; always shown to other users rounded to a ~1 km grid
Data we receive from third-party sign-in providers
Dangdi offers several ways to sign in. We only receive the limited data
described below, and only after you authorise it — we never receive your
password for these accounts.
- WeChat Login: if you sign in with WeChat, we receive your WeChat OpenID and UnionID (stable identifiers we use to recognise your account), your nickname, and your profile photo (avatar) URL. We do not receive your email address, WeChat Moments, contacts, chat messages, or any other content. WeChat is operated by Tencent; the sign-in is processed by Tencent under WeChat's own terms, and that processing may take place on servers in China. By choosing WeChat sign-in you consent to this transfer.
- Facebook Login: if you sign in with Facebook, we receive your Facebook account id, name, email address, and profile photo URL. We do not receive your Facebook friends list, posts, or any other content.
- Microsoft 365: administrator accounts use Microsoft OAuth; we receive your email address and display name.
Content you create
- Articles you author, photos you upload, bookmarks, likes, follows, comments, hobbies you select
Usage data
- Articles you view and how long you read them (in seconds) and how far you scroll (as a percentage)
- Searches you perform, topic and filter taps, shares
- Device identifiers used to throttle abusive traffic and associate a guest session with a device
- If you enable push notifications, a device push token (issued by Apple Push Notification service on iOS, or Firebase Cloud Messaging on Android, via Expo) used solely to deliver the notifications you asked for; you can turn this off in your device settings at any time
- IP address (held in web-server access logs for up to 30 days) and basic request metadata
3. How we use your data
- To provide the service: publishing articles, authenticating you, showing your profile to other users
- To personalise recommendations — we generate vector embeddings of article text and compare them to topics and to other articles; no free-text "AI profile" is generated about you
- To operate email notifications (transactional emails only; you can opt out at any time using the unsubscribe link)
- To detect abuse and protect the service
- To improve the product through aggregated analytics
4. Legal bases (GDPR Article 6)
- Contract (Art. 6(1)(b)): creating and maintaining your account, delivering the service you asked for
- Legitimate interests (Art. 6(1)(f)): abuse detection, product improvement, service security
- Consent (Art. 6(1)(a)): optional features you explicitly enable — sharing approximate location, optional marketing emails
5. Who we share data with
We do not sell personal data. We share with the following sub-processors,
which are contractually bound to protect it:
- Amazon Web Services (AWS SES) — transactional email delivery; region eu-west-1 (Ireland)
- Hetzner Object Storage — uploaded images and user-generated media; located in the EU
- Typesense — full-text search indexing of public article titles and bodies
- OpenAI — we send article text (not personal data) to generate vector embeddings used for related-article and topic suggestions; data is processed in the United States. We rely on Standard Contractual Clauses for this transfer.
- Expo and Amazon Web Services (AWS SNS) — to deliver push notifications to your device, which are routed through Apple Push Notification service (APNs) on iOS and Google Firebase Cloud Messaging (FCM) on Android
- Facebook, Microsoft, and WeChat (Tencent) — only when you choose to authenticate with them; see "Data we receive from third-party sign-in providers" above. WeChat sign-in involves a transfer to Tencent, including servers in China.
6. How long we keep it
- Account data: for as long as your account exists, plus up to 30 days after deletion to complete removal across systems
- Articles you authored: retained while your account is active; deleted or anonymised when you delete your account
- Usage events (article views, searches): up to 90 days in identifiable form, then anonymised
- Web-server access logs: up to 30 days
- Backups: encrypted and retained up to 30 days on a rolling basis
7. Your rights
Under GDPR you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion ("right to be forgotten") — see Data deletion
- Request a portable export of your data
- Object to processing based on legitimate interest
- Withdraw consent for any optional processing you previously enabled
To exercise any of these, email privacy@dangdi.io. We respond
within 30 days.
8. Complaints
If you believe we have mishandled your data, you can complain to us at
privacy@dangdi.io or directly to the Danish data protection
authority, Datatilsynet: datatilsynet.dk/english.
9. Security
Passwords are stored salted with bcrypt; API traffic runs over TLS;
database backups are encrypted at rest; access to production systems is
restricted and audited. No system is perfectly secure — if a breach occurs
that is likely to affect your rights, we will notify you and the authority
without undue delay.
10. Children
Dangdi is not intended for children under 13 (or the age of digital
consent in your country, whichever is higher). We do not knowingly collect
data from children below that age.
11. Cookies and local storage
We use a small number of strictly-necessary items in your browser's
localStorage: a session token, a device identifier for guest
mode, and UI preferences. We do not use third-party advertising cookies or
cross-site trackers.
12. Changes to this policy
We will update this page when the policy changes and update the
"Effective date" above. Material changes will be communicated in the app or
by email.