← Back to DiLi App
1. Who We Are
DiLi App is a mobile contact management app that lets you store your own contact details and choose exactly what information to share with your connections. It is made by:
Company: DiLi App Limited
Company number: 17201072
Address: Flat 201, 46 Botanic Square, London, E14 0LW, United Kingdom
Email: admin@dilime.app
DiLi App is available worldwide. This Privacy Policy applies to all users regardless of where they live. Some countries and regions provide additional privacy rights. Where required, we include jurisdiction‑specific supplements for residents of the United Kingdom, European Union, United States (including California), Canada, Brazil, Australia, and other regions with mandatory privacy laws. If any local law grants you stronger rights than those described in this policy, your local law will apply.
DiLi App Limited is the data controller for the data described in this policy.
2. What Data We Collect
We collect the following categories of personal information: account information inclduing identifiers such as email address and name, optional contact details you choose to add, and non-identifying app usage data. We do not collect any sensitive personal information such as health, financial, or biometric data.
2.1 Account & authentication data
We collect the minimum information needed to create and secure your account:
- Your email address (used to sign in and for transactional emails)
- Your password, stored only as a secure hash. We never see or store your plain-text password
- If you sign in with Google or Apple, your name and email address as provided by those services
- Payment information processed and stored securely by our payment provider. We do not process or store your card details; these are handled directly by the provider in accordance with PCI-DSS standards.
2.2 Contact information you choose to share
You can choose to add the following contact details to your profile. Each field is optional, and you control exactly which of your connections can see each item:
- First name
- Last name
- Personal email address
- Personal phone number
- Home address
- Workplace name
- Work phone number
- Work email address
- Social media handles (LinkedIn, Instagram, Facebook, TikTok, X)
- Birthday
- Profile photo
All contact fields, except your name and social media handles, are encrypted at rest. You decide who sees what, and you can change or revoke this at any time.
2.3 App usage data (non-identifying)
To help us improve DiLi App, we collect aggregated or pseudonymised usage statistics that do not identify you:
- Number of connections and groups
- Frequency of viewing ID cards or updating your own
- Device model, operating system version, and crash logs
- Country‑level location: We do not collect your precise GPS location. We only infer your country of residence based on the country associated with the Apple App Store or Google Play Store from which you downloaded the app. This information is non‑precise and does not identify your exact location.
These data help us understand how the app is used, diagnose issues, and improve performance without tracking your identity.
2.4 What we do NOT collect
- Precise GPS location
- Any information from your other apps
- Your phone's contact list
- Your photos, messages, microphone, or camera roll
3. How We Use Your Data
3.1 To run the app
- Provide your DiLi App ID card and let you edit it
- Show your connections the details you have chosen to share
- Send birthday reminders to your connections, but only if you have shared your birthday with them
- Automatically push updates to your connections when you change your details
3.2 To run our business
- Process your subscription payment
- Send account emails (e.g. password reset, payment confirmation) via Resend
- Maintain the security of your account
- Provide customer support
- Improve app performance using aggregated or pseudonymised analytics
- Comply with our legal obligations
We do not share your data with third parties for cross‑context behavioural advertising.
4. Legal Bases for Processing (GDPR)
We only process your data when we have a lawful reason to do so:
- Contract: To create and log in to your account, maintain your subscription, and to store and display optional contact information that you choose to add. You can withdraw consent at any time in the app.
- Legitimate interests: To use aggregated or pseudonymised analytics, maintain security, and prevent fraud. We have assessed that these interests are not overridden by your rights and freedoms.
- Legal obligation: To keep accounting and tax records, and to respond to lawful requests
5. Who We Share Your Data With
We do not sell your data to anyone, ever. We do not share your data with third parties for marketing purposes.
5.1 Other DiLi App users
In this context, other DiLi App users means people you have connected with, not the entire DiLi App user base. Your connections can only see the contact details you have explicitly shared with them through your group visibility settings.
You can change or remove their access at any time. Either side can end the connection whenever they choose, without giving a reason.
5.2 Our service providers
We use a small number of trusted providers to operate DiLi App. They process your data only on our instructions and are all GDPR-compliant:
- Supabase, a secure cloud database and storage
- Google Sign-In / Apple Sign-In (optional authentication, subscription billing)
- Resend, a service provider for transactional email delivery for example for sign-in links and password resets
- Analytics and error-monitoring tools (using aggregated or pseudonymised data only)
These providers process data only on our instructions and under strict contractual safeguards.
5.3 Legal authorities
We will disclose data to law enforcement or regulators only when we are legally required to do so, and only to the extent required.
6. International Data Transfers
We store and process data in the United Kingdom and the European Union. Some of our service providers (such as Google Play Store and Apple Store) may store or process data outside the United Kingdom or European Union. We only transfer data where necessary to provide the service, and we ensure appropriate legally approved safeguards are in place. These may include:
- Standard Contractual Clauses approved by the European Commission
- The UK Addendum to the SCCs or the UK International Data Transfer Agreement (IDTA)
- Adequacy decisions where applicable
These safeguards ensure that your personal data remains protected to a standard equivalent to UK and EU law.
All providers are assessed to ensure they offer GDPR-level protection.
7. How We Keep Your Data Secure
We take security seriously. We use technical and organisational measures to keep your data secure, including:
- Encryption of data in transit (TLS 1.2 or higher)
- Application-level encryption of sensitive contact fields at rest (phone, email, work email, work phone, address, date of birth, workplace) using AES-256/PGP symmetric encryption
- Standard database-level encryption at rest for first name and last name
- Encryption of backups
- Secure password hashing (bcrypt / Argon2)
- Role-based access controls so staff can only access what they need
- Organisational measures such as limiting access to authorised personnel and requiring confidentiality commitments
- Regular security reviews
- Procedures to detect, investigate, and respond to potential security incidents
- Service provider due diligence and contractual data protection obligations
8. Requesting Account and Data Deletion
You can request deletion of your account and associated data in two ways (see Delete Your Account page for more details):
- In the app: Go to Settings, scroll to the Danger Zone section, and tap "Delete account." Your account and data are deleted immediately.
- Without the app: Email us using the email address associated with your DiLi App account. We will delete your account and all related data within 30 days.
Some limited data may be retained after deletion where required by law or for fraud prevention (see section 9 below).
9. How Long We Keep Your Data
We keep your data only for as long as necessary for the purposes described in this policy:
- Account data is kept in our live system until you delete your account.
- Optional contact details are deleted when you remove them or delete your account.
- Backups of the live system are replaced daily.
- Payment and legal records are kept for as long as required by UK law (typically 6–7 years).
- Security logs and analytics data are retained in aggregated or pseudonymised form for up to 12 months to maintain and improve the service.
- Support communications and rights-requests are retained for up to 12 months for audit and compliance purposes.
When you delete your account in the app, your account and contact data are immediately removed from our live systems. This deletion is permanent and cannot be reversed.
10. Your Rights
DiLi App users have the right to:
- Access a copy of your personal data
- Correct any inaccurate data
- Delete your data ("right to be forgotten")
- Restrict how we process your data
- Object to processing based on legitimate interests
- Receive your data in a portable format
- Withdraw consent at any time (without affecting prior processing)
- Request human review of any automated decision that has a legal or significant impact on you. DiLi App does not currently carry out automated decision-making or profiling within the meaning of Article 22 UK GDPR or EU GDPR
- Lodge a complaint with a supervisory authority in their country of residence. In the UK, this is the ICO at ico.org.uk
- Right to non‑discrimination for exercising your rights
To exercise any of these rights, contact us at admin@dilime.app. We will respond within 30 days. We may ask you to verify your identity before responding to your request.
11. Children
DiLi App is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under the age of 18. If you believe that a child has created an account or provided personal data, please contact us so that we can investigate and take appropriate action.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes through the app at least 14 days before they take effect. The "Last updated" date at the top will always reflect the most recent version.
For material changes, we will ask you to review and actively acknowledge the updated Privacy Policy in the app before continuing to use DiLi App.
13. Data Protection Officer
We have voluntarily appointed a Data Protection Officer to oversee our data protection practices:
Name: Lina Kramer
Email: lina@dilime.app
You may contact the Data Protection Officer directly for any questions, requests, or complaints regarding how we handle your personal data.
14. Contact Us
If you have any questions about this Privacy Policy you can contact us at:
Email: admin@dilime.app
Address: Flat 201, 46 Botanic Square, London, E14 0LW, United Kingdom
← Back to DiLi App