D
Dritta

Privacy Policy

Last updated: [DATE — fill in before publishing]

Draft for legal review. This policy was written to accurately describe what Dritta's app and backend actually do today, based on the real data the app collects and how it's used. It has not been reviewed by an attorney and should be before this page goes live — in particular the retention, children's-privacy, and regional-rights sections (GDPR/CCPA/etc.) need confirmation against your actual legal obligations and business entity details.

1. Who we are

Dritta ("Dritta," "we," "us," or "our") operates the Dritta mobile application and related services (the "Service"), which help people save and share recommendations for places with friends. This policy explains what information we collect through the Service, how we use it, and the choices you have.

2. Information we collect

We collect the following categories of information:

CategoryExamplesSource
Account information Name, email address, username, profile photo Provided by you, or by Apple/Google when you sign in with those services
Content you create Recommendations ("recs"), comments, tags, lists you create or save, places you add Provided by you
Location Approximate or precise device location Collected only with your permission, to show nearby places and recommendations
Contacts Phone numbers from your device address book Collected only with your permission, to help you find friends already using Dritta — your contacts are matched using a hashed (non-reversible) comparison; we do not store your raw contact list
Social graph Who you follow, who follows you, lists you follow Generated by your activity in the app
Device & usage data Device type, app version, push notification token, general usage of app features Collected automatically

3. How we use your information

4. How we share your information

We do not sell your personal information. We share information in the following limited circumstances:

5. Your choices

6. Data retention

We retain your information for as long as your account is active, or as needed to provide the Service. If you delete your account, we delete or anonymize your personal information within a reasonable period, except where we're required to retain it for legal, security, or fraud-prevention purposes. [CONFIRM: specific retention windows once decided.]

7. Children's privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it. [CONFIRM: intended minimum age — 13 assumed here per US COPPA baseline; adjust if targeting a different minimum age or region.]

8. International users

Dritta is operated from the United States, and information you provide is processed and stored in the United States. If you're located outside the United States, you understand that your information will be transferred to and processed in the United States. [CONFIRM: whether GDPR/UK-GDPR-specific language, a Data Protection Officer contact, or an EU representative is needed based on your actual user base.]

9. Security

We use industry-standard technical and organizational measures — including encryption in transit and access controls on our infrastructure — to protect your information. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

10. Changes to this policy

We may update this policy from time to time. If we make material changes, we'll notify you through the app or by other reasonable means before the changes take effect.

11. Contact us

Questions about this policy or your information can be sent to privacy@dritta.io. [CONFIRM: preferred contact address and, if applicable, mailing address.]