1. Introduction
This draft explains the categories of information that may be involved when people use Disket and the decisions that must be confirmed before public release. Disket is currently under development, so this document does not claim production practices that have not yet been verified.
2. Information you provide
Using a messaging service may involve information that a person chooses to provide, such as account details, profile information, messages, attachments, and other content. The exact account fields and whether each field is required remain subject to the final product implementation.
TODO(PRIVACY): Confirm the production account-registration fields and which fields are required.
3. Information processed when you use Disket
Operation of the service may require processing account identifiers, message-routing information, timestamps, device or application information, and diagnostic records. This section will be updated to match verified production behavior.
TODO(PRIVACY): Confirm what device, log, diagnostic, analytics, and crash-reporting information is collected in production.
4. Messages and user content
Disket’s product direction includes private chats, groups, channels, and Echo. Processing requirements may differ between conversation content and content an author intentionally publishes through Echo.
TODO(PRIVACY): Confirm production message processing, server access, delivery behavior, and message-retention policy.
TODO(PRIVACY): Confirm the privacy controls and visibility rules for Echo content.
5. Attachments
Planned messaging capabilities include attachments. Storage, delivery, access controls, and deletion behavior must be documented after the production implementation is confirmed.
TODO(PRIVACY): Confirm attachment-storage locations, access behavior, and retention periods.
6. Contacts
Disket may offer ways to share a contact or find people. This draft does not assume that a user’s address book is uploaded.
TODO(PRIVACY): Confirm whether contacts are uploaded, processed locally, or only selected through a device picker.
7. Location information
Location or map sharing is part of the planned product direction. Any access should depend on the feature used and applicable device permission, but the exact production behavior remains to be documented.
TODO(PRIVACY): Confirm whether Disket processes precise or approximate location, how permission is requested, and how shared location data is retained.
8. Device and technical information
Technical information may be needed to operate, secure, and troubleshoot the service. The specific data fields, purposes, and retention have not yet been finalized for this policy.
TODO(PRIVACY): Document production device identifiers, IP-address handling, application metadata, and security logs.
9. How information is used
Information will only be described here after the purposes are confirmed. Likely operational purposes must not be treated as final policy commitments until the product’s data flows have been reviewed.
TODO(PRIVACY): Confirm and document every production purpose for processing personal information.
10. Data sharing and service providers
Disket has not supplied a final list of production processors or circumstances in which data may be disclosed. This section must be completed before release.
TODO(PRIVACY): Confirm third-party processors, legally required disclosures, infrastructure providers, and any other data-sharing practices.
11. Data storage and international processing
The production storage locations and jurisdictions have not been confirmed for this public draft.
TODO(PRIVACY): Confirm infrastructure locations, server jurisdictions, cross-border transfers, and applicable safeguards.
12. Data retention
Retention periods depend on the final operation of accounts, messages, Echo content, attachments, logs, and backups.
TODO(PRIVACY): Define and verify retention periods for each production data category, including backup retention.
13. Account and data deletion
The account-deletion process and its effect on messages, published Echo content, attachments, logs, and backups must be confirmed.
TODO(PRIVACY): Confirm the account-deletion workflow, authentication requirements, deletion scope, and deletion timeframes.
14. Security
Disket intends to apply security measures appropriate to the service. This draft makes no claim about encryption type, certifications, or guarantees.
TODO(PRIVACY): Confirm security controls and encryption guarantees before public release.
15. Children’s privacy
The minimum age, parental-consent approach, and handling of information involving children have not been set out in the available product specification.
TODO(PRIVACY): Confirm the minimum user age and any child-safety or parental-consent requirements.
16. Your rights and choices
Available rights and request procedures will depend on applicable law, the user’s location, and the finalized product operation.
TODO(PRIVACY): Confirm applicable privacy jurisdictions, user rights, request procedures, and identity-verification requirements.
17. Changes to this policy
When this policy changes, the revised version and its effective date will be published on this page. Any additional notice process will be documented once confirmed.
TODO(PRIVACY): Confirm how material policy changes will be communicated to users.
18. Contact
Questions or privacy requests should be directed to Disket through the privacy contact below once it has been established.
Privacy contact: {{PRIVACY_EMAIL}}
Mailing address: {{COMPANY_ADDRESS}}
TODO(PRIVACY): Insert and verify the privacy contact email and responsible legal entity details.