Privacy Policy
Last updated: September 9, 2026
DiShu ("we," "our," or "the app") is operated by Siyu Zhang as an individual developer. We are the data controller for personal information processed through the app. This policy explains what data we collect, why, how we use and share it, how long we keep it, and the rights you have.
If you have questions, contact us at support@dishu.link.
1. Information We Collect
Account information
- Authentication identifier. When you sign in with Apple or Google, we receive a unique identifier we use to recognize your account on return visits. We do not receive or store your Apple ID or Google account password.
- Email address. We store the email address your sign-in provider confirms for you. If you sign in with Apple and choose to hide your email, we receive only Apple's private relay address (an address ending in @privaterelay.appleid.com). We do not attempt to identify your real email through the relay. Your email is also how we recognize that an Apple sign-in and a Google sign-in belong to the same account.
- Profile information. Your chosen display name (nickname) and optional avatar photo. If you sign in with Google, the name on your Google account becomes your starting nickname, and your Google profile photo is shown until you upload an avatar (the app loads that photo from Google's servers).
- Age range. To enforce our minimum age, the app asks Apple for the age range declared for the Apple Account on your device each time you sign in, whichever sign-in method you use. We receive and store the range (under 16, 16 to 17, or 18 and over), how it was declared (by you, by a parent or guardian, or confirmed by a payment method or ID), and the time of the check. We never receive or store your date of birth or exact age.
Location data
- Your current location. The app requires Precise Location while it is in use; it does not work with approximate location and never uses your location in the background. While the app is open, your current location is sent to our servers to find notes near you: when you open the map, when you move to a new area, and periodically every few minutes. Our servers use it to answer the search and do not keep a history of where you have been.
- Note location. Each note you create is anchored to the exact spot where you create it: latitude, longitude, altitude, the floor level if your device reports one, and, only if you choose to add it, the direction you were facing. To label the spot, the app sends its coordinates to Apple Maps and stores the place name and Apple place identifier it returns.
User-generated content and activity
- Notes. The content of each note you create (either composed from our vocabulary of phrases and words, or written freely where that option is available), its location as described above, and whether you made it public or private.
- Reactions. Your likes and dislikes on notes.
- Reports and blocks. When you report a note or an account, we store the reason you chose, the optional comment you write (up to 500 characters), and the time, linked to your account. When you block another user, we store that block. We use these to enforce community rules.
Technical and security data
- Sign-in records. For each sign-in session we record the IP address and the app identification string (user agent) it came from, with timestamps. We keep them as a security record and look at them only if we need to investigate suspicious activity on your account.
- Authentication tokens. Short-lived access tokens and refresh tokens are issued to your device after sign-in to keep you logged in. Tokens are stored on your device in the iOS Keychain and presented to our server with each request.
- Server logs. Our servers log the type, outcome, timing and a random request identifier of each request. These logs contain no IP address, no account identifier and no content, and are kept for a short period.
- Abuse prevention. Your IP address is used, in memory only, to limit abusive request rates. It is not stored for that purpose.
- Server error reports. When something goes wrong on our servers, a technical error report (the error message, a stack trace, the type of request, a random request identifier and details about our server; never your content, email, location or account identifier) is sent to a third-party error-monitoring provider located in the European Union so we can fix the problem.
- Crash and diagnostic data. If you have chosen in iOS settings to share crash data with app developers, Apple may pass us anonymized crash reports. The app itself contains no third-party analytics or crash-reporting SDK; the diagnostics it gathers stay on your device. If that changes, we will update this policy and the App Store privacy labels.
2. How We Use Your Information
- To authenticate your account and keep you signed in
- To enforce our minimum age of 16, as the law requires in several countries
- To display your profile (nickname, avatar) to other users
- To show notes near your current location
- To place your notes at the correct spot and label it with a place name
- To show reaction totals on notes and profiles
- To enforce our community guidelines (processing reports and blocks)
- To detect and prevent fraud, abuse, stolen credentials and security incidents
- To find and fix errors in our service
- To respond to support requests and user inquiries
- To comply with legal obligations and respond to valid legal requests
We do not use your information for advertising, profiling, or training machine-learning models for unrelated purposes.
3. Legal Bases for Processing (EU/EEA/UK Users)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR / UK GDPR:
- Performance of a contract (Article 6(1)(b)) — to provide the Service you have signed up for, including authenticating you, checking that you meet the minimum age our Terms require, showing nearby notes, and saving content you create.
- Legitimate interests (Article 6(1)(f)) — for security, fraud and abuse prevention, enforcement of community rules, applying one minimum age worldwide (including where the law of another country requires it), basic server logging, and finding and fixing errors in our service. We have considered the impact on you and believe these uses do not override your rights.
- Legal obligation (Article 6(1)(c)) — to respond to legally binding requests and to meet obligations placed on us by EU, EEA-state or UK law.
- Consent (Article 6(1)(a)) — where we explicitly ask for it (for example, location permission via the operating system).
4. Data Storage, Location, and Security
- Account, content, report and block data is stored on managed cloud database and hosting infrastructure located in Singapore.
- Avatar images are stored with a third-party cloud object-storage provider in the Asia-Pacific region and delivered through its global content-delivery network. Avatar images are publicly reachable by anyone who has their address.
- Server error reports are stored with a third-party error-monitoring provider in the European Union.
- Authentication tokens are stored on your device using the iOS Keychain.
- All communication between the app and our servers is encrypted in transit (TLS).
- Photos you upload as avatars are resized and stripped of embedded metadata (such as camera location tags) before being stored.
- Database backups may retain copies of your data for a limited period (currently up to 7 days) after deletion before being overwritten in the normal backup rotation.
- Data on your device. The app keeps a copy of your own profile, your sign-in tokens, your drafts and any notes waiting to be sent (with their location), cached avatar images of other users (for up to 30 days), and on-device diagnostics. This data stays on your device until you delete the app; drafts and unsent notes are not removed by signing out.
- If you are in the EU/EEA or UK, your data is processed outside that region. We apply appropriate safeguards (such as Standard Contractual Clauses or equivalent mechanisms) for international transfers.
5. Data Sharing
We do not sell, rent, or share your personal information with third parties for advertising, profiling, or any commercial purpose. We do not use third-party analytics or advertising services.
We share information only with:
- Apple — for sign-in authentication, for the age range described in Section 1, for displaying the map (the app uses Apple Maps), and for labelling note locations (the app sends a note's coordinates to Apple Maps to look up a place name). Apple's privacy policy applies to those services.
- Google — for sign-in authentication if you choose Google, and for showing your Google profile photo until you upload an avatar. Google's privacy policy applies to those services.
- Cloud database / hosting provider — who hosts our backend infrastructure under our instructions.
- Cloud object-storage and content-delivery provider — for storage and delivery of avatar images.
- Error-monitoring provider — who receives the technical server error reports described in Section 1, under a data-processing agreement.
- Other users of the app — see Section 6.
Legal disclosure. We may disclose information when we reasonably believe it is required by law, by valid legal process, or to protect the rights, safety, or property of our users, the public, or us.
Business transfers. If we transfer the app or its underlying business to another party, your information may be transferred as part of that change, subject to this policy or an updated policy of equivalent protection.
6. Your Content and Other Users
Public notes. A note you make public can be discovered by anyone using DiShu near its location, and is shown at its exact spot, both as a pin on the map and as coordinates. Your display name and avatar are shown alongside it. If you do not want a place to be visible to others, make the note private or do not create it there.
Private notes. A note you mark "Only me" is visible to you alone. It is never shown to or searchable by anyone else, though its reactions count toward the reaction totals on your profile.
Reactions. Other users see the total likes and dislikes on a note and on your profile. Nobody is shown who reacted.
Blocking. If you block another user, their content is hidden from you and your content is hidden from them. Neither of you is told that a block is the reason.
Reports and moderation. A note you report will not be shown to you again. A reported public note may be hidden from other users automatically while we review the report; you will continue to see your own note even while it is hidden. See the Terms of Service, Section 4, for how moderation works.
7. Data Retention and Deletion
- While your account is active. We keep account, content, and related operational data as long as your account exists. Sign-in records (IP address and app identification string) are kept for as long as your account exists.
- Age range. We hold only the range, how it was declared and the time of the check. We keep them for two purposes: as a record that a check was made and what it showed, and to review reports that an account may belong to someone under 16. We never use or disclose them for anything else without your consent, unless the law requires it. Each sign-in replaces the previous record, and the record is destroyed when your account is deleted.
- Deleting a note. When you delete a note, it is immediately removed from view for everyone. Our systems keep the record until your account is deleted, at which point it is anonymized as described below.
- Deleting your account (Settings → Delete Account):
- Your account is scheduled for deletion and you are signed out everywhere. You have 30 days to change your mind: signing back in during that period cancels the deletion and your account continues as before.
- After 30 days, your profile information (nickname, email, avatar), age range, authentication tokens, sign-in records, sign-in provider records, reactions, the reports you filed and the reports about you, and the blocks you created or received are permanently deleted from our servers.
- Notes you posted are reattributed to a generic "Deleted User" identity so they remain visible at their location but are no longer linked to you. Notes you had already deleted are anonymized in the same way.
- If you signed in with Apple, we also ask Apple to revoke DiShu's sign-in authorization, so DiShu disappears from your Apple Account settings.
- Backups containing the deleted data may persist for a limited period (currently up to 7 days) before being overwritten in the normal backup rotation.
- If you are under 16. If a sign-in shows an age range under 16 for an existing account, the account is closed, signed out everywhere, and scheduled for deletion on the same 30-day timeline. Only a sign-in that shares an age range of 16 or over during that period can cancel it.
- If you wish to permanently remove specific notes before deleting your account, please remove them first from within the app or contact us.
- Server logs are kept for a short period. Server error reports are kept by our error-monitoring provider for a limited period (currently 30 days).
8. Your Rights
Everyone
- You can access, edit, or delete your profile information at any time from within the app (Settings).
- You can delete your account at any time, which removes the personal information described in Section 7.
- You can contact us at support@dishu.link for any privacy question, to ask for a copy of your data, or to ask us to correct it.
Australian users (Privacy Act 1988)
We handle personal information in line with the Australian Privacy Principles, whether or not the Privacy Act 1988 requires that of a small business like ours. Sections 1, 2, 4 and 5 describe the kinds of personal information we collect and hold, how we collect and hold it, the purposes we use it for, and the countries it is disclosed to (Singapore, the European Union, and, for Apple and Google services, the countries those companies operate in). You may ask us for access to, or correction of, the personal information we hold about you by emailing support@dishu.link; we will respond within a reasonable time and may need to verify your identity first.
If you have a complaint about how we have handled your personal information, contact us first and we will investigate and reply within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au. The Commissioner can always consider a complaint about how we handle your age range, which the Online Safety Act 2021 places under the Privacy Act; for other matters, the Commissioner's powers over a small business like ours are limited.
EU / EEA / UK users (GDPR / UK GDPR)
If you are in the EU, EEA, or UK, you have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your data ("right to be forgotten"), subject to limits where we have a legal basis to keep it.
- Restriction — ask us to limit processing in certain circumstances.
- Objection — object to processing based on legitimate interests.
- Portability — receive your data in a structured, machine-readable format and ask us to transfer it to another service where technically feasible.
- Withdraw consent — where we rely on consent, you can withdraw it at any time without affecting prior processing.
- Lodge a complaint with your local data-protection supervisory authority. We encourage you to reach out to us first so we can try to resolve the matter directly.
To exercise these rights, contact us at support@dishu.link. We may need to verify your identity before responding. We do not make decisions about you by automated means that have legal or similarly significant effects; the automatic hiding of reported notes described in Section 6 is always followed by human review.
California residents (CCPA / CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the CPRA:
- Right to know the categories of personal information we collect, the purposes for which we use it, and the categories of third parties we share it with (described in Sections 1, 2, and 5).
- Right to delete personal information we have collected about you, subject to legal exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of "sale" or "sharing" of your personal information. We do not sell or share your personal information as those terms are defined in the CCPA, so there is nothing to opt out of. We have no actual knowledge of selling or sharing the personal information of anyone under 16, because we do not sell or share personal information at all.
- Right to limit use of sensitive personal information. We do not use sensitive personal information for purposes that would require this opt-out.
- Right to non-discrimination for exercising any of these rights.
The categories of personal information we collect, in CCPA terms, include identifiers (account ID, email, IP address), characteristics of protected classifications (age range), internet or network activity (request metadata), geolocation data, and user-generated content. Retention for each category is described in Section 7. To exercise your rights, contact us at support@dishu.link; we will verify your request by confirming that it comes from the email address on the account.
9. Children's Privacy
DiShu is not intended for anyone under 16, or under the higher minimum age that applies where you live. We check the age range declared on the device at every sign-in and do not create accounts for anyone under 16. We do not knowingly collect personal information from anyone under the applicable minimum age. If we learn that we hold data from such a user, we close the account and delete the data promptly, as described in Section 7. If you believe a child has provided us with personal information, please contact us at support@dishu.link. Our age rule is explained at dishu.link/age-suitability.
10. International Users
Our infrastructure is located outside your country of residence unless you live in Singapore. By using the app, you understand that your information will be transferred to and processed in the locations described in Section 4. Where required, we apply appropriate safeguards (such as Standard Contractual Clauses) for transfers from the EU/EEA, UK, or other regulated jurisdictions.
11. Changes to This Policy
We may update this privacy policy from time to time. The "Last updated" date at the top reflects the most recent revision. For material changes that affect your rights, we will provide reasonable notice within the app or by email before the changes take effect. Continued use of the app after the changes take effect constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this privacy policy or your data, or wish to exercise any of the rights described above, contact us at:
support@dishu.link