Pre-launch
Privacy Policy
Dilder is a pre-launch project. We are testing whether there is demand for a custom-designed product before building it, so we collect very little — and this page describes what that actually is, rather than what a template would say. Nothing is sold and no payments are taken today.
Who is responsible
Dilder is currently run by an individual based in Croatia and is not yet a registered business. That person decides how the data described here is used and can be reached at hello@dilder.io. When a registered business takes over, which will happen before any payment is taken, it will be named here.
What we process, why, and for how long
Legal bases refer to Article 6(1) of the GDPR. Where we rely on our legitimate interest, you can object at any time by emailing us.
Waitlist (launch news)
- What
- The email address you enter to be notified, and the optional interest you pick.
- Why
- To tell you when Dilder launches. We have not sent any emails yet.
- Legal basis
- Your consent (a). You can withdraw it at any time by emailing us, and we delete your address.
- Kept
- Until you withdraw, and deleted automatically 24 months after you signed up at the latest.
Design reservation
- What
- Your email, the design you reserved, the expected price you were shown, your answer on whether you would pay a deposit later, a random visitor identifier and the link or site you arrived from.
- Why
- To contact you about the design you reserved — for example when it can be ordered — and to count how many people want it. Reserving does not add you to the waitlist, and we do not use this email for other news.
- Legal basis
- Steps you asked for before a possible purchase (b) for contacting you; our legitimate interest in measuring demand (f) for the counts.
- Kept
- Deleted automatically 24 months after the reservation, or sooner if you ask.
Site analytics
- What
- Which steps of the site you reach (landing page, configurator, price), with a random visitor and session identifier, the price variant you were shown, the page path, the campaign link or site you came from, your account ID if you are signed in, and — only when the 3D preview fails — coarse device details (graphics support, screen size, processor count). Never your email and never text you typed.
- Why
- To measure whether there is real demand before anything is manufactured, and to fix the 3D preview.
- Legal basis
- Our legitimate interest in measuring demand for the product (f). Keeping the identifier in your browser between visits needs your consent — see below.
- Kept
- Deleted automatically 12 months after each record is made.
Account (optional)
- What
- Your email address and either a password — stored only as a one-way hash, never readable — or, if you sign in with Google, your Google account ID. Google also sends your name; we do not store it. Designs and presets you save while signed in are kept with the account.
- Why
- To let you sign in and keep your designs.
- Legal basis
- Providing the account you asked for (b).
- Kept
- Until you ask us to delete the account.
Designs and AI suggestions
- What
- The shape settings of a design you configure. If you use “Design with AI”, the text you type is sent to OpenAI to generate a suggestion; we do not store that text. The generated shape — without your text — may be shown to other visitors as a preset.
- Why
- To show your design back to you, keep it attached to a reservation, and generate the suggestion you asked for.
- Legal basis
- Providing the feature you asked for (b). Please do not type personal information into the AI box.
- Kept
- A design on its own holds no personal data. Linked to an account or reservation, it follows that account or reservation.
Server and security logs
- What
- IP address, browser type, the page requested, the time, and your account ID if you are signed in.
- Why
- To keep the site secure, stop abuse (such as automated sign-in attempts or misuse of the AI feature) and fix errors.
- Legal basis
- Our legitimate interest in running a secure site (f).
- Kept
- 14 days, then deleted automatically. Rate-limit counters are held in memory for at most an hour.
What is stored in your browser
We do not use advertising or tracking cookies. Some local storage is needed for the site to work or was asked for by you, so it needs no consent: the age confirmation, your unit preference, a sign-in token while you are signed in, and your privacy choice itself.
The analytics identifiers — your random visitor identifier, price variant and the link you arrived from — are kept between visits only if you accept them in the privacy banner. If you decline, or have not chosen yet, they are kept only until you close the tab. You can change your choice at any time with “Privacy choices” at the bottom of every page. Clearing your browser storage removes all of it.
Services we use
- Hetzner hosts the site and its database on a server in Nuremberg, Germany.
- OpenAI (United States) receives the text you type into “Design with AI”, and only that, to generate a suggestion.
- Google is involved only if you choose to sign in with Google, for that step.
The site loads no third-party scripts, fonts or trackers; every file comes from dilder.io. No email service and no payment service is in use today. We do not sell or rent your data or share it with advertisers.
Your rights
You can ask for a copy of your data, its correction or deletion, to restrict or object to its use, or to receive it in a portable form, and you can withdraw consent at any time. Email hello@dilder.io from the address concerned; we reply within one month.
If you think we have mishandled your data, you can complain to the Croatian data protection authority, the Agencija za zaštitu osobnih podataka (azop.hr), or to the data protection authority where you live.
Changes
This project is early and this policy will change as Dilder becomes a real product — in particular before we take any payment. Material changes will be announced here before they take effect.