Privacy Policy
Last updated: July 28, 2026
1. What We Collect
- Account data: Email, display name, date of birth (to verify you are 18 or older), and profile image provided during registration.
- Messages: All direct messages and group chats are end-to-end encrypted (E2E) and stored exclusively as ciphertext. We cannot read your messages.
- Files: Uploaded files are stored securely on our self-hosted infrastructure. File attachments under 7MB are encrypted client-side (AES-256-GCM) before upload, providing end-to-end encryption for file sharing.
- Presence: Your online status and the time you were last online, so the people you talk to can see whether you are available. Settings lets you hide this from other people; we still record it to operate the service.
- Device information: Your browser and operating system, combined into a readable device name such as "Chrome on Windows" that labels the encryption keys on this device. It is stored in your browser and included in backup files; when you create an account backup, the readable label is stored with its encrypted blob.
- Push notifications: If you allow browser notifications, we store what your browser needs in order to receive them on that device: a delivery address at your browser vendor's push service, and the two keys that let us encrypt a notification for that browser. It addresses a browser, not you, and we use it only to alert you while the app is closed. Nothing is stored until you grant notification permission. The Notifications section of Settings turns push notifications off for the device you are using and deletes that record from our servers straight away; each device is separate, so turning one off leaves the others alone. We also delete the record when the push service reports the delivery address is no longer valid, for example after you turn notifications off for Dimsocial in your browser, and when your account is deleted.
We use this information to run the messaging service, to authenticate you and secure your account, to deliver notifications about messages, calls, and friend requests, and to fix bugs and improve the product.
2. What We Do NOT Collect
- We do not collect your location, contacts, or browsing history.
- We do not build behavioral profiles or track your activity for advertising.
- We do not require a phone number, government ID, or biometric data.
- We do not sell, rent, or share your personal data with advertisers.
3. End-to-End Encryption
Direct messages and group chats use E2E encryption. Your encryption keys are generated and stored locally in your browser (IndexedDB). The server never receives your unencrypted private keys or plaintext message content for encrypted conversations.
- Encryption keys are derived using ECDH P-256 key agreement and HKDF.
- Messages are encrypted with AES-256-GCM.
- Group messages use the Sender Keys protocol with symmetric chain key derivation.
- Key backups are encrypted with a generated recovery key or a passphrase you choose using PBKDF2 (600,000 iterations).
An account key backup stores an encrypted key blob and a readable device label on our servers. We cannot decrypt that blob, and if you lose its recovery key or passphrase, your encrypted history is unrecoverable.
Traffic between your device and our servers is encrypted in transit with TLS. Messages and file attachments that are encrypted on your device are stored only as ciphertext, so we cannot read them. Other account data is held in our own database on infrastructure we operate, protected by access controls, rate limiting, input validation, and CSRF protection.
4. Age Requirement
Dimsocial is for adults 18 and older. We check your date of birth at sign-up and do not create accounts for anyone under 18; nothing is stored when a sign-up is declined for age. If we become aware that an account holder is under 18, we will take steps to delete the account and associated data.
5. Abuse Reports
When you report an E2E encrypted message, the decrypted content is submitted along with the encrypted envelope for cryptographic verification. Report data is only accessible to administrators and is used solely for moderation purposes.
6. Data Retention
- Account data is retained while your account is active.
- Messages are retained indefinitely unless deleted by the sender or an administrator.
- Abuse reports are retained for moderation review.
- Push notification records are retained until you turn push notifications off for that device in Settings, the push service reports the delivery address invalid, or your account is deleted.
7. Third-Party Services
- Self-hosted file storage: File uploads are stored on Dimsocial infrastructure.
- Resend: Transactional email delivery.
- KLIPY: GIF search and sharing.
- Browser push services: Google, Mozilla, or Apple, depending on your browser. Delivering a notification discloses the delivery address to the push service that operates it, and hands that service the notification itself. What a notification contains depends on the event. Every one of them names the person who triggered it, by display name, and some also name the group or channel involved. A new group post additionally carries the post title and up to the first 100 characters of the post, because group posts are not end-to-end encrypted. A direct message carries the sender's display name and the fixed words "New encrypted message" and never the message itself. Each notification is encrypted for your browser with the keys above, so the push service can see the delivery address but not what the notification says.
Beyond these providers, we disclose data only when the law or legal process requires it, or when it is necessary to protect the safety of our users. No third party receives your data for its own purposes.
8. Your Rights
You can delete your account and its associated data from Settings, or by contacting support. You can update your profile information at any time, and you can ask us for a copy of the personal data we hold about you. E2E encrypted messages cannot be recovered after account deletion if no key backup exists.
9. Contact
For privacy-related inquiries, contact us at support@dimsocial.com.
10. Changes to This Policy
We may update this policy from time to time. We will notify users of significant changes through the app or by email.