Data policy
Last updated October 1, 2026.
About this policy
This page is the plain-language data policy for Dumper: what kinds of data the apps and website handle, what each is used for, who it touches, and how you can get rid of it. Theprivacy policycovers the legal detail; this page is the map.
Data categories
- Your content — tasks, notes, brain dumps, journal entries, habits, repeating tasks, bookmarks, reminders, categories and settings. Stored in the app's own database on your device by default; uploaded only if you turn on Premium cloud sync.
- Attachments — files you attach to synced content. Uploaded and stored only when sync is on.
- Account data — the email address you verify, your first and last name, and any postal address you add to your profile. Passwordless: we never collect or store a password.
- AI-composer content — the text you explicitly hand to the AI composer, such as a brain dump you ask it to turn into tasks.
- Subscription data — your plan, its status and period, and monthly AI usage counts. If you buy Premium through Google Play, the payment itself is handled by Google and we never receive your card details.
- Technical data — session tokens that authenticate requests, a per-device identifier used only to keep sync in order, and the request IP when our service rate-limits or blocks abuse.
- Website data — an httpOnly sign-in session cookie, and your theme and accent colour in local storage. No advertising or analytics cookies, no tracking pixels.
What we do not collect
Dumper does not collect advertising identifiers, precise or coarse location, contacts, photos or your phone book; does not embed ad networks, analytics or tracking SDKs in the app; and does not read anything from your device beyond what the features you use require. If you never create an account, we collect nothing at all about you.
Purposes
- App functionality — storing and syncing your content, running your account and subscription, and generating drafts when you use the AI composer.
- Communication — delivering sign-in codes and replying when you write to us. Not marketing; we send no promotional email.
- Security and abuse prevention— rate-limiting, blocking abuse, and keeping sessions secure.
We do not use your content or account data for profiling, targeted advertising, or training machine-learning models, and we do not sell or rent it.
Sharing
Data is shared only with the providers that operate the service, and only as needed: Cloudflare (hosting, database, storage), Resend (sign-in-code email), the third-party AI model provider (text you send through the composer, via a gateway), and Google when a Premium purchase is made through Google Play. Legal requests from authorities may require disclosure.
How to delete your data
Device-only content: delete it in the app, or uninstall the app — then it is gone, and it never left your device in the first place.
Account and synced content: delete your account from the account page in the app or on this website, or email hello@ibrahimturan.com from your account's address — thedelete-account pagehas the details. Deleting the account removes your account record, sessions, synced content and attachments from our servers, normally within a few days and no later than 30 days; provider backups age out within 30 days after that. Individual synced items you delete are removed from the sync store for every device on your account.
Retention
We keep account and synced data while your account exists, and the minimum technical data — request logs, rate-limit counters, expired code records — only for weeks. Sign-in codes live for minutes. Everything else is covered by the deletion rules above.
Security
How this data is protected is described on thesecurity page.
Contact
Questions about this policy or a deletion request:hello@ibrahimturan.com