Legal
Privacy Policy
Last updated: August 20, 2026
Dumpling is made by By Azur LLC ("we", "us"), a New Hampshire company. This policy covers the Dumpling apps, our website, our API, and our MCP server. The short version: we collect only what running the app requires, we don't sell it, we don't show ads, and nothing you write trains an AI model. The long version is below, because the short version isn't a legal document.
What we collect
Everything below comes either from you directly or from your device as you use the app. We don't buy personal information, and we don't collect it from data brokers, social networks, or public records.
| Category | What it is | Why we have it | Who else sees it |
|---|---|---|---|
| Account | Your email address and a hashed password. Your display name, if you set one. | To create your account, sign you in, and email you about the service. | Our email provider, for the messages we send you. |
| Your content | Tasks, notes, projects, contacts, calendar events, goals, habits, tags, attachments, and your AI chat history. | It's the product. We store it and sync it between your devices. | Our hosting and backup providers. Our AI provider, only for the categories you enable. |
| Technical | IP address, device and OS type, app version, timestamps. We store the IP; we don’t look up where it is. | To keep the service running and secure: rate limiting, abuse prevention, and diagnosing crashes and performance problems. | Our hosting provider, which necessarily sees your IP to serve the request. Our error-diagnostics provider gets the device and app details but is configured to receive no IP and no account identifier. |
| Usage | Which features you use and when, as pseudonymous events. On the website, cookieless page views. | To understand what's actually used, so we build the right things. | Nobody. In-app events stay in our own database; website analytics run on analytics software we host ourselves. |
| Payment | Your subscription status, plan, and billing email. | To give you the plan you paid for. | Stripe. Your card number never reaches us. It goes straight from you to Stripe. |
| Support | Whatever you write to us, and our replies. | To answer you, and to remember the conversation if you write again. | Our email provider. |
| Waitlist | If you sign up before launch: your email and which page you submitted it from. | To confirm you're on the list and tell you when it's your turn. | Our email provider. |
Two things worth calling out. Dumpling never asks your device for your location. There's no GPS permission in the app. If you turn on the weather widget you type a city yourself, and our server looks up the forecast on your behalf, so the weather service sees a city but never sees you. And attachments you upload are stored as files alongside the rest of your content; we don't scan or analyse them.
How we use it
To run the app: storing your content, syncing it across your devices, backing it up, sending the emails the service requires, taking payment, powering AI and auto-connections, and keeping the whole thing secure and standing up. We also look at aggregate usage to decide what to build.
We do not use your content for advertising, we do not profile you, and we do not make automated decisions about you that produce legal or similarly significant effects.
If you're in the EEA or UK, the GDPR requires us to name a legal basis for each of those. Ours:
| What we're doing | Legal basis |
|---|---|
| Running the app: accounts, storage, sync, backup, payment, service emails | Performance of our contract with you |
| Keeping it secure: rate limiting, abuse prevention, crash and performance diagnostics, audit logs | Our legitimate interest in a service that works and isn't abused, and compliance with law |
| Understanding usage to improve the product | Our legitimate interest in building the right features. Aggregate and pseudonymous wherever it can be |
| Optional features: AI, push notifications, calendar sync, weather | Your consent, given by turning the feature on and withdrawable by turning it off |
| Complying with legal obligations, and establishing or defending legal claims | Compliance with law, and our legitimate interest in defending ourselves |
AI features
When you use the AI assistant, the data you've allowed is sent to our AI provider, OpenRouter, which routes it to a model provider (such as Google or OpenAI) to generate a response.
You control what it can reach. In Settings you choose which categories the assistant may access (tasks, notes, knowledge, people, calendar); people is off by default. Turn AI off entirely and nothing leaves our servers for a model provider.
Three commitments about that data:
- It never trains a model. Not ours, because we don't train models, and not our providers'. We keep prompt logging and model training disabled on our OpenRouter account.
- It isn’t retained. Our OpenRouter account is configured to use only zero-data-retention models, meaning the provider processes your prompt to answer it and keeps nothing afterwards. We don’t store your prompts either, beyond your own chat history in the app, which you can delete.
- You can see the boundary. The assistant tells you which of your data it looked at, and the same category toggles apply to auto-connections and semantic search.
Cookies and tracking
This is a shorter section than most sites have, because we run fewer trackers than most sites.
- The website sets no cookies. Our analytics are cookieless and run on software we host ourselves. We don't use Google Analytics, ad pixels, session replay, or any third-party advertising tracker.
- The app stores things on your device: your login token in your operating system's secure storage, plus a local cache so the app opens instantly and works offline. That's strictly necessary to provide the service you asked for, so no consent banner is required for it. Clearing it means signing in again.
- Do Not Track. There's no agreed standard for what a DNT signal obliges a site to do, so we don't respond to it. It makes no practical difference here, because we have nothing to stop.
- Global Privacy Control. We honour GPC signals as opt-out requests. Since we don't sell or share personal information for advertising, there's nothing for it to switch off, but the signal is respected.
Who we share it with
To run Dumpling we use a small set of service providers. Each handles your data only to provide its part of the service, under contract, and none of them may use it for their own purposes. The current list, with what each one receives and where it runs, lives on its own page so we can keep it accurate:
See our full list of service providers →
Beyond those providers, there are three situations in which your data could leave our hands. We'd rather name them than imply they don't exist:
- Legal and safety. If we're compelled by valid legal process (a subpoena, court order, or law-enforcement demand we're legally required to honour) we may have to disclose data. Where we're permitted to tell you, we will. We may also disclose what's necessary to investigate fraud or abuse, or to protect someone's safety.
- Business transfers. If By Azur LLC is ever sold, merged, or goes through bankruptcy, your data would transfer with the service to the acquirer, who would remain bound by this policy until they gave you notice of any change. If that happens, we'll tell you before it takes effect.
- Professional advisors. Lawyers, accountants, and auditors, in the ordinary course of advising us, bound by professional confidentiality.
What we don't do, plainly: we have never sold personal information, and we have never shared it for cross-context behavioural advertising, as those terms are defined by US state privacy laws. Not in the past twelve months, not ever. We don't show ads. We don't share your content with anyone outside the situations described on this page.
Where it's stored, and transfers
Your data lives on servers we operate at OVHcloud in the United States. Off-site backups are encrypted before they leave that server and stored with Cloudflare R2. It's encrypted in transit, and stored in an ordinary database format so the app can work with it, which means it is not end-to-end encrypted. Access is limited to the few people who operate the service, and only for support and maintenance.
If you're outside the United States, using Dumpling means your data is transferred to and stored in the US. The US is not covered by an EU adequacy decision, so where the law requires it we rely on appropriate safeguards: Standard Contractual Clauses with our providers, or the EU-U.S. Data Privacy Framework where a provider is certified under it. You can ask us which mechanism applies to a particular provider.
How long we keep it
The short answer: your content for as long as your account exists, technical data for months rather than years, and nothing forever.
| What | How long |
|---|---|
| Your content and account | Until you delete it, or delete your account |
| Deleted account, live database | Removed immediately and irreversibly |
| Deleted account, encrypted backups | Ages out as backups rotate: daily snapshots within 7 days, then weekly and monthly snapshots, with the last copy gone within about 6 months |
| Security and audit logs | 90 days |
| Usage analytics | Pruned on a rolling window; aggregates may be kept indefinitely once they no longer identify anyone |
| Payment records | As long as tax and accounting law requires, typically 7 years. Held by Stripe as well as by us |
| Support email | 2 years from the last message in the thread |
| Waitlist email | Until you unsubscribe, or until the list is closed, whichever comes first |
Backups are the reason "immediate" deletion has an asterisk. They exist so a server failure doesn't lose your data, which means they can't selectively forget one account. They're encrypted, they're never restored except in a disaster, and they age out on the schedule above.
Your rights, and how to use them
Most of these you can exercise yourself, right now, without asking us:
- Access and export. Settings → Data & Privacy → Export data gives you everything as JSON.
- Correct. Edit anything in the app; edit your account details in Settings.
- Delete. Delete individual items, or your whole account, from Settings → Data & Privacy. Account deletion is immediate and irreversible. Step-by-step instructions.
- Withdraw consent. Turn off AI, notifications, calendar sync, or weather in Settings at any time.
For anything else, such as a copy in a particular format, restriction of processing, an objection to processing, or a question about what we hold, email support@getdumpling.app.
How we handle a request
Verification. We'll ask you to send the request from the email address on your account, and if there's doubt we may ask you to confirm something only the account holder would know. We won't ask for a copy of your ID unless a request is high-risk and there's no other way to be sure. We ask because handing your notes to someone impersonating you would be far worse than the inconvenience.
Timing. We'll respond within 45 days. If a request is genuinely complex we may take one further 45 days, and we'll tell you before we do.
Authorized agents. Someone may make a request on your behalf if they give us written proof you authorized them; we may still confirm it with you directly.
Appeals. If we refuse a request, we'll tell you why, and you can appeal by replying to that email with "Appeal" in the subject. We'll review it and respond within 45 days. If we still say no, you can complain to your state Attorney General or, in the EEA and UK, your data protection authority.
Cost. Free, unless a request is manifestly unfounded or repetitive, and we'd tell you before charging anything.
US state privacy rights
If you live in a state with a comprehensive privacy law (California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and a growing list of others) you have the rights described above: to know what we collect and why, to access and get a copy, to correct, to delete, to appeal a refusal, and to opt out of sale, of targeted advertising, and of profiling.
The last three don't apply to anything we do. We do not sell personal information, we do not share it for cross-context behavioural advertising, we do not use it for targeted advertising, and we do not profile you. There is no "Do Not Sell or Share" link on this site because there is nothing to opt out of. If that ever changes, this policy changes first.
You won't be treated differently for exercising any of these rights. We won't degrade the service, change your price, or close your account because you asked.
California
The categories we collect map to the CCPA's statutory categories as: identifiers (email, IP address, device identifiers), commercial information (subscription and transaction records), internet activity (usage events, app version), geolocation data (only if you use the weather widget, and only the city you typed yourself, since we run no IP-to-location lookup), and, because it's a notes app, whatever you choose to put in your own content. We collect them from you and from your device, for the business purposes described under How we use it, and disclose them to the service-provider categories listed on our service providers page. We disclose none of them for money or for advertising.
Shine the Light. Under California Civil Code §1798.83, California residents may ask which personal information we disclosed to third parties for those parties' own direct marketing. Our answer is none. Email us with "Shine the Light Request" in the subject if you'd like that in writing.
Consumer notice under California Civil Code §1789.3. The provider of this service is By Azur LLC, a New Hampshire limited liability company. Complaints may be directed to support@getdumpling.app, which a person reads and is the fastest way to reach us. You may also contact the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs at 1625 N. Market Blvd., Suite N112, Sacramento, CA 95834, or by phone at (800) 952-5210.
If you're in the EEA or UK
By Azur LLC is the data controller for the personal data described here. Our contact details are under Contact, and the legal bases we rely on are in the table under How we use it.
On top of the rights above, the GDPR and UK GDPR give you the right to data portability (our JSON export satisfies it), the right to object to processing based on legitimate interests, the right to restrict processing while a dispute is resolved, and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We make no such decisions. The AI assistant drafts and suggests; it decides nothing about you.
If you're unhappy with how we've handled your data, please tell us first, though you don't have to. You can complain directly to the supervisory authority where you live, where you work, or where the problem happened. In the UK that's the Information Commissioner's Office; in the EEA, your national authority is listed by the European Data Protection Board.
Sensitive information
Dumpling never asks you for sensitive personal information: health, religion, politics, sex life, race, biometrics, precise location, government identifiers. We don't want it and we have no feature that needs it.
But it's a notes app, and people write down their lives. If you put something sensitive in a note, we process it exactly the way we process everything else you write: to store it, sync it, back it up, and, only if you've enabled AI for that category, send it to a model provider to answer your question. We never use it to infer characteristics about you, we never use it for advertising or profiling, and it never trains a model. If you'd rather it wasn't on our servers at all, don't put it in Dumpling. That's an honest answer, not a dismissive one.
Google user data
If you connect Google Calendar, we ask for two things. Read access lets us show your existing events alongside your tasks, on Today, on Next 7 Days, and in the calendar. Write access is used in exactly one place: when you ask the AI assistant to create, change, or delete an event, it does that in your Google Calendar. Nothing writes to your calendar unless you asked for it in so many words. You choose this per account when you connect one. Pick read-only and we're never granted write permission for that account at all, so nothing in Dumpling can change it even by mistake. Connecting a personal calendar with write access and a work calendar read-only is a perfectly normal setup.
Dumpling's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely: your Google Calendar data is used only to provide the calendar features you asked for. It is not sold, not used for advertising, not used to train AI or machine-learning models, and not read by a human except with your permission, for a security investigation, or where the law requires it.
You can disconnect Google Calendar in Settings at any time, which revokes our access and removes the synced events, or revoke it yourself from your Google account permissions.
Security
Passwords are hashed with Argon2 and never stored in a readable form. Login tokens are stored hashed, rotate on use, and can be revoked. Traffic is encrypted with TLS. The database enforces per-user isolation at the row level, so one account's queries can't reach another's rows even if application code has a bug. Backups are encrypted before they leave the server. Access to production is limited and logged.
No system is perfectly secure, and anyone who tells you otherwise is selling something. If a breach ever affects your data, we'll notify you and the relevant regulators as the law requires, and we'll tell you what actually happened. Found a vulnerability? Our security page explains how to report it.
Children
Dumpling isn't built for children and isn't directed at them. You must be at least 13 to use it, and if you're under the digital age of consent where you live (16 in parts of the EEA) a parent or guardian must agree on your behalf. We don't knowingly collect personal information from children under 13. If we learn we have, we'll delete it. If you're a parent who believes your child has an account, email us and we'll sort it out.
Changes to this policy
We'll update the date at the top whenever this changes. For any change that materially affects your rights or how we use your data, we'll tell you in the app and by email before it takes effect, and give you time to object or leave. We won't quietly broaden what we do with your data and hope you don't read the diff.
Contact
Questions about this policy, or about your data, go to support@getdumpling.app. A person reads it.
By Azur LLC, a New Hampshire limited liability company, is the controller of the personal data described in this policy. Email is our contact channel for privacy requests and formal notices. If you need a postal address to serve a legal notice, ask and we'll provide one.