Privacy Policy
On this page
1. Scope and responsible operator
This policy describes how the Dilack operator identified on this page handles personal information on the website and in account, community, voice, video and screen-sharing features. These practices describe the current version; material new uses require updates and, where necessary, a specific choice or consent.
Server administrators may process information for their own management purposes. They must explain those practices and comply with their legal duties. This does not remove Dilack’s responsibility for processing that it performs or determines.
2. Account and authentication information
We process display names, email addresses, account identifiers and profile information supplied by you or your sign-in provider. We store a cryptographic password hash rather than a readable password. We receive identifiers and authorized information from Google or GitHub when you choose to sign in or link them; we do not receive your password for those providers.
Authentication may store provider tokens, session records, access and expiration dates, IP addresses and browser information. Legacy ChatGPT sessions use identifiers and profile information supplied through that authentication mechanism.
3. Server and usage information
We store server and channel names and settings, descriptions, ownership, membership, roles, invitations, access status and records necessary to enforce permissions. Participants may see your name, presence and microphone, camera or screen-sharing state through room features.
We process connection, call signaling and security information, including participant identifiers, WebRTC negotiation parameters and error events. Infrastructure may also log requests, IP addresses, browsers and timestamps. If you uploaded audio files through previously available features, those files and preferences may remain stored until deletion or handling of an applicable request; hiding a feature does not automatically erase its data.
4. Voice, video and screen sharing
The current version uses WebRTC connections between participants. The server coordinates sessions and signaling; voice, camera and screen content is sent to call participants. Network discovery services, such as STUN, help establish connections and receive technical network information. Direct connections may reveal your IP address to participants or their devices.
The current version does not implement call recording or transcription by Dilack. This does not prevent participants from recording on their own devices. WebRTC transport protection does not prevent an authorized recipient from viewing, listening to, copying or recording received content.
Microphone, camera and screen capture require browser permissions and your action. You can stop transmission and revoke browser permissions. If the architecture changes to media relaying, recording or other material processing, this description and notices will be updated before those new uses.
5. Purposes and legal bases
We use information to create and authenticate accounts, maintain linked sign-in methods, connect participants, manage access, fulfill requests, protect the service, investigate incidents and meet legal duties. In the current version, we do not use call content for advertising or training artificial intelligence models.
Where law requires a specific legal basis, it depends on the purpose: performance of a contract, legal obligations, legitimate security and operational interests compatible with your rights, or consent where necessary. A technical browser permission does not replace all legal consent requirements.
6. Sharing and international processing
We share necessary information with chosen participants, administrators with relevant permissions and hosting, storage, authentication and security providers. The current infrastructure uses Sites/OpenAI and Cloudflare services; Google and GitHub receive information when their authentication flows are used. Those providers also publish their own policies.
We may disclose information to comply with valid legal requirements, protect people and investigate fraud or abuse within legal limits. Business reorganizations or transfers may involve information transfers with required protections and notices. In the current version, we do not sell personal information or share it for cross-context behavioral advertising.
Information may be processed in the United States and other countries where providers operate. We do not guarantee US-only storage. Where required, international processing depends on legally applicable transfer mechanisms and safeguards; this policy alone does not replace those mechanisms.
7. Cookies and local storage
We use session and security cookies for authentication and sign-in protection. Preference cookies remember language and theme; local storage may remember options such as room sound volume and activation. The current version includes no advertising cookies or first-party advertising tracking tools.
You can change Dilack preferences, clear cookies and local data, or block them in your browser. Blocking necessary cookies may prevent sign-in. Clearing browser data does not automatically delete your account or service records. New nonessential tracking technologies will require legally applicable notices and choices.
8. Retention and security
Account and server information is kept as necessary to provide the service and fulfill the described purposes. Removal may depend on a request and assessment of legal duties, security, fraud prevention and disputes. We do not promise automatic deletion of every record after a single fixed period.
Operational presence and signaling records are cleaned up during room activity; this does not guarantee immediate deletion of infrastructure logs, backups or records subject to legal retention. Specific periods will be established for new categories or requirements where applicable.
We use authentication, permission and communication protection controls supported by the implemented features. No service is invulnerable. We will investigate incidents and provide legally required notifications.
9. Your choices and rights
You can manage media permissions, local preferences and available sign-in methods in settings. Use the listed contact to request access, correction, deletion, a copy or portability of information, restriction of or objection to certain processing, or withdrawal of consent where applicable. Each right depends on applicable law.
We may verify your identity and an authorized agent’s authority before responding, requesting only proportionate information. We may deny or limit requests where law permits, explaining the reason and available review options. You may also contact the competent authority. We will not discriminate against you for exercising protected rights.
Residents of US states, Brazil and other jurisdictions may have additional rights. References to rights do not mean every legal regime applies to every user or business. Where a right to opt out of sale, advertising-related sharing or targeted advertising applies, we will honor it; those activities are not part of the current version.
10. Age, changes and contact
The service is not directed to children under 13 and requires compliance with the minimum age shown on this page. We do not knowingly solicit information from children below the applicable threshold. If you learn that a child supplied information contrary to these conditions, contact us for review and appropriate action. A simple age declaration does not remove child protection duties.
We will post changes with an updated version and communicate material changes appropriately. Additional consent will be requested where required. Use the information panel below for privacy matters; label mailed requests “Dilack — Privacy.”
Operator and contact
- Legal entity
- State of incorporation
- Provided address
- 4630 S KIRKMAN RD STE ORLANDO, FL 32811
- Legal and privacy contact
- support@dilack.com
- Proposed minimum age
