dysl.me

Legal, but readable

Privacy notice

Who is responsible?

dysl.me is the data controller for dysl.me. Contact us at privacy@dysl.me. Address: DYSL.me - No fixed abode.

What information we process

We do not intentionally store browser user-agent strings in the results database.

Encrypted links and who can see results

Before a response, request details are held in a Sodium-encrypted URL token rather than a requests table. A short link stores that encrypted token so it can redirect. The URL is a bearer link: anyone who receives it can open the question, and anyone can append /results to view its result. Do not share it with people who should not have access. Encrypted links may also appear in browser history and infrastructure access logs.

After submission, the response and associated display names are stored for operating results and future aggregate statistics. Love-mode notification emails may also be stored with the completed result. Lunch notification emails remain in the encrypted link and are used to send the one response email.

Why we use it

We do not use personal data for advertising, sell it, send marketing, or make decisions with legal or similarly significant effects.

Public leaderboards

Leaderboard codes are short, public and guessable; they are not passwords. On personal love links, leaderboard participation is optional and off by default. An “Invite Many People” link is explicitly presented as an open leaderboard: submitting it automatically publishes the responder’s supplied first name, score, emotional stage and position. Anyone who knows or guesses the code can view that information.

Service providers and transfers

We share information only where needed to run dysl.me, including Cloudron-hosted infrastructure, MySQL, email delivery, network/security providers, MaxMind for country and coordinate estimation, Data Thistle for nearby GB event searches, Postcodes.io for ONS-derived rural/urban classification, and DiceBear for leaderboard avatars. MaxMind receives the visitor’s IP address. Data Thistle receives the rounded search-cell coordinates, adaptive 15-, 25- or 30-mile radius and date range from our server. Postcodes.io receives browser coordinates rounded to approximately 100 metres but no IP address forwarded by the application, but not the visitor’s IP from the browser request. DiceBear receives a one-way deterministic seed—not the readable name, email or leaderboard code—but it and its infrastructure receive normal connection data such as the viewer’s IP address. Requests use a no-referrer policy. Providers may process information outside the UK or EEA using an applicable transfer safeguard.

Retention and security

Completed response records are retained for historical statistics until deletion is requested or the dataset or service is retired. IP addresses and all browser-reported or MaxMind-estimated coordinates in the separate location-accuracy table are deleted after 14 days, matching the intended MaxMind correction cycle. Event search cache rows—including their search coordinates and event content—stop being used and are deleted after 24 hours. A minimal API-call ledger containing only the request class (day refresh or period fallback), outcome and timestamps is retained for a rolling 31-day quota window; it contains no coordinates, IP address, date choice or user identity. Short-link mappings remain while their links are supported; the short-lived selected-event session record expires after about 30 minutes. Provider logs follow the relevant provider’s retention settings.

We use authenticated encryption, keyed pseudonymous request hashes, HTTPS, access controls, CSRF protection and restricted browser security headers. No online service can guarantee absolute security, so keep private links private.

Your rights

Depending on where you live and the circumstances, you may ask for access, correction, deletion, restriction or portability, or object to processing based on legitimate interests. Email privacy@dysl.me. We may need the relevant link, leaderboard code or other information to locate and verify a record. You may also complain to the data-protection authority where you live or work.

Cookies, children and changes

We use one essential session cookie and local storage to remember dismissal of the cookie notice. We do not use analytics, advertising or cross-site tracking. See our cookie policy.

dysl.me is not directed to children under 16. We may update this notice when the service, providers or law changes; the date above shows the latest version.

Nearby drinks searches

For creators in supported European and North American countries, the optional Drinks finder sends a rounded geographic-cell centre—not the creator’s name, email, token or IP address—to the public Overpass API to find OpenStreetMap features tagged as pubs or bars. We cache the cell centre, venue name, public coordinates, type, address, opening-hours text and website for seven days, including an empty result. A selected venue is sealed into the encrypted invitation.

Browser location is used only after the creator taps the search button and grants permission. Opening-hours information is community-contributed and may be incomplete or out of date, so check directly with the venue before travelling.

OpenStreetMap and Overpass

Pub and bar data is provided by OpenStreetMap contributors through the Overpass API. The provider receives the rounded search-cell centre and our server’s ordinary connection data. It does not receive the dysl.me visitor’s browser IP from the application request. Search and normalized venue-cache rows are deleted after seven days; the minimal request outcome ledger is retained for 31 days.