Privacy
Your dacha is yours.
Our Dacha is a little place built for exactly two people. This page explains, in plain words, what we hold, why we hold it, who helps us run the service, and how you stay in control. No fine-print games.
The short version
- Our Dacha is private by design: your shared world is visible only to the two of you.
- Your data lives on our own server in a data centre in Germany (EU), not on a rented data platform.
- Live location sharing and the cycle journal are optional, off until you turn them on, and shared only with your one partner, only as much as you choose.
- Payments are handled by Apple and Google. We never see your card or bank details.
- A short, named list of helpers (weather, map tiles, place names, notification delivery) each receive the minimum needed to do one job. They are all listed below.
- You can export everything you have made, and delete your account, from inside the app at any time.
- No ads. No third-party trackers or analytics. No public feeds, followers, or metrics.
- We never sell your data. We never trade it. It is not a product.
Who we are
Our Dacha is made by Dacha Town, a small, independent software studio. When this page says "we," "us," or "the studio," that is who we mean: the people who built the app and who run the server it lives on. For the purposes of data-protection law, Dacha Town is the controller of the personal data described on this page. You can reach us any time at hello@dacha.town.
What we collect
We hold as little as we can while still making the app work. Here is the whole list:
-
Your account
Your email address (to sign in and to reach you about your account), the display name you choose, your avatar if you set one, and the pairing that joins your account with your one partner's account into a shared dacha.
-
The things you make together
Chat messages, letters, notes, and postcards; photos and drawings you upload, with their captions, reactions, and comments; your moods and statuses; daily-question answers and diary comments; dates, wishes, and countdowns; gifts, keepsakes, and everything in your shared world's economy, from the pantry and garden to your Lunari balances; and your moves and saved state in the games you play together. This is your shared world, and it is the whole point of the app.
-
The cycle journal, only if you use it
An optional, private space for period, symptom, energy, and cycle notes. This is health information, and it gets its own section: see The cycle journal below.
-
Location, only as much as you choose
If you turn on live sharing, your current location, so your partner can see your pin on your private map. Separately, a saved home place you set by hand powers weather, the local time, and the little place label under your house. See Location below.
-
Place searches
If you search for a place by name (for example, to set your home town), the text you type is sent to a geocoding service to find it on the map. It is not linked to a profile of you.
-
Subscription state, never payment details
When subscriptions launch, Apple or Google processes the payment and sends us a signed confirmation. We keep the product and transaction identifiers and your entitlement state (active, expired, refunded), so the app knows what you have paid for. We never receive or store your card or bank details. See Subscriptions & payments.
-
Notification tokens, if you opt in
If you say yes to notifications, your device gives us a push token we use to deliver them. Nothing more.
-
Technical housekeeping
Ordinary server logs and limited authentication, network, error, and security records that keep the service up, safe, and debuggable. We do not use any of this to build a profile of you.
That is the whole list. We do not ask for your contacts or your phone number, and we do not run advertising or analytics SDKs, so there is no hidden collection happening underneath.
How we use what we collect
We use your information for one set of reasons, and one set only:
- To run the app: to show the two of you your shared rooms, moods, photos, letters, diary, gifts, games, and map.
- To deliver the notifications you have asked for (mail arriving, your partner coming home, and the like).
- To verify and honour your subscription, including restores, renewals, refunds, and the read-only archive if a plan lapses.
- To keep the service working, safe, and backed up.
- To answer you when you write to us.
We do not use your content to train AI models, to advertise, to "improve engagement," or to measure you in any way. There are no growth metrics here. The audience is exactly two people, and we mean to keep it that way.
Our legal bases
Where the GDPR or UK GDPR applies, we rely on:
- Performance of a contract, for the core service: your account, your shared world, and your subscription.
- Consent, for the optional things: live location sharing, the cycle journal, and push notifications. You can withdraw consent at any time by switching each of them off, and the app stops.
- Legitimate interests, for keeping the service secure and preventing abuse, in ways you would reasonably expect and that do not override your rights.
- Legal obligation, on the rare occasions the law requires us to keep or produce something.
Location, specifically
Live location is a feature you choose, not a default. It is off until you deliberately turn it on, and you can turn it off again at any time, in the app and in your device's own settings.
- Your live location is shared only with your one partner: never publicly, never with advertisers, never with anyone else.
- It exists to do one warm thing: let the two of you find each other as pins on a private map.
- When you switch sharing off, the app stops collecting your location and clears the stored precise coordinates. We do not keep a history of where you have been.
- The map itself is drawn from tiles served by OpenFreeMap, using OpenStreetMap data. The tile service sees the map area your app asks to draw, as any map service must, but it does not receive your name, your account, or your partner's location. It requires no account and sets no cookies. Attribution is shown on the map.
- The friendly place label under your pin (a town name, not coordinates) is looked up on your own device via BigDataCloud, using only the coordinate your device has just authorised. Saved places and your partner's coordinates are never sent there.
- Your saved home place (which you type in yourself) is used to fetch your local weather and time of day from MET Norway, the Norwegian Meteorological Institute, so the dacha's sky can match yours. The weather service receives a place, not a person.
- Searching for a place name in Settings does not leave our server. The place list lives in our own database, so no third party learns which towns you look up.
If you ever feel unsure, the safe choice is simply to leave location off. The rest of the dacha works beautifully without it.
The cycle journal, specifically
The cycle space is an optional, private journal for period, symptom, energy, and cycle notes. Because this is health information, it is handled with extra care:
- It is opt-in. The space does not exist until its owner creates it, and only its owner can write in it.
- The owner controls sharing. Your partner sees exactly as much as you choose to show, from nothing at all to gentle phase context. You can change or stop sharing at any moment.
- It is stored in the same couple-scoped, access-controlled database as the rest of your world, on our own server, and nowhere else.
- It is never used for advertising, never shared with any third party, never used to build a profile, and never sold. Full stop.
- You can edit or delete entries, or delete the whole space, whenever you like.
One honest boundary: the cycle journal is a private wellness diary, not a medical device. It does not diagnose, treat, or advise, and it should never substitute for a clinician.
Push notifications
Notifications are opt-in. If you say yes, your device gives us a push token we use to send the small messages the app sends: your partner left you a note, your daily question is ready, that sort of thing. Delivery runs through Apple's and Google's push services on their platforms (and standard Web Push in the browser), and we keep the content of what passes through them deliberately minimal. You can turn notifications off in the app or in your device settings whenever you like, and we stop.
Subscriptions & payments
Full access to Our Dacha on mobile is offered through auto-renewable subscriptions (individual or couple, monthly or annual) sold by Apple through the App Store and by Google through Google Play. That means:
- Apple or Google takes the payment. We never receive or store card numbers, bank details, or billing addresses.
- We receive a signed confirmation of the purchase, which we verify and keep in the form of product and transaction identifiers and entitlement state, so the app knows your plan is active, restored, expired, refunded, or revoked.
- If a plan lapses, your dacha becomes a read-only archive: nothing is deleted, and you can export everything. Resubscribing wakes it back up.
- Managing or cancelling the subscription happens with Apple or Google, in your device's subscription settings.
- Lunari and every other in-app item are fictional. They cannot be purchased with real money, cannot be redeemed, and have no real-world value, so there is no purchase data to collect about them.
The services we rely on
Because we self-host, the list of outside services is short, and each one sees only the minimum needed to do its single job. Here is the complete roster:
-
Apple (App Store, StoreKit, and push delivery)
Processes iOS subscription payments and delivers push notifications to iPhones. Sees what any App Store purchase or push delivery requires; never sees inside your dacha.
-
Google (Google Play billing and push delivery)
The same two jobs on Android: subscription billing and notification delivery.
-
OpenFreeMap (map tiles, with OpenStreetMap data)
Draws the base map behind your two pins. Receives standard tile requests for the map area being drawn; receives no account identity and no partner locations. Requires no account, no API key, and sets no cookies.
-
MET Norway (weather)
The Norwegian Meteorological Institute. Provides the real weather and daylight for the home place you set, so your dacha's sky matches yours. Receives a place, not a person.
-
BigDataCloud (place labels)
Turns your device's current, permission-authorised coordinate into a friendly place name, on your device. Receives a single coordinate at the moment you share; never your saved places or your partner's location.
-
Our own server
Everything else, which is to say: your actual world. It runs on a dedicated server we rent in a professional data centre in Germany and administer ourselves. The data-centre operator provides the hardware and the building; it does not have access to your data.
There are no analytics providers, no advertising networks, no data brokers, and no "partners" beyond this list. If the list ever changes, this page changes with it.
This website (dacha.town)
The site you are reading does not track you. It has no analytics, no cookies set for measurement, no advertising pixels, and no third-party scripts. Every image, font, and script is served from our own domain under a strict Content-Security-Policy, so your browser is not quietly reaching out to anyone else while you visit.
Everything shown on the site is invented example material: example photos, example notes, example answers. No real couple's data ever appears here.
Where it lives & how we keep it safe
Your data is stored on a backend we host ourselves: a self-hosted Supabase stack built on PostgreSQL, running on the studio's own server in Germany. Everything travels over encrypted HTTPS. We are not handing your world to a third-party cloud product to do with as it pleases.
Inside the database, your data is couple-scoped with row-level access control. In plain terms: each couple's rows belong to that couple, and the database itself enforces that one couple can never read another's. The walls between dachas are built into the data, not just the app on top of it.
No method of storage is perfectly secure, and we will not pretend otherwise. But we keep our software updated, we keep the surface that faces the public deliberately narrow, and we keep backups so your shared world is not lost to a bad day.
Your choices & your rights
Everything optional stays in your hands, from inside the app:
- Location: turn live sharing on or off at any time; turning it off clears your stored precise coordinates.
- Cycle journal: choose exactly what your partner sees, change it, or delete the space entirely.
- Notifications: switch them off in the app or in your device settings, and we stop sending them.
- Export: use "download everything" to export your world as structured JSON, a readable PDF, and your original photos and media, in one ZIP.
- Delete: delete your account and its data from inside the app, no email required. The full walk-through is on our account deletion page.
Depending on where you live, the law also gives you formal rights over your personal data: to access it, correct it, delete it, restrict or object to its processing, take it with you in a portable format, and withdraw consent at any time without affecting what happened before. We honour all of these. Write to hello@dacha.town and we will respond within 30 days. If you are in the EU or UK, you also have the right to complain to your local data-protection authority, though we would be grateful for the chance to fix things first.
For California residents: we do not sell personal information, and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. The rights to know, delete, and correct all work as described above.
Keeping it, and deleting it
We keep your account and your shared world for as long as you have an account with us, so your dacha is there when you come back to it. We do not expire your memories on a timer.
When you want it gone, it goes. You can delete your account from inside the app (Settings → Account → Delete account), or ask us by email. Deletion permanently removes your login, profile, avatar, pairing, and settings from our live systems. Copies remaining in routine backups age out automatically on the normal backup rotation and are never restored or used for anything else.
One honest note: because a dacha is shared, things you made together (a letter you sent, a photo you both commented on) remain part of your partner's copy of your shared world after you leave. When the second partner also deletes their account, the remaining dacha records and stored media are removed too. The account deletion page spells out exactly what goes and what stays.
Children
Our Dacha is made for adults sharing a life together. You must be at least 13 to use it, and at least the age at which you can consent to an online service where you live (16 in parts of the EU). We do not knowingly collect information from children, and the app is not directed at them. If you believe a child has given us information, please contact us and we will remove it.
International transfers
Your world is stored in Germany, inside the EU. The platform services above (Apple, Google) and the map, weather, and geocoding services may process their small slices in their own regions, under their own published safeguards, as part of doing the job you asked them to do (delivering a notification, billing a subscription, drawing a map). Nothing beyond those slices leaves our server.
Changes to this policy
If we change how any of this works, we will update this page and move the "last updated" date at the top. If a change is significant, something that meaningfully affects your privacy, we will tell you in the app rather than hoping you notice.
How to reach us
We are a small studio and a real person reads your mail. For anything about your privacy, your data, deleting your account, or this policy:
Dacha Town
Email: hello@dacha.town, privacy and data requests welcome.
Account deletion: dacha.town/delete-account.html
Or visit our support page.
Thank you for trusting us with your little place. We do not take it lightly.