DEMI / privacy
Privacy policy
What DEMI processes, why it is needed, and the choices you have.
Last updated:
Data we process
Google sign-in provides your name, verified email, profile image, and account identifier for authentication. DEMI does not request access to Gmail, Drive, contacts, or calendars.
DEMI also stores profile and internal identity data, friend/block relationships, existing messages, notifications, utility records, and security/session information such as access times, IP address, browser, and device.
How data is used
Data supports accounts, available utilities, synchronization, abuse prevention, troubleshooting, and service reliability. Google data is used for sign-in, account linking, and profile display.
DEMI does not sell personal data or use Google data for advertising.
Storage and providers
DEMI runs on Vercel, stores primary data in Neon PostgreSQL, and uses Google OAuth for Google sign-in. Providers process data to operate their respective parts of the service.
Security and retention
DEMI uses HTTPS, secure sessions, access controls, and encryption for stored OAuth tokens. No system is completely secure; protect your sign-in credentials and do not share sessions.
Data is retained while an account is active or as needed for security, backups, and legal obligations. Valid deletion requests are handled through deletion or anonymization within technical and legal limits.
Your choices
You can update your display name, manage blocked accounts, and disconnect Google when another safe sign-in method remains. You can request access, correction, or deletion of your data.
Contact
Send privacy requests to privacy@demi.io.vn.