Privacy Policy
Dunly is a personal to-do list provided by Rooche. Your workspace gives you access to Dunly and controls where your data lives — but the list itself is yours: your tasks are private to you, and no one else can browse them. This policy explains what Dunly collects and how it is handled.
This page is the Dunly privacy supplement. It describes what Dunly itself stores. The Rooche Platform Privacy Policy governs everything it does not cover — accounts and sign-in, billing, support, retention, and your rights under the Data Privacy Act of 2012 (RA 10173).
What we collect
- Account information from your account system. When you sign in, the account system verifies your credentials and tells Dunly who you are — your username, display name and language preference. Dunly never stores your password.
- The tasks you write. Titles, notes, due dates, and whether they're done.
- The recordings and files you attach. Voice notes, videos, photos and files you choose to add to a task, along with basics like filename and duration.
- Support conversations. If you contact us from inside the app: your message, anything you choose to attach, and basic context (which app, which version) so we can help.
Dunly has no advertising and does not collect your location, contacts, or anything from your device beyond what is listed above. With your consent, Dunly collects privacy-safe usage analytics — coarse, screen-level events (which screens are used, and whether a request succeeded) to help us improve the app. These carry no personal data and nothing you enter: no names, task titles or content, attachments, or identifiers. Analytics is off until you opt in (Settings → Privacy) and you can turn it off again at any time. This analytics is processed on our behalf by Google Analytics (GA4); the legal basis is your consent, and withdrawing it stops collection.
Who can see your tasks
You, and only you. Every task and attachment belongs to one signed-in person, and Dunly serves it back only to that person. There is no screen, role or setting that lets administrators — or anyone else — read your list or play your recordings.
Where it lives
Your tasks and attachments are stored in an isolated backend hosted on our infrastructure. Recordings and files are never given public or guessable links — they are served only through the app, to you, signed in. Data is encrypted in transit (TLS).
The apps also keep an offline copy of your own list on your device, so Dunly works with no connection: tasks and recordings captured offline are stored on the device and sync when you're back online. That cache is kept per signed-in user, so on a shared machine one person's cached list never appears in another person's session.
Sharing and children
Both are platform-wide: see the Rooche Platform Privacy Policy — we do not sell your data, and Dunly is not directed at children.
Integration API keys
You can create API keys to connect other software to Dunly. A key you create in the app acts as you, on your own task list only — so treat it like a password. A key can instead be scoped as its own separate account with its own isolated task list. Either way, an API key can never read or change another person's private tasks. Keys are stored only as a cryptographic hash; the plaintext is shown once at creation and never again.
Retention
Your tasks and attachments are kept for as long as you use Dunly. You can delete a task or an attachment in the app at any time. If you want something removed that you cannot remove yourself, contact us and we will handle it.
Changes
If this policy changes, the current version will always be at this address, with its date above.
Contact
Reach us any time from the app's Get help screen.
Platform policy: rooche.biz/privacy · Terms: rooche.biz/terms