privacy policy

effective August 29, 2026 · v3.1

who we are

dull is operated by OÜ Auklora, a private limited company registered in Estonia (registry code 17118384) at Mäe tn 3, Kiili, 75401 Harju maakond, Estonia. OÜ Auklora is the data controller for the purposes of applicable data protection laws. you can reach us at [email protected].

a note on terminology

throughout this policy, we use pseudonymous to describe identifiers and events that do not directly reveal your name or email, but that may be linked to a device, subscription, or optional friends account. a pseudonymous identifier could in principle be re-associated with a specific person if combined with other information. true anonymous data (per GDPR Recital 26: impossible to re-identify by any reasonably likely means) is rare in mobile apps; we reserve the word for cases where it is technically accurate, for example aggregated SKAdNetwork postbacks and Apple AdServices attribution tokens. for everything else we use pseudonymous.

data protection officer

dull's processing activities do not meet the criteria for mandatory designation of a Data Protection Officer under GDPR Art. 37. we have voluntarily designated Kaspar Noor as the point of contact for all data-protection and privacy matters, including the Singapore PDPA Data Protection Officer role and the Korean PIPA Personal Information Protection Officer (CPO) role. you can reach Kaspar at [email protected].

the short version

dull is an app that loads social media websites in a web view and applies filters to make them less sticky. it hides short-form feeds and algorithmic content, enables grayscale mode, adds friction gates, enforces daily time limits and scheduled quiet hours, and lets you lock settings behind a PIN. everything that matters to your browsing runs on your device. here's the short version:

your browsing stays on your device

we don't collect, store, or transmit the content you view inside dull. the pages, posts, videos, accounts, searches, and messages you view never leave your device. Dull stores its usage dashboard locally; the limited device-keyed product events described below, including platform session and duration events, are sent to our analytics providers.

limited analytics and ad measurement, no browsing profiling

no Google Analytics, no crash reporters, no behavioral retargeting, and no lookalike audiences built from in-app behavior. we collect a limited set of product-analytics events, such as which screens were reached, which features were enabled, whether a nudge was shown, and whether a platform browser was opened, so we can understand how the app is used and improve it. these events describe app behavior, not browsing content. after a user authorizes Apple's App Tracking Transparency prompt, the current app may also use the Meta SDK in supported regions, currently outside the EU/EEA, the UK, and South Korea, to send pseudonymous install, app-open, and "paywall viewed" events so we can measure whether ad spend leads to subscriptions. under Apple's definitions, the Device ID, Purchases, and Product Interaction data used in this measurement flow are linked to a device or account and used for tracking. if you choose to use friends, the separate account data described below is linked to that friends account.

friends is optional

the core dull browser does not require an account. if you choose to use friends, you create a small dull account with Sign in with Apple so you can invite friends and share streak and goal-day progress. this friends account is separate from the social media accounts you use inside dull.

most app data stays local

your preferences (which platforms you've enabled, appearance settings, friction gate configuration, grayscale settings, time limit settings, scheduled quiet hours, and commitment delay state) and detailed usage statistics are stored locally on your device using UserDefaults. if you set a PIN lock, a SHA-256 hash of your PIN, not the PIN itself, is stored in the iOS Keychain. if you use friends, dull session credentials are also stored in the Keychain and sent to our authentication service when needed to keep you signed in. only the limited friends data listed below is synced to our backend.

cookies stay on-device

when you log into Instagram or YouTube through dull, those platforms set cookies in the web view. these cookies are stored locally on your device. we can't see them and don't access them.

website advertising cookies (getdull.app)

on our marketing pages (for example getdull.app/go) we use the Meta Pixel and Meta Conversions API to measure whether our ads lead to sign-ups and purchases. these set cookies in your browser and share a hashed identifier with Meta for advertising and analytics. in the EU/EEA, the UK and Switzerland they run only after you accept the cookie banner; in other regions they are on by default and we honor your browser's Global Privacy Control (GPC) signal. this is separate from the in-app Meta SDK described below, and from the platform cookies above.

you can withdraw or change your choice at any time — it's as easy as giving it:

third-party services

RevenueCat (subscription management)

RevenueCat manages subscription status and processes transaction data from Apple. the legal basis for this processing is performance of a contract and legitimate interest. we need RevenueCat to provide and manage your subscription and to understand whether the app is working for subscribers. RevenueCat may receive:

  • a pseudonymous app user ID generated by RevenueCat
  • transaction and purchase data from Apple
  • device type, OS version, and app version
  • where you heard about dull (if you choose to tell us during or after sign-up)
  • which platforms you selected during onboarding
  • pseudonymous usage signals for subscription management: whether you have ever opened a platform browser, total number of browse sessions, number of days you have used the app, which platforms you have opened, and which optional features are enabled (e.g. grayscale mode, time limits, quiet hours, opening challenge)
  • if you sign into friends, the stable identifier Apple assigns to dull for that sign-in, stored as a customer attribute so we can connect the friends sign-in to subscription outcomes

RevenueCat does not receive your Apple password or the content you browse. if you delete your friends account, we remove the friends-linking Apple identifier from the RevenueCat customer record. deletion of a friends account does not delete App Store purchase records or cancel an active subscription. retention: subscription and transaction data is retained for the period required by applicable accounting and tax law (typically 5 years from the end of the financial year of the transaction); other RevenueCat customer attributes are retained for as long as needed for subscription management and a reasonable wind-down period, in accordance with RevenueCat's own retention policy. see RevenueCat's privacy policy for full details.

Convex (optional friends accounts)

Convex hosts the backend used only by the optional friends feature. when you choose Sign in with Apple, our authentication endpoint receives an Apple identity token so it can verify the sign-in. we do not store that identity token after verification. Convex stores:

  • a stable token identifier derived from the identifier Apple assigns to dull
  • your name, only if Apple provides it and you choose to share it
  • friends relationships, invite records, and invite timestamps
  • the current and longest streak and goal-day values you choose to share with friends
  • account creation, invite acceptance, relationship creation, and streak update timestamps
  • a session-token version used to invalidate signed-in sessions

we do not send your browsing content, social media credentials, detailed local usage history, email address, Apple password, or payment details to Convex. the legal basis is performance of the friends service you request. pending invite links expire after 30 days. account, relationship, accepted-invite, and shared progress records are kept while the friends account exists.

account deletion: in dull, tap delete account at the bottom of the signed-in friends screen, or open settings > account > delete account. after you confirm, we delete the friends user record, relationships, invites, shared streak and goal-day data, and associated timestamps from the active database, invalidate dull session tokens, and request revocation of dull's Sign in with Apple authorization. a failure by Apple to complete revocation does not delay deletion of our copy. processor backups, if any, may retain an encrypted residual copy until overwritten on the provider's normal backup schedule and are not used for ordinary product operations.

deleting the friends account does not delete your local dull preferences, your social media cookies, an App Store subscription, Apple transaction records, or an email address you separately submitted on our website. those are separate data and services. see Convex's privacy policy and security overview.

Mixpanel (pseudonymous product analytics)

dull uses Mixpanel to understand where users drop off, which features get adopted, and whether the product is working — so we can improve it. Mixpanel receives:

  • a pseudonymous device ID (vendor ID, not your Apple ID, name, or email; it normally resets after every app from this developer is removed from the device)
  • when the app is opened (whether it's a fresh launch or a return from the background), whether it is the very first time you have ever opened the app, and your current subscription status at the time (active, lapsed, or no subscription)
  • which onboarding screens you saw, the aspirations you selected, the pain points you selected (e.g. "I open it for one thing, lose 40 minutes" — these are pre-written multiple-choice options, not free-text input), the screen-time bucket you entered along with the underlying numeric value (in hours), the time limit you set during onboarding (in minutes), which specific platforms you selected, whether you completed onboarding, and a summary of which features (time limits, grayscale, friction gate) were enabled at completion
  • paywall events: when the paywall was shown, where it was shown from, whether it was a first-time or reactivation view (i.e. whether you had subscribed before), whether it was dismissed, whether a trial or purchase completed (product ID and whether it was a free trial), whether a restore happened
  • where you told us you heard about dull (referral source), if you chose to share that
  • which steps of the post-paywall setup flow you reached and whether you completed it
  • when a platform browser is opened (which platform — Instagram, YouTube, Facebook, X, Reddit) and how long each session lasts (in seconds)
  • when you enable or disable key features in settings (friction gate, time limits, commitment delay, PIN lock, grayscale — including which platform grayscale was toggled for)
  • anti-bypass events: when you activate or end a session bypass, when you start a 24-hour commitment delay, when a filter becomes loosened after the delay
  • contextual nudge events: when a nudge was shown, tapped, or dismissed (rule ID only)
  • time limit events: when a time limit gate appears (platform and whether it was a daily limit or scheduled block), when a bonus-time extension is used
  • friction gate events: when a friction gate challenge is shown (platform and challenge type — e.g. wait timer, breathing exercise, math problem), when it is completed (including how many seconds the challenge took), and when it is abandoned without completing
  • when you view your weekly usage receipt
  • app version and iOS version

we do not pass browsing content, social media activity, your name, your email, or your friends account identifier to Mixpanel. events describe whether and when something happened, including the platform and duration fields listed above, not what you looked at. we do not call Mixpanel's identify API, but all events are attached to the persistent device-level vendor ID described above. that same device ID is stored as a RevenueCat customer attribute so server-side subscription events can be joined to the corresponding analytics cohort. for App Store labeling, Product Interaction and Device ID are therefore linked to the user through a device even though Mixpanel does not receive a name or email. your IP address is used transiently by Mixpanel's servers to derive approximate city and country, then the raw IP is discarded. the derived coarse location may remain associated with the device-keyed analytics event, so we declare Coarse Location as linked analytics data. the legal basis for this processing is legitimate interest: understanding product usage is necessary for us to improve dull and sustain the business. you have the right to object to this processing at any time under GDPR Art. 21; email [email protected] and we will stop. retention: Mixpanel retains event-level data for up to 14 months on our project configuration, after which it is anonymized or deleted. see Mixpanel's privacy policy for full details.

Apple Ads attribution

dull uses Apple's AdServices framework to measure whether app installs came from an Apple Ads campaign. on first launch, the app requests an anonymous attribution token from Apple. this token does not contain your Apple ID, device identifier, or any personal information — it is a privacy-safe, aggregated signal provided by Apple. the token is forwarded to RevenueCat so we can understand which search terms lead to subscriptions. no tracking prompt is required because AdServices does not use the IDFA or track you across apps. see Apple's AdServices documentation for details.

ad network measurement (Meta, Google, TikTok)

if dull runs paid advertising campaigns on Meta (Facebook/Instagram), Google, or TikTok, we use the following mechanisms to measure whether those campaigns are effective. the legal basis is legitimate interest: understanding whether our advertising spend leads to subscriptions. we do not use your browsing content or friends account data for behavioral retargeting, and we do not build lookalike audiences from in-app behavior. Apple nevertheless classifies the device identifiers, purchase conversions, and app-interaction events described below as tracking because these signals are linked with ad-network data for advertising measurement. under Apple's definitions, Device ID, Purchases, and Product Interaction are linked to a device or account and used for tracking. this tracking is limited to attribution and conversion measurement; it does not personalize content or ads inside Dull. you have the right to object to this processing at any time under GDPR Art. 21.

  • SKAdNetwork: Apple's privacy-preserving attribution framework. when you install dull after seeing an ad, Apple may send an aggregated, anonymous signal to the relevant ad network confirming that an install occurred. no personal data, browsing history, or user identifier is included. no ATT prompt is required for this mechanism.
  • RevenueCat server-side attribution (Conversions API): after ATT authorization, when a subscription purchase occurs, RevenueCat may forward a pseudonymous conversion event (that a purchase happened, the subscription tier, and the revenue value) to the ad network's API. this is sent server-to-server from RevenueCat's servers to the ad network's API using the pseudonymous match identifiers described below.
  • Meta SDK: in supported regions, the current version of dull initializes the Meta SDK (FBSDKCoreKit) only after ATT authorization. it can then send install or app-activation, app-open, and "paywall viewed" events to Meta. the SDK sends a pseudonymous Meta-generated ID ($fbAnonId), app and device metadata, and the event name. it does not send your browsing content, social media activity, or friends account information. before initial authorization, and on launches where permission is denied or restricted, Dull does not initialize the Meta SDK or send these identifiers and events. if authorization is revoked after the SDK has already started, Dull disables advertiser-ID collection and stops its Meta events as described below. in the EU/EEA, the UK, and South Korea, the Meta SDK is not initialized in the current release, even if ATT was previously authorized. before we enable it there, we will ship a separate in-app consent step that meets the applicable consent standard. retention: Meta retains attribution events under its own retention policy.
  • App Tracking Transparency / IDFA: during first-time post-paywall setup, if the system status is still undetermined, dull shows iOS's standard ATT prompt before enabling Meta attribution. if you tap allow, dull may send the IDFA, IDFV, IP matching flag, device metadata, and Meta-generated $fbAnonId to RevenueCat, which uses them to improve match accuracy when forwarding eligible subscription events to Meta's Conversions API. if you tap "ask app not to track," Dull does not initialize the Meta SDK, does not collect those Meta matching identifiers, and nothing changes about how the app works. if permission is later revoked, Dull stops Meta events, disables advertiser-ID collection, and requests removal of its stored $fbAnonId from RevenueCat. no rewards or restrictions are tied to your choice. iOS controls whether the system prompt can be shown again. in the EU/EEA, the UK, and South Korea, the Meta SDK and ATT prompt are currently suppressed entirely.

match identifiers used for server-side Meta attribution after ATT authorization: $fbAnonId (Meta-generated pseudonymous ID), IDFV (Apple vendor ID, scoped to apps from this developer), IP address (used by ad networks transiently for matching, then dropped), and IDFA. RevenueCat keeps these as customer attributes to forward them with eligible subscription events. because the identifiers, purchase events, and app-interaction events can be matched with ad-network data, Apple treats Device ID, Purchases, and Product Interaction in this flow as linked and used for tracking.

Apple

when you purchase a subscription, Apple processes your payment and may collect data as described in Apple's privacy policy. we do not receive your payment details from Apple.

Resend (email delivery)

if you submit your email through one of our forms (e.g. the Android waitlist at getdull.app/android) we use Resend to store the address and send you email from us. Resend receives:

  • the email address you submitted
  • which form or list you joined (e.g. android-waitlist)
  • a coarse referral source if available (UTM parameter, referring page, or "direct") — never a precise URL or anything that would identify you
  • the email address as the sole identifier for delivery

we do not pass your IP address, browser fingerprint, or any data from the Dull app itself to Resend. submissions are handled by a server-side endpoint hosted on Cloudflare; the endpoint receives your IP transiently to process the request and apply abuse protection, but does not store it.

by submitting your email you consent to receiving the specific notification you signed up for (e.g. an email when the Android version ships, plus a one-time confirmation). product updates, new feature announcements, and any future marketing emails are sent only if you separately opt in to those — we ask for that as a distinct checkbox on the form, unchecked by default. we do not sell your email address, share it with other companies for their own marketing, or use it for behavioural targeting on third-party platforms.

the legal basis for this processing is consent. you can withdraw consent at any time by clicking the unsubscribe link on any email we send, or by emailing [email protected] — we'll remove your address from all our lists. retention: we keep waitlist and marketing contacts for up to 36 months from your last interaction with our email, or until you unsubscribe, whichever comes first. see Resend's privacy policy for full details.

international data transfers

dull is operated from Estonia (EU). some of the third-party services we use are based outside the EU/EEA, which means your data may be transferred internationally. here's the picture:

dull is available worldwide through the Apple App Store, including in mainland China. we have not yet built the PIPL-specific compliance infrastructure (a Chinese representative, separate consents in Chinese, cross-border standard contract or CAC security assessment, Chinese-language notice) that the Personal Information Protection Law contemplates for active in-China operations. we are not actively marketing in China and treat any data of mainland-China users with the same baseline safeguards described elsewhere in this policy. this is residual risk we are openly disclosing rather than hiding behind a regional block; the section on changes to this policy describes how we will notify you if our posture changes.

you can request a copy of the relevant transfer safeguards (SCCs or DPF certification) by emailing us at [email protected].

regional rights

the rights below depend on where you live. personal data we may hold includes an email address if you submitted one, pseudonymous app-analytics events, subscription records, and the optional friends account data described above. to exercise any right, email [email protected]. friends users can delete their account from the signed-in friends screen or in settings > account > delete account. we respond to other requests within the timeline applicable to your jurisdiction, and in any case within 45 days.

EU/EEA and UK (GDPR / UK GDPR)

access, rectification, erasure, restriction, portability, objection (including to processing based on legitimate interest, per Art. 21), withdrawal of consent at any time without affecting prior lawful processing, the right not to be subject to automated decision-making (we don't do any — see below), and the right to lodge a complaint with a supervisory authority. the lead authority for dull is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), aki.ee. EU/EEA residents may also bring complaints to their local supervisory authority. UK residents may contact the Information Commissioner's Office (ICO) at ico.org.uk.

automated decision-making: we do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.

source of data: all personal data we hold comes either directly from you (e.g. an email you submitted) or from your device and the third-party services described above (Apple, RevenueCat). we do not buy data, append data from data brokers, or enrich your profile from third-party sources.

United States — state privacy laws

if you live in California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Tennessee, Delaware, New Hampshire, New Jersey, Maryland, or Minnesota, you have some or all of the following rights under your state's privacy law: the right to know what personal information we have, the right to delete it, the right to correct it, the right to portability, the right to opt out of targeted advertising, the right to opt out of any "sale" or "sharing" of personal information, the right to opt out of profiling for decisions with legal or similarly significant effects, and the right to limit the use of sensitive personal information. some state laws are narrower than others — Texas's TDPSA, for example, focuses on the sale of sensitive personal data — so the specific rights that apply depend on your state. we honor verified requests within the time required by your state's law (typically 45 days). we will not discriminate against you for exercising these rights.

California (CCPA/CPRA — additional specifics)

  • categories of personal information collected in the past 12 months under Cal. Civ. Code §1798.140(v): identifiers (pseudonymous device IDs, IP address transiently for geolocation, email if submitted, the stable Apple identifier used for an optional friends account, and an optional Apple-provided name), internet/electronic activity (app-event analytics), commercial information (subscription transactions via Apple/RevenueCat), relationship and user-content information used for friends (invites, friend relationships, and shared streak or goal-day values), and inferences (none drawn for profiling).
  • sources: directly from you, your device, Apple, RevenueCat, and other friends users when they invite or connect with you.
  • purposes: to provide and support dull, operate friends, manage subscriptions, measure ad effectiveness, and improve the app.
  • retention: for the periods listed in each third-party section above, or until you ask us to delete it, whichever is shorter.
  • sensitive personal information under §1798.121: we do not collect SPI. you do not need to exercise the right to limit use of SPI.
  • do not sell or share my personal information: we do not sell your personal information. the Meta and RevenueCat attribution described above may qualify as "sharing" or targeted-advertising processing under some US state laws because device and purchase signals are matched with ad-network data, even though Dull does not use browsing content for retargeting or build lookalike audiences from in-app behavior. the iOS ATT choice controls whether Dull enables this Meta measurement and shares its matching identifiers. privacy-preserving Apple Ads and SKAdNetwork attribution may still operate without ATT authorization. to object to other ad-measurement processing, email us at [email protected]. we honor Global Privacy Control (GPC) signals on getdull.app as a valid opt-out signal, and we show visible confirmation on the page when a GPC signal is received, in line with CCPA Regs §7025(c)(6) effective January 1, 2026.
  • shine the light (Cal. Civ. Code §1798.83): we do not disclose personal information to third parties for their own direct marketing purposes.
  • non-discrimination: we do not deny service, charge different prices, or provide a different level of quality to consumers who exercise CCPA rights.

Korea (PIPA)

see the Korean PIPA disclosures section below for the items required by PIPA Art. 30 (CPO, processors, breach procedure, automatic data-collection tools, overseas transfer details).

Japan (APPI)

see the Japan APPI disclosures section below for cross-border transfer and personal-related-information specifics.

Singapore (PDPA)

you have the right to withdraw consent (we will action withdrawal within 10 business days), the right to access your personal data, the right to request correction of your personal data, and the right to lodge a complaint with the Personal Data Protection Commission (PDPC) at pdpc.gov.sg. our Data Protection Officer for PDPA purposes is Kaspar Noor, reachable at [email protected].

Australia (Privacy Act / APPs)

you have rights under APP 12 (access) and APP 13 (correction) of the Australian Privacy Principles. you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. for cross-border disclosures, see the international data transfers section above.

Korean PIPA disclosures (한국 개인정보 보호법)

in addition to the general disclosures above, the following items apply to users in the Republic of Korea under the Personal Information Protection Act (PIPA):

Japan APPI disclosures (日本 個人情報保護法)

in addition to the general disclosures above, the following items apply to users in Japan under the Act on the Protection of Personal Information (APPI):

the longer version

dull functions as a specialized browser. when you tap a platform, it loads that platform's mobile website inside a WKWebView and applies filters — injecting CSS/JavaScript to hide short-form content feeds and algorithmic content. grayscale mode, friction gates (challenges shown before opening an app), daily time limits, scheduled quiet hours, commitment delay (a 24-hour cooldown before loosening filters), and PIN lock (which protects settings behind a hashed PIN stored in the iOS Keychain) are all applied locally. all of this happens entirely on your device.

we have no servers that process the content of your browsing. the optional friends backend stores only the account, relationship, invite, shared progress, and timestamp data listed above. it does not receive the pages, posts, videos, searches, messages, or social media accounts you view in dull. third-party services receive only the data described in their respective sections.

deleting the app removes local app data according to iOS behavior, but it does not by itself delete an optional friends account or cancel a subscription. use delete account on the signed-in friends screen or in settings > account before uninstalling if you want the friends account removed. manage or cancel a subscription separately in your Apple account's subscription settings.

waitlists and email

dull is iOS-only today. for platforms we haven't shipped yet (currently Android), you can submit your email at getdull.app/android to be notified when that version is available.

we will always send you the thing you specifically signed up for (e.g. the Android launch notification). other email about Dull — product updates, new features, usage tips, and any future promotions or discounts — is sent only if you separately opt in via the optional marketing checkbox on the form. we keep messaging volume low and on-topic; we never sell your address or share it with other companies for their marketing.

every email we send includes a one-click unsubscribe link, and you can also email [email protected] to be removed from all lists. emails are stored by Resend (described under third-party services above). the legal basis is consent — submitting the form is the consent for the specific notification, and ticking the marketing checkbox is separate consent for marketing.

children and minors

dull is intended for users aged 13 and older. depending on where you live, the minimum age to use dull on your own (without parental involvement) may be higher than 13:

dull is rated 13+ on the App Store. we do not currently ask your age inside the app. the App Store age rating and Family Sharing handle the floor, and adding an in-app age step would add friction to onboarding without materially changing what data leaves your device. for users in the EU/EEA, the UK, and South Korea, we suppress the Meta SDK and the ATT prompt entirely, regardless of age, because the consent standard for those regions is stricter than what an iOS-system prompt can meet. in other regions, the standard ATT prompt may be shown during first-time setup when the system status is undetermined, and the Meta SDK runs only after authorization; Apple's App Store age rating handles the under-13 floor. if you are pursuing children's-privacy compliance more deeply (for example as a parent or guardian asking about your child's data), email [email protected] and we will work with you directly.

marketing materials describe dull as useful for teens who are self-aware about social media use. this does not change the legal baseline above. if you are a parent and want your child to use dull, you are welcome — please review these terms and our privacy policy yourself, and supervise the install.

if you are a parent or guardian and believe we have inadvertently collected personal information from a child below their jurisdiction's threshold, email us at [email protected] and we will delete it.

data we do not collect

for clarity, dull does not collect any of the following:

IP addresses are processed transiently by Mixpanel to derive approximate city and country, and by Cloudflare on the waitlist endpoint for abuse protection. the raw IP is not retained by Dull; Mixpanel may retain the derived coarse location with the device-keyed analytics event as described above. device identifiers (vendor ID, IDFV, IDFA) are pseudonymous as described above. the international data transfers section above lists every recipient of personal data outside the EU/EEA.

changes to this policy

we may update this policy. when we do, we will revise the effective date and version number at the top of this page, and add an entry to the changelog below. if we make material changes, we'll notify you in the app or on our website. your continued use of dull after any changes constitutes acceptance of the updated policy.

changelog

questions? [email protected]