DCT
← Back to DCT

Privacy Policy

Last updated: July 12, 2026

DCT is built around one idea: your photos belong to you, in storage you control. We don't keep a copy of your photos on our servers. Every photo is encrypted in your browser before it ever leaves your device, then sent straight to your own cloud storage account — starting with Dropbox, with more providers planned. This page explains exactly what information we do handle, why, and what we never do with it.

1 The short version

  • Your photos and files are stored in your own cloud storage account (currently Dropbox), not on our servers.
  • Files are encrypted in your browser (AES-256) before upload, so we never see their contents.
  • We store a small amount of account and bookkeeping information (below) so the app can function — sign-in, approval, and knowing which folder a file went to.
  • We do not sell, rent, or share your information with advertisers or data brokers, and we don't use it for anything beyond running DCT.
  • You can ask us to delete your account and its associated records at any time.

2 Information we collect

To operate accounts, approvals, and sign-in, our database stores the following. Nothing here includes the actual content of your photos.

DataWhy we store it
Email addressAccount identification, sign-in, and one-time login codes
Password (hashed, never in plain text)Authenticating your sign-in
Encryption saltUsed only in your browser to derive your personal encryption key — we cannot use it to read your files
Account status & roleAdmin approval workflow (pending / approved / denied) and permissions
Temporary one-time codes & login attempt countersVerifying sign-in and preventing brute-force attempts; codes expire automatically
Cloud storage connection (e.g. Dropbox access/refresh tokens)Lets the app upload/download files to your connected cloud account on your behalf
File metadata (file name, folder path, encryption IV, file type, size, upload date)Letting you browse and retrieve your own encrypted files

We never store your raw password, and we never store the decrypted contents of your photos anywhere on our servers.

3 Where your photos actually live

When you upload a photo, it is encrypted on your device using AES-256 before it ever reaches our server. The encrypted file is then forwarded directly to the cloud storage account you connected — today that's Dropbox, using an authorization you grant directly to Dropbox via OAuth. We keep only the access token needed to talk to that account and a pointer (file name and path) so the app can list and fetch your files later.

We are adding support for additional cloud providers over time. When a new provider is added, the same principle applies: your files are stored in an account you own and control, not on our infrastructure, and this policy will be updated to name each supported provider.

4 How we use your information

  • To create and secure your account, and to route new registrations to an administrator for approval.
  • To send one-time sign-in codes and account-status emails (approved/denied) to your email address.
  • To connect to your cloud storage provider and upload, list, or download your encrypted files at your request.
  • To detect and block suspicious sign-in activity (failed login lockouts, expiring one-time codes).

We do not use your information for advertising, profiling, analytics resale, or any purpose beyond operating DCT for you.

5 Who we share information with

We do not sell or rent your personal information. Limited data is shared only where necessary to run the service:

  • Your connected cloud provider (e.g. Dropbox): receives your encrypted files, via the authorization you grant it directly.
  • Email delivery service: used only to send one-time codes and account-status notifications.
  • Legal requirements: we may disclose account information if required by law or to protect the security of the service.

We do not share data with advertisers, data brokers, or analytics companies.

6 Cookies & sessions

DCT uses a single session cookie to keep you signed in, and a hidden security token (CSRF) to protect form submissions. We do not use tracking or advertising cookies.

7 Data retention & deletion

We keep your account and file-metadata records for as long as your account is active. One-time login codes expire within minutes and are cleared after use. If you'd like your account and associated records deleted, contact us using the details below — note that deleting your DCT account does not delete files already stored in your own connected cloud account, since those remain yours to manage directly with that provider.

8 Security

  • Client-side AES-256 encryption before any file leaves your device.
  • Passwords are hashed, never stored or transmitted in plain text.
  • Every sign-in requires a one-time email code in addition to your password.
  • New accounts require manual admin approval before access is granted.
  • Repeated failed sign-in attempts temporarily lock the account.

9 Children's privacy

DCT is not directed at children under 13, and we do not knowingly collect information from them.

10 Changes to this policy

If we make material changes — such as adding a new cloud storage provider or changing how data is handled — we will update the "Last updated" date above and, where appropriate, notify you by email.

11 Contact us

Questions about this policy or your data? Reach out to the administrator at the contact address provided when your account was approved.

DCT · private by design