Privacy Policy

Last updated: April 12, 2026

1. Introduction

Dedicto ("we," "our," or "us") is an AI-powered text analysis service that helps users decode psychological subtexts in written communication. Dedicto is operated by an individual developer based in Turkey. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our service at dedicto.co.

By using Dedicto, you agree to the collection and use of information as described in this policy. If you do not agree, please stop using the service.

2. Data Controller

For the purpose of the GDPR and KVKK, the data controller is the operator of Dedicto, an individual based in Turkey. You can reach us at info@dedicto.co.

3. Data We Collect

We collect and process the following categories of personal data:

  • Account information: Your email address (required for authentication) and display name (optional).
  • Text input: The text you submit for analysis. This is sent to our AI provider to generate insights.
  • Analysis results: The AI-generated output produced from your text, stored in your analysis history.
  • Usage data: Analysis counts used to enforce plan limits (daily and monthly).
  • Payment data: Billing information is handled exclusively by Paddle (our merchant of record). We do not store credit card numbers or full payment details.

We do not collect device identifiers, IP addresses for tracking purposes, or behavioral analytics beyond what is strictly necessary to operate the service.

4. Legal Basis for Processing (GDPR)

If you are located in the EEA or UK, we rely on the following legal bases:

  • Contract performance: Processing your text and managing your account to deliver the service you signed up for.
  • Legitimate interests: Enforcing usage limits and preventing abuse of the service.
  • Consent: Where you have actively agreed to our Terms of Service and this Privacy Policy at signup.

5. How We Use Your Data

Your data is used solely to provide and improve the Dedicto service:

  • To authenticate your account and manage your session.
  • To process your text through AI and return analysis results.
  • To store your analysis history so you can review it later.
  • To enforce daily and monthly usage limits based on your subscription plan.
  • To process subscription payments via Paddle.

We do not use analytics or tracking scripts. We do not serve advertisements. We do not sell, rent, or share your personal data with third parties for marketing purposes.

6. Third-Party AI Processing

To generate analyses, your submitted text is sent to Anthropic (Claude AI) and/or Replicate via their respective APIs. This means your text input is processed on their infrastructure. Their own data policies apply. We recommend reviewing Anthropic's Privacy Policy and Replicate's Privacy Policy.

Important: Do not submit text containing sensitive personal data (such as medical, financial, or government-issued identification information) that you do not wish to be processed by third-party AI systems.

7. Payment Processing

Paid subscriptions are handled through Paddle, our merchant of record. Paddle acts as a reseller of our service and is responsible for collecting and remitting applicable taxes. We do not store your credit card numbers or full payment details on our servers. Paddle processes payment information under their own privacy policy and applicable PCI-DSS standards.

8. Cookies and Local Storage

Dedicto uses only essential cookies required for authentication and session management, provided by Supabase. We use browser local storage solely to remember your preferences within the app (such as dismissed modal states). We do not use any marketing, advertising, or third-party analytics cookies.

9. Data Retention

Your analyses are stored until you choose to delete them or delete your account. You can delete individual analyses or all of your data at any time through the Settings page. When you delete your data or account, it is permanently and irreversibly removed from our active database. Residual data may remain in encrypted backups for up to 30 days before being overwritten.

10. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Correct inaccurate personal data (your display name can be updated in Settings).
  • Erasure: Delete your account and all associated data through Settings, or by contacting us.
  • Portability: Export your analysis data in JSON format from Settings.
  • Objection: Object to processing of your data in certain circumstances.
  • Restriction: Request restriction of processing while a complaint is being investigated.

You can exercise most rights directly through the Settings page. For additional requests, contact us at info@dedicto.co. We will respond within 30 days.

If you are located in the EEA or UK and believe we have not handled your data correctly, you have the right to lodge a complaint with your local data protection authority.

11. KVKK (Turkish Users)

If you are located in Turkey, your personal data is protected under the Turkish Personal Data Protection Law (KVKK, Law No. 6698). You have equivalent rights under KVKK, including the right to learn whether your data is being processed, to request information about processing purposes, to request correction or deletion, and to object to outcomes produced by automated processing. To exercise your KVKK rights, please contact us at info@dedicto.co.

12. Data Security

We implement appropriate technical and organizational measures to protect your personal data. All data is transmitted over encrypted connections (HTTPS/TLS). Authentication is managed through Supabase, which uses industry-standard bcrypt password hashing and JWT session tokens. Access to our database is restricted to authenticated service accounts only. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security against all threats.

13. Children's Privacy

Dedicto is not intended for use by individuals under the age of 16 (or 13 outside the EU). We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at info@dedicto.co and we will delete it promptly.

14. International Data Transfers

Your data may be processed and stored on servers located in the United States and other countries via our sub-processors (Supabase, Anthropic, Replicate, Paddle). These transfers are made pursuant to appropriate safeguards such as standard contractual clauses or adequacy decisions where applicable.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page. For significant changes, we will attempt to notify you by email. Your continued use of the service after changes constitutes acceptance of the revised policy.

16. Contact

For any questions about this Privacy Policy, your data rights, or to submit a data request, please contact us at:

info@dedicto.co