Effective 1 August 2026
Christoph Dethloff, sole trader (Einzelunternehmer)
Kolingasse 1, 1090 Vienna, Austria
[email protected]
+43 720 975237
This policy covers the dial it in mobile app, getdialitin.com, the beta mailing list, support, and the associated cloud service. It explains which personal data is processed, why, for how long, and the choices and rights available to you.
The app processes your email address and authentication records; coffee, bag, recipe, setup, grinder and machine details; shot feedback and notes; ratings; AI barista conversations and learned notes; retained shelf photos; plan and usage records; and support feedback you send. Most app content is first stored locally on your device and is mirrored to your account in Convex so it can be restored or used across devices.
This processing is necessary to provide the account, sync, recipe, correction, memory and support features you request (Article 6(1)(b) GDPR). Optional fields and photos are not required, but the corresponding feature cannot use information you do not provide. An email address is required for the beta account because cloud sync, usage limits and deletion are account-based.
A coffee-bag photo selected for extraction is temporarily uploaded to Convex and sent with the extraction request through Cortecs and its configured inference provider. It is deleted after the scan. A setup photo is compressed and sent for recognition without being retained as an app photo. If you choose to keep a bag image on the shelf, a smaller rendition remains in Convex storage until you remove the coffee or delete the account. The original local image remains on your device until you remove it or clear the app's storage.
Recipe, correction, taste-profile and AI barista requests send the relevant coffee, setup, recipe, shot and conversation context through Cortecs. Cortecs processes prompts and replies to route the request and does not use them to train its own models. Its selected inference providers process the request under the configured routing terms. AI output can be wrong and does not make decisions with legal or similarly significant effects about you.
Bag extraction or equipment recognition may send a short text search query, such as a roaster and coffee name or a recognized brewer model, to Linkup when the AI requests public web information. Photos and your account email are not sent to Linkup. The resulting public source links can be shown with the extracted facts.
These operations provide the features you request (Article 6(1)(b) GDPR). Security and reliability metadata is processed as described below. Do not put information about another identifiable person into coffee notes or AI barista messages.
If you accept optional analytics in the app, PostHog receives a pseudonymous app or account identifier, app version, platform, screen and feature events, AI operation metadata, latency, usage counters, and crash or error diagnostics. Event properties are filtered to exclude email addresses, coffee names, roasters, origins, equipment names and free-text notes. Native session replay is disabled. You can withdraw consent at any time in Settings; withdrawal does not affect processing that took place before it.
On getdialitin.com, Simple Analytics receives aggregate page-view and event data such as the page path, referrer, time zone, browser, screen dimensions and the interactions described on this page only after you accept optional analytics in the cookie banner. It does not use cookies, fingerprinting, IP addresses or user, browser or device identifiers. The website stores only your analytics choice in local storage so the banner does not reappear; that preference is not sent to Simple Analytics. If you decline, the analytics script is not loaded. You can reopen “Privacy choices” in the footer to change your choice. Do Not Track visitors are ignored by default. The website event metadata contains only non-personal values such as a selected platform or page section. The legal basis is your consent (Article 6(1)(a) GDPR and section 165(3) Austrian Telecommunications Act 2021).
Convex records bounded operational data such as authentication and upload challenges, pseudonymous abuse counters, AI provider/model status, latency, warnings, error categories, token usage and estimated cost. This is used to secure the service, enforce beta limits, diagnose failures and keep the service reliable. The legal basis is our legitimate interest in operating a secure and dependable beta (Article 6(1)(f) GDPR). We do not use this data for advertising or to evaluate you outside the service.
When a dial-in finishes, Convex records one summary of it: how many shots it took, whether it was completed or abandoned, the brew method, grinder and machine names, roast level and process, the AI model used, and how far the recipe’s numbers were from the ones you ended up using. This tells us whether our recommendations are actually good, which is the core of the product, and it is the only way we can tell that a recipe was wrong when you corrected it instead of giving up. It is recorded for every account and is not part of optional analytics, because a quality measurement that only covers people who opted in would be misleading. The legal basis is our legitimate interest in improving the accuracy of the service (Article 6(1)(f) GDPR). These records are removed when you delete your account, and we do not use them for advertising or to evaluate you outside the service.
If you join the beta list, your email address, optional name, platform preference, consent text and consent time are sent to Brevo. You join only after confirming the email. You may unsubscribe through any marketing email. The legal basis is consent (Article 6(1)(a) GDPR). Transactional sign-in codes are also delivered through Brevo as necessary to provide your account (Article 6(1)(b) GDPR).
To prevent signup and sign-in abuse, the service keeps keyed, non-reversible hashes derived from the submitted email or network address with short-lived counters. The raw values are not stored in those counters. This processing is based on our legitimate security interest (Article 6(1)(f) GDPR).
We use the following categories of recipient only for the stated purposes:
We select EU processing where it is available. Where a provider or subprocessor processes data outside the European Economic Area, the transfer must be covered by an applicable European Commission adequacy decision or appropriate safeguards such as the Commission's standard contractual clauses. You can ask us for information about the safeguard relevant to your data.
Providers may keep encrypted backups for a limited recovery period. Data required to establish, exercise or defend legal claims, or to meet a legal obligation, may be retained for the applicable period. Statistics that can no longer identify or be linked to a person may be kept.
You can initiate account deletion in the app under Settings. This removes the account and its setups, coffees, bags, recipes, shots, chat, memories, feedback, usage records and retained shelf images. See account deletion if you cannot sign in.
Under the GDPR, you may request access, rectification, deletion, restriction, objection and, where applicable, a portable copy of your data. Where processing relies on consent, you may withdraw it at any time. Email [email protected]. We may need to verify that the request concerns your account.
You may complain to the Austrian Data Protection Authority atdsb.gv.at, or to the competent authority where you live or work.
We will update this page when the service or its data handling changes. Material changes will be brought to users' attention in the app or by email where appropriate.