1. Comprehensive Introduction and Scope
This Privacy Policy represents our formal, transparent commitment to safeguarding the personal data, textual communications, and browsing telemetry of every individual who accesses or interacts with Dego FutureMe (hereinafter designated as "the Platform," "our Service," "we," "our," or "us"). This policy governs all interactions occurring across domain dego.my, including our web client, mobile interfaces, application programming interfaces, automated email dispatchers, and public community repositories.
Because the core functional architecture of our service involves holding data across multi-year temporal intervals—frequently spanning 6 months, 1 year, 3 years, 5 years, or an entire decade—our data protection architecture has been deliberately engineered to provide enduring cryptographic resilience, strict access compartmentalization, and adherence to international statutory standards.
2. Detailed Taxonomies of Information We Collect
To operate our temporal delivery service with absolute reliability, we collect and process several distinct categories of user information:
A. Information Explicitly Provided by the User
- Letter Content & Subject Lines: The full textual manuscript, thoughts, reflections, predictions, and header titles you write into our composer desk. If designated as Private, this manuscript is stored with restricted access and is never displayed publicly.
- Recipient Electronic Mail Addresses: The specific destination email address designated by the author for dispatch upon arrival at the scheduled future delivery date and time.
- Account Identity Credentials: When you register an account, we record your full legal or chosen name, email address, and an irreversibly hashed password utilizing the industry-standard
BCRYPTkey derivation function with an adaptive work factor. We never store plaintext passwords under any circumstances. - Temporal Delivery Parameters: Metadata pertaining to your scheduled delivery, including selected interval duration presets (6m, 1y, 3y, 5y, 10y), custom target calendar timestamps, and privacy audience flags.
- Customer Support Correspondence: Transcripts, inquiries, or feedback submitted through our contact desk or via direct electronic mail communications.
B. Information Automatically Recorded via Technical Telemetry
- Network and Connection Diagnostics: Internet Protocol (IP) addresses, Internet Service Provider (ISP) identifiers, network connection speeds, and approximate regional geographic approximations. IP addresses are processed strictly to enforce rate limits, mitigate denial-of-service (DDoS) events, and deter malicious script attacks.
- Browser & Device Characteristics: User-agent strings, browser vendor and version numbers, device classifications (desktop, mobile, tablet), display resolutions, and operating system types.
- Operational Dispatch Logs: Machine logs detailing the exact timestamp, response codes, and server connection receipts generated when our automated background cron dispatcher attempts transmission of an email to destination mail servers.
3. Google AdSense, DoubleClick DART Cookies & Advertising Disclosures
To sustain free server hosting, database backups, cryptographic key rotations, and global email infrastructure without charging mandatory fees to our users, Dego FutureMe partners with accredited third-party advertising vendors, predominantly Google AdSense. Full compliance with Google’s Advertising Policies requires the following explicit operational disclosures:
- Third-Party Vendor Participation: Google and its affiliated advertising network partners utilize cookies to serve advertisements on dego.my based upon a user's prior visits to this website or other destinations across the World Wide Web.
- DoubleClick DART Cookie Usage: Google's use of advertising cookies (specifically the DoubleClick DART cookie) enables it and its certified partner network to serve tailored commercial displays to our users based upon their browsing patterns across independent digital properties.
- User Choice and Opt-Out Rights: Users possess the unconditional right to decline personalized advertising. You may opt out of personalized AdSense advertising by visiting the official Google Ads Settings Portal. Alternatively, you may opt out of third-party vendor tracking cookies for interest-based advertising by visiting the Digital Advertising Alliance at www.aboutads.info or the Network Advertising Initiative at www.networkadvertising.org/choices/.
- Isolation of Private Letter Data: We explicitly warrant that our advertising partners have zero access to the private bodies or text of your letters. Advertising scripts are strictly confined to browser interface containers and are technically blocked from parsing your private reflections.
4. Legal Bases for Processing Under the GDPR (EEA & UK Users)
Under the European Union General Data Protection Regulation (Regulation (EU) 2016/679) and the equivalent UK GDPR, we must establish a recognized lawful basis for every processing activity concerning personal data. We process your data under the following legal frameworks:
- Performance of a Contract (Article 6(1)(b)): When you schedule a letter or create an account, processing your recipient email and storing your manuscript is strictly necessary to fulfill our contractual obligation of delivering that communication on the date you specified.
- Explicit User Consent (Article 6(1)(a)): For non-essential cookies, newsletter communications, and the publication of anonymous community letters on our public wall, we rely upon your explicit, affirmative, uncoerced consent.
- Legitimate Interests (Article 6(1)(f)): We process device diagnostics and server logs to maintain system security, detect fraudulent activities, ensure server uptime, and optimize technical delivery speeds.
- Compliance with Legal Obligations (Article 6(1)(c)): In limited scenarios, processing may be required to comply with statutory fiscal, taxation, or law enforcement mandates issued by competent jurisdictions.
5. California Consumer Privacy Act (CCPA & CPRA) Disclosures
This section provides mandatory supplementary disclosures for residents of the State of California pursuant to the California Consumer Privacy Act of 2018 (CCPA) and the California Privacy Rights Act of 2020 (CPRA):
- Categories of Personal Information Collected: Identifiers (name, email, IP address), commercial history (account creation timestamp), Internet activity (browsing telemetry on our site), and sensory/textual reflections (manuscripts written into our editor).
- Prohibition on Sale or Sharing: We do NOT sell your personal information for monetary compensation, nor do we share your personal information with third parties for cross-context behavioral advertising outside of standard AdSense configurations that you may disable.
- Right to Know & Right to Delete: California residents have the statutory right to request disclosure of the specific pieces of personal information collected about them over the prior 12 months, as well as the right to demand the permanent deletion of such data.
- Right to Non-Discrimination: We strictly uphold your right not to receive discriminatory treatment, altered service tiers, or diminished functionality for exercising your statutory privacy entitlements.
6. Security Infrastructure, Encryption & Data Storage
Because letters written on our platform may traverse years before arriving at their destination, our engineering team adheres to stringent data protection standards:
- Cryptographic In-Transit Security: All client-to-server interactions are protected via modern Transport Layer Security (TLS 1.2 and TLS 1.3) protocols utilizing forward secrecy cipher suites, preventing interception or man-in-the-middle tampering.
- Database Isolation and Security at Rest: Database tables holding user manuscripts are safeguarded behind parameterized queries and prepared statements (PDO), rendering SQL injection vulnerabilities structurally impossible.
- Role-Based Administrative Safeguards: Access to backend database consoles is restricted to verified super-administrators utilizing multi-factor authentication, with all administrative access audited and logged.
- Incident Response & Breach Notification: In the improbable event of a security compromise impacting personal data, we commit to notifying affected users and appropriate supervisory authorities within 72 hours of verification, in strict compliance with GDPR Article 33.
7. International Cross-Border Data Transfers
Our server infrastructure and redundant cloud backup repositories may be situated in multiple jurisdictions, including the United States and the European Economic Area. Whenever personal data is transferred across international borders from the European Economic Area (EEA) or the United Kingdom to countries not deemed to offer an adequate level of data protection, we implement European Commission-approved Standard Contractual Clauses (SCCs) and supplementary technological safeguards to ensure equivalent data protection.
8. Data Retention and Deletion Lifecycle
Our retention lifecycle is tailored to the temporal nature of our service. Scheduled time capsules are retained in our database until their execution timestamp matures. Following delivery, letters authored by registered users remain accessible in their personal vault indefinitely unless the author deletes them. For guest letters, once delivery verification is completed, residual server logs are rotated and purged periodically. You may request immediate, irreversible deletion of your account and any pending letters at any time by contacting our support desk.
9. Children's Online Privacy Protection (COPPA Compliance)
Our services are strictly directed toward individuals aged 13 and older (or aged 16 and older in specific European jurisdictions). We do not knowingly solicit, collect, or process personal data from children under these age thresholds. If a parent, legal custodian, or educator discovers that a minor under 13 has submitted personal information without verified parental consent, please contact us immediately. Upon verification, we will promptly excise such records from our database repositories.
10. Exercise of User Rights & Regulatory Inquiries
Whether you reside in the European Union, the United Kingdom, California, or elsewhere globally, you may exercise your rights of data access, correction, portability, or erasure by submitting a formal request to our Data Protection Officer:
Data Protection & Regulatory Compliance Desk
Entity: Dego FutureMe
Official Host: dego.my
Direct Contact Email: admin@dego.my
Digital Support Portal: https://dego.my/contact-us
Statutory Response Time: Within 30 calendar days of verified identity confirmation.