Privacy Policy
Version 2.0, DAAAM by Munashe Chitima
Last updated: 24 June 2026
1. Who we are
DAAAM is a sole trader business operated by Munashe Chitima, Melbourne, Victoria, Australia. "We", "us", "our" refers to this business. Contact: privacy@daaam.media
2. What DAAAM is: local-first by design
DAAAM ingests your media, extracts compressed proxy frames on your device, and uses AI to make your library searchable. Your original files, your database, your proxy frames, transcripts, GPS data, and metadata all remain on your device. We do not receive, host, or retain any of this unless you explicitly enable Cloud Vision.
3. What we collect and why
3.1 When you purchase ($69 license)
- Email address: to deliver your licence key.
- Name: to personalise the licence email (collected by Stripe at checkout if billing address collection is enabled).
- Payment data: processed by Stripe. We receive only your email, name, and last-4 card digits. We do not store full card numbers.
We store your email, name, and account ID in our billing database (Modal / SQLite) to service your account.
3.2 When you use Cloud Vision
- Proxy frames (JPEG stills) are sent from the App to our control plane for AI captioning. Frames are processed in real time by Google Gemini and not retained after the API call completes.
- Usage data (number of frames processed, session duration, and hours consumed) is stored server-side for billing and balance tracking.
- Your original files are never sent. Only the compressed proxy JPEGs.
3.3 Analytics (PostHog)
The App and website use PostHog for product analytics. We collect: event names (e.g. "app opened", "search performed"), anonymous session IDs, and coarse device information. We do not collect your file names, search queries, or library content. You can opt out of analytics in Settings → Privacy.
3.4 Support communications
If you contact us by email or use the in-app "Report a problem" feature, we store your email address and the content of your communication to resolve your issue.
4. What we do not collect
- Your original media files
- Your local database or library contents
- Your search queries or tags
- Your GPS coordinates or location data
- Your transcripts or captions
- Facial recognition or biometric data (we perform none)
- Device identifiers beyond what's necessary to enforce seat limits
5. How we use your data
- License delivery and activation: sending your key and verifying activation.
- Billing and balance management: tracking cloud hours purchased and consumed.
- Transactional emails: licence delivery, top-up confirmations, low-balance warnings. Sent via Resend (resend.com).
- Product improvement: aggregated, anonymous analytics via PostHog.
- Support: responding to your requests.
We do not sell your data. We do not use your data for advertising. We do not share your data with third parties except as described in Section 6.
6. Third-party services
- Stripe: payment processing. Stripe's privacy policy governs payment data.
- Resend: transactional email delivery. Your email address is shared with Resend to send emails you expect (licence key, billing confirmations).
- PostHog: anonymous product analytics.
- Google Gemini: AI captioning for Cloud Vision. Proxy frames you submit are processed under Google's API terms. Frames are not retained by Google for model training under our API agreement.
- Modal: our control plane runs on Modal (modal.com). Your account ID and billing data are stored in Modal-hosted infrastructure.
7. No biometric data
DAAAM does not perform facial recognition. It does not generate face embeddings, biometric templates, voiceprints, or any biometric identifier. Cloud Vision produces descriptive text captions; it does not identify who any person is.
8. Your data as controller
Because the App is local-first, you are the data controller for the personal data of people who appear in your footage. We have no relationship with those people and no ability to respond to their requests. If someone in your footage seeks to exercise privacy rights, they must contact you.
9. Data retention
- License and billing records: retained for as long as your account is active and for 7 years thereafter for tax/legal compliance.
- Cloud Vision session data (usage metrics): retained for billing accuracy and balance history.
- Proxy frames: not retained after processing. Gone when the API call ends.
- Support communications: retained for up to 3 years or until you request deletion.
- Analytics data (PostHog): retained per PostHog's data retention settings (90 days by default).
10. Security
We use Ed25519 digital signatures for license authentication, HTTPS for all API communication, and server-side enforcement for billing (client-side balance figures are display only). Our control plane runs on Modal with secrets managed via Modal's encrypted secret store. We do not store full payment card numbers.
11. Your rights
Depending on your location, you may have rights to access, correct, delete, or port personal data we hold about you. To exercise these rights, email privacy@daaam.media. We will respond within 30 days. Under the Australian Privacy Act and the GDPR/UK GDPR, you also have the right to complain to your local data protection authority.
12. Cookies
Our website (daaam.media) uses PostHog for analytics, which may set a first-party cookie to identify sessions. We use no third-party advertising cookies. You can clear cookies at any time via your browser settings.
13. Changes to this policy
We may update this policy. Material changes will be notified by email or on daaam.media before they take effect. The current version is always available at daaam.media/legal/PRIVACY_POLICY.
14. Contact
Privacy enquiries: privacy@daaam.media
General support: support@daaam.media
Website: daaam.media
Postal: Melbourne, Victoria, Australia