Privacy Policy

Effective date: 19 May 2026  ·  Last updated: 5 July 2026 (rev. 4)
This policy applies to all users of dix.su, including residents of the European Union and European Economic Area. We comply with the General Data Protection Regulation (GDPR) where applicable.

1. Data Controller

The data controller for personal data processed through dix.su is:

FieldValue
NameRoman Alexandrovich Sakhno (sole proprietor / ИП)
Tax ID (ИНН)614104707933
Registration number (ОГРНИП)323237500434312
Contact e-mailprivacy@dix.su
Websitedix.su

2. Data We Collect

DataRequired?Source
Email addressRequiredLogin form; OAuth providers
One-time login code (OTP)Required for email loginSent to your email
Display nameOptionalAccount settings; OAuth providers
Biography (bio)OptionalAccount settings
Profile photo (avatar)OptionalUpload in account settings; OAuth providers
Social profile linksOptionalAccount settings; verified OAuth accounts
Phone numberOptionalAccount settings
OAuth account identifierWhen using social loginGoogle, GitHub, VK, Facebook, Yandex, Telegram
Ethereum wallet addressOptionalMetaMask connection in account settings
IP address, User-AgentAutomaticServer technical logs
Tunnel technical data (IP, connection time)Automatic when using tunnelsProxy tunnel service

3. Purposes of Processing

4. Legal Basis for Processing

We process your personal data on the following legal grounds:

5. Retention Periods

DataRetention period
Account data (email, profile)Until account deletion or 3 years of inactivity
Short links and click statisticsUntil deleted by user or upon account deletion
IP addresses and tunnel logs30 days, then automatic deletion
OAuth account identifiersUntil account deletion or unlinking in settings
Ethereum wallet addressUntil account deletion or wallet unlinking
Deleted account data (recovery buffer)30 days from deletion request, then permanent destruction

Recovery buffer. When you delete your account, data is not destroyed immediately. It enters a 30-day recovery buffer during which it is inaccessible to other users and not actively processed. You may restore your account at dix.su/account/restore. After 30 days all data is permanently and irreversibly destroyed.

6. Cookies

We use strictly necessary (session) cookies only, required for authentication to work. We do not use analytics, advertising, or tracking cookies. No third-party tracking scripts are loaded.

Because we use only strictly necessary cookies, your consent is not required under GDPR for their use — however we display a notice as a courtesy.

7. Data Sharing and International Transfers

We do not sell or share personal data for commercial purposes. The following transfers occur in the normal operation of the service:

7.1. OAuth Providers. When you sign in via a third-party service, we receive the data that service provides under OAuth 2.0. You independently accept that provider's terms:

ProviderData receivedCountry / transfer type
Google (Google LLC)Email, name, avatarUSA — international transfer
GitHub (Microsoft)Email, username, avatarUSA — international transfer
Facebook (Meta)Email, name, avatarUSA — international transfer
VK (VK Online Technologies)Name, avatar, VK IDRussia
Yandex IDEmail, username, avatarRussia
TelegramName, avatar, Telegram IDUAE — international transfer

By choosing to sign in via a foreign provider you consent to the associated international transfer (GDPR Art. 49(1)(a); 152-FZ Art. 12).

7.2. Public Profile. Profile data (name, bio, avatar, links) that you enter is publicly accessible at dix.su/p/your-slug.

7.3. Payments via Lemon Squeezy. For international card payments, checkout is handled by Lemon Squeezy Inc. (Merchant of Record, Ireland). Lemon Squeezy processes your payment data under their own Privacy Policy. We receive only the user ID and tariff ID from the transaction webhook — no card data.

7.4. Law Enforcement. Data may be disclosed to authorised government bodies upon lawful request.

Data Location. All user data is stored on servers located in the Russian Federation. For EU/EEA residents this constitutes a transfer to a third country. The transfer is made on the basis of your consent (GDPR Art. 49(1)(a)) given at registration.

8. Your Rights

Under GDPR (Arts. 15–22) and 152-FZ (Arts. 14–17) you have the right to:

To exercise your rights, contact privacy@dix.su. We respond within 30 days.

9. Security

10. Changes to This Policy

We may update this policy from time to time. The current version is always available at dix.su/en/privacy. For material changes we will notify registered users by email. Continued use of the service after changes are posted constitutes acceptance of the updated policy.

11. Contact

For all privacy-related questions and requests: privacy@dix.su