The data controller for personal data processed through dix.su is:
| Field | Value |
|---|---|
| Name | Roman Alexandrovich Sakhno (sole proprietor / ИП) |
| Tax ID (ИНН) | 614104707933 |
| Registration number (ОГРНИП) | 323237500434312 |
| Contact e-mail | privacy@dix.su |
| Website | dix.su |
| Data | Required? | Source |
|---|---|---|
| Email address | Required | Login form; OAuth providers |
| One-time login code (OTP) | Required for email login | Sent to your email |
| Display name | Optional | Account settings; OAuth providers |
| Biography (bio) | Optional | Account settings |
| Profile photo (avatar) | Optional | Upload in account settings; OAuth providers |
| Social profile links | Optional | Account settings; verified OAuth accounts |
| Phone number | Optional | Account settings |
| OAuth account identifier | When using social login | Google, GitHub, VK, Facebook, Yandex, Telegram |
| Ethereum wallet address | Optional | MetaMask connection in account settings |
| IP address, User-Agent | Automatic | Server technical logs |
| Tunnel technical data (IP, connection time) | Automatic when using tunnels | Proxy tunnel service |
We process your personal data on the following legal grounds:
| Data | Retention period |
|---|---|
| Account data (email, profile) | Until account deletion or 3 years of inactivity |
| Short links and click statistics | Until deleted by user or upon account deletion |
| IP addresses and tunnel logs | 30 days, then automatic deletion |
| OAuth account identifiers | Until account deletion or unlinking in settings |
| Ethereum wallet address | Until account deletion or wallet unlinking |
| Deleted account data (recovery buffer) | 30 days from deletion request, then permanent destruction |
Recovery buffer. When you delete your account, data is not destroyed immediately. It enters a 30-day recovery buffer during which it is inaccessible to other users and not actively processed. You may restore your account at dix.su/account/restore. After 30 days all data is permanently and irreversibly destroyed.
We use strictly necessary (session) cookies only, required for authentication to work. We do not use analytics, advertising, or tracking cookies. No third-party tracking scripts are loaded.
Because we use only strictly necessary cookies, your consent is not required under GDPR for their use — however we display a notice as a courtesy.
We do not sell or share personal data for commercial purposes. The following transfers occur in the normal operation of the service:
7.1. OAuth Providers. When you sign in via a third-party service, we receive the data that service provides under OAuth 2.0. You independently accept that provider's terms:
| Provider | Data received | Country / transfer type |
|---|---|---|
| Google (Google LLC) | Email, name, avatar | USA — international transfer |
| GitHub (Microsoft) | Email, username, avatar | USA — international transfer |
| Facebook (Meta) | Email, name, avatar | USA — international transfer |
| VK (VK Online Technologies) | Name, avatar, VK ID | Russia |
| Yandex ID | Email, username, avatar | Russia |
| Telegram | Name, avatar, Telegram ID | UAE — international transfer |
By choosing to sign in via a foreign provider you consent to the associated international transfer (GDPR Art. 49(1)(a); 152-FZ Art. 12).
7.2. Public Profile. Profile data (name, bio, avatar, links) that you enter is publicly accessible at dix.su/p/your-slug.
7.3. Payments via Lemon Squeezy. For international card payments, checkout is handled by Lemon Squeezy Inc. (Merchant of Record, Ireland). Lemon Squeezy processes your payment data under their own Privacy Policy. We receive only the user ID and tariff ID from the transaction webhook — no card data.
7.4. Law Enforcement. Data may be disclosed to authorised government bodies upon lawful request.
Data Location. All user data is stored on servers located in the Russian Federation. For EU/EEA residents this constitutes a transfer to a third country. The transfer is made on the basis of your consent (GDPR Art. 49(1)(a)) given at registration.
Under GDPR (Arts. 15–22) and 152-FZ (Arts. 14–17) you have the right to:
To exercise your rights, contact privacy@dix.su. We respond within 30 days.
{slug}.dix.su): TLS is terminated at the platform server — the operator can technically access decrypted traffic during request processing (as with any reverse proxy or CDN).e2e-<token>.dix.su, available in private mode): TLS is terminated on the user's own device with their own Let's Encrypt certificate — the operator cannot read tunnel traffic; the server performs a blind relay of encrypted bytes.We may update this policy from time to time. The current version is always available at dix.su/en/privacy. For material changes we will notify registered users by email. Continued use of the service after changes are posted constitutes acceptance of the updated policy.
For all privacy-related questions and requests: privacy@dix.su