Privacy Policy
Last updated 4 October 2026
This policy explains what personal data DHY Global LLC (12012 Saw Mill Ct, Silver Spring, MD 20902, USA — "we") collects when you use Ideasip, why, and the choices you have. We are the controller of this data: we decide why and how it is used. We never sell your personal data. We don't show ads, and we don't track you across other websites or apps.
What we collect
- If you listen as a guest: a random device id created by the app (kept in your browser or app, and in a cookie our server sets), when that device was first and last seen, the country your connection comes from, the free title it played, and your listening progress. It is not linked to your name or email.
- If you create an account: your email address or mobile number; your name, email and an account id from Google or Apple if you sign in with them; a recovery email if you add one; and your password, which we store only as a salted one-way hash — we never see or keep the password itself.
- What you do in Ideasip: your place in each brief, the free titles you've used, download settings, ratings, reviews, flags, feedback, topic requests and searches that found nothing (searches are kept without your account).
- If you buy a plan: the plan, its price, currency and dates, whether it is in a trial, renewing, cancelled or overdue, and the reference numbers and messages the payment provider sends us about the customer, subscription and payments. Card, PayPal and mobile-money details go straight to the payment provider. We never see or store your full card number.
- Technical data: our hosting provider processes your network (IP) address to deliver Ideasip and protect it from abuse, and briefly counts sign-in attempts per network. We don't store IP addresses with your account or your device record.
Why we use it
- To run Ideasip: sign you in, keep your place across devices, give you free titles, play and protect the audio, and remember your settings (this is needed to provide the service you asked for).
- To sell you a plan and keep it working: start the checkout, turn your plan on, renew or end it, and answer questions about it (needed for our contract with you).
- To keep it safe: limit sign-in guessing and misuse of free listening (our legitimate interest in a secure service).
- To improve it: see which briefs people finish, fix mistakes you flag, and decide what to make next, using counts rather than profiles where we can (our legitimate interest).
- To contact you about your account: sign-in and reset codes, and important changes. We send marketing only if you have agreed to it.
Who we share it with
Only service providers who process it for us under contract, and only what they need:
- Cloudflare — hosting, our database, storage and content delivery;
- Resend — sending sign-in and reset emails;
- Google and Apple — only if you choose to sign in with them;
- Paddle (Paddle.com Market Ltd and its group) — if you buy a subscription outside Africa. Paddle is our reseller and the Merchant of Record for those orders: it takes your name, email, country, billing address and payment details on its checkout, charges you, works out and pays tax, prevents fraud and handles refunds. Paddle uses this data as a controller in its own right, under its privacy notice, and tells us your email, country, plan and payment status so we can turn your plan on;
- local payment providers (such as Chapa, for Telebirr, CBE Birr and cards in Ethiopia) — only if you buy a plan or pass from them;
- our professional advisers (such as accountants and lawyers), where they need it to advise us.
We may also disclose data to courts, regulators, tax and other authorities if the law requires it, or to protect people's safety or our rights. If DHY Global LLC is ever sold or merged, this policy continues to apply to your data.
Our providers may process data in the United States and other countries. Where the law requires it, such as for data from the UK or the EU, we use appropriate safeguards for these transfers, such as the European Commission's standard contractual clauses.
How long we keep it
Account data is kept while your account exists. When you delete your account, we delete it, your progress, free titles, plan and our records of its payments, ratings and flags straight away, and devices you used become anonymous guest records. Sign-in and reset codes expire after 10 minutes (a reset code from support after 24 hours), and records of sign-in attempts after at most an hour. We keep anonymous guest records only as long as they are useful for running free listening and understanding use.
Paddle, as the seller of subscriptions, keeps its own records of your purchases for as long as tax law requires, under its privacy notice. Deleting your Ideasip account doesn't cancel a subscription: cancel it first on the Plans page or at paddle.net.
Your choices and rights
- Delete account: Profile → Delete account removes your account and what is kept under it, on every device.
- You can see your account details in Profile, change your password or recovery email, and sign out.
- You can ask us for a copy of your data (including in a portable, machine-readable form), to correct it, to restrict or object to how we use it, or to delete it, and you can withdraw any consent you gave (such as to marketing emails) at any time, by writing to [email protected]. We answer within one month.
- Depending on where you live, laws such as Ethiopia's Personal Data Protection Proclamation (No. 1321/2024), the EU and UK GDPR, and US state privacy laws give you these and other rights, including the right to complain to your data protection authority.
Cookies and storage on your device
Ideasip stores a few things on your device so it works: your sign-in session, your device id, your settings and downloaded briefs (in the browser or app storage), and two cookies our server sets — one keeping your device id, one tying protected audio links to your browser. There are no advertising or cross-site tracking cookies.
Children
Ideasip is not meant for children under 13, and we don't knowingly collect their data. If you think a child has given us personal data, write to us and we will delete it.
Security
Data is encrypted in transit, passwords are stored as salted hashes, protected audio links are signed and short-lived, and staff access is limited to those who need it. No system is perfectly secure; if a breach affects your data, we will tell you as the law requires.
Changes
If we change this policy, we update the date at the top and, for important changes, tell you in the app or by email first.
Contact
For anything about your data: DHY Global LLC, 12012 Saw Mill Ct, Silver Spring, MD 20902, USA · [email protected]