Privacy policy
Last updated: 8 September 2026
Fields to be completed before publication are shown in square brackets: company name, address, registry number and effective date.
This policy explains which data is processed when you use the DEK Plus applications for Android, Windows and Android TV, and this website. The data controller is [COMPANY NAME], [ADDRESS], registry no. [REGISTRY NO]. Contact: destek@dekplus.io.
Short summary
- Most of the application works without an account. If you create an account, only a name, an e-mail address and a password are requested.
- Your backups, the files you transfer, your clipboard and your notifications are encrypted on your device. The key that decrypts them is not held on our servers.
- Your camera video and audio are transmitted encrypted; they are never present on our servers in unencrypted form. The photo taken at the moment of motion is held temporarily in encrypted form and is deleted as soon as your phone downloads it.
- We do not show advertisements, we do not collect an advertising identifier, and we do not sell your data to anyone.
- You can delete your account yourself from within the application.
An account is optional
You can install and use the application without creating an account. Acting as a camera, watching a camera, sending files to a phone next to you, and using the toolbox and the Vault do not require an e-mail address.
An account is required only for the following: pairing a computer or a television, backup, accessing your files from outside your home network, and clipboard sharing.
What is requested at sign-up
- Name — used to tell your devices apart; it is not verified.
- E-mail address — the identifier of your account. It is verified with a six-digit code sent to your address.
- Password — not stored in plain text. It is hashed with PBKDF2-SHA256 using a random salt and 100,000 iterations.
No phone number, username, date of birth or profile photo is requested. There is no social media sign-in and no SMS verification.
Device identifier
Each device generates its own identifier on first launch (for example DEK-6V46T7). This identifier is independent of your account, is created without asking for an e-mail address, and is kept in the device's encrypted storage. Application data is not included in device backups; when you move to a new phone the identifier is not carried over, and the new device receives a new identifier. You can reset the identifier at any time from the profile screen.
Encryption
Where the keys are
When you pair your devices, a QR code appears on the screen of your computer or television, and you scan it with your phone. That QR code carries the encryption key shared between your devices. The key passes from one screen to the other; it does not go out to the internet, does not pass through our servers, and is not stored on our servers. The key is kept in the operating system's secure storage on your phone, and protected by Windows' own encryption mechanism on your computer.
The practical consequence of this is: because we do not hold the key, we cannot decrypt your encrypted content either. This is also why you have to pair again when you move to a new device.
What is transferred and stored in encrypted form
- Your cloud backups — the file is encrypted with AES-256-GCM, and the file name is encrypted as well. The server does not accept unencrypted uploads. The copy on the server is deleted as soon as your computer downloads the file; a file that is not downloaded is deleted automatically after 7 days.
- File transfer between devices — in all transfers between phone, computer and television, both the content and the file name are encrypted. The same applies on the same Wi-Fi network: a file you send from phone to phone, a backup going to your computer, and a picture you cast to the television leave the device encrypted. Someone listening on the network can see neither the file nor its name.
- Remote file access — a file you download from your computer stays encrypted for as long as it passes through the server for transfer; folder listings and previews are also sent inside an encrypted envelope. There is no limit on file size.
- Clipboard text — transmitted inside an encrypted envelope; the server cannot open the envelope.
- Notifications and the replies you write from your computer — sent inside an encrypted envelope. Neither the Google service that delivers the notifications nor our server can see the content.
- The photo taken when motion is detected — encrypted with a separate key for each event; this key is stored in a form that only the authorised viewer devices can open. The photo is deleted from the server after it is downloaded.
- Vault — encrypted on your device with AES-256-GCM. The key is derived from your PIN and your recovery code; it is never written anywhere in raw form. The vault is never uploaded to the cloud.
- Your account password — not stored in plain text; it is hashed with PBKDF2-SHA256 using a random salt and 100,000 iterations.
Camera stream
Live video and audio are encrypted with DTLS-SRTP. The encryption key is generated for each session between the camera and the viewer device and exists only in the memory of those two devices. When on the same network, the devices talk directly; encryption applies on the local network in exactly the same way. When on different networks, a direct connection is attempted; if the network does not allow it, the stream flows through a relay server. The relay only forwards the encrypted packets; it cannot decrypt their content and does not record them.
The phone acting as a camera does not broadcast unencrypted video, photos or the PIN onto the local network. Photos taken remotely and commands such as flash and zoom also pass through the same encrypted channel. The viewing PIN is sent to the camera only on the first connection, over the encrypted connection; the camera verifies it, and the server does not store it. The only information exposed on the local network is the camera's name and identifier. The same encrypted stream is used when watching from a television.
What is not encrypted
To be honest, not everything is encrypted. The following is readable on our servers, because it is necessary for the system to work:
- Your e-mail address; the name, type and brand of your devices; and their last-seen times.
- The log of motion events: camera name, time, and whether a person was detected. Not the footage itself.
- The name and last connection time of the viewer devices you have authorised for a camera.
- Transfer metadata: from which device to which device, when, and what size.
- The text of motion notifications may be visible while passing through the Google service that delivers the notification.
- So that devices on different networks can find each other, IP addresses are seen by Cloudflare, which provides the connection infrastructure. These addresses are used to establish the connection and are not stored by us.
There are also things that remain unencrypted on your devices: video recordings made by the camera are written unencrypted to the phone's gallery, and motion recordings on the computer are written unencrypted to the computer's disk. These stay on your device, under your control.
Data that reaches our servers
- Account information — e-mail address, name and the hash of your password. Kept until your account is deleted.
- Device record — device identifier, device name and type, brand, last-seen time, notification token and interface language. The computer client additionally reports processor, memory and storage information. Deleted when you remove the device from your account.
- Motion events — only the timestamp, the camera name, whether a person was detected, and whether a recording was made. No video or audio is sent. The last 100 events per camera are kept and deleted after 30 days.
- Cloud backup — files you send while your computer is switched off are held temporarily in encrypted form, downloaded when the computer starts up, and deleted from the server the moment they are downloaded. A file that is not downloaded is deleted automatically after 7 days. If you do not want to wait, you can delete them immediately with the "Delete my files in the cloud" option on the profile screen. The server can read neither the names nor the contents of these files.
- Files downloaded from outside your home — in remote file access, the file you download passes through the server in encrypted form for transfer and is deleted within 7 days. The server can decrypt neither its content nor its name.
- Files sent to the television from outside your home — pass through in encrypted form in the same way and are deleted within 7 days.
- Motion photo — encrypted with a separate key for each event and deleted as soon as your phone downloads it; if it is not downloaded, it is deleted automatically after one day at the latest.
- Clipboard text — copied text you share with your computer passes through the server inside an encrypted envelope; text sent to the phone is deleted within one hour at the latest, and text sent to the computer is never stored.
- Shortened links — the address you enter into the link shortening tool is stored so that the short link can keep working.
Data that never leaves your device
- Vault — files are encrypted on the device with AES-256-GCM. The key is never held anywhere in the clear; it is derived from the PIN and the recovery code. The vault is not uploaded to the cloud.
- Toolbox — inspection of photos, videos, audio, PDF and APK files, and conversion operations, are performed on the device; the file is not sent to the server.
- Reading text from photos — the model ships with the application, and processing is done on the device.
- Phishing check — works offline with a list embedded in the application; no query is sent to any address.
- Gallery backup — when you choose "Back up gallery", photos and videos go directly to your computer over Wi-Fi, in encrypted form; they do not pass through the cloud. (Automatic backup is different: if the computer is switched off, the file waits in the cloud in encrypted form, see Cloud backup.)
If you use the domain name lookup tool, the domain name you type is sent to the public server of the relevant registry so that the lookup can be performed.
Permissions requested
- Camera — camera mode and QR code scanning.
- Microphone — audio for the camera stream and push-to-talk.
- Photo, video and audio files — backup, sending files and casting to the television.
- Access to all files — file explorer and file backup.
- Contacts — sharing a contact card on the file sending screen.
- Location — Android makes this permission mandatory for Wi-Fi and Bluetooth scanning. It is used in the network and Bluetooth scanning tools; your location is not collected, not stored and not sent anywhere.
- Bluetooth and nearby devices — the Bluetooth scanning tool, phone-to-phone transfer and camera discovery.
- Notification access — mirroring notifications to the computer and the television, and replying from the computer. You must grant this permission separately in the system settings.
- Installing applications — installation of the application file you send to the television.
- List of installed applications — application sharing and the television notification filter.
- Display over other applications — drawing the notification box on the television.
- Running in the background — camera streaming, backup and keeping the connection alive.
- Fingerprint — application lock.
No SMS, call log or calendar permission is requested. You can revoke permissions at any time from the device settings; only the related feature stops working, and the rest of the application continues to work.
Service providers
- Cloudflare — server, database, file storage and the connection infrastructure between devices.
- Resend — delivery of verification code e-mails.
- Google Firebase — notification delivery, crash reports and usage statistics.
- Google Play — distribution of the application.
Usage statistics
Counts of which screens of the application are used, and crash reports, are collected. The following are not included in these records: your contacts, your file names, your file contents, your folder paths, your location, your installed applications, your e-mail address, your device identifier and your IP address. Your user identifier is never reported to the statistics service.
No advertisements are shown, and advertising identifier collection is turned off. The current version of the application does not have a setting to turn off the collection of statistics and crash reports.
About your rights
You have the right to access your data, to have it corrected, to request its deletion, to restrict its processing, and to receive your data in a portable format. You can delete your account yourself from the profile screen in the application; deletion removes your account and the records linked to it. You can also clear your backups in the cloud with the "delete my files in the cloud" option. For other requests, you can write to destek@dekplus.io.
If you consider the response to your request insufficient, you can lodge a complaint with the data protection authority of the country you are in. In Türkiye, this authority is the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu).
Children
DEK Plus is not directed at users under the age of 13, and we do not knowingly collect data from this age group.
Changes
When we update this policy, we change the date at the top of the page. If there is a significant change, we will notify you within the application or by e-mail.