Privacy policy

Privacy policy

Last updated 2 September 2026

DagWorld is an app for the published work of Dag Heward-Mills, holding his books, quotes, music, video and audio messages. It is published by Benlottejnr Apps of Hitchin, United Kingdom, the publisher of VerseUp and VerseFlash. This policy explains what the app collects, why, and how to get rid of it.

The short version

  • DagWorld needs an account. Everything it holds is saved against you, so there is no signed-out mode and no anonymous browsing.
  • An account exists for one reason, to keep your own library in sync across your devices. It is free, and it opens the whole book catalogue without any payment.
  • There are no advertising identifiers, no third-party ad networks and no third-party analytics trackers in the app.
  • We do not collect your location or your contacts, and we never see your payment card details.
  • Deleting your account removes the personal layer. See Delete account.

An account is required

DagWorld has no signed-out mode. The catalogue, the search, the quotes and the player all sit behind sign-in, because every one of them saves something against you: where you reached, what you highlighted, what you kept. Creating an account is free and takes no payment details, and it gives you the whole book catalogue.

Our servers keep ordinary web request logs when the app talks to the API, which include an IP address, a timestamp and the endpoint requested. These are operational records used to keep the service running and to investigate abuse, and they are not used to build a profile of you.

What we collect when you sign in

Signing in is done with Google, with Apple, or with an email address and a password. Where you use Google or Apple we never see a password at all. Where you set one with us, we never store the password itself: it is put through a one-way hash, so what we hold cannot be turned back into what you typed, and nobody here can read it.

  • Account identity. Your email address, a display name, and, where you signed in with Google or Apple, a stable provider id that lets us recognise you next time. If you use Apple's Hide My Email, we only ever see the relay address Apple gives us. Where you signed up with an email address, we also hold a one-way hash of your password.
  • Reading, listening and watching progress. Which book, message, video or song you are in, and how far through it you are.
  • Your own annotations. Highlights, bookmarks and notes you create, along with the passage each one is attached to.
  • Saved quotes, books, songs and messages. Anything from the catalogue that you save to your own collection.
  • Your own quotes. Quotes you write or keep yourself, with the account that saved them. They are private to you: nobody else sees them, nobody reviews them, and there is no route by which one becomes public. They are deleted with your account.
  • A device token, only if you allow notifications. Your device asks before any notification can be sent, and nothing is stored unless you allow it. Once you do, we keep a push token for that device and the time of day you chose for each kind of notification, so it arrives when you asked for it. Setting up the app asks you for those times, and each kind can be switched off afterwards under Topics and notifications. Refuse the device prompt and no token is ever stored.
  • Diagnostic and crash data. Basic technical information such as the app version, the device model, the operating system version and a crash stack trace when something fails. We use this to fix faults.

What we do not collect

  • No advertising identifiers, and no advertising at all in the app.
  • No third-party ad or analytics trackers, and no tracking of you across other apps or websites.
  • No location data, precise or approximate.
  • No contacts, photo library, microphone or camera access.
  • No payment card details. A subscription is bought through Apple's App Store or Google Play, and they never pass card details to us. We only learn that a purchase exists, whether it is a trial or a paid period, and when it expires.

Why we collect it

  • To sync your own library across your devices. Progress, highlights, bookmarks, notes and saved quotes exist so that a book you left half read on a phone is half read on a tablet too, and a message you stopped halfway through picks up where it stopped.
  • To know what you are entitled to. We record the state of your subscription so the app can tell whether the quotes, the music, the video and the audio messages are open to you. The books are free and need no such check.
  • To send the notifications you allowed. The daily quote, a reminder of quotes you kept yourself, a morning note of what is new in the catalogue, and a monthly nudge to choose your themes, each at the time you chose and each switchable off on its own.
  • To keep the service working. Diagnostics, crash reports and request logs let us find faults, stop abuse and keep the app stable.

Legal basis

Where UK and EU data protection law applies, we rely on the following bases.

  • Performance of a contract. Creating your account and syncing your library are the service you asked for, so we process that data to provide it.
  • Consent. Notifications are sent only where you allowed them at your device's own permission prompt, which is where consent is given. You can withdraw it at any time by turning a notification off in the app or turning them off in your device settings, and the stored device token is discarded.
  • Legitimate interests. Diagnostics, crash reporting and request logs, so that the app works and stays secure. We balance this against your interests and keep the data to the minimum that serves the purpose.

Downloads and offline use

Books, songs, audio messages and podcast episodes can be downloaded for offline use. Downloaded files are stored on your device and are not shared with anyone. Deleting a download, or deleting the app, removes those files from the device.

Who else is involved

We keep the list of third parties as short as we can. These are the only ones that touch your data.

  • Apple. Sign in with Apple, app distribution and any in-app purchase. Apple's own privacy policy governs what Apple does with the data you give Apple.
  • Google. Sign in with Google, app distribution and any in-app purchase, and push delivery through Firebase Cloud Messaging. Firebase Cloud Messaging receives the device token and the notification payload so that the daily quote can reach your device. Videos in DagWorld are played from YouTube, which is Google's, inside the app; YouTube sets its own cookies and applies its own policy to that playback.
  • RevenueCat. The service that checks a subscription with Apple or Google and tells our servers whether it is active. It receives your DagWorld account id, the store's purchase receipt and the subscription's status, and its software inside the app records an identifier for the device it runs on. It never sees your card. When you delete your account we ask RevenueCat to delete its record of you as well. RevenueCat's own privacy policy governs what it does with that data.
  • Our hosting provider. The servers, database and file storage that run the DagWorld API and hold the catalogue and your account data.

We do not sell your data, and we do not share it with advertisers or data brokers. We may disclose data if we are legally required to, for example in response to a valid legal order.

Where your data is held

DagWorld's servers, database and file storage are located in the United States, in Amazon Web Services' Northern Virginia region (us-east-1). We are based in the United Kingdom, so your data does leave the UK and the European Economic Area to reach them. That transfer relies on the safeguards data protection law permits, which here are the standard contractual clauses and the UK international data transfer addendum in our agreement with Amazon Web Services.

How long we keep it

Your account data, progress, annotations and saved quotes are kept for as long as your account exists. When you delete your account they are removed, subject to the exceptions below.

The rest runs on fixed cycles:

  • Crash and error reports the app sends us: 90 days. A nightly job deletes anything older, so nothing accumulates.
  • Server logs: until they roll over. These are not kept on a timer. Our servers hold a small rolling window and discard the oldest as new entries arrive, which in practice is a few days.
  • Database backups: 30 days. After that they expire automatically and cannot be restored from.
  • Whole-server snapshots: the 7 most recent. One is taken daily and the eighth-oldest is discarded as each new one is made.

Because backups and snapshots are point-in-time copies, a record you deleted can persist inside one until that copy expires on the cycle above. It is not used for anything in the meantime, and it goes when the copy goes.

Deleting your account

You can delete your account from inside the app, or by writing to us. Deleting your account removes the personal layer: your identity, your progress across every medium, your highlights, bookmarks and notes, your saved items and any stored device token. Full instructions, including what survives deletion, are on the Delete account page.

Your own quotes go with the account too. What stays is only what we are required to keep for legal or accounting reasons, such as the record that a subscription existed, and diagnostic data that was already stripped of anything identifying.

Your rights

Depending on where you live, you may have the right to ask for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable form. You can exercise any of these by emailing privacy@dagworld.org. We will respond within the time limit set by the law that applies to you, which is one month in the UK and the EEA.

If you are in the UK or the EEA and you think we have handled your data badly, you can complain to your data protection regulator. In the UK that is the Information Commissioner's Office.

Children

DagWorld is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has created an account, write to privacy@dagworld.org and we will delete it.

Security

Traffic between the app and our servers is encrypted in transit. Access to the production database is restricted to the people who run the service. No system is perfect, but we keep the amount of data we hold small, which is the most reliable protection there is.

Changes to this policy

If we change this policy we will update the date at the top of this page. If a change materially affects how we handle your data, we will tell you in the app before it takes effect.

Contact

For anything about privacy or your data, email privacy@dagworld.org. For everything else, email support@dagworld.org.

Benlottejnr Apps, 9 Baliol Chambers, Hollow Lane, Hitchin SG4 9SB, United Kingdom. Benlottejnr Apps is a sole trader rather than a registered company, so there is no company number to give. We are the data controller for everything described on this page. We have not appointed a data protection officer, because we are not required to; privacy enquiries go to the address above.

The content in DagWorld is the copyright of Dag Heward-Mills.