Ding ("the app", "we", "us") is a meditation timer for iOS (iPhone and Apple Watch) and Android.
This policy explains what data the app handles and how. It covers both versions; where they differ,
the platform is named. It is written to be plain and honest: most of Ding works entirely on your
device with no account and no data leaving your phone. Data only reaches our servers if you choose
to connect Discord.
The short version
The timer, presets, statistics, widgets — and, on iOS, iCloud sync and optional logging to Apple
Health and Calendar — all work without any account and never send data to us.
The only sign-in is an optional Discord connection. It powers one optional social
feature ("Together") that shows which members of your own Discord communities meditated today.
We request only the Discord scopes identify and guilds. We do not
request your email and never see your Discord password.
We do not sell your data, show ads, or use third-party analytics or tracking SDKs.
You can delete all data we hold about you at any time from within the app.
Data that never leaves your device
The following are stored locally on your device (on iOS, where you enable it, also in your own
private iCloud account via Apple's CloudKit). We have no access to any of it:
Your meditation statistics and session history — on iOS via Apple SwiftData and your private
CloudKit database; on Android in a local database on that device.
Your timer presets — on iOS synced through your private iCloud key-value store; on Android stored
on that device.
iOS only: optional entries written to Apple Health (mindfulness minutes)
and your Calendar. Ding only writes these on your instruction; it does not read
them back, and they never reach our servers. The Android version does not use Health Connect or
your calendar at all.
Practice history you import from a file (for example an Insight Timer export) or export to a file.
The file is read and written on your device only; we never receive it.
Your app settings and preferences.
The Android version has no cloud sync: this data stays on that one device. Android's
automatic backup is switched off for Ding, so it is not copied to Google Drive either.
Data collected only if you connect Discord
If you tap "Connect Discord" and authorize the app, our backend creates a record for you and stores
the following, linked to your Discord user ID:
Discord user ID, and your Discord display name and avatar, so your name can be
shown in the "Together" feature.
The list of Discord communities (servers) you belong to, and which of them you
have chosen to make yourself visible in. Visibility is mutual: you and another person only appear
to each other when you have both opted into a shared community.
A short-lived, encrypted Discord access token (valid ~7 days) used solely to keep
your community membership up to date. It is not stored on your device.
The fact and duration of your meditation sessions (start time and length) while you
are connected, so the feed and streaks can be shown to your communities.
"Thank you" acknowledgements you send to others after a session.
Co-meditation pairings you create with another user (e.g. a partner) to practice together.
After you authorize Discord, our server issues a personal session token (valid ~90 days) so the app
can talk to our backend without re-authorizing each time.
Anonymous usage count
Ding keeps a simple daily count of how many meditation sessions happened, used to show community
activity. This counter contains no personal information and is not tied to your identity.
Diagnostics (iOS only, opt-in)
If you turn on diagnostics in Settings, the iOS app may send technical information about touch input
(such as touch size and timing, but never touch coordinates or screen content) to
help us fix issues like the timer pausing accidentally. This is off by default and,
when enabled, is linked to your Discord ID only if you are connected. You can turn it off at any time.
The Android version does not collect this.
Android permissions
The Android version asks for a few system permissions. None of them collect data or send anything to
us:
Notifications — to show the running session and to sound the bell when the app is
in the background.
Alarms & reminders (exact alarms) — so the bell rings at the right second even
if the system has put the app to sleep.
Foreground service and wake lock — to keep the timer running with the screen off.
Run at startup — to restore a session that was still running when the phone
rebooted.
Internet — used only for the optional "Together" feature and Discord sign-in. With
Discord not connected, the app makes no network requests carrying personal data.
How we use the data
We use the data above only to provide the app's features — showing who in your communities is
meditating, computing streaks, delivering "thank you" acknowledgements, enabling co-meditation, and
keeping your community list current. We do not use it for advertising, profiling, or any purpose
unrelated to the app.
Sharing and third parties
Discord is the source of your community data; your use of Discord is governed by
Discord's own privacy policy.
Apple provides iCloud, Health, and CloudKit for the iOS version; data you sync
stays within your own Apple account.
The App Store and Google Play distribute the app and gather their own install and
crash statistics under their own policies. We embed no analytics or advertising SDK of any kind in
either version.
We do not sell, rent, or share your personal data with any other third parties, and we use no
advertising or analytics networks.
Data retention and deletion
You can delete everything we store about you at any time:
In the app, open the "Together" profile and tap "Delete my data". This works the
same on iOS and Android and immediately removes your Discord ID, community membership, visibility
choices, session tokens, and related records from our servers, and removes your entries from the
community activity archive.
Disconnecting Discord ("Disconnect") signs you out on the device; deleting your data (above) also
erases the server-side record.
Your local statistics and presets live on your device — and on iOS, in your iCloud. Remove them by
deleting the app or using the reset option in Settings; on iOS, also via your iCloud settings.
Data tied to a deleted account is removed on a best-effort basis and is not retained for further use.
Security
Discord access tokens are stored encrypted on our server. Traffic between the app and our backend is
sent over HTTPS. Your Discord password is never seen or stored by Ding.
Children
Ding is not directed to children under 13, and we do not knowingly collect personal data from children.
Changes to this policy
We may update this policy as the app evolves. Material changes will be reflected here with a new
"Last updated" date.
Contact
For any question about this policy or your data, or to request deletion, contact us at:
support.ding@gmail.com