Privacy policy
Last updated : 16 August 2026
DashScreen displays your content on your screens: to do that, we need to store your account, your media and your screen configuration. This page explains exactly what data we process, why, who it is shared with, how long it is kept and how to take back control of it. We never sell your data, we show no advertising, and we use no advertising or analytics trackers.
1. Who is responsible for your data
The data controller is Thiris, publisher of DashScreen (referred to below as “we”), 6 rue Arthur Adamov, 94500 Champigny-sur-Marne, France.
This policy covers the whole DashScreen service:
- the dashscreen.info website;
- the client.dashscreen.info customer web area;
- the DashScreen iOS app;
- the DashScreen Android app;
- the Player that displays your dashboard on your TVs, iPads, iMacs or Raspberry Pi.
2. The data we collect
Account
- first and last name (optional);
- email address (required — it is your login);
- password, stored hashed — never in clear text;
- internal account ID, creation date, last login date.
Content you create
- photos and images you upload, together with their folders and names;
- technical photo metadata (capture date, orientation, dimensions, device model) read from EXIF data;
- messages published on your screens;
- your dashboards and widget configuration: weather city, RSS feed addresses, camera or web page URLs, and any credentials you enter yourself for those sources.
Screens (Players)
- unique device identifier (UUID), hostname, the name you give the screen;
- operating system, Player version, display resolution;
- name of the Wi-Fi network (SSID) the screen is connected to;
- last activity date, monitoring screenshots and technical error logs, used for diagnostics.
Sessions and security
- session token, stored hashed on the server;
- device name (make and model) and platform, so you can recognise your active sessions;
- token creation, last-use and expiry dates;
- email address and IP address of login attempts, successful or failed, to block brute-force attacks.
Service keys
- the WeatherAPI.com key you provide, if you choose to use your own weather key. It is optional.
Website
- a PHP session cookie and your language preference (see the Cookies section);
- whatever you type into the contact form: name, email address, subject and message. It is used only to reply to you.
What we do not collect
- No location data: the apps never request location permission; the weather city is simply typed in.
- No access to your photo library: images are sent through the system picker or the iOS / Android share sheet, and we never browse your device storage.
- No payment data, no profiling, no advertising or analytics trackers.
3. Why we process it, and on what legal basis
| Purpose | Data involved | Legal basis (GDPR) |
|---|---|---|
| Create and manage your account | Identity, email, password | Performance of the contract |
| Display your content on your screens | Media, messages, dashboards, paired screens | Performance of the contract |
| Send you service emails (confirmation, password reset, replies to your requests) | Email address | Performance of the contract |
| Secure access: sessions, login rate limiting | Tokens, IP address, email, device name | Legitimate interest (service security) |
| Diagnose faults and improve reliability | Technical logs, exceptions, monitoring screenshots | Legitimate interest (service reliability) |
| Display the weather | Chosen city, WeatherAPI key you provide | Performance of the contract, at your request |
| Answer your rights requests and meet our legal obligations | Email correspondence | Legal obligation |
4. What we never do
- We never sell, rent or trade your data to anyone, for any commercial purpose.
- We show no advertising and carry out no advertising profiling.
- We use no analytics tools and no third-party analytics SDK in the apps.
- There is no sharing between accounts: your photos, messages and dashboards appear only on the screens paired with your own account. Nothing is published publicly.
5. Who else has access to your data
Your data is accessible to the people who operate the service at Thiris, strictly on a need-to-know basis, and to the following providers, acting as processors:
| Provider | Role | Data involved | Country |
|---|---|---|---|
| OVHcloud | Hosting of the website, application servers and your media | All service data | France |
| Scaleway (Online SAS) | Database hosting | Account, screens, configuration, logs | France |
| WeatherAPI.com | Weather forecasts, called only when the weather widget is configured | City name and API key. No identity data is sent. | United Kingdom |
| Mandrill (Mailchimp / Intuit) | Transactional email delivery | Recipient email address and message content | United States |
| Apple App Store, Google Play | Distribution and updates of the mobile apps | Download data handled by those platforms under their own policies | United States |
We may also disclose data to an administrative or judicial authority, but only under a lawful order.
A word about the sources you add yourself. When you configure an RSS feed, an embedded web page, a traffic map or a camera, your screen contacts that service directly: it can see your screen’s IP address and applies its own privacy policy. Those services are outside our control.
7. How long we keep it
| Data | Retention period |
|---|---|
| Account, media, screens, dashboards | For as long as the account is active, then erased within 30 days of your deletion request |
| Dormant account | 3 years without any login, after a reminder email left unanswered |
| Session tokens | Until they expire or you revoke them from the app |
| Login attempts (email, IP) | 12 months |
| Technical logs, exceptions, monitoring screenshots | 12 months |
| Support email correspondence | 3 years after the last contact |
8. Deleting your account and data
You can request permanent deletion of your account at any time, without installing the app, from the dedicated page: dashscreen.info/delete.php. You can also use our contact form, quoting the account’s email address.
What is deleted: your account and credentials, your paired screens and their configuration, your media library, your dashboards and messages, and your session tokens, which are revoked immediately.
What may be kept: security logs for their normal retention period, and any records the law requires us to keep (accounting or legal obligations, where applicable). This data is no longer used to provide you with the service.
Timescale: requests are processed within 30 days and confirmed by email. After that, deleted data cannot be recovered.
9. Your rights
Under the GDPR, you have the following rights over your data:
- access — obtain a copy of the data we hold about you;
- rectification — correct inaccurate or incomplete data;
- erasure — ask for your data to be deleted;
- restriction — ask us to freeze a processing activity while it is verified;
- objection — object to processing based on our legitimate interest;
- portability — receive your data in a machine-readable format;
- withdraw consent at any time, where processing relies on it;
- set directives about what happens to your data after your death.
To exercise these rights, use our contact form, quoting the email address linked to your account. We reply within one month. Proof of identity may be requested where there is reasonable doubt about who you are.
If our answer does not satisfy you, you may lodge a complaint with the French data protection authority (CNIL) — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr — or with the supervisory authority of your country of residence.
10. How we protect your data
- Encryption in transit: all traffic between the apps, the screens and our servers goes over HTTPS only.
- Hashed passwords on the server; they are never stored or transmitted in clear text.
- Hashed session tokens in the database, with expiry and revocation available at any time from your session list.
- Encrypted storage on the device: the token is kept in the Keychain on iOS and in
EncryptedSharedPreferences(AES-256-GCM) on Android. - Optional biometric unlock (Face ID, Touch ID, fingerprint) to protect access to the app.
- Login rate limiting to counter brute-force attacks.
- Restricted access to servers and database, limited to the people who need it to operate the service.
No system is infallible: in the event of a data breach likely to create a risk to your rights, we notify the CNIL within 72 hours and inform you directly where the risk is high.
11. Transfers outside the European Union
Your data is hosted in France. There are two limited exceptions:
- Mandrill (Mailchimp / Intuit, United States), for transactional email delivery. This transfer is covered by the European Commission’s standard contractual clauses.
- WeatherAPI.com (United Kingdom), a country recognised as adequate by the European Commission. Only the city name and the API key are sent.
12. Minors
DashScreen is intended for an adult audience. The service is not aimed at people under 18 and we do not knowingly collect their data. If you believe a minor has sent us data, contact us and we will delete it.
13. Changes to this policy
This policy may change, in particular if the service evolves or if we start working with a new provider. The last update date is shown at the top of this page. In case of a substantial change, we will notify you by email at the address linked to your account.
14. Contact us
For any question about this policy or about how your data is processed:
- Form: our contact page
- Post: Thiris — 6 rue Arthur Adamov, 94500 Champigny-sur-Marne, France