Dito
Dito Privacy Policy
Last updated
Ler em portuguêsDito records a healthcare appointment, with the consent of the professional, and turns it into an organized summary sheet: diagnosis, medicines, exams, warning signs, follow-up and pending items. Dito is a product of Works2DEV, the controller of the data described here under Brazil’s General Data Protection Law (Law No. 13,709/2018 — LGPD).
Because Dito deals with health data, which the LGPD treats as sensitive personal data, this policy is written to be read in full. The key points:
Summary
- Dito is local-first. Recordings, summary sheets and the list of people you care for stay on your device.
- Audio leaves your phone only to become a summary sheet. It is sent encrypted for transcription and extraction, and neither our service nor the transcription provider stores the audio or its content.
- No sign-up. You don’t provide a name, e-mail or phone number to use the app. We use an anonymous identifier.
- We don’t sell data, we don’t show ads, and your data is not used to train AI models.
- When you delete a summary sheet, it is removed from the device together with the original recording.
What data exists and where it lives
On your device
| Data | Detail |
|---|---|
| Appointment recordings | Audio you record, stored in the app’s private area, protected by the operating system |
| Summary sheets | Diagnosis, medicines and doses, exams, warning signs, follow-up date and pending items, generated from the recording or typed by you |
| People you care for | Name and relationship only. Each summary sheet belongs to one person |
Summary sheets and people are kept in an encrypted local database, with the key stored in the device’s secure vault (Keychain on iOS, Keystore on Android).
During processing
When you ask Dito to generate a summary sheet, or use an AI feature inside one, the audio or text needed is sent, encrypted in transit, to our transcription service. The service forwards the content to the transcription and AI provider and returns the result to your device. This content is not stored: the provider operates under a zero data retention agreement.
On our service (no content)
To make the app work and prevent abuse, our service keeps only technical metadata:
- an anonymous app identifier (Firebase Authentication, with no name, e-mail or phone number);
- integrity attestation for the app and device (Firebase App Check, with App Attest/DeviceCheck on iOS and Play Integrity on Android), to confirm that requests come from the genuine app;
- quota usage: transcribed minutes, declared duration and dates;
- subscription status, validated with Apple or Google from the purchase receipt;
- a device signal (DeviceCheck on iOS, an app-scoped identifier on Android) used only to prevent the free trial from being restarted.
These records expire automatically and contain no audio, transcript or summary-sheet content.
Payments
Subscriptions are billed by the App Store or Google Play. We never receive or store card or payment details.
Device permissions
- Microphone: used only while you record an appointment.
- Notifications: while recording, a “Recording appointment” notice is shown so you know the microphone is on, even when the screen is locked.
Without the microphone, you can still use typing mode and write down the summary-sheet fields in the app.
Recording another person: consent
Dito is designed to record with the knowledge and agreement of the professional you see. Before each recording, the app shows a ready-made phrase to ask for permission and asks you to confirm that the professional agreed. You are responsible for obtaining that consent. If the professional prefers not to be recorded, use typing mode.
Purposes and legal bases
| Purpose | Data | Legal basis (LGPD) |
|---|---|---|
| Generate the summary sheet from the recording | Audio and appointment content (health data) | Specific and prominent consent of the data subject or legal guardian (art. 11, I) |
| Store and organize your summary sheets on the device | Summary sheets and people you care for | Consent (art. 11, I). The data stays under your control |
| Operating the service, quota and subscription | Anonymous identifier, quota usage, subscription status | Performance of contract (art. 7, V) |
| Security and fraud prevention | Integrity attestation, device signal | Legitimate interest (art. 7, IX) and fraud prevention (art. 11, II, g) |
| Legal obligations and defense of rights | Technical records | Legal obligation and regular exercise of rights (art. 7, II and VI) |
You can withdraw consent at any time: delete the summary sheets and recordings in the app, or uninstall it.
Who we share with
We rely on providers that process data on our behalf (processors), under contract:
| Provider | Purpose | Where |
|---|---|---|
| Google (Firebase): Authentication, App Check, Cloud Functions and Firestore | Anonymous identifier, integrity, quota and subscription | southamerica-east1 region (São Paulo, Brazil) |
| OpenAI | Transcription and summary-sheet extraction, with zero retention | United States |
| Apple and Google | App distribution, subscriptions and purchase validation | Per each store’s policies |
Sending content to OpenAI is an international data transfer, made with your specific consent and with contractual zero-retention guarantees (LGPD, art. 33).
Sharing you do yourself: when you export a summary sheet as a PDF and send it through WhatsApp, e-mail or another app, the content becomes subject to the rules of whoever receives it. We have no access to that exchange.
We do not sell, rent or share data for advertising.
Backups and switching devices
Dito may be included in system backups (iCloud on iOS, Google Backup on Android), depending on your device settings. Those backups are managed by Apple or Google, not by Works2DEV. On Android, very large recordings may not fit in the cloud backup: after a restore, the summary sheet comes back, but the original audio may not.
How long we keep data
- On the device: until you delete it. Deleting a summary sheet removes the sheet and the original recording. Uninstalling the app removes local data, except whatever is in system backups.
- Processed content: not stored, by us or by the transcription provider.
- Metadata on our service: for as long as needed for quota, subscription and fraud prevention, with automatic expiration, or for the period required by law.
Security
Encryption in transit for every request, an encrypted local database with its key in the device vault, third-party keys kept only on the server (never in the app), app-integrity verification and restricted access to infrastructure.
Children and teenagers
Dito is intended to be operated by adults (18+). Parents and guardians may use it to follow appointments of children and teenagers in their care. In those cases, data is processed in their best interest and with the guardian’s consent (LGPD, art. 14).
Your rights
Under the LGPD (art. 18), you may request confirmation of processing, access, correction, anonymization, blocking or deletion, portability, information about sharing, withdrawal of consent and review of automated decisions. You may also lodge a complaint with Brazil’s data protection authority (ANPD).
Since almost everything lives on your device, you exercise most of these rights directly in the app: view, correct, export and delete summary sheets. For metadata on our service, write to privacidade@works2dev.com.br. We reply within 15 days.
Dito is not a medical service
Dito organizes what was said in the appointment. It does not diagnose, does not prescribe and does not replace your healthcare professional. See the Dito Terms of Use.
Changes
If we change how we handle your data, we will update this page and let you know in the app when the change is relevant.
Contact and Data Protection Officer
privacidade@works2dev.com.br. App support: suporte@works2dev.com.br.
- Data controller
- Works2DEV Soluções Empresariais Ltda
- CNPJ (Brazilian company ID)
- 63.081.910/0001-66
- Headquarters
- Ribeirão Preto/SP — Brazil
- Data Protection Officer
- privacidade@works2dev.com.br