1. Scope of this policy
This Privacy Policy applies to the Dacura File Repair desktop client and its related account, sign-in and membership entitlement services.
We value your privacy and data security. This policy explains how we collect, use, store, protect and otherwise process information when you use Dacura File Repair, and how you may exercise your rights.
2. Processing of file repair data
2.1 Local processing
Files you choose for repair, their contents, normal sample files, repair results and preview content are processed only on your device by default.
Signing in, checking membership entitlements, purchasing a subscription or enabling local diagnostics does not cause files selected for repair to be uploaded to a server.
The client does not actively scan disks, folders or files you have not selected, and does not use files selected for repair for advertising, profiling, artificial intelligence model training or purposes unrelated to file repair.
2.2 Normal samples
When using advanced repair, you may choose a normal file created by the same device or in the same format as a repair sample. It is used only to extract file structure, encoding parameters and necessary metadata locally. It does not overwrite the original and is not uploaded to a server.
2.3 Temporary files
Temporary repair results are stored in an application-specific cache accessible to the current user and are encrypted.
For previews, the client temporarily decrypts only the content required within a controlled scope. When a member saves a result, the client decrypts the temporary file and writes it to the location the user selects.
Temporary files produced during the repair are removed when the program closes normally. A small amount of encrypted cache may remain after an abnormal termination and will be handled on a later launch or cache cleanup. Repair results that you explicitly save are not temporary files and are not automatically deleted by the client.
3. Information processed by account services
You may use basic local features without signing in. Sign-in is primarily used for account identification, device-session management and membership entitlement synchronization.
When you register or sign in, we may process:
- Email address or mobile number;
- Display name or account nickname;
- Verification-code delivery and validation results;
- Password verification information;
- The account identifier, email address and basic profile returned by Google sign-in;
- A hash of a randomly generated device identifier;
- Device name, operating-system type and application version;
- Sign-in time, session state and token state;
- Purchased products, subscription status, membership period and entitlement status;
- Security records needed to prevent verification-code abuse, account attacks and unusual sign-ins.
The client does not retain your plaintext password, SMS verification code, email verification code or Google OAuth authorization code.
4. Google account sign-in
When you choose to sign in with Google, the client connects to Google's authorization service through your system browser.
Dacura requests only the basic permissions needed for sign-in:
- openid: confirm your Google account identity;
- email: receive the email address associated with your Google account;
- profile: receive basic account details such as your display name.
This information is used only to create or identify a Dacura account, establish a session and synchronize membership entitlements. It is not used for advertising, reading contacts or email, profiling or analyzing file repair content.
The 127.0.0.1 address shown during Google sign-in is a temporary OAuth callback created by the client on your computer solely to receive the authorization result. It does not mean your account data is sent to another local server. The local listener closes after authorization completes, is cancelled or times out.
You may revoke Dacura's access from the third-party app authorization page in your Google account. Revoking Google authorization does not automatically delete an existing Dacura account. Contact us using the details in this policy to request account deletion.
Google's own privacy policy also governs its processing of relevant information.
5. Verification codes and password sign-in
When you sign in using an email or mobile verification code, we provide the relevant email address or mobile number and verification-code message to the email or SMS provider to the extent necessary for delivery.
Verification codes are valid only for a short period and are subject to delivery-frequency limits, failed-attempt limits and security controls.
For password sign-in, the password is transmitted over an encrypted network connection. The server does not store it in plaintext, but stores a securely processed result used for account verification.
6. Microsoft Store and membership entitlements
When you purchase or subscribe to a Pro membership through Microsoft Store, Microsoft processes Microsoft account, order, payment, license, subscription, renewal, cancellation and refund information under its own rules.
The Dacura client and account service obtain only information needed to confirm membership entitlements, such as:
- Store product identifier;
- Whether a license is valid;
- Subscription status and validity period;
- Identifiers needed for order or entitlement verification;
- Entitlement restoration and synchronization results.
We do not directly collect or store complete payment information such as your bank card number or card security code.
7. Local diagnostic information
Anonymous diagnostics are disabled by default.
Only after you enable diagnostics may the client record necessary diagnostic events locally, including:
- Time of the event;
- Feature event name;
- Application version.
Local diagnostic records do not include the file name, full path or contents of a file selected for repair, account passwords or verification codes, and are not uploaded automatically.
You may disable diagnostics and clear local diagnostic records at any time under Settings — Privacy & Security.
8. Purposes for using information
We process relevant information only as necessary to:
- Provide account registration, sign-in and password reset;
- Send and verify SMS or email codes;
- Complete Google account authorization;
- Create, refresh and terminate device sessions;
- Prevent account theft, verification-code abuse and malicious requests;
- Query, restore and synchronize membership entitlements;
- Process Microsoft Store subscriptions and purchase status;
- Provide customer support and handle account appeals;
- Comply with applicable laws and regulations.
We do not sell personal information to third parties without your explicit consent.
9. Third-party services
We may use the following types of third-party services to provide relevant features:
| Service | Information processed | Purpose |
|---|---|---|
| Alibaba Cloud and other cloud infrastructure | Data needed for account, device and entitlement services | Host online account and entitlement services |
| Google identity services | Google account identifier, email and basic profile | Google account sign-in |
| Microsoft Store | Order, license and subscription status | Purchases, subscriptions and entitlement verification |
| Alibaba Cloud SMS | Mobile number and verification-code content | Deliver mobile verification codes |
| Alibaba Mail | Email address and verification-code content | Deliver email verification codes |
Third-party providers may process information only to the extent necessary to provide the relevant service and are governed by their own privacy policies and applicable laws.
10. Storage and security
Account, device and membership entitlement data is stored on servers in China.
Our security measures include:
- HTTPS-encrypted network communications;
- Lifecycle management for access and refresh tokens;
- Windows DPAPI protection for persisted sign-in credentials of the current user;
- System Keychain and similar platform security on macOS;
- Encryption and integrity checks for temporary repair results;
- Hashing device identifiers;
- Verification-code rate limits, sign-in protection and device revocation;
- Least-privilege restrictions on service and personnel access.
No network, software or storage system can promise absolute security. If a data security incident may affect your rights, we will respond and provide notice in accordance with applicable law.
11. Retention
We retain relevant information only for as long as needed for the purposes in this policy and to meet legal obligations:
- Verification codes are valid only for the short period needed for the current verification;
- Sign-in tokens remain until sign-out, expiration or session revocation;
- Account information remains until the account is lawfully deleted;
- Device and entitlement records remain while needed to provide sign-in and membership services;
- Order and dispute records are retained as required for tax, audit and consumer-protection purposes;
- You control local diagnostic information and may clear it at any time;
- Unsaved temporary repair files are removed under Section 2.
After the retention period, we delete or anonymize information unless applicable law requires otherwise.
12. Your rights
Subject to applicable law, you may request to:
- Access account information we process;
- Correct inaccurate or incomplete information;
- Delete your account and related personal information;
- Withdraw consent previously given;
- Terminate sessions or revoke a device;
- Receive an explanation of our personal information processing rules;
- Submit a complaint or comment about our processing.
You may also:
- Continue using basic local features without signing in;
- Sign out in the client;
- Revoke third-party authorization in your Google account;
- Manage or cancel a subscription in Microsoft Store;
- Disable and clear local anonymous diagnostic records;
- Clear temporary repair cache.
To close or delete an account, email itemir@itemir.com. We may require reasonable identity verification and will respond within the period required by applicable law.
13. Cross-border processing
Google, Microsoft and other third-party providers may process necessary information outside your country or region using their global infrastructure. Their privacy policies describe the relevant locations and safeguards.
Where applicable law requires separate consent, a security assessment or other cross-border safeguards, we will complete those steps before processing.
Files selected for repair and repair results remain on your computer by default and are not transferred across borders merely because you use third-party sign-in or a store subscription.
14. Children
The software is mainly intended for users with full legal capacity and is not directed primarily to children.
A user below the age required by applicable law should use the software only with the guidance and consent of a parent or other guardian. If we learn that a child's personal information was processed without valid consent, we will promptly delete it or take other legally required action.
15. Changes to this policy
We may update this policy to reflect product changes, legal requirements or changes to third-party services.
For material changes, we will provide notice through the client, account center, official website or Microsoft Store listing. Where renewed consent is legally required, we will obtain it before continued use of the relevant feature.
16. Contact us
Personal information controller/operator: Itemir Technology Co., Ltd
Email: itemir@itemir.com