Last updated: September 2026
This Privacy Policy explains which personal data DUCKIER INTERACTIVE FZCO processes when you use the ddownload file hosting service through the website, the mobile and TV apps, the browser extension, the programming interface (API), the affiliate programme and the helpdesk, for which purposes and on which legal basis this happens, to whom data is disclosed, how long it is kept and which rights you have. It is written to meet the information duties of Art. 13 and 14 of the General Data Protection Regulation (GDPR) and the disclosure requirements of the app and extension stores through which our software is distributed.
The controller responsible for the processing described in this Privacy Policy is:
DUCKIER INTERACTIVE FZCO
IFZA Business Park, Building A1
Dubai Digital Park, Dubai Silicon Oasis
Dubai, United Arab Emirates
Commercial register number: 58902
Telephone: +971 50 740 3386
Contact addresses:
This Privacy Policy applies to all products and services that we offer under the ddownload brand, regardless of the way you access them:
Where we additionally offer an app through another app store, the statements in this Privacy Policy apply accordingly. Sign-in to all products is possible with email address and password, with a device code (apps, TV apps, browser extension) or through the sign-in services of Google, Apple or Microsoft. You can protect your account with two-factor authentication. The apps can send push notifications.
This Privacy Policy does not apply to third-party websites, apps or services that you reach through links or that you use together with our products, in particular the app stores, the sign-in services, the payment providers and link protection services. Their own privacy notices apply to them.
When you register, we collect your email address, the username you choose, your password (stored as a salted hash only, never in plain text), the time and IP address of registration and your preferred language (taken from your browser setting or, failing that, from the country of your IP address). Optionally you may add a phone number, a billing address (name, street, city, postcode, country, used for invoices), two-factor authentication (authenticator secret or email code), a list of permitted IP addresses and an API key. During use we store the time and IP address of your last sign-in, the account status (active, blocked, scheduled for deletion, support function restricted), your Ultimate status and term, your notification and email preferences and internal notes made by our support team about your account (for example regarding blocks, refunds or identity checks).
Accounts created in the app without an email address (guest accounts) contain only a generated username, the sign-in data and the device data described in section 3.12 until you add an email address.
Password sign-in: For each successful sign-in we record the time, the IP address, the sign-in method (password, Google, Apple, Microsoft, device code) and the platform (website, app, TV, extension, API) in a sign-in log so that you and we can detect unauthorised access. Failed sign-in attempts are counted per account and IP address for a short time in order to slow down automated attacks.
Two-factor authentication: If you enable two-factor authentication, we store the authenticator secret (for time-based one-time codes) or use one-time codes sent to your email address. We do not store the codes you enter beyond their validity.
Sign-in with Google, Apple or Microsoft: Instead of a password you can register and sign in with your Google, Apple or Microsoft account (Google and Apple also in our apps, Microsoft on the website). You are redirected to the respective provider, which learns that you are signing in to ddownload and, after your approval, sends us your email address and a provider-specific user identifier (with Apple, possibly an anonymised relay address). We store this identifier to match your account on your next sign-in; we request no further profile data (no name, no picture, no contacts). The provider's own processing, including the data it collects about the sign-in, is governed by its privacy notice; the provider acts as an independent controller.
Device code: On TVs, in the browser extension and in the apps you can sign in without entering a password. The device shows a short code, which you confirm on another device where you are already signed in. For this pairing we store the code, the IP address of the requesting device and the time until the code expires (10 minutes). After confirmation the device receives a device token (section 3.3).
When you sign in within an app, on a TV, in the browser extension or through the API, we issue a device token and store with it the platform, the app or extension version, the browser or device identifier (user agent), the IP address at sign-in and at last use and the respective timestamps. You can see all signed-in devices in your account settings and sign each one out individually, which invalidates the token immediately. Signing out in the app or extension also revokes the token on our server.
If you buy Ultimate, a traffic package or another paid service, we process the product, amount, currency, date, chosen payment method, the transaction number assigned by the payment provider, the payment status (paid, refunded, disputed), the IP address and country at the time of payment, the billing address if you have provided one, and the risk rating supplied by the payment provider. We never receive or store full card numbers, card security codes or online banking credentials; these are entered directly with the payment provider.
Payment methods and what each provider receives: Depending on the method you choose, we transmit the data required for the payment (amount, currency, transaction number, email address and, where applicable, billing address and IP address) to the respective provider, which acts as an independent controller under its own privacy notice: Stripe (credit and debit cards, Apple Pay, Google Pay), PayPal, cryptocurrency payments through third-party crypto payment providers, prepaid and voucher payments (prepaid codes and vouchers sold by us or by authorised resellers) and bank transfer. For bank transfers we process the payer name, the amount and the payment reference shown on the bank statement in order to match the payment to your account.
In-app purchases: If you buy Ultimate through Google Play or the Apple App Store, the app sends us the receipt issued by the store (Google: purchase token; Apple: transaction identifier). We verify it through the store's server interface, store the receipt, product, term and renewal or cancellation status in order to link the subscription to your account, and receive notifications from the store about renewals, cancellations and refunds. Your payment details remain with the store, which acts as an independent controller.
Subscriptions: For automatically renewing subscriptions we store the subscription identifier of the payment provider or store, the billing period, the next renewal date and the cancellation status. We do not store your payment instrument ourselves.
Invoices and receipts: We generate receipts for each payment and keep the invoice-relevant details (amount, date, payment method, transaction number, billing address) for the statutory retention period even after the account has been deleted (section 8).
Uploaded files: When you upload a file, we store the file itself, the file name, size, type, checksums, the time of upload, the IP address of the uploader, the folder assignment, the sharing settings (public, private, password protected), an optional description and, for videos and images, generated previews. Anonymous uploads without an account are linked to the IP address of the uploader only.
Access statistics: For each file we keep daily counts of downloads and data volume without IP addresses.
Import functions: At your request our servers fetch content from external sources into your account. For remote uploads we store the source address and status. For torrent imports we store the magnet link or torrent file, its info hash, the file names, progress and result; during a torrent import our servers connect to other participants of the respective torrent network, who see the IP address of our server, not yours. When importing link containers (DLC) and when extracting archives we store the contained links or the archive password you provide only for the duration of the job. If you use FTP access, we log the username, time, IP address, path and file name of each transfer.
Deleted files: Deleted files are moved to a trash folder first and are permanently removed after the periods stated in section 8. Files removed following a copyright complaint or a violation of our Terms are recorded in a blocklist by checksum and size, which contains no personal data, so that the same file cannot be uploaded again.
Web server and API logs: For each request to our website, our API and our storage servers, the receiving system records the IP address, date and time, requested address, HTTP status, transferred data volume, referring page, browser identifier (user agent) and, where you are signed in, the account identifier. These logs are used for operation, error analysis, capacity planning and security.
Download activity: For each download we store, for a short period stated in section 8, the file, time, IP address, browser identifier, browser language, referring page, data volume transferred, result (completed, aborted, refused) and, if the uploader takes part in the affiliate programme, the reward credited to them. This data serves to enforce download limits, to detect abuse and to settle commissions. Download links are signed with your IP address and are valid only for a short time; the storage server that delivers the file sees your IP address. From the individual records we generate daily statistics per account and file without IP addresses.
Page views of purchase and offer pages: When you open purchase, offer or discount pages, we log the page, account and IP address in order to detect misuse of discount offers.
Error and security logs: Application errors, payment notifications, rate-limit events and security events (for example blocked requests, detected automation, suspicious sign-ins) are logged with IP address, account identifier, time and the technical cause.
We determine the country and the network operator (autonomous system) of an IP address, and whether the address belongs to a data centre, an anonymisation or proxy service or a Tor exit node. This lookup is performed locally on our systems using geolocation databases licensed from a provider of geolocation data and the public list of Tor exit nodes; no IP address is transmitted to the database provider. We use the result to pre-select the language, to show the payment methods available in your country, to restrict uploads from certain countries, to enforce country restrictions and for the abuse and fraud checks described in section 9. We do not determine your precise location; the apps do not request location permissions.
If you contact us through the helpdesk, by email or through the contact form, we process your email address, the name you give, the content of your messages and any attachments, the time of each message, the account concerned and, for helpdesk tickets, the IP address from which the ticket was created. Support staff can see the account data described in section 3.1 in order to answer your request. Identity documents or proof of address that we request in individual cases (for example before an affiliate payout or when restoring access to an account) are stored in the ticket and deleted after the check is completed (section 8). We may restrict the helpdesk function for accounts that misuse it; this is recorded in the account.
If you take part in the affiliate programme, we additionally process your chosen payout method and the payout details required for it (for example PayPal address; for bank transfer the account holder's name, IBAN, BIC, bank and country; for cryptocurrency payouts the wallet address), your earnings and payout history, the downloads and purchases attributed to you (without the personal data of the downloading users) and the referring pages recorded for attribution. Before a payout we may request proof of identity or address in individual cases where this is necessary for fraud prevention or required by law. Affiliate earnings notices can be sent to you as push notifications (section 3.10) or by email.
Only if you enable notifications in the app do we store a push token issued by the push delivery service of the app framework, together with platform, language and app version. Messages (currently earnings notices of the affiliate programme) are handed to that push delivery service, which forwards them to the push service of the respective operating system vendor (Google for Android, Apple for iOS). These services receive the token and the message text, not your account data. You can disable notifications at any time in the app or in the system settings; the token is then deleted.
Purpose: The optional ddownload browser extension recognises ddownload links on the web pages you visit, shows file name and size, and lets you download files through your browser with your account.
Sign-in and local storage of the account key: You sign in with a device code (section 3.2) or with email address and password. The extension then stores your account identifier, your API key, a device token and your email address exclusively in the local storage of your browser (not in the browser's synchronisation). A device session is created on our server (section 3.3). All local data is removed when you sign out or uninstall the extension; the device token is revoked on our server when you sign out.
Page scanning: In order to recognise links, the extension uses the permission to access the pages you visit and checks their content locally in your browser for links to ddownload.com, ddl.to and ddl.ch. The address and content of the pages you visit are not transmitted to us. Only the file codes found are sent to our server to retrieve the file name and size; this request contains no account data, and our server sees your IP address. Automatic detection is switched on by default and can be switched off in the extension settings, after which scanning happens only when you click the extension icon.
Link protection services: At your request the extension resolves links from link protection services of third parties (for example filecrypt, cript.to, hide.cx). These requests are made from your browser with any cookies you hold for those sites, and the operators of those services see your IP address; their own privacy notices apply.
Downloads: When you start a download, the extension requests a download link from our API with your account key, and your browser downloads the file from our storage server, which sees your IP address as with any download. Your download queue (file code, name, size, status), language, theme and target folder are stored locally only.
No analytics, no advertising: The extension contains no analytics or advertising components, does not read form input or passwords, does not track your browsing history and uses page content solely for link detection. Data obtained through the extension is used only to provide and improve the functions described here; it is not sold, not used for advertising, not used to determine creditworthiness and not transferred to third parties for their own purposes.
Device identifier: When you create an account from the app, the app sends a per-device identifier (Android: an identifier provided by the operating system; iOS: a random identifier generated on first launch and stored in the Keychain, which may survive reinstalling the app). We store only a salted hash of this identifier and use it solely to grant the one-time welcome data allowance once per device and to track how much of it has been used. It is not used for advertising, profiling or tracking across apps.
Crash and error reports: To find and fix defects, the app sends automatic crash and error reports to a provider of error and crash reporting services acting as our processor. A report contains the error and its stack trace, a short trail of the actions leading up to it, and technical context such as device model, operating system version and app version. It does not contain your account data, your file names or the contents of your files; personal data collection is switched off in the reporting component. Crash reporting is active only in released builds.
Automatic folder backup (Android, Ultimate): The app offers an optional automatic backup that is switched off by default. When you enable it, the Android folder picker asks you to select exactly one folder; the app receives access to that folder only, reads the name, size and content of the files stored directly in it (not in subfolders) and uploads them to a dedicated backup folder in your account, where they are treated like any other file. You can switch the feature off in the app or revoke the folder access in the system settings at any time.
Local storage on the device: Sign-in credentials are held in the protected storage of the operating system (Keychain or Keystore). File lists, recently opened files, offline copies, the app-lock PIN (as a hash) and the vault PIN are stored on the device only and removed when you sign out or uninstall; offline copies remain until you delete them.
Streaming to other devices (Chromecast, AirPlay): When you stream to a device on your local network, the app searches the local network for suitable devices with your permission and hands the playback link to the target device.
App updates: On launch the app checks for updates with the update service of the app framework or with ddownload.com. This transmits your IP address, app version and platform, but no account data.
Direct download as APK: If you download the Android app as an APK file from our website, the download is logged like any other download from our website (section 3.6).
No advertising or tracking: The apps contain no advertising or tracking components and do not request location, contact or microphone permissions. Photo and file access is requested only when you choose files to upload or enable the automatic backup.
On TVs you sign in with a device code (section 3.2). The TV app stores the device token, your language and your volume setting locally on the TV until you sign out or remove the app. Videos are streamed directly from our storage servers, which see the IP address of the TV. The TV apps contain no advertising, analytics or crash reporting components. The stores through which you install the TV apps (Amazon Appstore, Samsung, LG) process installation and, where applicable, purchase data as independent controllers under their own privacy notices. For the web version for TVs, the statements on usage data and cookies in sections 3.6 and 5 apply.
If you use the API with your API key, we log each request with IP address, time, endpoint, account and result, as described in section 3.6. If you build your own application on the API and offer it to other people, you are the controller for the data processed in your application; we see only the IP address of the calling system and the account of the API key used.
Transactional emails: We send emails that are necessary for the contract and the security of your account, for example email confirmation, password reset, two-factor codes, purchase confirmations, payment and renewal notices, deletion confirmations, sign-in notices and changes to our Terms or this Privacy Policy. These emails are delivered through email delivery providers acting as our processors, which receive the recipient address, subject and content.
Renewal reminders and offers: If you have bought Ultimate, we send you email reminders and renewal offers for the same service before your term ends (usually 7, 3 and 1 day before expiry). We record which of these emails were sent to your account so that you receive each one only once. You can opt out at any time via the link in each email or the switch for promotional emails in your account settings. Newsletters to users who have never made a purchase are sent only with your consent.
Besides the data you provide and the data created during use, we receive: from the sign-in services (Google, Apple, Microsoft) your email address and user identifier when you use them; from payment providers and stores the payment status, transaction number, risk rating, refund, dispute and chargeback notices and the country and type of the payment instrument; from rights holders and other reporters the file addresses and the information given in their reports; from a provider of geolocation data the databases described in section 3.7; and from the public Tor exit list the addresses of Tor exit nodes.
For the data safety and privacy declarations of the stores, the following applies to our apps and the extension: We collect contact data (email address), account identifiers, device and session identifiers, purchase history (in-app purchases), diagnostic data (crash reports in the mobile apps) and technical usage data (IP address, app version). Data is transmitted encrypted. We do not sell data, do not use it for advertising and do not use third-party advertising or analytics components. Users can request deletion of their data through the account settings or by email (section 10). The browser extension processes web page content only locally for link detection and transmits only file codes.
We process personal data for the following purposes on the following legal bases:
Providing an email address and password (or sign-in through Google, Apple or Microsoft) is necessary to create an account; without it no registered account can be created. The apps may be used with a guest account without an email address in a limited way. All other details are voluntary; without a billing address we cannot issue an invoice with your address, and without payout details we cannot pay out affiliate earnings.
Strictly necessary cookies: "xfss" keeps you signed in (session cookie, HttpOnly); "login" remembers your sign-in for up to 30 days if you choose "stay signed in"; "guest_pw", "transaction_id", "renew_offer_token" and "file_id" briefly hold the state of a purchase or sharing process. These cookies are necessary for the service and require no consent.
Functional cookies: "lang" (language) and "design" (display settings). These store your choices and require no consent.
Affiliate programme: When you open a download link we set the session cookie "aff" containing the identifier of the uploader and, where applicable, store the referring page ("ref_url"), so that a commission can be attributed to the uploader if you later buy Ultimate. The cookie contains no information about you, is not passed to third parties and expires with the browser session. The legal basis is our legitimate interest in operating the affiliate programme (Art. 6(1)(f) GDPR); you may delete or block the cookie at any time without any restriction of use.
No analytics or advertising cookies: We do not use any third-party web analytics or tracking service and set no analytics or advertising cookies. Usage statistics are compiled solely from our own server data in aggregated form.
The website loads all fonts and script libraries from our own servers. Beyond that, the following third-party services are embedded on individual pages. When such a page loads, your browser connects directly to the respective provider, which receives your IP address, your browser identifier and the address of the page you are viewing; no account data is transmitted.
Bot protection: On the sign-in, registration, payment and download pages we use a bot protection service of a security service provider that checks whether a person is operating the page. The service loads a script from the provider's domain, evaluates technical characteristics of your browser and may set its own cookies for this check; they are not used for advertising. The purpose is the defence against automated abuse; the legal basis is our legitimate interest in protecting the service against automated access (Art. 6(1)(f) GDPR).
Reviews on Trustpilot: On the homepage we show quotations from customer reviews as static text, and on the homepage and after registration we link to our profile on the review platform Trustpilot. No script from Trustpilot is loaded, and no data is transmitted to Trustpilot when the page is opened. Only if you follow the link does Trustpilot A/S, Copenhagen, Denmark, process your data as an independent controller under its privacy policy at https://corporate.trustpilot.com/legal/for-reviewers/privacy-policy-end-user. The legal basis for showing the quotations and the link is our legitimate interest in presenting customer feedback (Art. 6(1)(f) GDPR).
Chart library on the affiliate report page: The report page of the affiliate programme uses the Google Charts library to draw charts; it is loaded from Google only when you open that page. Google Ireland Limited, Dublin, Ireland, thereby receives your IP address and the technical request data mentioned above and processes them as an independent controller under its privacy policy at https://policies.google.com/privacy. The purpose is the graphical presentation of your earnings; the legal basis is our legitimate interest in a clear presentation of the report (Art. 6(1)(f) GDPR).
No advertising networks, no analytics: We do not embed any advertising networks and no analytics or tracking services.
Our apps, TV apps and the browser extension do not use cookies. They store sign-in tokens and settings in the local storage of the device or browser as described in sections 3.11, 3.12 and 3.13. This data remains on your device and is removed when you sign out or uninstall.
We disclose personal data only where this is necessary for the purposes described above, where you have consented or where we are legally obliged to do so. Recipients fall into the following categories:
Processors that act on our behalf and under our instructions on the basis of data processing agreements pursuant to Art. 28 GDPR:
Independent controllers that process your data under their own privacy notices:
We do not sell personal data and do not share it with third parties for their advertising purposes.
We are established in the United Arab Emirates. Our processors and the other recipients listed in section 6 process data within the European Economic Area as well as in third countries. Where personal data of persons in the EEA is transferred to a third country for which the European Commission has not adopted an adequacy decision, we rely on appropriate safeguards, in particular the standard contractual clauses of the European Commission, supplemented by technical and organisational measures such as encryption in transit, encrypted backups, access controls and data minimisation. Where a transfer is necessary for the performance of your contract (for example a payment to a provider you have chosen) or is based on your explicit consent, Art. 49 GDPR applies. You can request further information on the safeguards in place and, where applicable, a copy of them at [email protected].
We keep personal data only for as long as necessary for the respective purpose or as required by law. On expiry, data is deleted or irreversibly anonymised. The following periods apply:
To protect the platform against abuse (in particular account takeover, commercial resale of access, circumvention of limits, copyright infringement and payment fraud), we evaluate certain events automatically and, in some cases, make automated decisions:
The legal basis is our legitimate interest in security, abuse prevention and the protection of the rights of third parties (Art. 6(1)(f) GDPR) and, as far as the decision is necessary for the performance of the contract, Art. 22(2)(a) GDPR. Where such an automated decision produces legal effects concerning you or similarly significantly affects you, you have the right to obtain human intervention, to express your point of view and to contest the decision. To do so, contact [email protected] or [email protected]; a member of our team will review the decision and inform you of the outcome. We do not use automated decision-making for any other purpose and do not create profiles for advertising.
Under the GDPR you have the following rights with regard to your personal data:
To exercise your rights, contact [email protected] from the email address of your account or use the functions in your account settings. We may ask you to confirm your identity, for example by signing in or by replying from the registered email address, to protect your account against requests by unauthorised persons. We respond within one month of receipt; for complex or numerous requests we may extend this period by up to two months and will inform you of the extension and its reasons. Exercising your rights is free of charge unless requests are manifestly unfounded or excessive.
Our products are intended for adults. You must be at least 18 years old to create an account, to purchase Ultimate or to take part in the affiliate programme. We do not knowingly collect personal data from persons under 18. If you believe that a person under 18 has provided us with personal data, please contact [email protected] and we will delete the data and the account.
We apply technical and organisational measures appropriate to the risk in order to protect your data against unauthorised access, loss, destruction and alteration, in particular:
You contribute to the security of your account by choosing a strong, unique password, enabling two-factor authentication, keeping your API key and device tokens confidential, signing out devices you no longer use and informing us immediately at [email protected] if you suspect unauthorised access.
We may update this Privacy Policy when our products, the law or our processing change. The current version with its date is always available at ddownload.com/privacy and in the apps and the extension. For material changes, in particular new purposes, new categories of recipients or changes that reduce your rights, we will inform registered users by email to the address on file or by a notice at sign-in before the changes take effect. Earlier versions are available on request at [email protected].
For all questions about this Privacy Policy and the processing of your personal data, and to exercise your rights:
DUCKIER INTERACTIVE FZCO
IFZA Business Park, Building A1
Dubai Digital Park, Dubai Silicon Oasis
Dubai, United Arab Emirates
Commercial register number: 58902
Telephone: +971 50 740 3386
Data protection: [email protected] Data protection officer: [email protected] Support: [email protected] Legal infringements and copyright complaints: [email protected]