Privacy, in plain words.
The operating system, website, checkout and support form do different things, so this policy keeps them separate. Effective 5 September 2026.
The operating system
The installed operating system sends no product telemetry or analytics to Dagric. This does not mean bundled applications never send data to their publishers: Firefox's data collection is explained below. There is no required Dagric account and no Dagric advertising identifier. Dagric does not automatically collect your files or application history; applications you use for browsing, sync or uploads have their own data-handling settings. Network requests needed for updates, browsing and optional services are listed below. Website visits, purchases, downloads and support messages are covered separately later on this page.
Documented Dagric-configured and known stock-system connections. Where a connection is on by default and can be switched off, the item says so and explains how. This inventory covers the connections Dagric configures plus the stock-system connections identified in this review; it is not a claim that every optional app or future upstream version makes no additional request. Items marked Pro are on the paid edition only, and optional third-party applications may make additional requests under their own privacy terms.
- Debian's mirrors, for system updates and anything you install.
- Our purchase-entitlement check (
dagric-gate.dagric.workers.dev) — contacted only by the Hub's or setup wizard's Upgrade to Pro flow, only after you paste the purchase code from your receipt, and never otherwise. It sends two things: that code, so we can ask Stripe whether the purchase is real, and an anonymous machine fingerprint — a one-way hash of a hardware identifier salted with your purchase code. The fingerprint enforces one active guided-upgrade/support service slot per single-machine purchase; it cannot be turned back into a serial number, and the same hardware produces a different value for every purchase, so it cannot track a machine across customers, sessions, or anything else. If you never start the upgrade, this host is never contacted. We keep, against your purchase, only what enforces that service slot: the fingerprint and the dates it was first and last seen. There is no raw serial number or IP address in that activation record. Ask support with your purchase if a replacement machine needs the slot moved, or if you want the activation record deleted. Browser-download records are described under This website and checkout below. - Our update channel (
dagric-os.web.app), which carries fixes to Dagric's own tools, wallpapers and settings. It is checked on the same schedule as any other software source, so we see the same thing a Debian mirror sees: an IP address asking for a package list. We do not log it for analytics and there is no identifier in the request. Remove/etc/apt/sources.list.d/dagric.listand it stops for good — the rest of the system keeps updating from Debian. - A time server (
debian.pool.ntp.org), so the clock is right. This matters more than it sounds: with a wrong clock your computer refuses security updates outright, because it cannot tell whether the signatures on them are still valid. Dual-booting Windows, or a laptop whose small internal battery has died, both put the clock out on their own. Stop it withsudo systemctl disable --now chrony— but then nothing keeps the clock right, and updates can stop. - Flathub. The Flathub remote is added while the disc image is being built, so it is configured before you have done anything at all, and three separate things reach it. The software centre contacts it to list or install a Flatpak app — browsing is enough, because the app list itself is fetched from there. The software centre's update notifier starts with your desktop session and checks it for Flatpak updates without being asked. And eight of the Hub's one-click installers — Bottles, Cryptomator, Heroic, Joplin, LocalSend, ONLYOFFICE, ProtonUp-Qt and Upscayl — install from Flathub directly, with the software centre not involved.
- The KDE Store (
store.kde.org), which is behind every Get New Wallpapers…, Get New Global Themes… and Get New Widgets… button — in System Settings, and on the desktop's own right-click menu. Nothing is fetched until you press one; then a listing of what other people have uploaded comes back. Read the rest of this before you press one. We do not vet any of it, and a Plasma theme or widget is not a picture — it is a program, and it runs in your session. Dagric's own wallpapers and styles are already on the disc and need none of this. - Mozilla's add-on site, only when you browse or install an add-on yourself. Dagric does not preinstall or force any Firefox extension. An extension you choose may contact Mozilla for installation and updates; remove it under ☰ → Add-ons and themes to stop those extension-update checks.
- Firefox's data collection. Dagric ships Debian's Firefox ESR package without Dagric-specific browser policy or changed first-run settings. Dagric does not disable Firefox's data collection: Firefox can automatically send Mozilla information about browser performance, device configuration and how its features are used. These reports go to Mozilla, not Dagric. Review ☰ → Settings → Privacy & Security → Firefox Data Collection and Use to turn off technical and interaction data collection if you prefer. The daily usage report has a separate control; turning off technical and interaction data does not turn that report off. See Mozilla's technical and interaction data guide and daily usage report guide. Available controls and defaults can vary with the Debian ESR version; review the other choices shown there, including crash reports.
- Firefox's security and connection services. Safe Browsing
downloads lists of harmful sites and can make follow-up checks using partial information
derived from a site's address. Certain download checks can send Google the file's name,
origin, size and a cryptographic hash. This is not a promise that no browsing-related data
leaves the browser. Mozilla explains the checks and controls in its
phishing
and malware protection guide; switching this protection off reduces protection against
dangerous sites and downloads. Firefox also checks
detectportal.firefox.comfor network-login requirements and fetches settings and blocklists from Mozilla. Not every connection has a switch in the ordinary Settings page; Mozilla's automatic connections guide explains the individual controls and their trade-offs. - Encrypted DNS. Firefox keeps Debian and Mozilla's current defaults; Dagric neither forces a resolver nor locks the setting. Review or change it at ☰ → Settings → Privacy & Security → DNS over HTTPS. Chromium on Pro is set so your existing resolver is used over an encrypted connection when that resolver supports one, and plain DNS otherwise; no fixed provider is pinned. You can point either browser somewhere else or switch encrypted DNS off entirely. Be clear-eyed about the trade: this moves who can watch your lookups from the network operator to the resolver. On public Wi-Fi that is a plain win; on your own home connection it is closer to a lateral move.
- Your Wi-Fi hardware address is now different on every network. This is not an outbound connection, but it is the kind of thing this page exists to disclose. Every wireless card has a permanent, globally unique serial number that it announces to every access point in range, and it is the single most effective way a person is followed between physical places. Dagric sets a stable per-network address instead: constant for your home Wi-Fi, so your router still recognises the laptop and your DHCP reservation still works, and different for the café, so the two cannot be joined up. Wired connections are deliberately left alone, because there is no walking-past problem on a cable and school and office networks authenticate by that address. If a network filters by hardware address and refuses you, the override is per-connection, in Wi-Fi settings → Advanced → Restrict to device.
- Google's Widevine module. Some streaming services require DRM. The module is proprietary and is not on the disc image; Firefox may offer or fetch it according to Firefox's own current settings when protected playback is requested. Dagric does not force or lock that choice. Review it under ☰ → Settings → General → Play DRM-controlled content, and those services stop working.
- Chromium's own services (Pro). Pro ships a second browser, for the site that has only ever been tested against Chrome. Chromium is what Google Chrome is built from with Google's proprietary parts taken out, and Debian builds it without the API keys that Chrome Sync and the Google account features need — so those genuinely do not work here. What is left still talks to Google-operated servers on its own: a connectivity check, so it can tell a hotel Wi-Fi page from a broken network, and update checks for any extension you add from the Chrome Web Store. Dagric leaves Firefox's browser configuration to Debian/Mozilla and does not claim to have audited either publisher's changing online services. Nothing in Dagric launches it; Firefox is the default browser and stays the default until you change it.
- Mozilla again, and your own mail provider (Pro), for Thunderbird. It fetches its settings and blocklists from Mozilla exactly as Firefox does. Adding an account does one more thing worth knowing about: rather than make you type a page of server names and port numbers, Thunderbird looks them up — it sends the domain part of the email address you entered to Mozilla's configuration database, and asks your mail provider's own servers directly. This is one example on this page of a feature transmitting something you typed. Choose Configure manually at that screen and it asks nobody.
- lutris.net (Pro), because the gaming launcher is a catalogue and the catalogue is not on the disc. Lutris asks lutris.net's API for the list of game installers and for the runner and runtime versions a game needs; without that request it has nothing to show you. It is normal operation, not a prompt — it happens when you open Lutris. Nothing starts it for you.
- Syncthing's discovery and relay servers (Pro). Syncthing does not run until you start it. Once you do, it announces this machine's device ID and its network addresses to Syncthing's global discovery servers, and registers with the public relay pool, which is how two of your own machines find each other across the internet without you configuring anything. That device ID is a stable identifier for the computer. Switch both services off in Syncthing's own settings page — Actions → Settings → Connections, clear Global Discovery and Enable Relaying — after which your devices find each other only on the same network, or at addresses you type in yourself.
- GitHub, Valve and Blackmagic Design, only when you pick the matching row in the Hub, and only after the confirmation screen that tells you exactly what will be installed: Local AI fetches a pinned Ollama release archive from Ollama's official GitHub project and verifies its reviewed SHA-256 checksum before installation, GE-Proton for Steam fetches a release from GitHub, Steam installs Valve's installer package from Debian and Steam then updates itself from Valve on first run, and DaVinci Resolve opens Blackmagic Design's download page in your browser, because Dagric has not obtained permission to redistribute that software. The Hub's other installers use Flathub — see above.
- The Linux Vendor Firmware Service, which is how your laptop learns a
firmware update exists. It fetches a catalogue; it does not upload your hardware list.
Switch it off with
sudo systemctl disable --now fwupd-refresh.timer. - KDE's crash handler is installed, so a crashed application offers you a report. It never sends anything unless you read that dialog and choose to send it, and we receive none of it — it goes to KDE, not to us.
- Phone pairing (KDE Connect) starts with your desktop session on both
editions and announces this computer on your local network — a small broadcast
carrying the computer's name and a stable device identifier, so your phone can find it in the
pairing list. It goes no further than your own network: nothing is sent to us or to any
third party, and no pairing happens without you accepting it on both devices. It starts with
the desktop session and carries an identifier, which is exactly why it is named here. To stop
it, untick KDE Connect in
System Settings → Startup and Shutdown → Autostart, or remove the
kdeconnectpackage.
Internet requests reveal your IP address to the server being asked, as they do on any Linux distribution. Dagric adds no product-usage report to those requests. Some third-party programs process additional information when you turn on their services or sign in; their own privacy terms apply. Identifiers specifically worth calling out include the per-purchase service-slot fingerprint, KDE Connect's local announcement, and Syncthing's discovery identifier. Their different purposes and trigger conditions are described above.
To be precise about a phrase that is easy to over-read: “no telemetry” means Dagric does not add a system that reports how you use the installed OS to us. It does not mean the machine never talks to anyone — it checks for updates, fetches firmware metadata, and your browser contacts its own services. It also does not describe data you provide on this website, at Stripe checkout, or in a support message; those are disclosed below. Security says the same thing beside the rest of what we know is imperfect.
This website and checkout
- Local theme preference. If you switch this site between light and dark,
your browser stores one value named
dagric-themein local storage. It stays in your browser, is not an advertising identifier, and can be removed by clearing site data. Dagric.com itself sets no cookies. - Hosting and delivery. Google Firebase Hosting serves the pages. Cloudflare Workers and R2 serve the contact form and ISO downloads. Those providers process ordinary request data such as IP address, time, user agent, requested URL, routing and security signals to deliver and protect the services. We do not add Google Analytics, advertising scripts, pixels or cross-site trackers. See Firebase privacy and security and Cloudflare's privacy policy.
- Checkout and receipts. Stripe receives the email and payment details you enter, plus transaction, fraud-prevention and device/network data described in Stripe's privacy policy. Stripe may offer its optional Link service under its own terms. We receive the order details needed to deliver and support Pro: the checkout-session identifier, email and name if supplied, item, amount, payment status and later refund or dispute status. Your full card number and security code never come to us. Stripe can retain transaction data for payment, tax, accounting, fraud and legal duties under its own policy.
- Pro delivery. After checkout, Stripe places a checkout-session identifier in the private download URL. Treat that URL like a receipt: anyone you give it to may attempt to use your download allowance. Our Cloudflare gate asks Stripe whether the session completed, bought Dagric Pro and was later refunded. Cloudflare KV keeps the cumulative number of bytes served for that session to stop a shared link becoming a public mirror. If you use the in-place upgrade instead of downloading the ISO, it also keeps the salted machine fingerprint and first/last-use dates described above. Dagric does not put a raw hardware identifier or IP address in those KV records, although Firebase, Cloudflare and Stripe may process request logs under their policies.
- The contact form. Sending it saves what you typed — topic, message, and the name and email you choose to give — as a private file in Cloudflare R2 that only authorized Dagric operators can read. Cloudflare supplies the two-letter request-country code, which is stored with the message. The worker uses the IP address transiently for rate limiting but does not write it into the message. We use the submission to reply and handle support, refunds, security or legal requests; we do not add it to a marketing list.
- Support email. If you write to support@dagric.com instead, Microsoft 365 processes and stores the message for IMPRESSIONSDIRECT360 LLC. We use it to reply and handle the request, and nothing more. See Microsoft's privacy statement.
Purpose, retention and security
We use order information to deliver Pro, enforce the machine allowance, provide support, handle refunds and disputes, prevent abuse, and meet tax and accounting duties. Purchase and financial records are retained for as long as those duties and legitimate support needs require. Delivery and activation records remain while the related entitlement and re-download support are active, unless support deletes or resets them. Contact-form messages are automatically deleted from the private contact bucket 365 days after they are received and may be deleted sooner when they are no longer needed. You can ask us to delete a message at any time. If law, fraud prevention, a dispute or a refund requires a separate record, we retain only the record needed for that purpose.
Pages and forms use HTTPS. Contact messages and Pro files are in private Cloudflare buckets, access is restricted to the operator accounts that need it, and the site uses a restrictive Content Security Policy. Support email is protected by Microsoft 365 access controls. No internet service can promise perfect security; if we learn of a breach that requires notice, we will provide it as required by applicable law. Firebase, Cloudflare, Microsoft and Stripe operate globally, so their processing may occur outside your country, including in the United States.
What we never do
- Sell, rent, or share your data with advertisers or brokers.
- Fingerprint a browser or device for advertising, analytics, profiling, or cross-site tracking. This does not describe the disclosed per-purchase service-slot hash used only after you start the guided Pro upgrade.
- Require an account to use, update, or keep the software you bought.
Your choices and rights
Use the contact page to ask what Dagric holds about you, correct it, request a portable copy, object to or restrict a use, or ask for deletion. In practice that can include a Stripe order, delivery/activation records and messages you sent us. We may need proof that you control the purchase email or session before disclosing or changing an order record, and some financial or dispute records must be retained. Rights over data Stripe controls can also be exercised through Stripe's Privacy Center. Depending on where you live, you may also complain to your local privacy regulator.
Children and changes
The website and paid checkout are directed to people able to make a purchase or to a parent or guardian acting for a household. Dagric OS can be used by children without creating a Dagric account, but children should not send personal information through the contact form without a parent or guardian.
We will update the effective date when this policy changes. Material changes apply prospectively and will be stated plainly on this page.