How dhytte.no Keeps Your Cabin Data Safe and Private
---
How dhytte.no Keeps Your Cabin Data Safe and Private
Why Security and Privacy Matter for Cabin Data
Your cabin guest book, maintenance records, visitor list, and family photos aren't trivial documents. They contain:
- Location data: Where your cabin is and when you're not there
- Personal information: Names, relationships, contact information of family members and guests
- Visual records: Photos of your cabin, surrounding area, and property condition
- Activity logs: When the cabin is occupied, when it's empty, who visits frequently
- Financial records: Maintenance costs, rental income, property value indicators
In the wrong hands, this information could be used for property theft, break-ins, family surveillance, or identity theft.
If you're using a digital cabin log—whether dhytte.no or another platform—you need absolute confidence that your data is secure and private.
dhytte.no's Security Architecture
1. End-to-End Data Encryption
- All communication between your device and dhytte.no servers uses HTTPS encryption (TLS 1.2+)
- Your data is encrypted on the server using industry-standard encryption (AES-256)
- Only your family members (those with access to your cabin) can decrypt and view the data
- Even dhytte.no employees cannot read your cabin logs without proper authorization
2. Authentication & Access Control
- Two-factor authentication (2FA) is available for all accounts
- You invite specific family members by email; they accept the invitation
- Each family member has individually verifiable access
- You control who can view, add entries, or manage bookings
- You can revoke access instantly if needed
- Access logs show who logged in and when
3. Data Residency & Compliance
- Cabin data is stored in [EU/regional data centers] with compliance to GDPR (General Data Protection Regulation)
- Data is not transferred to third countries without explicit consent
- Backup systems are geographically distributed for redundancy (not in countries with weaker privacy laws)
4. Regular Security Audits
- Independent third-party security audits annually
- Penetration testing (attempting to break into the system)
- Vulnerability scanning and patching
- Code reviews for security issues
- Security certifications (SOC 2, ISO 27001 or equivalent)
5. Password Security
- Passwords are never stored in plain text—only hashed with bcrypt
- Minimum password complexity requirements
- Password reset uses secure email verification
- Passwordless authentication options (passkeys, biometric login)
- Sessions expire after inactivity to prevent unauthorized access
Privacy: What We Know (And What We Don't)
What dhytte.no Collects
-
Your email address and name
-
Your cabin's name and location (required to organize your records)
-
Family member names and email addresses (to invite them)
-
Guest list entries you create (visitor names, dates, activities)
-
Photos you upload
-
Maintenance records you log
-
Booking information you enter
-
Browser type and version (to ensure compatibility)
-
General location (country level, not precise)
-
Usage patterns (which features you use most, how often you log in)
-
Error reports (to fix bugs)
What dhytte.no Does NOT Collect
-
Your precise location data or movement patterns
-
Financial information (we never store credit cards—payment is processed through secure third parties like Stripe)
-
Device IDs or cross-device tracking
-
Biometric data (unless you enable fingerprint/face login, which stays on your device)
-
Health information (we don't infer medical conditions from guest visits)
-
Photos' metadata (GPS coordinates from photos are stripped before storage)
-
Your data with advertisers
-
Your email with marketing firms
-
Your cabin location with anyone without permission
-
Your family relationships with data brokers
-
Anything without your explicit consent
Data Retention & Deletion
How Long We Keep Your Data
- Active accounts: Data is kept as long as you use the service
- Inactive accounts: After 12 months of no login, your account enters dormancy
- Deletion requests: Upon your request, all data is deleted within 30 days (except as required by law)
- Backup retention: Backups containing your data are kept for [e.g., 90 days] before being purged
Your Right to Your Data
- You can download all your data in standard formats (JSON, CSV, PDF)
- You can export your cabin log as a PDF or digital archive
- You can request deletion of specific entries
- You can permanently delete your entire cabin record
Photo Privacy & Image Security
Photo Handling
- Photos are never shared or displayed publicly without your permission
- Photos are scanned for malware before storage
- Photo metadata (location, camera model, timestamp) is preserved in encrypted form
- You control who can view each photo (family members, specific guests, private)
AI & Automated Processing
-
dhytte.no does NOT use AI to analyze photos for:
- Facial recognition
- Object detection (identifying valuable items in your cabin)
- Location analysis
- Anything that could be used for targeting or theft
-
We may use AI for:
- Photo organization (automatic date detection, album suggestions)
- Search functionality (finding "photos from 2023" or "beach activities")
- Spam/malware detection
All automated processing is done to improve your experience, not to profit from your data.
Sharing & Guest Access
Controlled Sharing
- You choose which family members see the full cabin log
- You can create read-only links for specific guests
- You can set expiration dates on guest access
- You can require passwords for shared links
- You control whether guests' contributions are visible to all family members or private
What Guests Can See
When you share a booking confirmation or guest log with a visitor:
- They see basic cabin information (address, WiFi, house rules)
- They see their assigned dates
- They don't see other families' booking dates (privacy)
- They don't see your financial records or maintenance details
Third-Party Services
What We Use (And Why)
- Firebase/Cloud services: For secure data storage and backup
- Stripe (payment): Credit card processing (we never see your card number)
- SendGrid (email): Sending account notifications and invitations
- Cloudflare (CDN): Delivering content quickly and protecting against attacks
What We Don't Do
- We don't integrate with Meta/Facebook, Google Analytics, or other ad networks
- We don't allow third-party widgets or tracking pixels
- We don't share data with data brokers or lead-gen companies
- We don't use your data to train AI models (without explicit consent)
How to Protect Your Cabin Data
Even with our security, you have a role in protection:
Password Security
- Use a strong, unique password (15+ characters, mix of types)
- Use a password manager (1Password, Bitwarden, LastPass)
- Never share your password
Two-Factor Authentication
- Enable 2FA on your dhytte.no account
- Enable 2FA on your email account (your email is the reset mechanism)
- Use authenticator apps, not SMS (SMS can be intercepted)
Access Management
- Invite only family members you trust
- Review access regularly—remove co-owners if relationships change
- Use separate accounts for different purposes (owner vs. guest)
- Log out after use on shared devices
Photo Practice
- Don't photograph sensitive information (insurance documents, financial records)
- Don't photograph valuable items in detail (that's what insurance photos are for)
- Consider disabling geo-tagging on your camera
- Strip metadata from sensitive photos before uploading
Transparency & Accountability
Your Rights
Under GDPR and similar privacy laws, you have:
- Right to access: Know what data we hold about you
- Right to rectification: Correct inaccurate data
- Right to deletion: Request we delete your data
- Right to portability: Download your data in usable format
- Right to object: Opt-out of processing you disagree with
- Right to complain: Report to your local data protection authority if we violate privacy
To exercise these rights, contact [privacy@dhytte.no] or submit a Data Subject Access Request.
Incident Response
If dhytte.no discovers a security breach:
- You will be notified immediately (within 24–72 hours)
- We'll explain what data was compromised
- We'll outline steps you should take (password reset, monitoring, etc.)
- We'll cooperate with relevant authorities
Privacy Policy Updates
Our full privacy policy is available at [https://dhytte.no/privacy]. We review it annually and notify users of material changes.
What Makes dhytte.no Different
Many apps claim to be "secure" or "private," but few prove it. Here's what sets dhytte.no apart:
- Transparency: Open about what we collect, how we process it, and who can access it
- Minimal data: We collect only what's needed; we delete what's not
- No advertising: We don't rely on ad networks or data brokers
- European compliance: Built from the start for GDPR, not bolted on after
- Third-party audit: Regular independent security reviews
- Family-first design: We're built specifically for families, not mass-market data platforms
The Bottom Line
Your cabin data is sensitive and personal. It deserves protection.
When you use dhytte.no to document your cabin memories, maintain your guest log, and coordinate family visits, you're trusting us with information about your family, property, and relationships.
We take that trust seriously. Your data is encrypted, private, protected by regular audits, and governed by strict privacy policies. You control who sees what. You can download, modify, or delete your data anytime.