Legal/Privacy Policy

Draft — not legal advice, and not in force

This document has not been reviewed by counsel and has no effective date. It is published here for internal review only and is excluded from search indexing.

Data protectionApplies to diaphora.ai and app.diaphora.aiNo effective date

Privacy Policy

Diaphora Inc. ("Diaphora", "we", "us") builds an integration and automation platform. This policy explains what personal data we handle, why, how long we keep it, and what you can ask us to do about it.

Draft — not yet in force. This document has not been reviewed by counsel and carries no effective date. Do not rely on it.

Who this applies to

This policy covers:

  • diaphora.ai — our marketing site.
  • app.diaphora.ai — the hosted platform, on every plan including Free.

It does not cover the Frags runtime when you download it and run it yourself. Self-hosted Frags sends us nothing: no telemetry, no plan contents, no results. We have no visibility into it and hold no data from it, so there is nothing for this policy to apply to. That deployment is governed by Frags' open-source licence in the FragsHQ repository.

The two kinds of data, and why the difference matters

Almost every question about this platform resolves to which of these two buckets the data falls in.

Account data — we are the controller. Data about you as a customer: who signed up, which workspace they belong to, what they were billed, how many credits they burned. We decide why and how this is processed, and this policy governs it.

Customer Content — we are the processor. The plans you write, the inputs and outputs of every session, your results history, the credentials in your Vault, and anything your automations pull in from connected systems. We hold this and run it on your instruction. We do not decide what goes in it, we do not mine it, and we do not train models on it. If that content contains personal data about your customers or staff, you are the controller and we act on your behalf under the Data Processing Addendum.

What we collect

Account data (controller)

DataWhySource
Name, work email, companyCreate and secure your accountYou
Workspace membership and roleEnforce the seat limit on your planYou / your workspace admin
SSO and SAML identifiers (Enterprise)Authenticate you against your identity providerYour IdP
Billing contact, plan, billing cycleInvoice you and apply the annual discountYou
Payment method tokenTake payment — we never see or store full card numbersStripe
Credits consumed, sessions run, plan and schedule countsMeter usage, enforce caps, calculate overageGenerated by the platform
Support correspondenceAnswer youYou
IP address, browser, timestamps, audit eventsSecurity, abuse prevention, and the Enterprise audit logAutomatic

Customer Content (processor)

  • Plans you author, including prompts and schemas.
  • Session inputs and outputs — every credit spent produces a session, and the session's content passes through the platform.
  • Results history — retained for the period your plan provides (see the schedule below).
  • Vault credentials — see the section below.
  • Data pulled from connected systems — whatever your MCP servers, databases, file servers and APIs return when a plan calls them.

Your Vault credentials

The Vault holds the credentials your plans need in order to do anything: LLM API keys, database connection strings, API tokens, MCP server credentials and file-server logins. This is the most sensitive data on the platform and we treat it accordingly.

  • Credentials are encrypted at rest with keys we hold separately from the encrypted material, and encrypted in transit.
  • They are decrypted only at the moment a plan executes and only for the session that needs them.
  • They are never rendered back to you in plaintext after you save them, never written to logs, and never included in results history or support exports.
  • Diaphora staff cannot read your stored credentials. Support cannot retrieve one for you — if you lose a credential you re-enter it.

[NEEDS INPUT: confirm each bullet above against what the platform actually implements today. Anything not yet true must be removed rather than softened.]

Bring your own LLM keys — what it means for your data

Diaphora does not resell model tokens. You supply your own keys for Anthropic, OpenAI, Google or another provider, and your plans call those providers under your own account, on your own contract.

Consequently, when a session sends a prompt to a model:

  • The request goes out authenticated as you, not as Diaphora.
  • That provider's terms, privacy policy and data-retention settings apply to it — not ours.
  • Those providers are not our sub-processors, because we are not the ones engaging them. You are. They do not appear on our sub-processor list for that reason.
  • Whether your prompts can be used for model training is a question you settle with your provider, in your account settings with them. We cannot change it on your behalf and cannot see what you have chosen.

The prompt and the model's response do pass through our platform on the way out and back, and are stored in your results history under the retention schedule below.

How long we keep things

Results history retention is a function of your plan. This is the same schedule published on the pricing page:

PlanResults history retained
Free30 days
Starter1 year
Team2 years
EnterpriseUnlimited, or a custom period in your order form

Once a session's results pass the retention window they are deleted from live systems on a rolling basis and fall out of backups within [NEEDS INPUT: backup cycle, e.g. 35 days].

Everything else:

DataRetained
Account and workspace recordsFor the life of the account, then 30 days after closure
Vault credentialsUntil you delete them, or 30 days after account closure
Invoices and billing records7 years — US tax and accounting requirements
Security and audit logs[NEEDS INPUT: e.g. 12 months]
Support correspondence24 months from last contact
Marketing-site analytics[NEEDS INPUT: analytics retention]

Downgrading a plan shortens your retention window. Moving from Team to Starter reduces results history from two years to one, and history beyond the new window becomes eligible for deletion. Export anything you need before you downgrade.

Why we are allowed to process it

For customers in the EEA and UK, our lawful bases are:

  • Contract — running the platform, metering credits, billing you, providing support.
  • Legitimate interests — securing the platform, preventing abuse and fraud, and improving the product in aggregate. We have balanced these against your rights and you may object at any time.
  • Legal obligation — tax, accounting and lawful requests.
  • Consent — marketing email and any non-essential cookies. Withdrawable at any time.

We do not sell personal information, and we do not "share" it for cross-context behavioural advertising as CCPA/CPRA defines that term.

Who we share it with

  • Sub-processors — the vendors that run our infrastructure and tooling. Named individually, with locations, on the sub-processor page.
  • Your own workspace — workspace admins can see membership, usage and audit events for their workspace.
  • Professional advisers, under confidentiality obligations.
  • Authorities, where legally compelled. We will notify you unless prohibited by law.
  • An acquirer, if Diaphora is acquired or merges. You will be told before your data moves under a materially different policy.

LLM providers are not on this list. See the bring-your-own-keys section above.

Security

We maintain administrative, technical and physical safeguards appropriate to the sensitivity of the data, including encryption in transit and at rest, least-privilege access, audit logging, and background-checked personnel bound by confidentiality obligations. Enterprise customers additionally get SSO, SAML and exportable audit logs.

No system is perfectly secure. If a breach affects your personal data we will notify you, and any regulator we must notify, within the deadlines applicable to us — and without undue delay and in any case within 72 hours where the DPA applies.

[NEEDS INPUT: list any certifications or audits held or in progress — SOC 2, ISO 27001, penetration-test cadence. Claim nothing that is not actually held.]

Your rights

If you are in California, under CCPA/CPRA you may request to know the categories and specific pieces of personal information we hold, request deletion, request correction, and request that we limit the use of sensitive personal information. We will not discriminate against you for exercising these rights. We do not sell or share your personal information, so there is nothing to opt out of.

If you are in the EEA or UK, under GDPR/UK GDPR you have rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to your supervisory authority — the ICO in the UK, or your national DPA in the EEA.

Everyone else — we apply access, correction and deletion rights to all customers regardless of location, because operating one process is simpler than operating five.

To exercise any of these, email hello@diaphora.ai [NEEDS INPUT: consider a dedicated privacy@diaphora.ai alias]. We will verify your identity and respond within 45 days (CCPA) or one month (GDPR), extendable where the law allows.

If your request concerns Customer Content, we will refer you to the Diaphora customer that controls it. We cannot delete data on behalf of a controller who has not instructed us to.

International transfers

Diaphora is US-based. The platform runs on Google Cloud Platform, with data stored in managed PostgreSQL in [NEEDS INPUT: GCP region(s)]. Billing runs through Stripe and transactional email through Mailchimp, both US-based.

Where we move personal data out of the EEA or UK we rely on the European Commission's Standard Contractual Clauses together with the UK Addendum, and carry out transfer impact assessments where required. The SCCs are incorporated into the DPA.

If you need your data to stay in a particular region, that depends on which GCP region the platform runs in and is a question for us before you commit — not something you can configure per workspace today. [NEEDS INPUT: confirm whether regional pinning is offered on Enterprise; if not, say so plainly rather than leaving it ambiguous.]

Cookies

The marketing site and the platform use cookies that are strictly necessary for authentication, session management and security. [NEEDS INPUT: list any analytics or marketing cookies actually in use, the vendor behind each, and whether a consent banner is required. If non-essential cookies are set for EEA/UK visitors, consent must be collected before they fire.]

Children

The platform is a business product and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, email us and we will delete it.

Changes

We will post any revision here with a new effective date. For material changes affecting the hosted platform we will give at least 30 days' notice by email or in-product before they take effect.

Contact

Diaphora Inc. [NEEDS INPUT: registered Delaware address] hello@diaphora.ai

[NEEDS INPUT: if you appoint an EU or UK representative under GDPR Art. 27 — required if you have no EU/UK establishment but offer the service there — name them here.]

← All legal documents

What Diaphora collects, the split between account data we control and customer content we merely process, how long results history is kept on each plan, and the rights you can exercise.