Privacy Policy

What we collect, why we collect it, and what you can do about it.

Last updated: 2026-07-21

Account data

What we store about you.

When you create a Diado account we collect the name and email address you give us, a salted hash of the password you choose (we never store the plaintext), and session metadata that lets you stay signed in across devices. We log the IP address and user-agent of each sign-in for security review, and we store operational events (sign-in, password change, billing events) needed to keep your account healthy and auditable.

Customer data

The customers you put into Diado.

Diado’s Front Office stores the per-Owner Customerrows that power your inbox and quote pipeline. That includes the customer’s name, phone number, email address, postal address, the source channel that brought them in, any notes or files your team adds, and the history of conversation events (intake, qualification, quotes, follow-ups).

Analytics surfaces aggregate revenue and conversion across your own records to give you a working dashboard — those metrics describe your business, not an individual customer, and are treated as your data.

Payment data

Diado runs on Stripe.

Paid plans are billed through Stripe’s hosted checkout. Raw card numbers never touch our servers — Stripe collects them directly in their checkout and returns a payment status we read back via verifyCheckoutSession. The customer-visible invoice rows we persist hold only the amount and the status (paid, refunded, failed); no card fragments, no bank account numbers, no CVC.

Call data

Microphone access is local to your browser.

The Diado /demo call UI uses your browser’s microphone via getUserMediafor the in-browser guided demo only — the audio stream is processed locally for visualisation and is not recorded, uploaded, or sent to our servers. If you wire your own phone line into production calls, those calls route through Twilio and what is recorded is governed by your own configuration and your customers’ consent at the point of call.

How we use it

To run the Front Office you signed up for.

We use the data we collect to provide the Front Office — the page, the intake, the inbox, the quote pipeline — on your behalf. That includes contacting your customers as part of the workflows you configure, sending transactional email through our email service (intake confirmations, quote notifications, invoice receipts), and operating AI-assisted features through our AI proxy so we can keep provider keys off your infrastructure. We also use aggregated, de-identified usage data to improve the product.

We do not sell your data. We do not share it with third parties for advertising.

Your rights

Access, export, deletion.

You can access, correct, and export your account data and the customer data you’ve stored from inside the product. You can close your account and request deletion of your records at any time — account deletion removes your authentication material and your own account records; customer data you stored is removed with it. To exercise any of these rights, or to ask a question, email diado@polsia.app.

Retention

How long we keep things.

We retain your account data while your account is active, and for a short grace window after deletion to recover from accidental closure and to honour any remaining financial obligations. Customer records you put into Diado are retained under your own retention policy — you can purge them at any time. Payment records are retained per Stripe’s record-retention obligations and may persist longer than your account on Stripe’s side.

Subprocessors

The third parties that handle data on our behalf.

  • Better-auth— authentication, sessions, and credential storage for your account.
  • Stripe— billing and payment processing for paid plans.
  • Polsia email proxy— our authenticated email service that delivers transactional mail on behalf of your workflows.
  • Polsia AI proxy— our authenticated model gateway that powers the AI-assisted features inside the product.
  • Twilio— optional, only if you connect your own phone line to production calls.
  • OAuth providers— any third-party sign-in provider configured in your auth-config.ts (Google, Apple, etc.).

Governing law

The legal frame around this policy.

This policy is governed by the laws of the State of Delaware, United States of America, without regard to its conflict-of-laws principles. Any dispute arising from it is subject to the exclusive jurisdiction of the state and federal courts located in Delaware.

Contact

Questions about this policy.

Reach the privacy team at diado@polsia.app. We respond within five business days.