Politique de cookies
Cette Politique de cookies explique comment Diali utilise les cookies et technologies similaires pour faire fonctionner la plateforme et améliorer votre expérience, et, uniquement avec votre consentement, pour comprendre son utilisation et mesurer nos campagnes.
The short version: We use a handful of cookies to keep you signed in and keep bots out. Analytics and marketing cookies are set only if you accept them in the cookie banner, and you can change your choice at any time with "Cookie settings" in the footer. No cross-site tracking, and we never sell your data.
This Cookie Policy explains how Diali ("we", "us", "our") uses cookies and similar technologies when you visit diali.ai or use our platform. It should be read alongside our Privacy Policy.
Non-essential cookies are used only if you accept them in the cookie banner. Simply continuing to use the site is not consent.
What are cookies?
Cookies are small text files placed on your device (computer, tablet, or mobile phone) when you visit a website. They allow the site to remember your actions and preferences over a period of time, so you don't have to re-enter them whenever you come back.
Cookies can be "session" cookies, which expire when you close your browser, or "persistent" cookies, which remain on your device until they expire or you delete them. Ours are persistent, with the lifetimes listed below.
How we use cookies
We use cookies to keep the platform running correctly and remember your preferences. With your consent, we also use them to understand how the site is used (analytics) and to tell whether the advertising that brought you here worked (marketing). We do not sell your data and we do not track you across unrelated websites.
Strictly necessary cookies can't be switched off. Without them, signing in simply doesn't work. They store an opaque identifier, never your password or message content.
Types of cookies we use
Here is a breakdown of every category of cookie we use:
| Category | Purpose | Duration | Can you opt out? |
|---|---|---|---|
| Session | Keeps you signed in to your account (__Host-sessionid). HttpOnly, Secure, SameSite. | 30 days, ends when you sign out | No, required for the service |
| CSRF | Protects forms and API calls against cross-site request forgery (csrftoken). | 30 days, ends when you sign out | No, required for the service |
| Consent | Remembers the choice you made in the cookie banner (cookie-consent) so we do not ask again, and so we can prove what you agreed to. | 6 months | No, it records your choice |
| Functional | Remember how you use the interface, never used for tracking: your language (i18n_redirected, set when we first match the site to your browser's language or you switch it); dashboard layout (dash-sidebar-collapsed, dash-sidebar-agents-open, dash-ask-open); tips and tours you have dismissed or finished (diali-promo-dismissed, diali-tour-done, diali-gs-graduated, diali-agent-walkthrough); and an assistant you started setting up before signing in (nudge-draft-agents). | Language, layout and dismissed tips: 1 year · Finished tours: up to 5 years · Walkthrough and draft assistant: 7 days | Not through the banner; you can delete them in your browser at any time (the setting then resets) |
| Referral | Set only when you open a friend's referral link (diali-referral), so the referral is credited when you sign up. | 30 days | Only set if you follow a referral link; you can delete it in your browser |
| Analytics | PostHog (ph_…) and Google Analytics (_ga, _ga_…): which pages are visited, which features are used, session replays of your visits (what you type is masked; kept 30 days), click heatmaps and browser console errors, and which campaign or link brought you here. Never your messages or your assistant's data. If you reject analytics, PostHog still counts anonymous page views without setting any cookie or storing an identifier on your device. | PostHog: 1 year · Google Analytics: up to 2 years | Yes, set only after you accept analytics in the banner |
| Marketing | Google Ads click cookies (_gcl_aw, _gcl_gs) and the X (Twitter) Ads pixel (_twclid, the X click id, plus the cookies X sets on its own domains): attribute a sign-up or purchase to the ad you clicked so we can measure our campaigns, and report a purchase back to the ad platform as a conversion. No profiling, no cross-site tracking. | Google: 90 days · X click id: 30 days (per X's documentation); X's own cookies follow X's policy | Yes, set only after you accept marketing in the banner. The X pixel does not even load until then, and turning marketing off stops it. |
Third-party cookies
Some cookies are set by third-party services we use to operate or improve the platform. We only work with partners that comply with applicable data protection laws.
| Provider | Purpose | Privacy policy |
|---|---|---|
| Stripe | Payment processing and fraud prevention on checkout and billing pages | stripe.com/privacy |
| Cloudflare | Edge security and bot protection for the site | cloudflare.com/privacypolicy |
| Cloudflare Turnstile | Bot check on the signup, password reset, and contact forms | cloudflare.com/privacypolicy |
| PostHog | Product analytics, session replays, and heatmaps, only after you accept analytics (if you reject, only anonymous, cookieless page-view counts). Sent through our own domain (e.diali.ai), never shared with advertisers | posthog.com/privacy |
| Google Analytics | Site analytics and campaign attribution, only after you accept analytics | policies.google.com/privacy |
| Google Tag Manager & Google Ads | Loads our measurement tags; ad-click attribution only after you accept marketing | policies.google.com/privacy |
| X (Twitter) Ads | Ad attribution and purchase conversion measurement, only after you accept marketing: the X pixel (uwt.js) reports page visits and a completed purchase to X (requests to analytics.twitter.com and t.co) so X can tell which ad led to it. When a purchase is confirmed we also send X the order reference, the X click id if the pixel stored one, and a one-way hash of your email address, so the same purchase is counted once — and we send that only if you had accepted marketing when you paid. | x.com/en/privacy |
Google's tags (Tag Manager and the Google tag) load on every page so that our measurement can be verified, but they run in Google's Consent Mode: until you accept the analytics or marketing category they set no cookies and receive no identifier, only aggregate, cookieless signals. The X pixel has no such mode, so it works the other way round: its code is on every page, but it does not load and nothing is sent to X unless you have accepted marketing in the banner. If you reject marketing, or have not answered yet, X receives nothing. We do not use Meta Pixel or any other advertising network.
Managing your cookies
You can control and manage cookies in several ways:
- Browser settings: Every major browser lets you view, block, and delete cookies (Settings → Privacy). Blocking our strictly-necessary cookies will break sign-in.
- Cookie banner: analytics and marketing cookies exist only if you accepted them. To change or withdraw an earlier choice, use the "Cookie settings" link in the footer of any page: it reopens the banner with your current choices.
- Third parties: Stripe and Cloudflare cookies appear only on the pages that use them; PostHog, Google and X cookies follow your banner choice. See their policies for further opt-out options.
- Do Not Track / GPC: we do not track you across other websites, whatever these signals say. For the analytics and marketing cookies above, the banner is the control.
Heads up. Disabling essential cookies will prevent you from logging in and using the Diali platform. (Your theme preference is stored locally in your browser, not in a cookie.)
Do Not Track
Some browsers include a "Do Not Track" (DNT) feature that signals to websites that you do not wish to be tracked. There is currently no widely accepted standard for how websites should respond to DNT signals.
We do not track you across other websites regardless of your DNT or Global Privacy Control setting. For the analytics and marketing cookies described above, the cookie banner is the control: no analytics or marketing cookie is set until you accept, and rejecting keeps it that way. (If you reject analytics, PostHog still counts anonymous, cookieless page views, with no identifier stored on your device.)
Updates to this policy
We may update this Cookie Policy periodically to reflect changes in technology, regulation, or our own practices. When we make material changes, we will notify you via email or an in-app banner before the changes take effect.
The date at the top of this page always reflects when the policy was last revised. We encourage you to review it occasionally.
Contact us
If you have questions about our use of cookies or this policy, please contact us at hello@diali.ai. We are happy to help.
Vous avez encore des questions ?
Vous ne trouvez pas la réponse que vous cherchez ? Notre équipe est là pour vous aider.
