Privacy Policy
This Privacy Policy explains what personal data Diali collects, why, who we share it with, how long we keep it, and the rights you have.
The short version:
- We never read your conversations or use them to train models; only dashboard chat history is stored
- Your keys and connected-account tokens are encrypted, never exposed
- We never sell your data or use it to train models
- Hosted in Belgium (EU); some processors are outside the EU
- Account data is deleted within 30 days of closure
- You control your data: access, export, or erase it anytime
This Privacy Policy explains what personal data Diali collects, why, who we share it with, how long we keep it, and the rights you have. It applies to the Diali platform at diali.ai and the services described below (the "Service"). It sits alongside our Terms of Service and our Refund and Cancellation Policy.
Who we are
The Service is operated by Diali AI LLC, a limited liability company organised under the laws of the State of Wyoming, USA ("Diali", "we", "us", "our").
- Registered address: c/o Registered Agent, 30 N Gould Street, Sheridan, WY 82801, USA
- General contact: hello@diali.ai
- Privacy / data-protection contact: privacy@diali.ai
For the personal data described in this policy, Diali acts as the data controller (under EU/UK GDPR) and as a business (under the California Consumer Privacy Act, as amended by the CPRA).
Scope
This policy covers personal data we process about:
- Account holders and visitors to diali.ai (the marketing site, dashboard, and onboarding wizard);
- People who contact us (e.g. via support or contact forms); and
- People an assistant contacts. If a user directs their assistant to message or call you, we process limited data about you, your contact details (e.g. phone number or messaging ID) and delivery metadata, solely to deliver that communication. The user who directed the communication is responsible for its content and for having a lawful reason to contact you; assistants identify themselves as AI and offer you a way to opt out (e.g. replying STOP). Your rights under this policy apply to this data too.
It does not govern: (a) how a BYOK AI provider processes your conversations (their policies apply); (b) how messaging channels (Telegram, WhatsApp, Discord, Slack, Mattermost, Matrix) and the SMS or voice carrier account you connect (Twilio, Telnyx, or Plivo) handle your use of them; (c) how a third-party service you connect processes data in your own account there; or (d) third-party sites we link to.
Personal data we collect
We collect the following, grouped by purpose. We have designed the Service to collect as little as practical.
Account and identity data
- Name and email address.
- Password: stored only as an argon2id hash; we never store or can see your plaintext password.
- Email-verification status.
- If you sign in with a third party (Google, GitHub, or GitLab; Apple planned): the provider's user identifier and the email address associated with that provider. We do not retain the provider's access or refresh tokens.
Session, device, and security data
- Cookie-based session identifiers (stored in Redis, not in our primary database).
- IP address (received via Cloudflare), and derived approximate location (city-level), plus browser/device descriptors, used to show you your active sessions and to send "new sign-in" security notifications.
- Signals used to detect fraud and abuse, including repeated or automated account signups.
Billing and payment data
- We use Stripe to process payments. Payment card numbers are entered directly into Stripe and are tokenised. Diali does not receive or store your full card number.
- We store a Stripe customer identifier, subscription and invoice references, and limited card display metadata (card brand, last four digits, expiry) so you can see your saved payment method.
Service configuration data
- Assistant configuration: assistant name, tone/personality, selected use-cases, size, add-ons, chosen channels, and the assistant's language and timezone.
- Your own provider keys (the "vault"), in BYOK mode: the API keys you provide for your own AI/LLM providers, and later other tools. These are encrypted (AES-256) and stored as secrets in Google Secret Manager. Your running assistant is given a temporary stand-in token, never the underlying key. We validate keys against the relevant provider to confirm they work.
- Channel connection data: the credentials each channel requires, for example, a Telegram bot token and optional numeric allow-list, or the equivalent for Discord, Slack, Mattermost, or Matrix. These are passed to our provisioning system and stored as secrets; they are not retained in our primary database.
- Telephony data: if your assistant uses SMS or voice-call features, they run on the carrier account you connect (Twilio, Telnyx, or Plivo; voice calls are available on OpenClaw assistants). Your carrier credentials are stored as encrypted secrets like other provider keys, and phone numbers and call/message routing metadata are processed through that carrier account to deliver those communications.
Connected accounts (integrations)
If you connect a third-party account (such as email, calendar, notes, or task tools) so your assistant can act in it for you:
- We store the access and refresh tokens the provider issues, in our integrations vault, which runs on our own infrastructure. We do not receive or store your password for that service.
- We store the identity of the connection (which provider, which account identifier, when it was connected) so we can show it to you and let you disconnect it.
- Data your assistant reads from or writes to that account (the contents of your emails, calendar entries, notes, or tasks) is processed in order to carry out what you asked. We do not copy that content into our own storage or retain it after the request completes.
- Disconnecting an integration in the dashboard revokes our stored access.
Managed AI usage data (Diali AI mode)
If you use managed mode, we operate an inference gateway between your assistant and the AI provider. For each request we record the model and provider used, the number of input/output (and cached) tokens, the computed cost, the pricing version applied, the response status, and the error category if it failed; and your credit balance, grants and purchases, and the resulting usage ledger and daily rollups.
Dashboard chat history and messages between your assistants
- Messages in your messaging apps (Telegram, WhatsApp, and the other channels) are not stored by Diali.
- Conversations you hold with an assistant in the dashboard chat are stored in our database (the text of each message, and descriptors of pictures or files the assistant produced) so you can see your history across devices, search it, and export it.
- If you let your assistants message each other, the text of those messages is stored so you can review the exchange.
- Deleting a thread removes it from your history; its content is permanently erased when you delete the assistant or close your account. You can export your chat history from the dashboard at any time.
Marketing attribution data (only with your consent)
If you accept the matching category in our cookie banner, we measure whether the advertising that brought you here worked. We do not personalise ads or build profiles: our tags always tell Google that ad personalisation is denied.
- The click identifier an ad platform appends to the link you arrived on (Google Ads'
gclid, X'stwclid), kept in a first-party cookie by that platform's tag, only if you accept marketing (see the Cookie Policy). - Google: if you accepted analytics when you paid, we report the purchase, and later renewals and refunds of that order, to Google Analytics with your Google Analytics client identifier, the order reference, the amount, and the plan. We send Google no email address. Google Ads may count these purchases as conversions of the ad you clicked.
- X (Twitter) Ads: if you accepted marketing when you paid, we send X the order reference, the amount, the X click identifier if the pixel stored one, and a one-way (SHA-256) hash of your email address, so X can count the purchase as a conversion of the ad you clicked. X can only match the hash against accounts it already holds; it never receives your name or the plaintext address from us.
- We record your consent choice alongside the order, and we send nothing of the above for a purchase made without the matching consent.
Communications and support data
- Transactional email content and delivery metadata (sent via Resend).
- Messages you send us through contact/support forms, and notifications we generate for you.
- Files you upload to the Service, if any.
Operational telemetry
- Structured request logs and correlation identifiers, health/uptime metrics, and error reports (via Sentry). We explicitly exclude secrets, tokens, card data, and AI prompt/response content from logs.
- Product analytics (via PostHog), only if you accept analytics in the cookie banner: pages visited and features used, session replays of your visits (what you type is masked; replays are kept 30 days), click heatmaps, and browser console errors. If you reject analytics, PostHog still counts anonymous, cookieless page views, with no identifier stored on your device.
What we don't do
These are core commitments of the Service:
- We do not read your conversations or use them to train models, in either BYOK or managed mode. Messages in your messaging apps are not stored by Diali; only dashboard chat history and messages between your assistants are stored, as described in Section 3.
- We do not retain the content your assistant reads from or writes to a connected account.
- We do not access your messaging-app contacts or message history.
- We do not use your data (including anything passing through our managed inference gateway) to train AI models.
- We do not sell your personal data, and we do not "share" it for cross-context behavioural advertising (as those terms are defined under the CCPA/CPRA). The only data that reaches an advertising platform is the consent-gated conversion measurement described in Section 3, used solely to measure our own campaigns.
How and why we use your data
Under EU/UK GDPR we must have a lawful basis for each use. The table below sets out what we do and why.
| What we do | Data used | GDPR lawful basis |
|---|---|---|
| Create and secure your account; authenticate sign-in | Account, session/security data | Performance of a contract (Art. 6(1)(b)) |
| Provision, run, and update your assistant | Configuration, vault, channel data | Performance of a contract |
| Route your assistant's AI requests and meter usage (managed mode) | Managed AI usage metadata, credit balance | Performance of a contract |
| Let your assistant act in accounts you connect | Integration tokens, connection identity | Performance of a contract |
| Take payment and manage your subscription | Billing data, card mandate | Performance of a contract; legal obligation for tax/accounting records (Art. 6(1)(c)) |
| Send you transactional emails (verification, receipts, security, service notices) | Contact data | Performance of a contract / legitimate interests (Art. 6(1)(f)) |
| Deliver SMS/voice features your assistant uses | Telephony data | Performance of a contract |
| Protect the Service against fraud and abuse, including payment fraud; keep security logs | Session, security, billing data | Legitimate interests in securing the Service and preventing fraud |
| Diagnose and fix errors; monitor uptime | Telemetry data | Legitimate interests in a reliable service |
| Respond to your support requests | Communications data | Legitimate interests / performance of a contract |
| Send marketing email (if any) | Contact data | Consent (Art. 6(1)(a)); you may withdraw at any time |
| Measure our advertising: attribute a sign-up or purchase to the Google Ads or X (Twitter) Ads campaign that brought you here | Marketing attribution data | Consent (Art. 6(1)(a)) via the cookie banner's marketing category; withdraw by rejecting marketing, which stops all further reporting |
| Comply with legal obligations and respond to lawful requests | As required | Legal obligation |
Where we rely on legitimate interests, you have the right to object (see "Your rights" below). Providing your account and billing information is necessary to create an account and use the Service. Configuration data (such as channel details, and provider keys in BYOK mode) is necessary only to run the features you choose to enable. Connecting a third-party account is entirely optional. Any other information is optional.
AI providers, in both modes
Diali AI (managed): the default
Your assistant's requests go to our inference gateway, which forwards them through a third-party AI routing service to the model's developer (such as Anthropic, OpenAI, or Google), on Diali's account. In this mode: the routing service and the model's developer process your conversation content to produce the response; Diali does not use your content to train models and does not send it for training; the gateway records usage metadata only (Section 3), never the content; and you do not need, and do not give us, a provider account of your own.
Bring your own key (BYOK)
Your assistant runs on your provider account using a key you supply. In this mode: your key is encrypted and stored as described in Section 3, and Diali staff do not use it to read your conversations; the content you exchange with your assistant is processed by your chosen AI provider under that provider's terms and privacy policy, not ours (you are responsible for reviewing and complying with those terms); and Diali charges only the hosting subscription and does not meter your AI usage.
International transfers
We host your data in the EU (Google Cloud, Belgium). However, Diali is a Wyoming, USA company, and some of our processors and recipients (e.g. Stripe, the AI routing service and the managed AI providers, Microsoft, Resend, Zoho, PostHog, Google, X Corp., and the sign-in providers) are based in or transfer data to the United States and other countries.
Where personal data of individuals in the EU/UK is transferred outside the EEA/UK, we rely on appropriate safeguards: the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), and/or the EU-US Data Privacy Framework where the recipient is certified. You may request a copy of the relevant safeguards by emailing privacy@diali.ai.
How long we keep data
| Data | Retention |
|---|---|
| Account data | While your account is active; deleted within 30 days of account closure (subject to the exceptions below) |
| Sessions | Up to 30 days, or until you sign out; then purged automatically |
| Dashboard chat history and messages between your assistants | Until you delete the assistant or close your account (a deleted thread is hidden from your history at once and erased with the assistant) |
| PostHog session replays (only with analytics consent) | 30 days |
| Billing and invoice records | 7 years, to meet tax and accounting obligations |
| Provider keys, channel secrets, and integration tokens | Until you remove them, disconnect the integration, or delete the assistant/account |
| Managed AI usage events (per-request metadata) | 90 days |
| Managed AI daily usage rollups and credit ledger | Retained with your billing records, as they evidence what you were charged |
| Operational logs and error telemetry | 90 days |
| Support/contact messages | 24 months from resolution |
| Third-party recipient contact data (numbers/IDs, delivery metadata) | Only as long as needed to deliver the communication, plus short-term delivery logs |
After a retention period ends, we delete or irreversibly anonymise the data. We may retain limited data longer where required by law or to resolve disputes.
Security
We take protective measures including: passwords stored as argon2id hashes; provider keys, channel secrets, and integration tokens encrypted (AES-256) in Google Secret Manager; data encrypted at rest with keys managed in Cloud KMS; TLS in transit; edge protection via Cloudflare; network isolation between tenant workloads; access controls; and exclusion of secrets, card data, and AI prompt/response content from logs.
No system is perfectly secure, but we work to protect your data. In the event of a personal-data breach, we will notify the relevant supervisory authority and affected individuals as required by law, under GDPR, generally within 72 hours of becoming aware, where the breach is likely to result in a risk to your rights.
California privacy rights (CCPA/CPRA)
If you are a California resident, you have specific rights. In the 12 months preceding this policy, we collect the following categories of personal information (as defined by the CCPA):
| CCPA category | Collected? | Examples |
|---|---|---|
| Identifiers | Yes | Name, email, IP address, account and sign-in identifiers |
| Customer records / financial information | Yes | Billing metadata (card brand, last 4, expiry); subscription and credit-purchase records |
| Commercial information | Yes | Products/add-ons purchased, subscription history, credit balance and usage ledger |
| Internet/network activity | Yes | Session logs, device/browser info, service interactions; with analytics consent, session replays and click heatmaps |
| Geolocation | Yes | Approximate (city-level), derived from IP |
| Sensitive personal information | Yes | Account log-in credentials; the API keys you store in the vault; access tokens for accounts you connect |
| Audio/visual, biometric, precise geolocation, protected classifications, employment/education, inferences | No | None |
Sources of this information: you (directly), your device/browser, your sign-in provider if you use OAuth, and the third-party services you choose to connect. Purposes: as described in "How and why we use your data". Sale/Share: we do not sell personal information and do not share it for cross-context behavioural advertising; the consent-gated conversion measurement in Section 3 is used only to measure our own advertising, and rejecting marketing in the cookie banner stops it. Beyond that there is nothing to opt out of; where applicable we nonetheless recognise browser opt-out signals such as Global Privacy Control (GPC). We use sensitive personal information only to provide the Service (e.g. to authenticate you, to operate your assistant, and to act in accounts you connect), not to infer characteristics, so the CPRA "right to limit" use of SPI does not expand our uses.
Your California rights: to know/access, to delete, to correct, to opt out of sale/sharing (n/a, we do neither), to limit use of SPI (n/a as above), and to non-discrimination for exercising your rights. You may submit a request at privacy@diali.ai. You may use an authorised agent. We will verify your request against your account information before acting.
Your rights (EU/UK GDPR)
If you are in the EU, UK, or a comparable jurisdiction, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten"), subject to our legal retention obligations;
- Restrict or object to processing based on legitimate interests;
- Data portability: receive certain data in a structured, machine-readable format;
- Withdraw consent at any time where we rely on consent; and
- Not be subject to solely automated decisions with legal or similarly significant effects (we do not make such decisions).
To exercise any right, email privacy@diali.ai. We respond within the timeframes required by law (generally one month under GDPR; 45 days under the CCPA, extendable as permitted). We may need to verify your identity first. You also have the right to lodge a complaint with a supervisory authority: in the EU, your local data-protection authority; in the UK, the ICO. We'd appreciate the chance to address your concern first.
Children
The Service is not directed to children. You must be at least 16 years old to use the Service, consistent with the minimum digital-consent age under GDPR Art. 8. Because the Service is a paid subscription, users under the age of majority in their jurisdiction (typically 18) may only subscribe with the involvement of a parent or legal guardian, who must agree to the Terms of Service and provide the payment method. We do not knowingly collect data from anyone under 16. If you believe a child under 16 has provided us data, contact privacy@diali.ai and we will delete it.
Changes to this policy
We may update this policy. If we make material changes, we will notify you (e.g. by email or an in-Service notice) before they take effect where required. The "Last updated" date at the top of this page shows the current version.
Contact us
Privacy questions and requests: privacy@diali.ai. General enquiries: hello@diali.ai. Post: Diali AI LLC, c/o Registered Agent, 30 N Gould Street, Sheridan, WY 82801, USA.
Still have questions?
Can't find the answer you're looking for? Our team is here to help.
