Privacy Policy | Diaphora | Diaphora

Privacy Policy

Diaphora Inc. ("Diaphora", "we", "us") builds an integration and automation platform. This policy explains what personal data we handle, why, how long we keep it, and what you can ask us to do about it.

Draft — not yet in force. This document has not been reviewed by counsel and carries no effective date. Do not rely on it.

Who this applies to

This policy covers:

It does not cover the Frags runtime when you download it and run it yourself. Self-hosted Frags sends us nothing: no telemetry, no blueprint contents, no results. We have no visibility into it and hold no data from it, so there is nothing for this policy to apply to. That deployment is governed by Frags' open-source licence in the FragsHQ repository.

The two kinds of data, and why the difference matters

Almost every question about this platform resolves to which of these two buckets the data falls in.

Account data — we are the controller. Data about you as a customer: who signed up, which workspace they belong to, what they were billed, how many credits they burned. We decide why and how this is processed, and this policy governs it.

Customer Content — we are the processor. The blueprints you write, the inputs and outputs of every session, your results history, the credentials in your Vault, and anything your automations pull in from connected systems. We hold this and run it on your instruction. We do not decide what goes in it, we do not mine it, and we do not train models on it. If that content contains personal data about your customers or staff, you are the controller and we act on your behalf under the Data Processing Addendum.

What we collect

Account data (controller)

Data Why Source
Name, work email, company Create and secure your account You
Workspace membership and role Enforce the seat limit on your blueprint You / your workspace admin
SSO and SAML identifiers (Enterprise) Authenticate you against your identity provider Your IdP
Billing contact, blueprint, billing cycle Invoice you and apply the annual discount You
Payment method token Take payment — we never see or store full card numbers Stripe
Credits consumed, sessions run, blueprint and schedule counts Meter usage, enforce caps, calculate overage Generated by the platform
Support correspondence Answer you You
IP address, browser, timestamps, audit events Security, abuse prevention, and the Enterprise audit log Automatic

Customer Content (processor)

Your Vault credentials

The Vault holds the credentials your blueprints need in order to do anything: LLM API keys, database connection strings, API tokens, MCP server credentials and file-server logins.

Bring your own LLM keys — what it means for your data

Diaphora does not resell model tokens. You supply your own keys for Anthropic, OpenAI, Google or another provider, and your blueprints call those providers under your own account, on your own contract.

Consequently, when a session sends a prompt to a model:

The prompt and the model's response do pass through our platform on the way out and back, and are stored in your results history under the retention schedule below.

How long we keep things

Results history retention is a function of your blueprint. This is the same schedule published on the pricing page:

Blueprint Results history retained
Free 30 days
Starter 1 year
Team 2 years
Enterprise Unlimited, or a custom period in your order form

Once a session's results pass the retention window they are deleted from live systems on a rolling basis.

Everything else:

Data Retained
Account and workspace records For the life of the account, then 30 days after closure
Vault credentials Until you delete them, or 30 days after account closure
Invoices and billing records 7 years — US tax and accounting requirements
Security and audit logs 12 months
Support correspondence 24 months from last contact
Marketing-site analytics 2 years

Downgrading a blueprint shortens your retention window. Moving from Team to Starter reduces results history from two years to one, and history beyond the new window becomes eligible for deletion. Export anything you need before you downgrade.

Why we are allowed to process it

For customers in the EEA and UK, our lawful bases are:

We do not sell personal information, and we do not "share" it for cross-context behavioural advertising as CCPA/CPRA defines that term.

Who we share it with

LLM providers are not on this list. See the bring-your-own-keys section above.

Security

We maintain administrative, technical and physical safeguards appropriate to the sensitivity of the data, including encryption in transit and at rest, least-privilege access, audit logging, and background-checked personnel bound by confidentiality obligations. Enterprise customers additionally get SSO, SAML and exportable audit logs.

No system is perfectly secure. If a breach affects your personal data we will notify you, and any regulator we must notify, within the deadlines applicable to us — and without undue delay and in any case within 72 hours where the DPA applies.

Your rights

If you are in California, under CCPA/CPRA you may request to know the categories and specific pieces of personal information we hold, request deletion, request correction, and request that we limit the use of sensitive personal information. We will not discriminate against you for exercising these rights. We do not sell or share your personal information, so there is nothing to opt out of.

If you are in the EEA or UK, under GDPR/UK GDPR you have rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to your supervisory authority — the ICO in the UK, or your national DPA in the EEA.

Everyone else — we apply access, correction and deletion rights to all customers regardless of location, because operating one process is simpler than operating five.

To exercise any of these, email hello@diaphora.ai. We will verify your identity and respond within 45 days (CCPA) or one month (GDPR), extendable where the law allows.

If your request concerns Customer Content, we will refer you to the Diaphora customer that controls it. We cannot delete data on behalf of a controller who has not instructed us to.

International transfers

Diaphora is US-based. The platform runs on Google Cloud Platform, with data stored in managed PostgreSQL. Billing runs through Stripe and transactional email through Mailchimp, both US-based.

Where we move personal data out of the EEA or UK we rely on the European Commission's Standard Contractual Clauses together with the UK Addendum, and carry out transfer impact assessments where required. The SCCs are incorporated into the DPA.

Cookies

The marketing site and the platform use cookies that are strictly necessary for authentication, session management and security.

Children

The platform is a business product and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, email us and we will delete it.

Changes

We will post any revision here with a new effective date. For material changes affecting the hosted platform we will give at least 30 days' notice by email or in-product before they take effect.

Contact

Diaphora Inc.
hello@diaphora.ai