Skip to content
DIVAI
  • Platform
  • Solutions
  • Managed Services
  • How It Works
  • Pricing
  • Security
  • Company
English
  • English
  • العربية
  • Español
  • Français
  • Türkçe
Start Building

DIVAI Privacy Policy (English — Canonical Source)

1.0-draft · 2026-09-04

Pre-publication draft — version 1.0-draft dated September 4, 2026. Founder policy decisions are incorporated. This text is not yet in force and has not been approved by legal counsel.

Current product status: this website links to the authenticated app. Ordinary-customer admission, the Website Assistant, AI, Project Brain, Worker, credits and payments are not activated by this website release. Forward-looking provisions apply only if and when the relevant feature is activated.

  • DIVAI Terms of Service
  • DIVAI Privacy Policy
  • DIVAI Acceptable Use Policy
  • DIVAI Cookie & Tracking Notice
  • DIVAI Subprocessor List
  • DIVAI AI Processing Disclosure
  • DIVAI Project Memory ("Project Brain") — Customer Disclosure
  • DIVAI Billing, Subscription and Credit Policies
  • DIVAI Support and Service Availability Policy

1. Who we are

1.1. DIVAI LLC (“DIVAI,” “we,” “us,” “our”) is a limited liability company organized in the State of Alaska, United States. It is Active and in Good Standing.

1.2. We operate the DIVAI platform at divai.ai and app.divai.ai (together, the “Service”).

1.3. You can contact us about this policy or your personal data at: privacy@divai.ai.

1.4. Postal address: Draft item pending confirmation before activation..

2. Scope

2.1. This policy describes how we collect, use, retain, and delete personal data in connection with:

(a) the DIVAI web application (app.divai.ai); (b) the DIVAI website (divai.ai), including the Website Assistant described in Section 17; (c) the DIVAI mobile experience (planned); (d) our support and feedback channels; and (e) our consulting and development services, where applicable.

2.2. The Service is intended for users who are 18 years of age or older. It serves businesses and adult individuals. See Section 15.

2.3. The Service is offered globally where lawful.

2.4. “Customer-private data” in this policy means: your conversations, files, project content, private Project Brain memory, private preferences, customer-specific derived data that remains reversible or linkable to you or your project, and tenant- or project-specific context. Customer-private data is isolated by tenant and by project.

3. What we collect

We group the data we collect as follows.

3.1 Account identity and contact data

  • Name, email address, user ID, and workspace or organization name.
  • Optional contact details you choose to provide.

3.2 Authentication and session data

  • Login events, session identifiers, and multi-factor authentication state.
  • Credentials are managed by our authentication provider. We do not store raw passwords. Draft item pending confirmation before activation.

3.3 Device and browser data

  • IP address, browser type, device type, operating system, and approximate location derived from IP address.

3.4 Project and workspace content

  • Project names, settings, and configurations.
  • Prompts and messages you send to AI features.
  • Files and uploads you attach.
  • Plans, specifications, and requirements documents.
  • Generated outputs and artifacts produced for you.
  • Approvals you give on plans, builds, or deliverables.
  • Job and execution history (run records, errors, timestamps).
  • Project Brain private memory (see Section 5).

3.5 Usage data

  • Feature usage counts, request volumes, and rate-limit counters.

3.6 Credits, billing, invoices, and payment metadata (forward-looking)

Payments are not yet active. When billing is enabled, we intend to collect:

  • Credits balance and consumption ledger.
  • Billing name, billing address, and tax information.
  • Invoices, line items, and amounts.
  • Payment metadata: card brand, last four digits, payment status, and processor reference IDs. We do not intend to store full card numbers. Payment processing is planned via a third-party payment processor. Draft item pending confirmation before activation.

3.7 Audit and security logs

  • Administrative and permission changes, data-access events, authentication failures, and anomaly or abuse signals.

3.8 Support and feedback data

  • Support tickets and feedback submissions.
  • Safe metadata attached automatically to feedback, limited to: app version, surface or page, language, platform or device family, and a safe release identifier.
  • We never auto-attach passwords, tokens, secrets, full private project content, raw database rows, or card data.
  • Screenshots only when you select and attach them yourself.

3.9 Analytics and cookie data

  • Analytics events and cookie identifiers, only after consent where required. See Section 8 and our Cookie Notice.

3.10 Notification data

  • Notification preferences and delivery logs.

4. How we use data

4.1. We use the data above to:

(a) provide, operate, and maintain the Service, including processing AI requests you initiate; (b) operate Project Brain under your control (see Section 5); (c) meter usage, manage credits, and — when billing is enabled — process billing and payments; (d) secure the Service, prevent abuse, and debug problems; (e) respond to support and feedback submissions; (f) improve the product, but only through privacy-safe generalized learning as defined in Section 6; and (g) send marketing communications, only with your opt-in consent.

4.2. Service and account notices (for example, security or account notices) are separate from marketing and are not subject to marketing opt-out.

4.3. Legal bases for each use: Draft item pending confirmation before activation.

5. Project Brain and private memory

5.1. Project Brain is DIVAI’s project memory feature. It stores project context so the Service can keep continuity across your sessions.

5.2. Isolation. Project Brain memory is isolated by tenant and by project. Your memory is not pooled with, or exposed to, other customers.

5.3. Customer control. You can view, export, and delete your Project Brain memory. You may delete a single project, including its memory, without deleting your account.

5.4. Permanent rule — no raw cross-customer learning. We do not use your raw private content to train or improve models for other customers. This rule is permanent and is not changed by any product update.

5.5. Full details are in our Project Brain Memory Disclosure (Related policy).

6. Privacy-safe generalized learning

6.1. Definition (locked). DIVAI may retain learning only if it is:

(a) privacy-safe; (b) generalized; (c) not customer-specific; (d) not raw private content; (e) not reasonably reversible to a user or a project; and (f) not usable to reconstruct customer-private information.

6.2. Any derived data that remains reversible or linkable to you or your project is customer-private data, not generalized learning. It is handled under Section 12.

7. AI processing

7.1. When you use AI features, your prompts, files, and related context are routed through our AI request routing provider to underlying third-party AI model providers to generate results.

7.2. Provider abstraction. DIVAI selects providers and models internally. By default, you interact with DIVAI, and the Service does not require you to select or see an underlying model provider. Required processor and subprocessor disclosures remain available in our Subprocessor List (Related policy).

7.3. AI-specific handling is described in our AI Processing Disclosure (Related policy).

7.4. Sensitive data is routed only to approved routes, under our data classification, data-processing-agreement, retention, and least-data rules.

7.5. No zero-retention claim. We do not claim zero data retention for any AI route or provider. No such claim is made in this policy, and none may be made without exact-route proof.

8. Cookies and analytics

8.1. Our use of cookies and similar technologies is described in our Cookie Notice (Related policy).

8.2. Analytics (Google Analytics 4, planned) is consent-gated where required. Analytics scripts do not load before consent.

8.3. Declining analytics is effective: if you decline, no analytics cookies or scripts are set or loaded.

8.4. Essential technologies (authentication, session, security, load balancing) may run as necessary to operate the Service.

8.5. We treat a Global Privacy Control signal as a decline of analytics. Draft item pending confirmation before activation.

9. Subprocessors and international transfers

9.1. We use third-party providers (subprocessors) to deliver the Service. Our current customer-facing list is in our Subprocessor List (Related policy). We update that list and give advance notice of changes. Draft item pending confirmation before activation.

9.2. Your data may be processed in countries other than your own, depending on where our subprocessors operate.

9.3. For transfers of personal data from the EEA, UK, or Switzerland, we intend to rely on appropriate safeguards, such as Standard Contractual Clauses and the UK addendum. Draft item pending confirmation before activation.

10. Data retention

10.1. We retain personal data only as long as needed for the purposes in Section 4, under the following schedule:

Data category Retention target
Active customer data after a deletion request or account closure Deleted within 30 days
Backup copies Up to 90 days under normal backup rotation
Support and feedback records 24 months, then deleted or minimized
Security and audit logs 24 months
Billing and legal records As required by mandatory law Draft item pending confirmation before activation.
Formal export requests Fulfilled within 30 days
Active projects Kept while the project is active

10.2. You may delete one project without deleting your account. Deletion of a project follows the same schedule.

10.3. We do not claim that all data is immediately erased everywhere. Deleted data may remain in backups until the normal rotation deadline in Section 10.1.

10.4. Legal holds. If litigation, a regulatory inquiry, or a dispute is actual or reasonably anticipated, deletion of relevant data is suspended until the hold is released. Draft item pending confirmation before activation.

11. Your rights and choices

11.1. Subject to applicable law, you may:

(a) access the personal data associated with your account; (b) export your data in commonly used machine-readable formats Draft item pending confirmation before activation.; formal export requests are fulfilled within 30 days; (c) delete your content, one project at a time or by closing your account; (d) correct inaccurate data; (e) opt out of marketing communications at any time, using the unsubscribe mechanism in every marketing message; and (f) set or change your cookie and analytics preferences at any time.

11.2. How to make a request: email privacy@divai.ai or use the in-product controls. Identity verification and response procedures: Draft item pending confirmation before activation.

12. What we delete vs. what we may retain

12.1. On deletion (deletion request, project deletion, or account closure), we DELETE:

(a) raw private content (conversations, files, project content); (b) private Project Brain memories; (c) customer-identifiable or private project context; and (d) reversible derived representations of any of the above.

12.2. On deletion, we MAY RETAIN only:

(a) irreversible, privacy-safe, generalized learning as defined in Section 6; (b) billing and legal records that mandatory law requires us to keep; (c) security and audit evidence required for the lawful retention period (see Section 10); and (d) backup copies, only until the normal rotation deadline in Section 10.1.

12.3. Nothing outside Section 12.2 is retained after deletion.

13. Security

13.1. We protect personal data using measures appropriate to its sensitivity, including managed authentication, hosted infrastructure, access controls, and least-data routing rules.

13.2. No method of transmission or storage is completely secure. We do not guarantee absolute security.

14. No sale of personal data; no third-party advertising

14.1. We do not sell your personal data. Draft item pending confirmation before activation.

14.2. We do not show third-party advertising in the Service in Phase 1, and we do not use your data for third-party advertising.

15. Children

15.1. The Service is for users 18 years of age or older. It is not directed to children.

15.2. We do not knowingly collect personal data from anyone under 18. If we learn that we have collected such data, we restrict it and delete it as the law requires.

16. Regional rights

16.1. US state privacy laws. Residents of certain US states may have rights to know, access, correct, delete, and port their personal data, and to opt out of certain processing. The mechanisms in Section 11 are available for these requests. Specific state-by-state rights, exceptions, and appeal processes: Draft item pending confirmation before activation..

16.2. EEA, UK, and Switzerland (GDPR). If you are in the EEA, UK, or Switzerland, you may have rights of access, rectification, erasure, restriction, portability, and objection, and the right to complain to a supervisory authority. The mechanisms in Section 11 are available for these requests. Legal bases and representative requirements: Draft item pending confirmation before activation..

16.3. Other regions. Where other laws grant you rights, we intend to handle requests through the mechanisms in Section 11. Applicability per jurisdiction: Draft item pending confirmation before activation..

17. Website Assistant and lead attribution

17.1. The Website Assistant is a chat feature on our public website (divai.ai). Its purposes are support, sales, lead qualification, conversion, and public product guidance.

17.2. The Website Assistant has no access to authenticated customers’ private Project Brain data.

17.3. We do not silently link an anonymous website conversation to a customer account.

17.4. Any handoff from the website to the app requires your consent and uses a short-lived secure mechanism, a safe structured summary, privacy-safe attribution, and an authenticated destination.

17.5. We do not copy private customer content into global marketing data.

17.6. Customer logos and case studies are used only with written permission.

18. Changes to this policy

18.1. We may update this policy. We will post the revised policy with a new “last updated” date. For material changes, we intend to provide additional notice, such as an in-product notice or an email. Draft item pending confirmation before activation.

19. Contact

19.1. Questions about this policy or your personal data: privacy@divai.ai.

19.2. Postal address: Draft item pending confirmation before activation..

privacy@divai.ai

DIVAIdivai.ai

The Business OS that builds and operates — with your approval at every gate.

Start Building

Product

  • Platform
  • Solutions
  • Pricing
  • How It Works

Company

  • About
  • Managed Services
  • Contact
  • Book Consultation

Trust

  • Security & Trust
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Accessibility

© 2026 DIVAI. All rights reserved.

  • English
  • العربية
  • Español
  • Français
  • Türkçe

Cookies & analytics

We use Google Analytics (GA4) to understand aggregate usage — only with your consent, and only on divai.ai. Nothing is measured before you choose; change or withdraw anytime in the footer (see Cookie Policy).