Legal
Privacy Policy
Effective Date: August 27, 2026 · Applies to all Diorta websites, platforms, and digital products
At Diorta, your privacy is fundamental to how we build and operate our products. This Privacy Policy explains what data we collect from users of our websites and services, how we use it, how we protect it, and what rights you have over it. By using any Diorta Service, you agree to the practices described in this Policy.
1. Information We Collect
We collect the following categories of data:
- Account Information: Your name and email address when you register for any Diorta product or service.
- Payment Metadata: Transaction identifiers, subscription status, and billing history provided to us by our authorized third-party payment processor. We do not collect, store, or have access to your raw credit card number, CVV, or full banking details at any point. All sensitive payment data is handled exclusively by our payment processor on PCI-DSS compliant infrastructure.
- Usage Analytics: Platform interaction data including pages visited, features accessed, render count, subscription tier, API call logs, session duration, and error reports. This data is used to improve Service quality and performance.
- Processing Inputs: Design briefs, reference images, and parameters submitted to our creative features. These are processed transiently to render your requested output and are not retained beyond operational necessity.
- Creative Outputs: Rendered assets and content stored in your account dashboard for your access and management.
- Technical Data: IP address, browser type and version, operating system, device type, referrer URL, and session timestamps collected automatically when you interact with our Services.
- Communications: Messages you send us via contact forms, support tickets, or email, including content and metadata.
2. How We Use Your Data
We use the information we collect for the following purposes:
- To provide, operate, maintain, and improve our Services and AI-powered platforms.
- To process AI model inference requests and return generated outputs to your account.
- To manage your account, subscription lifecycle, credit balance, and billing.
- To analyze usage patterns and platform performance in order to improve product quality, reliability, and user experience.
- To send transactional communications (receipts, password resets, feature updates, and support responses).
- To detect, investigate, and prevent fraudulent activity, abuse, security breaches, and Terms violations.
- To comply with applicable legal obligations and respond to lawful government or regulatory requests.
We may also use aggregated, anonymized, non-personally identifiable usage data to improve our AI models, service infrastructure, and product features. This data cannot be used to identify you as an individual.
3. AI Processing & Model Training
Diorta does not use your personal prompts, submitted reference images, or individually generated outputs to train or fine-tune its proprietary AI models without your explicit, opt-in consent. To deliver AI-powered features, we engage trusted third-party AI infrastructure providers who process your inputs solely to return the requested output under strict data-processing agreements and confidentiality obligations. These providers do not retain your data beyond what is operationally necessary.
4. Data Storage & Security
We take the security of your data seriously and implement the following enterprise-grade controls:
- All user data is stored on secure, enterprise-grade cloud infrastructure with encryption at rest and encryption in transit enforced at all times.
- Strict data isolation controls are enforced at the database level, ensuring your data is inaccessible to other users.
- Our infrastructure providers maintain industry-leading security compliance certifications.
- Application delivery is handled through globally distributed, DDoS-protected hosting with automated security patching.
- All administrative access to production systems is restricted to authorized personnel only, governed by the principle of least privilege.
While we implement commercially reasonable security measures, no system is entirely invulnerable. In the event of a data breach affecting your personal information, we will notify you in accordance with applicable legal requirements.
5. Third-Party Service Providers
We work with carefully vetted third-party service providers to operate our Services. Each provider is engaged under formal data-processing agreements and is bound by strict confidentiality obligations. Categories of providers include:
- Secure Cloud Database & Storage Providers: For encrypted data hosting, user authentication, and file storage.
- AI Inference Providers: For processing AI model requests and returning generated outputs.
- Payment Processing Providers: For secure payment collection, subscription management, and tax compliance (acting as Merchant of Record).
- Application Hosting & Delivery Providers: For secure, high-availability global application hosting and content delivery.
- Transactional Email Providers: For delivering automated service emails and support communications.
6. Data Sharing & Non-Sale Policy
Diorta does not sell, rent, trade, or otherwise transfer your personal data to third-party data brokers, advertising networks, or any other commercial entities for their independent use. Your data is shared only with our vetted service providers who are bound by confidentiality obligations, or when required by applicable law, court order, or legitimate regulatory authority.
7. Data Retention
- Active Accounts: Your data is retained for as long as your account remains active and in good standing.
- Asset Deletion: Thumbnails or generated files deleted from your dashboard are removed from active storage immediately.
- Account Deletion: Upon account deletion, all associated personal data is purged from active databases. Residual copies may persist in encrypted provider backups for up to 30 days before automatic deletion.
- Legal Hold: We may retain certain data for longer periods where required by applicable law, legal proceedings, or to protect our legitimate business interests.
8. Your Privacy Rights
You have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your account and personal data, subject to legal retention requirements.
- Portability: Request an export of your data in a structured, machine-readable format.
- Objection: Object to specific data processing activities.
- Withdrawal of Consent: Withdraw consent for any processing activities that rely on consent as their legal basis.
To exercise any of these rights, Contact Us. We will respond within a reasonable timeframe in accordance with applicable law.
9. Cookies & Tracking
We use strictly essential cookies for user authentication, session security, and platform functionality. We do not use third-party advertising cookies, behavioral tracking cookies, or cross-site tracking pixels. You may configure cookie behavior in your browser settings; however, disabling essential cookies may impair platform functionality.
10. Children's Privacy
Our Services are not directed to children under the age of 13. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal data, please Contact Us and we will take prompt action to delete such information.
11. Changes to This Policy
We may revise this Privacy Policy from time to time. Material changes will be communicated via email or in-product notification before they take effect. The most current version will always be available at this URL. Continued use of our Services constitutes acceptance of any updated policy.
Privacy Contact
For privacy-related inquiries, data subject requests, or to report a privacy concern, Contact Us.
Last updated: August 27, 2026