Privacy

DI Cloud privacy policy

Last updated: July 6, 2026

The DI Cloud Privacy Policy explains who the data controller is, what data we process, for which purposes and on which legal bases, to whom we entrust data, how long we retain it, and what rights you have under the GDPR.

DI Cloud
This policy concerns the protection of personal data. Rules for using the service are set out in the separate Terms of Service. Controller: DECISION INTERFACE P.S.A. · KRS 0001248975 · NIP (Polish tax ID) 5214169992 · Aleja Wilanowska 115/44, 02-765 Warsaw, Poland.

1. Data controller

The controller of personal data is DECISION INTERFACE PROSTA SPÓŁKA AKCYJNA (Decision Interface P.S.A.), seated in Warsaw, Poland, Aleja Wilanowska 115/44, 02-765 Warszawa, KRS 0001248975, tax ID (NIP) 5214169992. For any personal-data matters, including exercising your rights, contact hi@hi-di.cloud. No data protection officer has been appointed; please write to that email address.

2. Scope and legal framework

This policy applies to processing in the web/PWA app and the iOS and Android mobile apps. Processing follows Regulation (EU) 2016/679 (GDPR) and Polish data-protection law. Providing data is voluntary but necessary to create an account and use the service.

3. Categories of data processed

We process: account data (email, user ID, profile name, settings, language, plan, limits); authentication and session data; user content (prompts, messages, notes, files, images, projects, workspace memory); technical and diagnostic data (product events, errors, model routes, latency, limit usage, IP address, device data); billing data (plan, subscription status, transaction identifiers). We do not store full card numbers or CVC codes.

4. Purposes and legal bases

We process data to: (a) provide the service and perform the contract — Art. 6(1)(b) GDPR; (b) comply with legal obligations, including accounting and billing — Art. 6(1)(c) GDPR; (c) pursue legitimate interests: security, abuse prevention, limit enforcement, service development and quality, and establishing or defending claims — Art. 6(1)(f) GDPR; (d) where covered by consent, e.g. optional features — Art. 6(1)(a) GDPR.

5. User content and AI providers

Starting an AI feature sends prompts, messages, attached files, images, selected workspace context, and responses to configured model providers, only as needed to perform the requested feature and handle safety, limits, and errors. Do not enter passwords, card details, one-time codes, or secrets. Under BYOK, the chosen provider operates under the user's account settings.

6. No use of data to train models

We do not use prompts, messages, files, images, responses, or private workspace context to train or fine-tune DI Cloud models. We use provider APIs and business configurations where providers state they do not use customer data for training without consent or offer retention controls; each provider's own policies are a separate layer beyond DI Cloud's control.

7. Recipients and processors

We entrust data to processors under data-processing agreements (Art. 28 GDPR), only as needed to operate the service: Supabase (database, authentication, files), Vercel (hosting and app delivery), AI model providers (OpenAI, Anthropic, Google, OpenRouter, Vercel AI Gateway, Mistral), Stripe (payments), Apple and Google (in-app purchases and notifications), Resend (transactional email). We do not sell personal data.

8. Transfers outside the EEA

Some providers process data outside the European Economic Area, including in the USA. Transfers rely on appropriate safeguards under the GDPR: Standard Contractual Clauses approved by the European Commission or adequacy decisions (including the Data Privacy Framework where applicable).

9. Retention period

Account and workspace data is retained while the account exists and as needed to provide the service. Billing data is retained for the period required by law (including tax law). Security, anti-abuse, and claim-related data is retained until the relevant limitation periods lapse. After account deletion, we delete or anonymize data we no longer need to keep.

10. Your rights

You have the right to access, rectify, erase, restrict processing, port your data, object to processing based on legitimate interests, and withdraw consent (without affecting processing before withdrawal). Exercise your rights in the app or by contacting hi@hi-di.cloud.

11. Complaint to a supervisory authority

You have the right to lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw.

12. Automated decisions and profiling

We do not make decisions producing legal or similarly significant effects based solely on automated processing. Automatic AI model or route selection serves only to technically perform the requested feature and is not such a decision.

13. Cookies and similar technologies

We use cookies and similar technologies necessary for sign-in, session maintenance, and security on the basis of legitimate interest. Any analytics or preference cookies are used only with consent. You can change cookie settings in your browser.

14. Data security

We use HTTPS/TLS encryption, Supabase authentication, workspace isolation, database Row Level Security, private file paths, signed links, rate limits, audit logs, error monitoring, and minimized exposure of secrets in logs. See the Security page for details.

15. Changes to this policy

We may update this policy; each version is dated. We will notify you of material changes in the app or by email.

16. Contact

For privacy, data export, account deletion, or security matters, contact hi@hi-di.cloud. The Polish-language version of this policy is the binding one; translations are provided for convenience only, and in case of any discrepancy the Polish version prevails.