DI Cloud privacy policy
Last updated: July 6, 2026
The DI Cloud Privacy Policy explains who the data controller is, what data we process, for which purposes and on which legal bases, to whom we entrust data, how long we retain it, and what rights you have under the GDPR.
1. Data controller
The controller of personal data is DECISION INTERFACE PROSTA SPÓŁKA AKCYJNA (Decision Interface P.S.A.), seated in Warsaw, Poland, Aleja Wilanowska 115/44, 02-765 Warszawa, KRS 0001248975, tax ID (NIP) 5214169992. For any personal-data matters, including exercising your rights, contact hi@hi-di.cloud. No data protection officer has been appointed; please write to that email address.
2. Scope and legal framework
This policy applies to processing in the web/PWA app and the iOS and Android mobile apps. Processing follows Regulation (EU) 2016/679 (GDPR) and Polish data-protection law. Providing data is voluntary but necessary to create an account and use the service.
3. Categories of data processed
We process: account data (email, user ID, profile name, settings, language, plan, limits); authentication and session data; user content (prompts, messages, notes, files, images, projects, workspace memory); technical and diagnostic data (product events, errors, model routes, latency, limit usage, IP address, device data); billing data (plan, subscription status, transaction identifiers). We do not store full card numbers or CVC codes.
4. Purposes and legal bases
We process data to: (a) provide the service and perform the contract — Art. 6(1)(b) GDPR; (b) comply with legal obligations, including accounting and billing — Art. 6(1)(c) GDPR; (c) pursue legitimate interests: security, abuse prevention, limit enforcement, service development and quality, and establishing or defending claims — Art. 6(1)(f) GDPR; (d) where covered by consent, e.g. optional features — Art. 6(1)(a) GDPR.
5. User content and AI providers
Starting an AI feature sends prompts, messages, attached files, images, selected workspace context, and responses to configured model providers, only as needed to perform the requested feature and handle safety, limits, and errors. Do not enter passwords, card details, one-time codes, or secrets. Under BYOK, the chosen provider operates under the user's account settings.
6. No use of data to train models
We do not use prompts, messages, files, images, responses, or private workspace context to train or fine-tune DI Cloud models. We use provider APIs and business configurations where providers state they do not use customer data for training without consent or offer retention controls; each provider's own policies are a separate layer beyond DI Cloud's control.
7. Recipients and processors
We entrust data to processors under data-processing agreements (Art. 28 GDPR), only as needed to operate the service: Supabase (database, authentication, files), Vercel (hosting and app delivery), AI model providers (OpenAI, Anthropic, Google, OpenRouter, Vercel AI Gateway, Mistral), Stripe (payments), Apple and Google (in-app purchases and notifications), Resend (transactional email). We do not sell personal data.
8. Transfers outside the EEA
Some providers process data outside the European Economic Area, including in the USA. Transfers rely on appropriate safeguards under the GDPR: Standard Contractual Clauses approved by the European Commission or adequacy decisions (including the Data Privacy Framework where applicable).
9. Retention period
Account and workspace data is retained while the account exists and as needed to provide the service. Billing data is retained for the period required by law (including tax law). Security, anti-abuse, and claim-related data is retained until the relevant limitation periods lapse. After account deletion, we delete or anonymize data we no longer need to keep.
10. Your rights
You have the right to access, rectify, erase, restrict processing, port your data, object to processing based on legitimate interests, and withdraw consent (without affecting processing before withdrawal). Exercise your rights in the app or by contacting hi@hi-di.cloud.
11. Complaint to a supervisory authority
You have the right to lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw.
12. Automated decisions and profiling
We do not make decisions producing legal or similarly significant effects based solely on automated processing. Automatic AI model or route selection serves only to technically perform the requested feature and is not such a decision.
13. Cookies and similar technologies
We use cookies and similar technologies necessary for sign-in, session maintenance, and security on the basis of legitimate interest. Any analytics or preference cookies are used only with consent. You can change cookie settings in your browser.
14. Data security
We use HTTPS/TLS encryption, Supabase authentication, workspace isolation, database Row Level Security, private file paths, signed links, rate limits, audit logs, error monitoring, and minimized exposure of secrets in logs. See the Security page for details.
15. Changes to this policy
We may update this policy; each version is dated. We will notify you of material changes in the app or by email.
16. Contact
For privacy, data export, account deletion, or security matters, contact hi@hi-di.cloud. The Polish-language version of this policy is the binding one; translations are provided for convenience only, and in case of any discrepancy the Polish version prevails.