DiActa — Privacy Policy

Effective date: August 21, 2026 Last updated: August 21, 2026


1. Who we are

DiActa AI LLC, doing business as DiActa ("we", "us", "our"), provides an AI-assisted social media content and publishing tool at diacta.ai.

This policy explains what personal information we collect, why, who we share it with, and what rights you have. It covers our website and web application (the "Service"). It forms part of our Terms of Service.

We are the data controller for the information described here. Contact us at privacy@diacta.ai.

2. A short summary

3. Information you give us

What Includes Why
Account Email address, password To create and secure your account, and to contact you about the Service
Brand profile Business name, industry, description, target audience, voice and art-direction preferences, brand colours, typography, do's and don'ts To generate content that matches your brand
Content Briefs and prompts you write, generated copy, generated images, scheduled and published posts To provide the core Service
Website URL A URL you optionally ask us to scan To pre-fill your brand profile from your own site
Communications Messages you send to support To help you

Passwords are handled by our authentication provider and stored only as salted hashes. We never see your password in plain text.

4. Information we collect automatically

We do not use advertising trackers, third-party analytics, session recording, or fingerprinting.

5. Information from and about third parties

5.1 Connected social accounts

If you connect a social media account (LinkedIn, Facebook, Instagram, X), our publishing partner completes the authorization and we receive the account's identifier, display name, and profile picture, plus the ability to publish on your behalf.

We never receive or store your social media passwords. Access tokens are held by our publishing partner, not by us. You can disconnect at any time from within DiActa or from the platform.

5.2 Billing

Our payment processor tells us your customer and subscription identifiers, subscription status, plan, trial end date, and country/tax status. We never receive your full card number — card details go directly to the processor.

5.3 How generated images are stored

Images you generate are held in a private storage bucket. They are not publicly readable and cannot be browsed or crawled by anyone.

When an image needs to be shown to you in the app, we mint a short-lived signed link for that moment, which expires on its own. Nothing is served from a permanent public address, so a link that is copied or forwarded stops working rather than granting indefinite access.

Publishing does not expose the bucket either: when you publish a post, we read the image on our servers and hand it to our publishing partner, which hosts the copy the social platform fetches.

Bear in mind that once a post is published, the image is public on that social platform under that platform's terms — that is the purpose of publishing it.

6. Who we share information with

We share personal information only with service providers who process it on our instructions to run the Service:

Provider What they receive Purpose Location
Supabase Account details, brand profile, content, usage records Authentication, database, file storage United States
Anthropic Your briefs and brand profile AI text generation USA
OpenAI Image prompts derived from your inputs AI image generation USA
Stripe Email, billing and tax details, payment method Payment processing, tax USA / global
Zernio Post content, images, connected-account details Social publishing and scheduling Spain (EU)
Vercel Request metadata, server logs Application hosting Global edge
ZeptoMail Email address, message content Transactional email (confirmations, password resets) United States

Our AI providers do not use your content to train their models under the API terms we operate on, and they retain inputs only briefly for abuse monitoring.

We may also disclose information: to comply with law, legal process, or a valid government request; to enforce our Terms or investigate abuse or fraud; to protect the rights, safety, or property of anyone; and to a successor in a merger, acquisition, or sale of assets (we will notify you before your information becomes subject to a different policy).

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

7. International transfers

We are based in the United States and our providers are largely US-based. If you use the Service from outside the US — including the EEA, UK, or Switzerland — your information will be transferred to and processed in the United States, which may not offer the same level of protection as your home country.

Where required, we rely on appropriate safeguards for these transfers, including the European Commission's Standard Contractual Clauses and equivalent UK provisions, as incorporated into our agreements with providers. You can request further detail at privacy@diacta.ai.

8. How long we keep information

Data Retention
Account, brand profile, generated copy While your account is open
Generated images 60 days from the day each image is created, then automatically deleted
After you delete your account Deleted promptly; residual copies in encrypted backups age out within [30–90] days
Rate-limiting entries (IP) Minutes to hours — a rolling window
Agreement record (date, version, IP) While your account is open, and for a reasonable period afterwards to defend legal claims
Billing and tax records As long as tax and accounting law requires (typically 7 years)
Server logs Per our hosting provider's standard retention

Deleting your account removes your account, brand profiles, stored images, usage records, and your configuration with our publishing partner, and cancels any subscription. It is permanent. Posts already published to social platforms remain there — remove those from the platform directly.

9. Your rights

Depending on where you live, you may have the right to: access the information we hold about you; correct it; delete it; export it in a portable format; object to or restrict processing; withdraw consent (for example, marketing emails); and not be discriminated against for exercising any of these.

How to exercise them. Much of this is self-service — you can view and edit your brand profile in the app, and delete your account and data from Settings. For anything else, email privacy@diacta.ai. We will respond within 30 days (or as your local law requires) and may need to verify your identity first.

9.1 If you are in the EEA, UK, or Switzerland (GDPR)

Our legal bases for processing are:

You have the right to lodge a complaint with your local supervisory authority.

9.2 If you are in California (CCPA/CPRA)

In the past 12 months we have collected the categories described in §3–§5: identifiers, commercial information, internet activity, geolocation (country-level only), and your own content. Sources, purposes, and recipients are set out above.

We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the past 12 months. We do not knowingly collect or sell the personal information of anyone under 16. You may exercise your rights to know, delete, correct, and opt out via privacy@diacta.ai, and may use an authorized agent.

9.3 Other US states

If you live in a state with a comprehensive privacy law (Virginia, Colorado, Connecticut, Utah, Texas, and others), you have comparable rights of access, correction, deletion, and portability, and a right to appeal a refused request. To appeal, reply to our decision or write to privacy@diacta.ai.

10. Cookies

We use strictly necessary cookies only:

We do not use advertising, analytics, or tracking cookies, so we do not show a consent banner. If that changes, we will update this policy and seek consent where required.

11. Marketing emails

We will send you transactional messages you cannot opt out of while you have an account — sign-up confirmation, password resets, billing notices, and important service changes.

Marketing emails are opt-in. The checkbox during onboarding is pre-ticked only in jurisdictions where opt-out consent is lawful, and unticked elsewhere. You can unsubscribe from any marketing email or by emailing privacy@diacta.ai.

12. Security

We protect your information with: encryption in transit (HTTPS/TLS) and at rest; hashed passwords; row-level security on our database; strict server-side authorization on every action; rate limiting on authentication endpoints; protections against cross-site scripting and server-side request forgery; and access to production systems limited to those who need it.

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal information we will notify you and any regulator as the law requires. Report a suspected vulnerability to security@diacta.ai — we welcome good-faith reports and will not pursue researchers who act responsibly.

13. Children

The Service is for business use by adults. It is not directed to anyone under 18, and we do not knowingly collect their personal information. If you believe a child has given us information, contact privacy@diacta.ai and we will delete it.

14. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you by purely automated means. The AI in DiActa generates draft content at your request — it does not evaluate, score, or make decisions about you.

15. Changes to this policy

We may update this policy. For material changes we will give at least 30 days' notice by email or in-app before they take effect, and we will update the "Last updated" date. Continuing to use the Service after that means you accept the updated policy.

16. Contact

DiActa AI LLC (d/b/a DiActa) 82 Wendell Ave STE 100 Pittsfield, MA 01201 United States

Privacy: privacy@diacta.ai Security: security@diacta.ai General: support@diacta.ai