Privacy Policy
Last updated:
At DiAgent we take your privacy seriously. This policy explains what data we collect, how we use it, and the control you have over it when you use our platform to build and publish AI agents.
1. Who we are
DiAgent is a platform that lets you build AI agents from your own content (documents, websites, or text) and share them via a link, a widget, or a QR code.
DiAgent's team is the data controller. For any privacy question, email us at nico@diagent.io.
2. What we collect
Account data: your email and password (stored encrypted by our authentication provider). If you sign up with Google, we receive your email and profile name.
Billing data: on paid plans, your name, address, and phone number, needed to issue your receipt. Payments are processed by Mercado Pago; we never store your card details.
Content you upload: the documents, URLs, and text you add to train your agents, along with the vector representations (embeddings) generated from them.
Usage data: messages exchanged with your agents, usage metrics, and technical data such as your IP address and browser type, which we use for security and abuse prevention.
3. How we use your data
We use your data to run the service: create and host your agents, generate responses, process payments, provide support, and protect the platform against fraud and abuse.
We do not sell your personal data or use it for third-party advertising.
4. Legal bases (GDPR)
Where the General Data Protection Regulation (GDPR or UK GDPR) applies, we process your data on these legal bases: performance of the contract (providing the service you signed up for), our legitimate interest (security, abuse prevention, and service improvement), compliance with legal obligations (for example, tax rules), and your consent where it is required — such as connecting optional integrations or receiving marketing emails.
Where processing is based on your consent, you can withdraw it at any time without affecting the lawfulness of prior processing or your use of the rest of the service.
5. Roles: controller and processor
For your data as a platform user (account, billing, usage), DiAgent acts as the data controller.
For the personal data of the end users who interact with the agents you publish, you are the data controller and we act as a processor, handling it on your instructions. If you need one, we can sign a data processing agreement (DPA) — request it by email.
6. Providers who help us
To operate, we rely on third-party providers that process data on our behalf: Supabase (database, authentication, and hosting), OpenAI and Groq (AI models that generate responses and embeddings), and Mercado Pago (payments).
If you connect optional integrations (for example Google Workspace or Microsoft 365), we share with those services only what is needed to perform the actions you authorized, via OAuth.
7. International transfers
Some of our providers process data in the United States or other countries. When we transfer personal data of people covered by the GDPR outside the European Economic Area, we use recognized safeguards such as the European Commission's standard contractual clauses or applicable adequacy decisions (including the EU–U.S. Data Privacy Framework where the provider is certified).
8. Your agents' content
The content you upload is yours. We use it solely to train and run your agents, and it is sent to the AI providers above only to generate responses.
Do not use DiAgent to upload sensitive personal data about third parties without a legal basis to do so. You are responsible for the content you upload.
9. Cookies and local storage
We use browser local storage to keep you signed in and remember your language preference. We do not use advertising or tracking cookies.
10. Retention and deletion
We keep your data while your account is active and as needed to provide the service. You can delete an agent and all of its knowledge base at any time from your dashboard.
Deleted content is removed from production systems within 30 days and from encrypted backups within 90 days.
If you'd like to delete your account, email us at nico@diagent.io: we delete or anonymize your personal data within 30 days, except what we must keep for legal obligations (for example, tax records), fraud prevention, or to establish or defend legal claims — and only for as long as the law requires.
11. Security
We apply reasonable technical and organizational measures to protect your data, including encryption in transit, per-user isolation, and usage limits. No system is 100% secure, but we work to minimize the risks.
12. Your rights
You can access your personal data, correct it, delete it, request a copy in a portable format, ask us to restrict processing, and object to processing. Where processing is based on your consent, you can withdraw it at any time.
To exercise these rights, email us at nico@diagent.io; we respond within the legal deadlines (30 days under the GDPR, extendable where the law allows). We will not discriminate against you for exercising them.
If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your data protection authority. In Argentina, with the Agencia de Acceso a la Información Pública.
13. California residents (CCPA/CPRA)
If you are a California resident, you have the right to know what personal data we collect, to access, correct, and delete it, and not to be discriminated against for exercising these rights. We do not “sell” or “share” personal data as defined by the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes other than those permitted.
You can exercise these rights — directly or through an authorized agent — by emailing nico@diagent.io. We will verify your request and respond within the CCPA's deadlines.
14. Children
DiAgent is not directed to children under 13, and we do not knowingly collect their data (consistent with the U.S. COPPA statute). If we learn we hold data about a child under 13, we delete it.
Where the GDPR applies, children under their country's age of digital consent (between 13 and 16) may only use the service with a parent's or guardian's authorization.
15. Changes to this policy
We may update this policy from time to time. If we make material changes, we'll update the “Last updated” date and, where appropriate, notify you.
16. Google user data (Limited Use)
If you sign in with Google, we receive only your email address and profile name, which we use to create and authenticate your account.
If you connect optional Google Workspace integrations, your agent accesses only what is strictly needed for the actions you authorized, always via OAuth: in Calendar, creating and listing events; in Gmail, SENDING mail only — we do not request permission to read your inbox; in Sheets, Slides, Docs and Forms, creating new files.
For Google Drive we use the drive.file permission, which grants no access to your Drive as a whole: we can only read the individual files you pick yourself in Google's own file picker (Google Picker) to import them into your agent's knowledge base. We cannot list, search, or open any other file in your Drive.
You can revoke these at any time from your Google account (myaccount.google.com/permissions) or by disconnecting the integration in DiAgent.
DiAgent's use of information received from Google APIs, and its transfer to any other app, adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we do not sell Google data, we do not use it for advertising, we do not use it to train general-purpose AI models, and no human reads it except with your explicit consent, for security purposes, to comply with the law, or when aggregated and anonymized.
17. Contact
Questions about your privacy? Email us at nico@diagent.io and we'll get back to you.