Privacy Notice
Privacy Notice
This Notice explains how DeepDivo processes personal data for accounts, automated research, document storage, public sharing and billing.
1. Controller and contact
The DeepDivo service operator is the controller, or equivalent responsible entity, for Service data. Requests to access, correct, delete, object, restrict, port, withdraw consent or complain may be submitted through the Help Center support channel.
2. Data we process
- Account: email, display name, password hash, role and status; administrator records also include access level, authorization expiry and action audit.
- Identity and security: session identifiers, CSRF cookie, IP, browser/device details, login and security logs. Trusted administrator-computer tokens are stored only as irreversible digests with device labels and confirmation and expiry times.
- Anti-abuse device identifier: an irreversible digest of a long-lived random HttpOnly identifier and free or promotional grant counts. It limits promotions per device, is not used for cross-site advertising, and does not guarantee unique hardware identification.
- Research content: topics, context, options, generated documents, source information, exports and public status.
- Usage and operations: job state, errors, processing time, feature actions, audit records and support communications.
- Billing and promotions: Credits ledger and reservations, plans, redemption campaigns and records, and payment-provider customer, transaction, subscription, discount, refund and status identifiers. Redemption codes are stored only as irreversible digests and masked prefixes. DeepDivo does not retain full payment-card details.
3. Purposes and legal bases
- Contract: accounts, generation, storage, exports, subscriptions and Credits.
- Legitimate interests: security, fraud and bulk-account prevention, troubleshooting, audit, reliability and core-product improvement, balanced against individual rights.
- Legal obligations: tax, accounting, consumer, anti-fraud, law-enforcement and dispute records.
- Consent: where required and no more appropriate basis applies. Consent may be withdrawn without affecting earlier lawful processing.
4. Cookies and local storage
The Service uses session, CSRF-security and anti-abuse cookies, an administrator-only trusted-computer cookie, plus local storage for drafts, interface preferences and recent-document state. They support requested service, security and preferences, not third-party behavioral advertising. Clearing cookies or changing devices may affect authentication, administrator-computer confirmation, preferences and promotional eligibility.
5. Recipients and providers
Paddle processes necessary data for checkout, payment, tax, invoicing, anti-fraud and order support and is independently responsible for that processing under its privacy notice. DeepDivo sends information required for an order and receives transaction, subscription, refund and status identifiers, but does not receive full payment-card details. Other hosting, infrastructure, search, model, error and security, email, support and file-generation providers process data only as needed under contracts and applicable law. Disclosure may also occur when legally required, to protect rights, investigate abuse or support a corporate transaction.
6. International transfers
Some providers may process data outside your country. Where required, transfers rely on adequacy decisions, standard contractual clauses or another lawful mechanism, with supplementary safeguards proportionate to risk. Contact us for information about applicable safeguards.
7. Public documents
Documents, titles, metadata and display names you publish can be read by anyone and may be indexed, cached or retained by third parties. Unpublishing stops future access through the Service but cannot erase third-party copies. Do not publish sensitive personal, confidential or unauthorized information.
8. Retention and deletion
- Documents, Word files and Markdown files are not automatically deleted merely because an account is inactive. They are generally kept until you delete the document or account, or removal is required for security, unlawful content, legal obligations or service closure.
- PDFs are temporary exports retained for 30 days after document completion and then automatically deleted. PDF expiry does not affect the online document, Word file or Markdown file.
- Account data is kept until account deletion or no longer needed; sessions expire on security schedules.
- Credits, subscription, transaction, refund, security, anti-fraud and audit records are retained as required for performance, disputes, tax, accounting and law. Backups may delete on their normal rotation; de-identified data may remain for statistics and reliability.
9. Your rights
Depending on local law, you may request access, correction, deletion, restriction, objection, portability, consent withdrawal, or complain to a regulator. Some records cannot be deleted immediately because of contract, security, fraud, financial-record or legal requirements. Identity may be verified before responding within the applicable period.
10. Security, children and automation
We use access controls, password hashing, session protection, audit and reasonable organizational measures, but no internet service is absolutely secure. Do not submit sensitive data the Service does not need. The Service is not directed to children below the local age of digital consent. Research generation and anti-abuse checks are automated, but the Service does not use them to make eligibility, credit, employment or insurance decisions with legal or similarly significant effects.
11. Updates
Material changes will be communicated in-app or through another reasonable channel, with renewed acknowledgment where required. The current version is published in the Legal Center. Previous versions may be requested through the Help Center.