Last updated 20 September 2026
Daiven is a product of Selenthir Sp. z o.o., a limited liability company registered in Poland. Selenthir is the data controller for everything described in this policy: we decide what is collected and why.
| Company | Selenthir Sp. z o.o. |
| Registered office | Tysiąclecia 35 / 41, 41-303 Dąbrowa Górnicza, Poland |
| KRS | 0001227518 |
| NIP (VAT) | PL6292521423 |
| Contact for privacy | legal@daiven.app |
This policy applies to the Daiven website at daiven.app, the Daiven application, and the emails we send you.
Daiven is for adults. You must be 18 or older to create an account. We do not knowingly collect personal data from anyone under 18, and if we learn that we have, we delete it and close the account.
Most software collects data about what you did. Daiven collects data about who you are — because that is the product. Over the course of onboarding and your conversations, the agents build a profile: what you value, the patterns you fall into, the people who matter to you, the decisions you are weighing and how they turned out. That record is what lets the Judge weigh a decision against your stated values rather than a generic standard.
This means the data Daiven holds is more sensitive than a typical subscription service's, and we have written this policy on that assumption rather than pretending otherwise.
Account and sign-in. Your email address, your name if you give one, a hashed password (never the password itself), and — if you sign in with Google or Facebook — the account link those providers return. If you turn on two-factor authentication we store the secret and your backup codes. We keep a record of the browsers you have signed in from so we can tell a familiar device from an unfamiliar one.
Your profile. The record the agents build and you can edit: values and the tensions between them, patterns, blind spots, beliefs, principles, habits, goals, memories you have shared, decisions and their reviews, people you mention and how they relate to you, and the delivery preferences the agents learn about how to reach you.
Your conversations. The messages you send and the replies you receive, summaries generated when a conversation goes quiet, a record of which agent handled what, and any rating you give a reply. Conversations with the Confidant are the exception — see below.
Things you bring in. Files you upload for import, which we process to extract profile entries; images you attach to a conversation; and voice input, which is transcribed so the agent can read it.
Billing. Your plan, subscription status, credit balance and credit transactions, and the customer and subscription identifiers our payment processor issues. We never see or store your card details — those go directly to Stripe.
Email records. Which of our emails were sent and whether they were delivered, and a suppression list of addresses that bounced so we stop mailing them. These records identify you by a one-way hash of your address rather than by the address itself.
Your address on our mailing list. Only if you ask for marketing email: we share your address and the name on your account with Sender, the platform that sends it — which holds it in the EU. Nothing else about you goes there — not your profile, not your conversations, not what you pay. If you turn marketing email off, we delete your address from Sender rather than merely stopping the sends.
Security and technical data. Your IP address, used for platform security and abuse prevention; a record of sign-ins, two-factor use and other security events; and, so that a single person cannot take the free trial repeatedly, a one-way hash of the email address a trial was granted to.
A record of what you agreed to. When you create an account we record which consents you gave, when, from which IP address, and which version of these documents was in force at the time. The law obliges us to be able to demonstrate your consent rather than simply claim it, and this is how. See how long we keep it for the one respect in which this record behaves differently from everything else.
Cookies and device storage. Covered in full in the cookie policy.
| What we do | Why | Legal basis |
|---|---|---|
| Create and run your account, sign you in | You cannot use Daiven without one | Contract — Art. 6(1)(b) |
| Run conversations and build your profile | This is the service you signed up for | Contract — Art. 6(1)(b), and explicit consent — Art. 9(2)(a) for the sensitive parts |
| Take payment, grant credits, issue invoices | To sell you a subscription | Contract — Art. 6(1)(b) |
| Keep accounting and tax records | Polish law requires it | Legal obligation — Art. 6(1)(c) |
| Rate-limit requests, recognise devices, detect abuse, prevent repeat trials | To keep accounts and the service safe, and to stop the free trial being farmed | Legitimate interests — Art. 6(1)(f) |
| Fix faults, measure performance, act on your ratings | To keep the product working and make it better | Legitimate interests — Art. 6(1)(f) |
| Record which channel you arrived from | To understand how people find us | Consent — Art. 6(1)(a) |
| Send marketing email | Only if you ask for it | Consent — Art. 6(1)(a) |
| Establish or defend legal claims | To protect the business | Legitimate interests — Art. 6(1)(f) |
Where we rely on legitimate interests, we have weighed our interest against your rights and concluded it does not override them: the data involved is limited, it is used for security and reliability rather than for profiling or advertising, and you can object at any time (see Your rights).
Where we rely on consent, you can withdraw it at any time, and withdrawing it is as easy as giving it. Withdrawal does not undo processing that already happened lawfully.
To do its job, Daiven records things that data protection law treats as special category data under Article 9 of the GDPR — your health and wellbeing, your beliefs, and details about your relationships and the people in your life.
We process that data on the basis of your explicit consent, and we ask for it twice, at two different moments:
When you create your account, as its own choice, separate from accepting these terms. This covers the fact that what you type reaches an AI provider in order to be answered at all.
Every time something is about to be written to your profile. Once you are set up, an agent never files anything about you silently. It shows you the exact entry it proposes to store, labelled with what it is, and nothing is written until you accept it. You can decline, and the conversation carries on regardless.
The first conversation works differently. Onboarding builds your starting profile out of what you tell it, rather than proposing each entry as it goes — otherwise setting up an account would mean approving several dozen cards before you had used it once. Everything it recorded is visible on your profile page from the moment you arrive, and you can edit or delete any of it there.
That second step is the one that matters most, and it is unusual. Most AI products store what they infer about you as a side effect of the conversation. Daiven asks first, item by item, in the moment.
Consent is not the only limit on what goes into your profile. Some kinds of information are excluded by design: we do not record them even if you offer them, even if they come up naturally in conversation, and even if you ask us to keep them. There is no setting that turns this off. It binds the agents before it binds you — they are instructed not to propose these entries at all, and a separate check runs before anything is written, for the times one slips through.
Broadly, it covers information that is more likely to be used against you than for you: things that could expose you to legal jeopardy or to discrimination, intimate detail that does nothing to help you stay aligned with your own values, and sensitive information about other people in your life — who never agreed to any of this, and cannot decline on their own behalf. Where a general fact is useful and its specifics are not, we keep only the general fact. That you have lived through something can matter to the work in a way that the details of it do not.
None of this narrows what you can talk about. An agent will discuss any of it with you, at whatever length is useful. The limit is only on what survives the conversation in writing.
We do not publish the precise list. A specification of what our safeguards look for would also be a specification of how to phrase something to get past them.
You can withdraw that consent at any time, in Settings under Data & Privacy. It is one control, and it does exactly what withdrawing consent means: everything the consent covered is erased — your profile, the relationship map, and every conversation you have had — and the account stops working. There is no other legal basis available to us for this data, so there is no quiet fallback and no reduced version of Daiven that carries on without it. That is a real trade-off and we would rather state it than bury it.
Withdrawing does not delete the account itself. When you sign in afterwards you are asked to choose: give the consent again and carry on with an empty profile, or close the account for good. Withdrawing is not, by itself, a ground for a refund — we treat it as a cancellation, and the refund terms say what that means.
If what you want is a clean slate rather than the door, you do not need any of this. Settings has a separate control that deletes your data and leaves your consent and your account intact. It asks you what to erase rather than deciding for you: your profile, your values, your patterns, your beliefs and habits, your goals, your decisions, your memories, the relationship map, your conversation history, the delivery preferences Daiven has learned, and your activity log are each a separate choice, and there is a single switch for all of it at once. Whatever you leave unticked stays exactly as it was. You can also remove individual entries whenever you like.
Being straight about this matters more than a list of security features, so here it is plainly. Your profile is never sold, never used for advertising, never used to train any AI model — ours or anyone else's — and never mined for analytics or research. No member of Daiven staff reads it in the ordinary course of running the service: the internal tools we use to operate Daiven show accounts, credit balances and error logs, and have no view of profile contents at all. Daiven is two people, so "staff" here is a named, countable set rather than an unspecified number with unspecified access.
It is decrypted for one purpose only — to answer you — and sent only to the AI provider generating that particular reply.
Your profile is encrypted field by field under a key belonging to your account alone. If our database were stolen, what the attacker got would be ciphertext without the keys to open it. That is the threat this protects against, and it is a real one.
What it does not mean is that the data is technically out of our reach. Our servers hold the master key and decrypt your profile in order to build each reply — that is unavoidable for any AI system that answers you using context about you, and any product claiming otherwise while still generating personalised responses is describing something it is not doing. We would rather tell you where the line actually is than imply a guarantee we cannot keep.
The Confidant is different by design. Those conversations are never written to our database. They do not update your profile, they are not visible to any other agent, they are not stored in your conversation history, and their content is left out of our logs.
Your message still travels to the AI provider that generates the reply — that part is unavoidable, and we would rather say so than let "never stored" imply more than it does.
To answer you, Daiven sends the AI provider serving that agent your message together with the relevant part of your profile. The model needs that context to respond as Daiven rather than as a generic assistant. This is how every AI product works, and it is the single most important thing to understand about where your data goes.
We use the following providers. Which one serves a given agent is a setting we can change, so we disclose all of them rather than only today's configuration:
| Provider | Role |
|---|---|
| OpenAI | Agent responses; also transcribes voice input |
| Anthropic | Agent responses |
| Agent responses | |
| xAI | Agent responses |
| OpenRouter | Routes requests onward to other model providers on our behalf |
None of these providers use your conversations to train their models. We use their APIs on commercial terms, under which content sent for processing is excluded from model training. OpenRouter offers a lower price in exchange for permission to route through providers that may train on the data; we have not taken it, and that setting is off on our account.
They do retain data briefly for their own abuse monitoring: OpenAI keeps abuse-monitoring logs for up to 30 days, and Anthropic deletes inputs and outputs within 30 days unless a conversation is flagged for a policy violation, in which case it may be held longer. Google logs prompts and responses only transiently for security and abuse prevention on the paid tier we use. Each provider's own policy is the authoritative statement of what it does, and we link them in the table below.
These are our processors. Each one handles data on our instructions, under a contract that requires it to protect that data and forbids it using the data for its own purposes.
| Processor | What it does for us | Location | Their privacy policy |
|---|---|---|---|
| Vercel | Hosts and serves the application | United States | vercel.com/legal/privacy-policy |
| Neon | Hosts the database holding your profile | United States | neon.com/privacy-policy |
| Upstash | Holds short-lived session state | United States | upstash.com/trust/privacy.pdf |
| Cloudflare | Sits in front of the site; security and delivery | United States | cloudflare.com/privacypolicy |
| Axiom | Stores our operational logs | United States | axiom.co/privacy |
| Resend | Sends our transactional email | United States | resend.com/legal/privacy-policy |
| Sender | Sends our marketing email | European Union | sender.net/privacy-policy |
| Stripe | Takes payment and holds card details | United States | stripe.com/privacy |
| OpenAI | Generates agent replies; transcribes voice | United States | openai.com/policies/privacy-policy |
| Anthropic | Generates agent replies | United States | anthropic.com/legal/privacy |
| Generates agent replies | United States | policies.google.com/privacy | |
| xAI | Generates agent replies | United States | x.ai/legal/privacy-policy |
| OpenRouter | Routes requests to model providers | United States | openrouter.ai/privacy |
If you sign in with Google or Facebook, that sign-in happens on their systems under their own privacy policies. We receive only the confirmation that it succeeded and the account link.
Sender, which sends our marketing email, is established in the European Union (Lithuania) and hosts subscriber data in the EU. Your address therefore stays inside the European Economic Area, and needs no Chapter V transfer safeguard.
Every other processor listed above is in the United States, so your personal data is transferred outside the European Economic Area. The European Commission has not issued a general adequacy decision for the United States, so each transfer needs its own safeguard under Chapter V of the GDPR.
We rely on the European Commission's Standard Contractual Clauses, incorporated into our data processing agreement with each provider, and — where a provider is certified under the EU–US Data Privacy Framework — on that certification. You can ask us for details of the safeguard applying to any particular provider by writing to legal@daiven.app.
| Data | Kept for |
|---|---|
| Account, profile and conversations | As long as your account exists |
| Profile data after a subscription lapses | Depends on your last plan: 14 days on the trial, 90 days on Lens, 180 days on Focus, kept indefinitely on Vision. We email you 7 days before anything is deleted. |
| Live session state | 24 hours |
| Sign-in security sessions | 15 minutes |
| Onboarding sessions in progress | 7 days |
| Operational logs | 30 days |
| Custom agents you created | As long as your account exists. Deleted if you withdraw AI-processing consent, and at any time from the agent's own page |
| Record of custom-agent creation attempts | Kept for safety review, including attempts we refused. When you delete an agent we strip what you wrote and the prompt it generated, keeping only the review outcome |
| Devices you can see in Settings → Security | While your account is active, or until you revoke the device |
| Security and sign-in records | Only as long as needed for security monitoring and to look into suspicious activity |
| Payment and accounting records | 5 years, as Polish tax law requires |
| Email delivery records and the suppression list | While needed to run email delivery and avoid mailing an address that bounces. These hold a hash of your address, not the address |
| Trial-grant hashes | For as long as we offer a free trial, so one person cannot take it repeatedly. This is a one-way hash and survives account deletion by design |
| Record of the consents you gave at sign-up | 6 years from the consent or its withdrawal. This record survives account deletion — see below |
When you delete your profile data yourself, it goes immediately and cannot be recovered. Deleting your account removes the account and everything attached to it, except the records above that we are required or entitled to keep.
About the consent record. The law requires us to be able to demonstrate that you consented, not merely to assert it. So when you create an account we keep a short record of what you agreed to: your email address, your IP address, the date, and which version of these documents was in force. It holds nothing about you beyond that.
That record outlives your account, and we would rather explain why than hide it in a table. A dispute about whether consent was ever given arrives after someone has left; if deletion erased the evidence, neither of us could settle it. We keep it under Article 17(3)(e) — establishing and defending legal claims — for six years, which is the general limitation period under Polish law, and then it goes.
Daiven sets no advertising cookies and carries no third-party tracker or social pixel. The only cookie you are asked about is a first-party one recording which link or campaign brought you here, and it is not set unless you agree.
The full list, with retention periods, and the controls to change your mind are in the cookie policy.
If you arrive through a tagged link or from another site and you agree to it, we record a short label for that channel — the name of the referring site, not an identifier for you. Withdrawing consent deletes the cookie and the copy held against your account.
We ask when you create your account whether you want occasional email about what is new in Daiven. It is a separate, unticked box, and it is genuinely optional — saying no changes nothing about the account you get. We record your answer either way, so that we can show the list was built from people who actually asked to be on it.
If you say yes, we pass your address and your account name to Sender, which is the platform that sends those messages. That is the only thing we send it, and it is the only reason your address is there at all.
You can change your mind in two places, and both do the same thing: the unsubscribe link in any message, and Settings → Email. Either way your address is deleted from Sender, not merely marked as unsubscribed, and the change is recorded against your account so the two never disagree. Unsubscribing never affects your subscription or your access to anything you have paid for.
Under the GDPR you have the right to:
We answer within one month. If a request is genuinely complex we may take up to two further months, and we will tell you within the first month if that happens. Exercising these rights is free unless a request is manifestly unfounded or excessive. We may ask you to confirm your identity first — not to obstruct you, but because handing your profile to someone impersonating you would be the worst possible outcome.
Automated decisions. Daiven's agents give you opinions, arguments and analysis. They do not make decisions that produce legal effects for you or similarly significantly affect you, so the Article 22 right does not arise. What an agent tells you is input to your judgement, never a substitute for it.
To exercise any of these rights, write to legal@daiven.app.
The same rights apply to you under the UK GDPR and the Data Protection Act 2018, and this policy should be read with "UK GDPR" substituted for "GDPR" throughout.
For transfers of UK personal data to our US processors we rely on the International Data Transfer Addendum to the Standard Contractual Clauses, or the International Data Transfer Agreement where an Addendum is not in place.
You can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint.
This section supplements the rest of the policy for California residents, using the vocabulary of the CCPA as amended by the CPRA.
Categories of personal information we collect. Identifiers (name, email address, IP address, account identifiers); commercial information (your plan, purchases and credit history); internet activity (how you use the app, and diagnostic data); audio information (voice input you record); inferences drawn about your preferences and characteristics; and sensitive personal information — your account credentials, and the contents of your conversations, which can reveal health, beliefs and personal relationships.
How we use sensitive personal information. Only to provide the service you asked for and to keep your account secure. We do not use it to infer characteristics about you for anyone else's purposes, and you therefore have nothing to limit under the "limit the use of my sensitive personal information" right — but if you want it gone, delete your profile data and it goes.
We do not sell or share personal information, in the CCPA's sense of those words, and we have not in the preceding 12 months. There is no advertising network, no data broker and no cross-context behavioural advertising anywhere in Daiven.
Your rights are to know, to delete, to correct, to opt out of sale or sharing (nothing to opt out of, as above), to limit the use of sensitive personal information, and not to be discriminated against for exercising any of them. Use the controls in Settings, or write to legal@daiven.app. You may use an authorised agent; we will ask for proof of their authority.
If you think we have handled your data badly, tell us first — legal@daiven.app — because most things are fixable directly.
You also have the right to complain to a supervisory authority:
We will update this policy as Daiven changes. The "last updated" date at the top always reflects the current version. If a change materially affects how we use your data, we will tell you before it takes effect — by email, or by a notice in the app — rather than quietly changing the page.
Previous versions are available on request.
Selenthir Sp. z o.o., Tysiąclecia 35 / 41, 41-303 Dąbrowa Górnicza, Poland.