In short
- We collect what Dium needs to run: your email and Moat profile, what you post, and how you use Flows.
- Posts in public Flows can be read by anyone. Direct messages are only for the people in them, but they are not end-to-end encrypted.
- We do not use advertising cookies. Site analytics is cookieless.
- [Confirm: we do not sell or share personal information], and we honour Global Privacy Control signals.
- You can see, fix, export or delete your data by writing to [email protected].
Who we are
This policy explains how [Legal entity name] (we), the company that runs Dium, handles personal information. Dium is built by TAO.ai. For the account, sign-in, safety and billing data described here, we are the controller. For data a business customer puts into its own Flows, we may act as its processor under our DPA, and that customer's privacy notice also applies.
Address: [Registered address]. Privacy contact: [email protected]. Data protection officer: [DPO name and contact, or state that none is appointed]. EU representative (GDPR Art. 27): [EU representative, or confirm not required]. UK representative: [UK representative, or confirm not required].
What we collect
We collect only what Dium needs to work. Some of it comes from you, some from the services you sign in with, and some from partners that invite you.
| Category | Examples | Where it comes from |
|---|---|---|
| Account and identity | Email address, Werify sign-in key, Moat public key, sign-in method, date you joined, last sign-in | You, through Werify sign-in, or a partner that signed you in |
| Profile | Display name, avatar, bio, headline, company, title, expertise and keywords. From your Moat profile: city, country, map coordinates, time zone, and any extra profile answers you gave Moat | You, directly or through Moat (Moat sends us updates when you edit your profile there) |
| Community membership | Flows and Rooms you joined, your role, your profile type, per-Flow name, title and company, join status, invitations | You, Flow owners and partners |
| Content | Waves, replies, live chat, reactions, likes, helpful votes, best answers, poll votes, Page content, uploaded images and PDFs (up to 3 MB each) | You |
| Direct messages | Messages, replies, edits, deletions, pins, reactions, read times, group membership | You and the people you message |
| Live sessions and opportunities | RSVPs and seats, breakout rooms, co-host roles, applications to opportunity Waves and how they were routed | You and hosts |
| Activity and presence | Whether you are online or typing, which Wave you are viewing, last seen time, notifications and whether you read them | Your use of Dium |
| Reputation and safety | Trust score, flags, reports you made or received, suspension status and moderation actions | Other members, Flow staff, Dium staff, and automatic rules |
| Preferences | Digest frequency (daily, weekly or none), digest time zone, quiet hours | You |
| Payments | Plan, amount, currency, order number, payment status and the confirmation Werify Paywall sends back. Not your card number | Werify Paywall |
| Page analytics | Visits and events on sponsor and exhibitor Pages (view, button click, message, download), linked to your account when you are signed in | Your use of Pages |
| Support conversations | What you type into the Dium support assistant or send to our support email | You |
| Technical data | IP address, browser and device type, pages requested, error logs, rate-limit counters | Your browser, our servers and Cloudflare Web Analytics |
We do not ask for special categories of data (such as health or religion). Do not post them unless you are comfortable with the audience of that Flow.
How we use it and why
| Purpose | Data used | Legal basis under GDPR |
|---|---|---|
| Create your account, sign you in, keep you signed in | Account, identity, cookies | Contract (Art. 6(1)(b)) |
| Run Flows, Waves, Pages, live sessions and direct messages | Profile, membership, content, direct messages | Contract |
| Send real-time updates, notifications and email digests at the times you chose | Activity, preferences, email | Contract |
| Take payment for paid plans | Payments, account | Contract; legal obligation for tax records (Art. 6(1)(c)) |
| Keep Dium safe: rate limits, abuse reports, flags, automatic suspension, security logs | Technical, reputation and safety, content | Legitimate interests in a safe service (Art. 6(1)(f)) |
| Show trust scores and best answers | Content, reputation | Legitimate interests in helping members find reliable answers |
| Show Page owners visit and click statistics | Page analytics | Legitimate interests of Page owners and Dium [COUNSEL: confirm basis, especially if visitors are identified] |
| Answer support questions, including through the support assistant | Support conversations, account | Contract; legitimate interests |
| Measure site traffic in aggregate (cookieless) | Technical | Legitimate interests in improving Dium |
| Send product news or the newsletter | Consent (Art. 6(1)(a)), which you can withdraw at any time | |
| Comply with the law and defend legal claims | Any relevant data | Legal obligation; legitimate interests |
You need to give us your email to have an account, because it is how you sign in. Everything else in your profile is optional.
What is public, and who sees what
Dium is a community product, so much of what you post is meant to be seen. This table shows who can see each kind of data. Dium staff can access data only when they need to support you, investigate a report or security issue, or meet a legal duty [confirm staff access controls and logging].
| Data | Anyone on the web | Other members | Flow owner and staff | Sponsors and Page owners |
|---|---|---|---|---|
| Display name, avatar, headline, company, expertise | Yes, through public profile search [confirm scope of public profile search] | Yes | Yes | Yes, if you visit or post on their Page |
| Waves and replies in a public Flow | Yes, for public Waves [confirm logged-out visitors can read public Flows] | Yes | Yes | Only in Flows they are part of |
| Waves and replies in a private Flow, or a limited or invite-only Wave | No | Only members allowed in | Yes | Only if allowed in |
| Direct messages | No | Only people in the conversation | No, unless a message is reported to them [confirm whether Flow staff can see reported DMs] | No |
| Email address | No | No [confirm member lists never show email] | [confirm whether owners see member emails] | No, unless you share it [confirm] |
| Membership, role and profile type | No | Yes, across the Flow and its Room | Yes | Only in Flows they are part of |
| Online, typing and current Wave | No | Yes | Yes | Only in Flows they are part of |
| City and map location from Moat | No | On the Flow's member map [confirm who can open the member map and how precise the pin is] | Yes | Same as members |
| Trust score | [confirm] | Yes | Yes | Yes |
| Your visits and clicks on a Page | No | No | Flow admins see Flow totals | Page owners see Page statistics [confirm whether visitors are named or counted only] |
| RSVPs and opportunity applications | No | Other attendees may see who is going | Hosts and owners see all | Only for their own sessions |
| Payment details | No | No | The Flow owner sees the plan | No |
Rooms join sibling Flows together. If you belong to a Flow in a Room, members of the other Flows in that Room can see your membership and message you.
Automatic decisions
Two things in Dium happen by rule, without a person deciding each case:
- Automatic suspension. A member who gets 5 flags from Flow staff, or one flag from a Flow owner or organizer, is suspended across Dium, and their Moat profile is blocked on other TAO.ai sites. You can ask for a person to review it, give your side, and have the decision changed, by writing to [email protected].
- Trust score. Your score is 3 points per best answer, 1 per helpful vote, 5 per live session hosted and 1 per answer. It affects how your profile is shown, not access to jobs, money or services [confirm the trust score does not gate any significant decision].
Who we share it with
[Confirm: We do not sell your personal information]. We share it only with:
- Other members, as the table above describes.
- Service providers that run parts of Dium for us, listed with purpose and location on our subprocessors page. Several are TAO.ai services: the OpsDB database proxy, the Echo real-time service, LNBOX email, the Mosaic gateway behind our support assistant, and the TAO.ai file CDN.
- Moat and Werify, the identity and sign-in services Dium shares with other TAO.ai products. We send Moat your email and Werify key to find or create your profile, and tell Moat when an account is suspended.
- Werify Paywall, to take payment. It handles your card details under its own privacy policy [COUNSEL: confirm whether Werify Paywall acts as an independent controller].
- Partners that invited you or embed Dium on their site. They already know who you are, and may receive activity in the Flows they run [confirm what data partners can read back through the API].
- Services you choose to use: when you join a live session, the meeting link opens Google Meet, Zoom or another tool, under its own terms. Embedded videos load from YouTube.
- Authorities or others when the law requires it, to protect people from harm, or in a sale or merger of our business (we will tell you before your data falls under a different policy).
International transfers
Dium is run from the United States. Our servers are hosted by [hosting provider] in [hosting region]. If you are in the EU, UK or Switzerland, your data is transferred to the US and other countries where our providers work. We protect these transfers with the European Commission's Standard Contractual Clauses (2021) and the UK International Data Transfer Addendum, and our providers do the same. Ask [email protected] for a copy of the safeguards. We do not claim to take part in the EU-US Data Privacy Framework [update only if Dium self-certifies].
How long we keep it
| Data | How long |
|---|---|
| Account and profile | While your account is open, then [deletion window, for example 30 days] after you ask us to delete it |
| Content and direct messages | Until you or the Flow owner delete it. Deleted items are first soft-deleted (hidden), then removed after [purge period] |
| Suspended accounts and moderation records | [retention period for moderation records] |
| Payment records | [retention period, for example 7 years for tax law] |
| Email digest copies | A copy of each digest is saved when it is sent, for [digest copy retention period] |
| Server and security logs | [log retention period] |
| One-time sign-in tokens | Deleted when used, and expire after 5 minutes (partner tokens) or 2 minutes (Moat hand-off) |
| Peer-to-peer file sharing signals | Deleted after 5 minutes. Files themselves are never stored on our servers |
| Support assistant conversations | [confirm whether support assistant conversations are stored, where, and for how long] |
| Backups | [backup retention period] |
How we protect it
We sign you in without passwords, keep sign-in cookies HttpOnly and Secure, check a token on changes to stop cross-site request forgery, limit how often requests can be made, and apply a strict content security policy in the app. Our security page has the full list and what we have not done yet. No system is perfectly secure. If we have a breach that puts you at risk, we will tell you and the regulators the law requires, without undue delay.
Your rights
Wherever you live, you can ask us to:
- See the personal information we hold about you and get a copy (access and portability).
- Correct it (most profile details you can edit yourself in Moat or Dium).
- Delete it, or delete your account.
- Stop or limit some uses (restriction and objection), including any use based on legitimate interests.
- Withdraw consent you gave, such as for newsletters, at any time.
- Have a person review an automatic decision, such as a suspension.
If you are in the EU, UK or Switzerland, you also have the right to complain to your data protection authority. We would like the chance to help first.
Extra information for US residents
This section covers California (CCPA as amended by the CPRA) and other US states with privacy laws, such as Colorado, Connecticut, Virginia, Texas and Oregon. [COUNSEL: confirm which state laws apply given Dium's size and revenue]. In the last 12 months we collected the categories below, for the purposes in How we use it and why, and disclosed them for business purposes to:
| Category | Examples | Disclosed for business purposes to |
|---|---|---|
| Identifiers | Email, name, Moat public key, IP address | Werify, Moat, email delivery (LNBOX), hosting and database providers |
| Customer records | Name, email, payment status | Werify Paywall |
| Commercial information | Plans bought and payment history | Werify Paywall |
| Internet or network activity | Pages and Waves viewed, Page clicks, presence | Hosting and database providers, Cloudflare Web Analytics (aggregate) |
| Geolocation | City, country and map coordinates from your Moat profile; approximate location from IP | Hosting and database providers [COUNSEL: if Moat coordinates are precise to within 1,850 feet, treat as sensitive personal information] |
| Professional information | Headline, company, title, expertise, opportunity applications | Hosting and database providers |
| Inferences | Trust score | Hosting and database providers |
| Content of communications | Direct messages and posts (sensitive personal information when you are not the intended recipient) | Hosting and database providers, email delivery for digests |
Sale and sharing. [Confirm before publishing: We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA, and we have not done so in the last 12 months. We have no actual knowledge of selling or sharing data of anyone under 16].
Sensitive personal information. We use it only to provide Dium (for example, to deliver your direct messages), not to infer things about you. So we do not offer a separate "limit" link.
Your rights. You can ask to know, access, correct and delete your personal information, to get it in a portable format, and to opt out of sale, sharing, targeted advertising and profiling. We will not treat you differently for using these rights.
Global Privacy Control. If your browser sends a Global Privacy Control (GPC) signal, we treat it as a request to opt out of sale and sharing for that browser, and for your account if you are signed in. [Confirm: we do not sell or share today, so the signal does not change what you see], but we record and honour it [confirm how the GPC signal is detected and logged].
How to ask. Email [email protected] from the address on your account, or use [in-app privacy request link or web form]. We may confirm your identity by sending a sign-in code to that address. An authorised agent can ask for you with your signed permission. We reply within 45 days.
Appeals. If we say no, you can appeal by replying to our answer or writing to [email protected] with "Appeal" in the subject. We will answer within 45 days (60 in some states) and, if we still say no, tell you how to contact your state attorney general.
Children
Dium is not for children under [13 / 16: match minimum age in the Terms]. We do not knowingly collect their data. If you think a child has an account, write to [email protected] and we will delete it.
Cookies and local storage
Dium uses a small set of cookies and browser storage to keep you signed in and make the app fast. We do not use advertising cookies or cross-site tracking. Our site analytics (Cloudflare Web Analytics) does not use cookies. The full list is on our Cookie Policy.
Changes to this policy
We will update this policy when Dium changes. For material changes we will tell you by email or in the app at least 30 days before they take effect. The date at the top shows the current version.
Contact us
[Legal entity name], [Registered address]. Email [email protected]. We aim to reply within [response target, for example 5 business days], and within one month for formal requests under GDPR.