Privacy policy

What Dium collects, why, who can see it, and how to use your rights. Written for members, owners and sponsors.

Last updated Effective [Effective date] Questions: [email protected]
Template, not live data. Draft for review. Confirm bracketed items and have counsel review before publishing.

In short

  • We collect what Dium needs to run: your email and Moat profile, what you post, and how you use Flows.
  • Posts in public Flows can be read by anyone. Direct messages are only for the people in them, but they are not end-to-end encrypted.
  • We do not use advertising cookies. Site analytics is cookieless.
  • [Confirm: we do not sell or share personal information], and we honour Global Privacy Control signals.
  • You can see, fix, export or delete your data by writing to [email protected].

Who we are

This policy explains how [Legal entity name] (we), the company that runs Dium, handles personal information. Dium is built by TAO.ai. For the account, sign-in, safety and billing data described here, we are the controller. For data a business customer puts into its own Flows, we may act as its processor under our DPA, and that customer's privacy notice also applies.

Address: [Registered address]. Privacy contact: [email protected]. Data protection officer: [DPO name and contact, or state that none is appointed]. EU representative (GDPR Art. 27): [EU representative, or confirm not required]. UK representative: [UK representative, or confirm not required].

What we collect

We collect only what Dium needs to work. Some of it comes from you, some from the services you sign in with, and some from partners that invite you.

Personal information Dium processes, from the current product design.
CategoryExamplesWhere it comes from
Account and identityEmail address, Werify sign-in key, Moat public key, sign-in method, date you joined, last sign-inYou, through Werify sign-in, or a partner that signed you in
ProfileDisplay name, avatar, bio, headline, company, title, expertise and keywords. From your Moat profile: city, country, map coordinates, time zone, and any extra profile answers you gave MoatYou, directly or through Moat (Moat sends us updates when you edit your profile there)
Community membershipFlows and Rooms you joined, your role, your profile type, per-Flow name, title and company, join status, invitationsYou, Flow owners and partners
ContentWaves, replies, live chat, reactions, likes, helpful votes, best answers, poll votes, Page content, uploaded images and PDFs (up to 3 MB each)You
Direct messagesMessages, replies, edits, deletions, pins, reactions, read times, group membershipYou and the people you message
Live sessions and opportunitiesRSVPs and seats, breakout rooms, co-host roles, applications to opportunity Waves and how they were routedYou and hosts
Activity and presenceWhether you are online or typing, which Wave you are viewing, last seen time, notifications and whether you read themYour use of Dium
Reputation and safetyTrust score, flags, reports you made or received, suspension status and moderation actionsOther members, Flow staff, Dium staff, and automatic rules
PreferencesDigest frequency (daily, weekly or none), digest time zone, quiet hoursYou
PaymentsPlan, amount, currency, order number, payment status and the confirmation Werify Paywall sends back. Not your card numberWerify Paywall
Page analyticsVisits and events on sponsor and exhibitor Pages (view, button click, message, download), linked to your account when you are signed inYour use of Pages
Support conversationsWhat you type into the Dium support assistant or send to our support emailYou
Technical dataIP address, browser and device type, pages requested, error logs, rate-limit countersYour browser, our servers and Cloudflare Web Analytics

We do not ask for special categories of data (such as health or religion). Do not post them unless you are comfortable with the audience of that Flow.

How we use it and why

PurposeData usedLegal basis under GDPR
Create your account, sign you in, keep you signed inAccount, identity, cookiesContract (Art. 6(1)(b))
Run Flows, Waves, Pages, live sessions and direct messagesProfile, membership, content, direct messagesContract
Send real-time updates, notifications and email digests at the times you choseActivity, preferences, emailContract
Take payment for paid plansPayments, accountContract; legal obligation for tax records (Art. 6(1)(c))
Keep Dium safe: rate limits, abuse reports, flags, automatic suspension, security logsTechnical, reputation and safety, contentLegitimate interests in a safe service (Art. 6(1)(f))
Show trust scores and best answersContent, reputationLegitimate interests in helping members find reliable answers
Show Page owners visit and click statisticsPage analyticsLegitimate interests of Page owners and Dium [COUNSEL: confirm basis, especially if visitors are identified]
Answer support questions, including through the support assistantSupport conversations, accountContract; legitimate interests
Measure site traffic in aggregate (cookieless)TechnicalLegitimate interests in improving Dium
Send product news or the newsletterEmailConsent (Art. 6(1)(a)), which you can withdraw at any time
Comply with the law and defend legal claimsAny relevant dataLegal obligation; legitimate interests

You need to give us your email to have an account, because it is how you sign in. Everything else in your profile is optional.

What is public, and who sees what

Dium is a community product, so much of what you post is meant to be seen. This table shows who can see each kind of data. Dium staff can access data only when they need to support you, investigate a report or security issue, or meet a legal duty [confirm staff access controls and logging].

DataAnyone on the webOther membersFlow owner and staffSponsors and Page owners
Display name, avatar, headline, company, expertiseYes, through public profile search [confirm scope of public profile search]YesYesYes, if you visit or post on their Page
Waves and replies in a public FlowYes, for public Waves [confirm logged-out visitors can read public Flows]YesYesOnly in Flows they are part of
Waves and replies in a private Flow, or a limited or invite-only WaveNoOnly members allowed inYesOnly if allowed in
Direct messagesNoOnly people in the conversationNo, unless a message is reported to them [confirm whether Flow staff can see reported DMs]No
Email addressNoNo [confirm member lists never show email][confirm whether owners see member emails]No, unless you share it [confirm]
Membership, role and profile typeNoYes, across the Flow and its RoomYesOnly in Flows they are part of
Online, typing and current WaveNoYesYesOnly in Flows they are part of
City and map location from MoatNoOn the Flow's member map [confirm who can open the member map and how precise the pin is]YesSame as members
Trust score[confirm]YesYesYes
Your visits and clicks on a PageNoNoFlow admins see Flow totalsPage owners see Page statistics [confirm whether visitors are named or counted only]
RSVPs and opportunity applicationsNoOther attendees may see who is goingHosts and owners see allOnly for their own sessions
Payment detailsNoNoThe Flow owner sees the planNo

Rooms join sibling Flows together. If you belong to a Flow in a Room, members of the other Flows in that Room can see your membership and message you.

Automatic decisions

Two things in Dium happen by rule, without a person deciding each case:

  • Automatic suspension. A member who gets 5 flags from Flow staff, or one flag from a Flow owner or organizer, is suspended across Dium, and their Moat profile is blocked on other TAO.ai sites. You can ask for a person to review it, give your side, and have the decision changed, by writing to [email protected].
  • Trust score. Your score is 3 points per best answer, 1 per helpful vote, 5 per live session hosted and 1 per answer. It affects how your profile is shown, not access to jobs, money or services [confirm the trust score does not gate any significant decision].

Who we share it with

[Confirm: We do not sell your personal information]. We share it only with:

  • Other members, as the table above describes.
  • Service providers that run parts of Dium for us, listed with purpose and location on our subprocessors page. Several are TAO.ai services: the OpsDB database proxy, the Echo real-time service, LNBOX email, the Mosaic gateway behind our support assistant, and the TAO.ai file CDN.
  • Moat and Werify, the identity and sign-in services Dium shares with other TAO.ai products. We send Moat your email and Werify key to find or create your profile, and tell Moat when an account is suspended.
  • Werify Paywall, to take payment. It handles your card details under its own privacy policy [COUNSEL: confirm whether Werify Paywall acts as an independent controller].
  • Partners that invited you or embed Dium on their site. They already know who you are, and may receive activity in the Flows they run [confirm what data partners can read back through the API].
  • Services you choose to use: when you join a live session, the meeting link opens Google Meet, Zoom or another tool, under its own terms. Embedded videos load from YouTube.
  • Authorities or others when the law requires it, to protect people from harm, or in a sale or merger of our business (we will tell you before your data falls under a different policy).

International transfers

Dium is run from the United States. Our servers are hosted by [hosting provider] in [hosting region]. If you are in the EU, UK or Switzerland, your data is transferred to the US and other countries where our providers work. We protect these transfers with the European Commission's Standard Contractual Clauses (2021) and the UK International Data Transfer Addendum, and our providers do the same. Ask [email protected] for a copy of the safeguards. We do not claim to take part in the EU-US Data Privacy Framework [update only if Dium self-certifies].

How long we keep it

DataHow long
Account and profileWhile your account is open, then [deletion window, for example 30 days] after you ask us to delete it
Content and direct messagesUntil you or the Flow owner delete it. Deleted items are first soft-deleted (hidden), then removed after [purge period]
Suspended accounts and moderation records[retention period for moderation records]
Payment records[retention period, for example 7 years for tax law]
Email digest copiesA copy of each digest is saved when it is sent, for [digest copy retention period]
Server and security logs[log retention period]
One-time sign-in tokensDeleted when used, and expire after 5 minutes (partner tokens) or 2 minutes (Moat hand-off)
Peer-to-peer file sharing signalsDeleted after 5 minutes. Files themselves are never stored on our servers
Support assistant conversations[confirm whether support assistant conversations are stored, where, and for how long]
Backups[backup retention period]

How we protect it

We sign you in without passwords, keep sign-in cookies HttpOnly and Secure, check a token on changes to stop cross-site request forgery, limit how often requests can be made, and apply a strict content security policy in the app. Our security page has the full list and what we have not done yet. No system is perfectly secure. If we have a breach that puts you at risk, we will tell you and the regulators the law requires, without undue delay.

Your rights

Wherever you live, you can ask us to:

  • See the personal information we hold about you and get a copy (access and portability).
  • Correct it (most profile details you can edit yourself in Moat or Dium).
  • Delete it, or delete your account.
  • Stop or limit some uses (restriction and objection), including any use based on legitimate interests.
  • Withdraw consent you gave, such as for newsletters, at any time.
  • Have a person review an automatic decision, such as a suspension.

If you are in the EU, UK or Switzerland, you also have the right to complain to your data protection authority. We would like the chance to help first.

Extra information for US residents

This section covers California (CCPA as amended by the CPRA) and other US states with privacy laws, such as Colorado, Connecticut, Virginia, Texas and Oregon. [COUNSEL: confirm which state laws apply given Dium's size and revenue]. In the last 12 months we collected the categories below, for the purposes in How we use it and why, and disclosed them for business purposes to:

CategoryExamplesDisclosed for business purposes to
IdentifiersEmail, name, Moat public key, IP addressWerify, Moat, email delivery (LNBOX), hosting and database providers
Customer recordsName, email, payment statusWerify Paywall
Commercial informationPlans bought and payment historyWerify Paywall
Internet or network activityPages and Waves viewed, Page clicks, presenceHosting and database providers, Cloudflare Web Analytics (aggregate)
GeolocationCity, country and map coordinates from your Moat profile; approximate location from IPHosting and database providers [COUNSEL: if Moat coordinates are precise to within 1,850 feet, treat as sensitive personal information]
Professional informationHeadline, company, title, expertise, opportunity applicationsHosting and database providers
InferencesTrust scoreHosting and database providers
Content of communicationsDirect messages and posts (sensitive personal information when you are not the intended recipient)Hosting and database providers, email delivery for digests

Sale and sharing. [Confirm before publishing: We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA, and we have not done so in the last 12 months. We have no actual knowledge of selling or sharing data of anyone under 16].

Sensitive personal information. We use it only to provide Dium (for example, to deliver your direct messages), not to infer things about you. So we do not offer a separate "limit" link.

Your rights. You can ask to know, access, correct and delete your personal information, to get it in a portable format, and to opt out of sale, sharing, targeted advertising and profiling. We will not treat you differently for using these rights.

Global Privacy Control. If your browser sends a Global Privacy Control (GPC) signal, we treat it as a request to opt out of sale and sharing for that browser, and for your account if you are signed in. [Confirm: we do not sell or share today, so the signal does not change what you see], but we record and honour it [confirm how the GPC signal is detected and logged].

How to ask. Email [email protected] from the address on your account, or use [in-app privacy request link or web form]. We may confirm your identity by sending a sign-in code to that address. An authorised agent can ask for you with your signed permission. We reply within 45 days.

Appeals. If we say no, you can appeal by replying to our answer or writing to [email protected] with "Appeal" in the subject. We will answer within 45 days (60 in some states) and, if we still say no, tell you how to contact your state attorney general.

Children

Dium is not for children under [13 / 16: match minimum age in the Terms]. We do not knowingly collect their data. If you think a child has an account, write to [email protected] and we will delete it.

Cookies and local storage

Dium uses a small set of cookies and browser storage to keep you signed in and make the app fast. We do not use advertising cookies or cross-site tracking. Our site analytics (Cloudflare Web Analytics) does not use cookies. The full list is on our Cookie Policy.

Changes to this policy

We will update this policy when Dium changes. For material changes we will tell you by email or in the app at least 30 days before they take effect. The date at the top shows the current version.

Contact us

[Legal entity name], [Registered address]. Email [email protected]. We aim to reply within [response target, for example 5 business days], and within one month for formal requests under GDPR.