Dijin is built with privacy-first controls. This policy explains what data is processed, why it is processed, and how users remain in control across memory, translation, note, insight, and context workflows.
1. Data categories
We process only the data required to run the product and support user-requested workflows.
- Account data: email, profile fields, and authentication metadata.
- Workspace data: memory, notes, insights, action items, and user-managed sharing state.
- Service diagnostics: health and security events used to keep the platform reliable.
2. Why we process data
Processing is limited to service delivery, security, and support operations.
- Provide memory and context features you explicitly use.
- Protect accounts, prevent abuse, and maintain service integrity.
- Respond to support requests, troubleshooting, and compliance obligations.
3. Security controls
Dijin applies layered controls for confidentiality, integrity, and access governance.
- Encryption in transit and at rest for managed cloud data paths.
- Role-scoped access controls and auditable service boundaries.
- Periodic security reviews and incident response procedures across all system components.
4. Data sharing boundaries
We do not sell user data. Sharing is limited to explicit product flows and required infrastructure partners.
- User-initiated sharing links and collaboration features.
- Service providers operating under contractual and security obligations.
- Lawful requests where disclosure is legally required.
5. Data retention
Retention windows are aligned with product operations and legal obligations.
- Workspace data remains available until user deletion or account closure.
- Operational and security logs are retained for limited monitoring periods.
- Backup and recovery copies expire under controlled lifecycle policies.
6. User rights and controls
Users can manage their data directly and may request additional rights handling through support.
- Access, correction, export, and deletion controls are available in product flows.
- Account and content removal requests are handled with verification safeguards.
- Region-specific rights (including GDPR/CCPA) are supported through formal request handling.
7. Connector data flow (third-party AI clients)
When you grant a third-party AI client (Claude, ChatGPT, Cursor, Zed, etc.) access to your Dijin memory via the OAuth Connector at dijin.co/oauth/authorize, the following data flow applies. Full technical reference: dijin.co/docs/connector.
- Scope-bound: each connector grant is limited to the specific scopes you select on the consent screen (summaries, evidence snippets, entities, action items, decisions, daily summaries, access log, contradictions, raw source text). Anything outside the selected scopes is refused server-side.
- Raw-source scope is the highest-trust scope (memory.transcript.read.raw). When granted, requests resolve under server-side device confirmation.
- Tamper-evident access ledger: every connector OAuth issuance, scope-denied event, rate-limit hit, and tool call appends a hash-chained row to your audit_logs. You can read it via the connector itself (getAuditLog tool) or via Settings → Privacy → Activity Log.
- Instant revocation: revoking a connector grant from Settings → Privacy → Connected Apps takes effect within one second, the AI client's next request returns token_not_found and is blocked.
- Token hashing: connector access tokens are SHA-256-hashed at rest. The raw token is shown once at issuance time and never stored unhashed. The AI client holds the raw token in its own configuration; if you reset/uninstall the AI client, the token's local copy is gone.
8. Google user data (Gmail connector)
If you connect a Gmail account, Dijin accesses Google user data under the read-only gmail.readonly scope. Dijin's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- What we access: nothing until you complete Google's OAuth consent. After connecting, a one-time discovery scan reads message headers only (sender, list and auto-reply headers — no message bodies) to show you who actually emails you. Message content is read only for the senders or domains you explicitly approve on the review screen.
- How we use it: solely to build your personal memory — extracting entities, decisions, and action items with evidence citations that you and the AI clients you authorize can recall. Gmail data is never used for advertising, never sold, and never used to train generalized AI or machine-learning models.
- Where it lives: approved messages are sealed into encrypted, signed archives (Cloudflare R2, EU region) and projected into your private memory graph (Supabase, eu-north-1 / Stockholm). Your Gmail refresh token is stored encrypted; access tokens are re-minted per use and never persisted.
- Human access: no one at Dijin reads your Gmail data. The Limited Use exceptions apply only with your explicit consent for a support request, for security or abuse investigation, or where disclosure is legally required.
- AI processing: only when Cloud Intelligence is ON, approved messages are sent ephemerally to Anthropic for extraction under a Zero Data Retention commitment — plaintext is never stored by the model provider and never used for model training.
- Deletion and revocation: disconnecting Gmail in Dijin stops all ingestion immediately; you can also revoke Dijin's access from your Google Account security settings at any time. Account deletion removes the Gmail connection, watch subscription, and discovery data, and tombstones archives with purge within 30 days.
9. Google user data (Calendar connector)
If you connect a Google Calendar account, Dijin accesses Google user data under the read-only calendar.readonly scope. Dijin's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- What we access: nothing until you complete Google's OAuth consent. After connecting, every event on your primary calendar is read automatically — unlike Gmail, there is no discovery scan or per-sender approval step, since a calendar has no equivalent "who do I actually talk to" filtering question.
- How we use it: solely to build your personal memory — extracting events, decisions, and action items with evidence citations that you and the AI clients you authorize can recall. Calendar data is never used for advertising, never sold, and never used to train generalized AI or machine-learning models.
- Where it lives: events are sealed into encrypted, signed archives (Cloudflare R2, EU region) and projected into your private memory graph (Supabase, eu-north-1 / Stockholm). Your Calendar refresh token is stored encrypted; access tokens are re-minted per use and never persisted.
- Live updates: Dijin registers a Google Calendar push-notification channel so new and changed events sync automatically; this channel is renewed weekly and never requires re-consent unless you revoke access.
- Human access: no one at Dijin reads your calendar data. The Limited Use exceptions apply only with your explicit consent for a support request, for security or abuse investigation, or where disclosure is legally required.
- AI processing: only when Cloud Intelligence is ON, event data is sent ephemerally to Anthropic for extraction under a Zero Data Retention commitment — plaintext is never stored by the model provider and never used for model training.
- Deletion and revocation: disconnecting Calendar in Dijin stops all syncing immediately; you can also revoke Dijin's access from your Google Account security settings at any time. Account deletion removes the Calendar connection and its push-notification subscription, and tombstones archives with purge within 30 days.
10. Google user data (Tasks connector)
If you connect a Google Tasks account, Dijin accesses Google user data under the read-only tasks.readonly scope. Dijin's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- What we access: nothing until you complete Google's OAuth consent. After connecting, every task list on your account is read automatically — like Calendar, there is no discovery scan or per-item approval step.
- How we use it: solely to build your personal memory — extracting tasks and action items with evidence citations that you and the AI clients you authorize can recall. Tasks data is never used for advertising, never sold, and never used to train generalized AI or machine-learning models.
- Where it lives: tasks are sealed into encrypted, signed archives (Cloudflare R2, EU region) and projected into your private memory graph (Supabase, eu-north-1 / Stockholm). Your Tasks refresh token is stored encrypted; access tokens are re-minted per use and never persisted.
- Live updates: the Google Tasks API has no push-notification support, so Dijin checks each task list for changes on an hourly schedule rather than in real time.
- Human access: no one at Dijin reads your task data. The Limited Use exceptions apply only with your explicit consent for a support request, for security or abuse investigation, or where disclosure is legally required.
- AI processing: only when Cloud Intelligence is ON, task data is sent ephemerally to Anthropic for extraction under a Zero Data Retention commitment — plaintext is never stored by the model provider and never used for model training.
- Deletion and revocation: disconnecting Tasks in Dijin stops all polling immediately; you can also revoke Dijin's access from your Google Account security settings at any time. Account deletion removes the Tasks connection and its cursor state, and tombstones archives with purge within 30 days.
Sub-processors
Dijin uses the following sub-processors to deliver the service. Each is bound by data-processing terms; users may revoke connector consent at any time, which transitively purges data from the relevant sub-processor within 30 days.
- Supabase (Postgres + Auth + Edge Functions, hosted in eu-north-1 / Stockholm). Stores user accounts, owner-signed memory metadata, encrypted OAuth tokens, and the per-user kg.* graph projection.
- Cloudflare (R2 object storage in EU region; Workers edge compute). Stores connector-attested vault archives sealed at the source by per-source Ed25519 signing keys.
- Anthropic (Claude Sonnet 4.6 + Opus 4.7 escalation) — invoked only when the user has Cloud Intelligence enabled; transcripts are sent ephemerally for entity and decision extraction under a Zero Data Retention commitment; never used for training.
- Resend (transactional email for sign-in, password reset, and account notifications). Delivers from the dijin.co domain only.
Questions about these terms?
Our support team can help with policy interpretation, compliance requests, and production usage questions.
Contact SupportContinue reading our trust documentation:
Next: GDPR Rights