DRAFT — FOR FOUNDER / LEGAL REVIEW

This policy is not yet in effect. Items marked TO CONFIRM: need a founder or legal decision before publication.

Legal — Privacy Policy

Privacy Policy

Daiton holds your company’s memory. That only works if you know exactly what we collect, what we do with it, where it lives, and how to make us delete it. This page is that list — in plain language, because you shouldn’t need a lawyer to find out what happens to your data.

Effective date: Not yet in effect — draft pending review

Operated by TO CONFIRM: legal entity name and jurisdiction

The short version. We collect your account details and the content your organization chooses to connect — Slack, email, meetings, docs, CRM records. We use it for one thing: building your organization’s memory and answering questions from your team and the AI agents you connect. It’s stored encrypted on AWS in the United States, kept while your account is active, and deleted when you ask. We don’t sell it, we don’t use it for advertising, and we don’t train AI models on it.

01 — what we collect

Five kinds of data. No hidden sixth.

  • Account information. Your name, work email, and sign-in credentials (including Google sign-in, if you use it). We use these to run your account and nothing else.

  • Content from the sources your organization connects. Your organization's admin chooses what to plug in: Slack messages, Gmail, Notion pages, calendar events, CRM records, meeting transcripts and recordings, and live voice capture. We store this content as received — including message and email bodies, and the names of the people who appear in them.

  • Facts derived from that content. Daiton extracts facts from connected content — “the Acme renewal closes March 1” — and each fact keeps a pointer back to the message, meeting, or record it came from.

  • Usage and security logs. Sign-ins, API calls, and agent-token activity: which credential did what, and when. We keep these to secure the service and to give your organization an audit trail.

  • Website analytics. On daiton.ai (this website) we use Vercel Analytics and, when enabled, Google Analytics via Google Tag Manager — these use cookies to measure site traffic. The product itself contains no advertising trackers.

What we don’t collect: anything from sources your organization hasn’t connected. Daiton has no access to a system until an admin in your organization plugs it in, and loses access the moment they unplug it.

02 — how we use it

One purpose: your organization’s memory.

We build and serve your memory. Connected content is processed to extract facts, link them to their sources, and answer questions — for the people in your organization and the AI agents your organization connects. Every answer stays inside your organization’s boundary: credentials are org-scoped, and one organization’s data is never visible to another.

Language models do the extraction. Content is processed by models from Anthropic and OpenAI only (including Anthropic’s Claude hosted on AWS Bedrock). This is enforced by an allowlist in our code that rejects every other provider — it is not a configuration that can quietly drift.

We keep the service running and secure. Logs and usage data are used to operate, debug, and protect Daiton — including the audit trail your organization sees.

Three things we never do: sell your data. Use it for advertising. Train AI models on it — our model providers process your content under API terms that exclude it from training. TO CONFIRM: verify training-exclusion terms are in our current Anthropic / OpenAI / AWS agreements

03 — storage & retention

Where it lives, and for how long.

Where: Amazon Web Services in the United States (N. Virginia, us-east-1). Data is encrypted in transit (TLS) and at rest.

How long: for as long as your organization’s account is active. Your memory is the product — we don’t expire it out from under you.

When you delete — honestly, how it works: Daiton’s memory is an append-only record: when a fact is corrected or superseded, the prior version is kept and marked superseded — that’s the audit trail. Deletion is therefore implemented as redaction: the content of the affected records is stripped or cryptographically destroyed so it is unrecoverable, it immediately leaves search, retrieval, and agent access, and the redaction survives backup restores. Minimal record skeletons (identifiers, timestamps, the fact that a redaction occurred) may remain for audit integrity. Encrypted backups age out within 35 days. TO CONFIRM: 35-day backup window — matches current PITR config? TO CONFIRM: redaction-vs-hard-delete framing — founder/legal sign-off; entity-level redaction and raw-source-copy erasure have known engineering gaps

Audit logs: access and security logs are kept up to 6 years, separate from content, to support security investigations and your organization’s own audit requirements. TO CONFIRM: 6-year audit retention is documented intent — confirm as policy

04 — third-party sharing

Who else touches it. The whole list.

We share data with exactly three kinds of parties: the service providers below, the AI agents your organization connects, and — if legally compelled — the law. Nobody else. We don’t sell data to anyone, and there are no data brokers or ad networks on this list.

ProviderWhat it does for youWhat it sees
Amazon Web ServicesHosting, storage, sign-in (Cognito), and Bedrock-hosted models — United States (us-east-1)All service data
AnthropicLanguage models that extract facts and answer questionsContent while it is being processed
OpenAILanguage models that extract facts and answer questionsContent while it is being processed
VercelHosting and analytics for daiton.ai (this website)Website visits
GoogleSign-in; website analytics when enabledYour sign-in identity; website usage
DeepgramSpeech-to-text, when you use voice captureAudio while you dictate or record
LiveKitReal-time audio transport, when you use voice captureAudio in transit
Recall.aiThe meeting bot, when your organization invites it to a meetingThat meeting's audio and video

TO CONFIRM: whether Langfuse (LLM observability) is enabled in production — if yes, it must be added to this table before publication

The AI agents you connect. Daiton’s purpose is to give your AI agents access to your organization’s memory — over MCP, at your direction. Every agent credential is scoped to your organization, readable in Settings, and revocable at any time. Which agents see your data is a decision your organization makes, not one we make for you.

Legal requests. If we’re legally required to disclose data, we comply — and we notify your organization unless the law prohibits it.

05 — your rights & controls

Your data. Your controls.

  • Disconnect anything, anytime. Your organization's admins control which sources are connected and can disconnect any of them at any moment. Agent tokens are revocable from Settings; revocation takes effect on the next request.

  • Ask for a copy. Email us and we'll give you the personal data we hold about you in a usable format.

  • Ask us to correct it. Facts in Daiton are correctable by design — and that includes facts about you.

  • Ask us to delete it. Honored by redaction, as described in section 03: the content is destroyed and immediately leaves search, retrieval, and agent access, then ages out of encrypted backups on the schedule there. Closing your organization's account deletes its memory the same way.

These controls map to the rights granted by the GDPR and, for California residents, the CCPA/CPRA — access, correction, deletion, portability, and non-discrimination for exercising them. We do not sell or share personal information as those terms are defined by the CCPA.

To exercise any of these, email privacy@daiton.ai TO CONFIRM: mailbox must exist and be monitored before publication. We respond within 30 days. A human reads it.

06 — people who aren’t users

Other people show up in your data.

Connected content includes people who don’t use Daiton — customers on the other side of an email thread, candidates in a meeting transcript, contacts in a CRM. Your organization decides what to connect, and it’s your organization’s responsibility to have the right to connect it.

Meeting recordings: if your organization records meetings through Daiton (the scribe or the meeting bot), obtaining any participant consent required by applicable recording laws is your organization’s responsibility. The meeting bot joins visibly and identifies itself — it does not record covertly. See the Terms of Service for the full clause.

If you’re one of those people and want your data corrected or removed, email privacy@daiton.ai — we’ll work with the organization that controls the data to resolve it.

Daiton is a workplace tool. It isn’t directed at children, and we don’t knowingly collect data from anyone under 16.

07 — changes & contact

If this page changes, you’ll know.

When we change this policy, we update this page and its effective date. For material changes — new data we collect, new parties who see it — we email your organization’s admins before the change takes effect.

Questions, requests, complaints: privacy@daiton.ai.