Privacy Notice
This notice explains how Div-idy handles personal information when you use our AI website-building, hosting, account, support, and billing services. Optional analytics is off unless you allow it. We do not ask for precise location when you create an account, and we do not sell personal information.
1. Who is responsible
Div-idy is the operator and controller of personal information used to run the Div-idy service. Our privacy contact is the Privacy Lead, Div-idy, at dividyapp@gmail.com. Div-idy is the service name. If you need the operator's legal or postal details for a formal request, contact the Privacy Lead.
When a Div-idy customer uses an unlisted shared project to collect information from visitors, that customer decides why the project collects the information and is generally responsible for the project's notice and lawful use. Div-idy hosts and processes those submissions for the customer and also processes limited information for platform security and operation.
2. Information we collect
| Category | Examples | Source |
|---|---|---|
| Account and identity | Email address, display name, Firebase user ID, sign-in and email-verification status, and the legal-document versions accepted at signup. | You and our authentication provider. |
| Projects and AI inputs | Prompts, instructions, code, text, images, audio you choose to submit, project settings, generated output, sharing status, and safety-review results. | You, authorized project collaborators, and generated service output. |
| Shared content and visitor submissions | Unlisted project content, ordinary form responses, room/game data, and messages submitted through a hosted project. | Project creators and project visitors. |
| Billing and subscription | Plan, subscription status, billing dates, transaction and Stripe customer identifiers, checkout status, cancellation or dispute details. Stripe processes full payment-card details; Div-idy does not store full card numbers or security codes. | You and Stripe. |
| Support and applications | Contact messages, cancellation or dispute requests, job application details, and our responses. | You. |
| Device, service, and security | IP address and request metadata in server logs, timestamps, browser/device information, authentication events, rate-limit activity, project views, error data, and abuse or fraud signals. | Your browser/device and our systems. |
| Optional analytics | Pages viewed, approximate region, device/browser type, referrer, and interaction measurements. | Google Analytics only after you allow analytics. |
Do not submit passwords, full payment-card details, government identifiers, medical records, private keys, or other highly sensitive information through prompts, projects, or support forms.
3. Why we use information and our legal bases
- Provide the service and perform our contract: create and secure accounts, save and share projects through unlisted links, generate AI output, deliver subscriptions and credits, process customer-requested billing actions, and provide support.
- Our legitimate interests, where applicable: prevent abuse and fraud, enforce platform rules, troubleshoot, protect users, maintain reliability, understand essential service performance, and improve features. We consider the effect on your rights before relying on this basis.
- Your consent: load Google Analytics and store its analytics identifiers. You may refuse or withdraw this choice at any time through the “Privacy choices” button without losing core service access.
- Legal obligations and claims: keep records required for tax, accounting, consumer protection, dispute handling, safety, or lawful government requests.
- Vital or public interests: only in uncommon situations where applicable law permits or requires this, such as an urgent threat to safety.
We do not use the Privacy Notice acknowledgment at signup as consent for optional analytics, marketing, or unrelated uses.
4. How we disclose information
We disclose information only as needed for the purposes above:
- Google Firebase for authentication, database, and storage infrastructure.
- Render for application hosting and operational logs.
- Stripe for checkout, payment processing, subscriptions, billing portals, fraud controls, refunds, and disputes.
- OpenAI to process the prompts and files you submit to AI features and return generated output.
- Google Analytics for optional site measurement after permission. Advertising personalization and Google Signals are disabled in our analytics configuration.
- Google/YouTube for documentation videos, but only after you choose to load an embedded video.
- Google Fonts to deliver fonts and icon styles used on some pages; the request exposes your IP address and basic browser request information to Google.
- Advisers, authorities, and affected parties when reasonably necessary to comply with law, establish or defend rights, investigate abuse, or protect safety.
- A successor in a business transaction if ownership or control of the service changes, subject to appropriate notice and legal protections.
Shared projects are available only through unlisted links. Div-idy does not list or intentionally index them, but anyone with the link may view, copy, or forward it.
5. International processing
Div-idy and its providers may process information in the United States and other countries. Privacy protections can differ from those where you live. Where applicable law requires a transfer safeguard, we use a legally recognized mechanism available for that transfer, such as an adequacy decision or contractual safeguards. Contact the Privacy Lead to request more information about safeguards relevant to your information.
6. Retention
We retain information only as long as reasonably necessary for the purpose collected, including:
- account and project information while the account or project remains active, and for a limited deletion/backup cycle afterward;
- project visitor submissions until the project owner removes them, the project/account is deleted, or retention is no longer needed;
- security, authentication, safety, and operational records for a limited period based on risk and troubleshooting needs;
- legal-acceptance, billing, tax, refund, dispute, and fraud-prevention records for the period required by law or reasonably needed to resolve claims; and
- support records while a request is open and afterward where needed to document its resolution.
We may keep de-identified information that can no longer reasonably identify you. Exact periods can vary by record type, provider backup cycle, legal obligation, and an active dispute.
7. Your privacy rights
Depending on where you live, you may have rights to access, receive a copy of, correct, delete, restrict, or object to processing of personal information; withdraw consent; request portability; opt out of certain sharing or targeted advertising; limit certain sensitive-information uses; appeal a denied request; and complain to a privacy regulator.
Div-idy does not sell personal information and does not use it for cross-context behavioral advertising. We honor applicable browser-based opt-out signals such as Global Privacy Control by keeping optional analytics off.
To exercise a right, email dividyapp@gmail.com from the address associated with your account and describe the request. You may also use an authorized agent where local law permits. We may verify identity and authority before acting. We will not discriminate against you for exercising a privacy right. If we deny a request, you may reply and ask us to review the decision.
8. Security
We use administrative, technical, and organizational measures designed to protect information, including authenticated access controls, ownership checks, rate and file limits, server-side controls for sensitive routes, restricted database rules, and payment processing through Stripe. No internet service is perfectly secure. Use a unique password, protect your device, and report suspected account misuse promptly.
9. Children
Div-idy accounts are intended only for people age 18 or older. We do not knowingly offer accounts to children or knowingly collect personal information from a child through account signup. Project creators must not use Div-idy to collect personal information from children in violation of applicable law. If you believe a child provided personal information improperly, contact us so we can investigate and delete it where required.
10. Automated processing
Div-idy uses automated rate limits, abuse controls, and project safety scans. A scan may block or refer creation of a share link for review, but it does not make a legal or similarly significant decision about an individual. Contact us if you believe an automated control affected your account or project incorrectly.
11. Changes to this notice
We will update the date and version above when this notice changes. For a material change, we will provide additional notice through the service, by email, or another appropriate method before the change takes effect where required. A new optional use that requires consent will not begin without that consent.
12. Contact and complaints
Email the Privacy Lead at dividyapp@gmail.com. You may also complain to the privacy or data-protection authority where you live or work. We encourage you to contact us first so we can try to resolve the concern.