Data Privacy & Security
Your writing is personal, and we treat it that way. This page explains what happens to your text when you use Diglot’s AI tools, how your data is protected, and the control you have over it.
Our core promise
Section titled “Our core promise”Your writing is yours. We don’t train on it, and neither do our AI providers.
- Our AI providers are contractually prohibited from using your content to train their models.
- Your text isn’t kept by those providers beyond returning your result.
- Diglot never sells or shares your content, and never uses it for anything beyond the features you’re using.
How your data is protected
Section titled “How your data is protected”In transit. All connections use modern encryption (TLS 1.3), and the app is served over a secure, locked-down connection. Internal traffic between our systems stays on a private network.
At rest. Your data is encrypted on our servers. Backups are encrypted before they’re stored, and uploaded files are encrypted as well. Passwords are securely hashed by our sign-in system (we never store your raw password), and we require a strong password and check it against known breached-password lists at signup. API key secrets are hashed and shown only once.
What we log — and what we don’t
Section titled “What we log — and what we don’t”We never log:
- Your document content (only its length)
- The text you send to or receive from AI tools (only its length and the quality level used)
- Your email address in application logs
- Passwords, tokens, or API keys
- Payment card details — checkout is handled on a secure, hosted page, so we never see your card
- Full IP addresses in analytics (we keep only country-level information)
We do log, to keep the app working:
- Basic request information (which page, success or failure, how long it took)
- Which AI quality level handled a request, and whether a cached result was used
- Anonymized feature-usage events (no content, no personal info)
- Error reports with personal information removed
Your privacy rights (GDPR)
Section titled “Your privacy rights (GDPR)”- Export your data — download a full copy of your account (documents, settings, citation library, and authorship records). See Account management.
- Delete your account — permanently removes all of your data; analytics events are anonymized.
- Take your work with you — export any document as DOCX, PDF, or TXT at any time.
- Cookie consent — if you’re in the EU, you’ll see a cookie banner. Analytics is off by default and only on if you opt in. Cookies needed to keep you signed in are always on.
- Authorship Certificate records — for documents you’ve Certified, the verification records are kept within the retention window so others can verify them, and are removed when you delete your account.
Cookies we use
Section titled “Cookies we use”| Cookie | Purpose |
|---|---|
| Sign-in cookie | Keeps you logged in |
| Referral cookie | Credits a friend’s referral |
| Consent cookie | Remembers your cookie choice |
| Tour cookie | Remembers UI tips you’ve seen |
| Tier cookie | Remembers your AI quality choice |
We don’t use marketing cookies, and the only analytics is opt-in for EU users.
How AI tools handle your text
Section titled “How AI tools handle your text”When you use a Diglot feature such as translate, paraphrase, or grammar check:
- Your text is sent securely to the AI provider that handles that task.
- The provider processes it and returns a result.
- The provider doesn’t keep your text beyond that request.
- The provider doesn’t train on your text.
To make translation faster, we may cache a scrambled fingerprint of a segment (not your actual words) for a short time.
Access and security controls
Section titled “Access and security controls”- Every request to your data requires you to be signed in, and you can only ever access your own content.
- Staff access is tightly controlled by role, and reading Co-writer chat content requires a specific permission that isn’t granted to anyone by default — so your private chats stay private.
- Standard browser security protections are in place to guard against common web attacks.
Good to know
Section titled “Good to know”- Your content is encrypted on our servers but not end-to-end encrypted on your device.
- Cloud AI features do involve sending your text to AI providers to be processed — that’s how cloud AI works. A fully on-premise option is planned for the future.
- We continue to invest in security reviews and certifications as we grow.
Common questions
Section titled “Common questions”Is my writing private? Yes. Your documents are encrypted on our servers, sent over secure connections, and never used to train AI. Only you can access them.
Does Diglot send my text to AI providers? Yes, when you use AI features. The provider used depends on your quality level and the task, and every provider is contractually prohibited from training on your content or keeping it.
Can Diglot employees read my documents? No. Staff access is role-controlled, and reading Co-writer chat content requires a permission that isn’t assigned to anyone by default.
What happens when I delete my account? All of your data is permanently deleted, and analytics events are anonymized. The one exception: if you’ve issued an Authorship Certificate, its verification records are kept within the retention window so others can verify it.
Do you comply with GDPR? Yes — data export, account deletion, opt-in EU analytics, and document portability. See our Privacy Policy at diglot.ai/privacy.
Can I use Diglot for confidential documents? Diglot uses strong, industry-standard security, including modern encryption in transit and at rest. For maximum confidentiality, a fully on-premise option is planned but not yet available.
Was this article helpful?
Thanks for the feedback! 🎉
Sorry this didn't help — contact support and our team will sort it out.