Skip to content

Diglot Privacy Policy

Last updated: 20/09/2026

Diglot OÜ (“Diglot”, “we”, “us”, “our”), a company being registered in the Republic of Estonia — until that entry is made, the controller is its founder personally — runs the Diglot bilingual writing platform at diglot.ai, in our web editor, browser extensions, desktop and mobile apps, and the Authorship Certificate feature (collectively, the “Service”). This Privacy Policy explains what personal data we process, why, on what legal basis, with whom we share it, and what rights you have.

For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, Diglot OÜ is the controller of personal data we collect from individual users. Where Diglot is offered to a school, university, or company under a B2B / education contract, that institution is the controller and Diglot acts as a processor under the terms of our Data Processing Addendum.

1. Quick summary

  • We collect what we need to give you the Service, keep it secure, and run our business — and not more.
  • We do not sell your personal data, and we do not use the substance of your writing to train third-party foundation models.
  • Some processing happens on infrastructure outside the EEA (notably U.S. AI providers). We use standard contractual clauses, the EU-U.S. Data Privacy Framework where available, and additional safeguards.
  • The Authorship Certificate’s keystroke and timing telemetry is opt-in, based on your explicit consent.
  • You can access, export, correct, or delete your data — see Section 8.

2. What we collect and why

CategoryExamplesPurposeLegal basis (GDPR Art. 6 / 9)
Account dataEmail, name, password hash, language preferences, planCreate and manage your account; provide the ServicePerformance of contract (Art. 6(1)(b))
User ContentDrafts, prompts, instructions, files (including PDFs you upload to your research library, and the text extracted from them), translations, editsRun the writing assistant and store your workPerformance of contract (Art. 6(1)(b))
Authorship telemetry (opt-in)The text and position of each recorded edit, when it was made, whether it was typed, pasted or inserted by an AI tool, and timing and cadence patterns derived from these (intervals between edits, pauses)Generate Authorship Certificates / Proof of ProcessExplicit consent (Art. 6(1)(a) and Art. 9(2)(a))
Usage telemetryFeature usage, button clicks, page views, performance metricsMeasure product quality, find bugs, improve UXLegitimate interest (Art. 6(1)(f)) — with opt-out
Device & log dataIP address, user agent, OS, app version, timestampsSecurity, fraud prevention, abuse mitigationLegitimate interest (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c))
Billing metadataPlan, transaction IDs, country, billing email — never full card numbersTake payment via our Merchant of Record (Dodo Payments); tax compliancePerformance of contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c))
Support communicationsEmails, chat messages, attachmentsResolve your support requestsLegitimate interest (Art. 6(1)(f))
Marketing (where applicable)Newsletter sign-ups, product-update preferencesSend product news you opted in toConsent (Art. 6(1)(a))
Partner-programme attributionAn opaque click identifier, the partner’s identifier, the page you arrived on, and — with cookie consent — IP address and user agentPay a partner for a sign-up their link actually produced, and detect fraudulent self-referralsLegitimate interest (Art. 6(1)(f)) for the referral record; consent (Art. 6(1)(a)) for storing the attribution cookie on your device

We do not intentionally collect special-category data (Art. 9 GDPR) other than the Authorship telemetry described above, which we treat as behavioural-biometric data and process only with your explicit, revocable consent.

3. Generative AI and your User Content

To produce outputs (translations, paraphrases, grammar suggestions, Cowriter responses), we send the relevant portion of your User Content — together with task-specific prompts — to one or more third-party AI providers (currently Google, Groq and OpenRouter — which may route a request on to an upstream model provider such as Anthropic, DeepSeek or Z.ai — Sapling (configured for grammar checks and AI-text detection, not currently in use), and Microsoft and Google for machine translation; see Subprocessors). We use enterprise / API endpoints under contracts that prohibit those providers from using your content to train their general-purpose foundation models. Where available we use EU-region or EU-resident inference endpoints.

We do not sell your User Content. We do not use the substance of your User Content to train third-party foundation models. We may use aggregated, fully de-identified signals (e.g., “users on plan X invoke Cowriter twice per session on average”) to improve our own product and quality.

If we ever introduce optional model fine-tuning on your content for our own product, we will ask for separate, granular consent before any such use.

3.0 Research library

If you upload a PDF source, we keep the file in our object storage, split its text into chunks, and send those chunks to Google (a Gemini embedding model) to compute vector embeddings, which we store in our database so we can search your sources. On paid plans, if a PDF has no text layer, we also send the file to Google to read it (OCR). When you ask a question about your sources, we send your question and the passages retrieved from your own sources to the AI providers listed above to produce a cited answer. Your sources are private to your account.

3.1 Anonymous free tools on diglot.ai

We offer several free writing tools on our public website (for example the paraphrasing tool, sentence rewriter, and thesis-statement generator) that you can use without an account. When you press Run on one of these tools:

  • The text you enter is sent to our third-party AI provider (currently Google, with Groq and OpenRouter as fallbacks) to generate the result, under the same no-training contractual terms described above. It is sent only when you explicitly run the tool — never as you type, and never automatically on page load.
  • We do not store the text you submit, or the result, on our servers. Our request logs record only non-content metadata (which tool ran, whether it succeeded, timing and cost), never the text itself.
  • We do not create an account or user profile for you, and we do not link these requests to your identity.
  • To keep the tools free and prevent abuse, each visitor may run a limited number of tools per day. We enforce that limit using your IP address, which we keep only in truncated or hashed form for this purpose and do not use to identify you. We also use Cloudflare Turnstile to check that requests come from a person rather than an automated script; Turnstile processes limited technical information (such as your IP address and browser signals) for that anti-abuse purpose. See Cloudflare in our Subprocessors.

4. Authorship Certificate / Proof of Process

The Authorship Certificate is off by default. You can turn it on per-document or globally. When on, the editor records, for each edit, the time it was made, its position in the document, its type (typed, pasted, deleted, replaced or inserted by an AI tool), and the text that was inserted or replaced. From these records we derive timing and cadence signals, such as intervals between edits, pauses, pasted text and time on the document. The record is a sequence of edits, not a per-keystroke log. We sign the resulting log with our key, make it append-only so it cannot be altered afterwards, and store it with your document. Because it contains the text of your edits, the log holds your writing as well as behavioural data. Turning the feature off stops new recording; it does not delete what was already recorded.

Because this telemetry can in principle be analysed as behavioural biometrics, we treat it under Article 9 GDPR. We rely on your explicit consent (Art. 6(1)(a) + Art. 9(2)(a)). You can:

  • turn the Certificate off at any time in Settings → Privacy → Authorship Certificate;
  • delete previously generated Certificates from each document;
  • request deletion of all stored Certificate logs by emailing legal@diglot.ai.

We do not use Certificate data to make automated decisions that produce legal or similarly significant effects on you, and we do not share Certificate data with academic institutions or any other third party except (a) at your direction (e.g., when you choose to attach a Certificate to a submission) or (b) where required by law.

5. How long we keep data

We keep personal data only as long as we need it. Indicative retention:

DataRetention
Account dataWhile your account is active. If you delete your account it is hidden immediately and permanently erased after a 30-day grace period; there is no re-activation window
User Content (documents, drafts)Until you delete it (documents you delete stay in Trash for 7 days on Free, 30 days on Spark and 90 days on Pro and Max, then are erased), or until 30 days after account closure (the export window — see Section 8)
Authorship telemetry (raw)Up to 5 years from the date of each edit, then deleted automatically. Because the log is an unbroken signed chain, we remove old events only once no edits have been recorded on that document for 5 years; while a document is still being edited, its earlier events are kept. Deleted sooner if you delete the document or your account. This is the period shown to you when you switch the feature on
Authorship Reports (summarised)Up to 5 years (typical academic-integrity audit horizon) or until you delete the related document
Usage telemetryUp to 24 months in identifiable form, then aggregated
Security and audit logsUp to 12 months
Billing records (with our Merchant of Record)Up to 7 years (tax / accounting law)
Research sources (uploaded PDFs, extracted text chunks and embeddings)Until you delete the source (this removes the stored file and its chunks and embeddings; sources have no Trash), or until your account is permanently erased after the 30-day grace period
Marketing preferencesUntil you opt out

Where law requires longer retention (tax, anti-fraud, dispute resolution), we keep the minimum necessary record for the legally required period and isolate it from production data.

6. Who we share data with

We use a limited number of carefully selected service providers. The full, up-to-date list is published at /subprocessors and includes (without limitation):

  • Dodo Payments — Merchant of Record (billing, tax, refunds), with Paddle as a standby provider that is not currently in use;
  • Supabase — managed Postgres, authentication and object storage, hosted in the United States (AWS us-east-1); Google Cloud — application hosting (Cloud Run, us-east1);
  • Google (Vertex AI), Groq, OpenRouter — generative AI inference (OpenRouter may route requests on to model providers such as Anthropic, DeepSeek and Z.ai); Microsoft (Azure Translator), Google Cloud Translation — machine translation;
  • Cloudflare — CDN, DDoS protection, WAF, Turnstile anti-abuse checks, site hosting (Pages) and encrypted database-backup storage (R2);
  • Amazon Web Services — a second copy of our encrypted database backups (S3);
  • PostHog — product analytics, anonymised session replays and click heatmaps (with IP anonymisation). In the EEA, the UK and Switzerland it uses cookies or device storage only with your analytics cookie consent and, before you choose, runs only in cookieless mode without a persistent identifier and without replays or heatmaps; elsewhere it is on by default and can be switched off at any time. A refusal stops it. Replays record page layout, clicks, scrolling and navigation with all on-screen text and every input masked — the contents of your documents, messages and forms are never captured;
  • Google Analytics 4 — traffic, conversion and advertising measurement on our marketing site and web app, using Google Consent Mode. Google’s tag loads for every visitor, unless your browser sends a Global Privacy Control signal, in which case it does not load at all. Without analytics cookies — in the EEA, the UK and Switzerland until you accept, and anywhere after you reject or withdraw consent — the tag sets and reads no cookies. It still sends Google cookieless signals — for example that a page was viewed, or that a sign-up, a checkout or your first document happened — together with your consent choice and the technical details every web request carries (such as the page address, browser type and IP address). These signals are not tied to a cookie identifier, and Google uses them to measure and model conversions in aggregate. We do not add your name, e-mail, document content or account identifier to them. With analytics cookies — after you accept, or by default outside the EEA, the UK and Switzerland — the tag also uses the _ga cookies to recognise your browser across visits, and we have enabled Google signals, which lets Google associate this measurement with the Google accounts of signed-in users who have turned on Ads Personalization, so we see aggregated demographics, interests and cross-device reports (never individual profiles). When you pay, our server reports the purchase (amount, currency, plan — no name or e-mail) to Google Analytics using the analytics identifier of the browser that started that checkout, only if you had accepted analytics cookies (the regional default is not enough). Advertising storage and Google Ads measurement stay off until you accept all cookies, everywhere. You can withdraw consent at any time with Cookie preferences in the website footer; the tag then returns to cookieless signals. You can control Google’s use of your account data at myadcenter.google.com and opt out of Google Analytics with Google’s browser add-on;
  • Meta (Facebook) Pixel — advertising measurement on our marketing site and in our web app, loaded only with your cookie consent;
  • Sentry — error monitoring;
  • Google — Sign in with Google, if you choose that method (we receive your user ID and e-mail address);
  • Scholarly and open-data services (for example Crossref, OpenAlex, Semantic Scholar, PubMed, arXiv) — citation and source look-ups, which receive the DOI, title or topic text you look up;
  • Resend — transactional email.
  • Brave Search — web search for the research features; queries derived from your research questions are sent to Brave;
  • Linear — issue tracking for the bug and feedback reports you send from the product (your e-mail address, message and any screenshot you attach);
  • Trybe — creator-campaign attribution on our marketing site, loaded only after you click Accept all (optional cookies), and never when your browser sends a Global Privacy Control signal;
  • Google Fonts — typefaces in our web app; loading them sends your IP address to Google;
  • Affonso (ZASolution, Germany) — partner-programme attribution and commission tracking, where you arrived through a partner link.

We may also disclose personal data:

  • to comply with a binding legal request, court order, or law-enforcement demand we believe is valid;
  • to investigate suspected fraud, abuse of the Service, or threats to the safety of users or the public;
  • in connection with a corporate transaction (merger, acquisition, financing, asset sale) — in which case we will notify you and require the recipient to honour this Privacy Policy.

We do not sell your personal data and we do not “share” it for cross-context behavioural advertising in the sense of the California Consumer Privacy Act (“CCPA / CPRA”).

7. International data transfers

Diglot is operated from the EU. Some of our subprocessors are based in the United States or operate global infrastructure. When personal data leaves the European Economic Area we rely on:

  • the EU-U.S. Data Privacy Framework (where the recipient is certified, e.g., Google);
  • the European Commission’s Standard Contractual Clauses (2021) and the UK International Data Transfer Addendum;
  • supplementary technical measures including TLS 1.2+ in transit, AES-256 at rest, and least-privilege access controls;
  • a documented Transfer Impact Assessment for each cross-border data flow.

You can request a summary of the safeguards by emailing legal@diglot.ai.

8. Your rights

Depending on where you live, you have some or all of the following rights:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — correct data that is inaccurate or incomplete.
  • Deletion / “right to be forgotten” — ask us to delete your data, subject to lawful retention obligations.
  • Restriction and objection — pause or object to certain processing (in particular processing based on legitimate interest).
  • Portability — receive your User Content (and any Authorship Certificates) in a structured, machine-readable format. After account closure you have 30 days to export your data; afterwards we may delete it (Section 5 / EU Data Act).
  • Withdraw consent — for any processing based on consent (e.g., Authorship telemetry, marketing). Withdrawal does not affect processing that already happened.
  • Lodge a complaint — with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or your local supervisory authority.

For California / U.S. residents, you also have:

  • the right to know, delete, and correct personal data;
  • the right to opt out of “sale” or “sharing” — even though we do not sell or share your data, we honour the Global Privacy Control (GPC) browser signal and provide a “Do Not Sell or Share My Personal Information” link in the website footer;
  • the right to limit use of sensitive personal information — for Authorship telemetry, just turn the feature off in Settings;
  • the right to non-discrimination for exercising any of the above.

For Australian residents, you have rights under the Privacy Act 1988 (as amended in 2024–2026), including the right to know how automated decision-making is used and to seek correction or destruction of your data. You can complain to the Office of the Australian Information Commissioner (oaic.gov.au).

To exercise any of these rights, contact legal@diglot.ai or use the in-app controls in Settings → Privacy. We will respond within 30 days (extendable by a further two months for complex requests, with notice).

9. Children

The Service is not directed to children under 13, and we do not knowingly collect personal data from anyone under 13. Where the EU age of digital consent in your country is higher than 13 (it ranges from 13 to 16 across the EEA), you must be at least the local digital-consent age, or have parental consent, to use the Service. If you believe a child under 13 has given us personal data, contact legal@diglot.ai and we will delete it.

For B2B / education customers, the institution is responsible for obtaining any required parental consent under COPPA, FERPA, or local law before students use the Service.

10. EU AI Act transparency

The Service uses generative AI from third-party providers and includes algorithmic features (translation, grammar, paraphrasing, the Authorship Certificate). In line with the EU AI Act:

  • you are always told when content has been AI-generated or modified;
  • the Authorship Certificate is presented as a record of process telemetry, not as an automated determination of authorship — the final assessment is up to a human (you, your teacher, your editor);
  • we do not use the Service to take legally significant or similarly significant decisions about you in a fully automated way (Art. 22 GDPR).

If you have questions about how a particular feature works, contact legal@diglot.ai.

11. Security

We use technical and organisational measures appropriate to the risk, including:

  • TLS 1.2+ in transit and AES-256 at rest;
  • access controls and audit logging on production systems;
  • regular dependency scanning, vulnerability management, and (over time) third-party penetration testing;
  • least-privilege defaults — only a small group of engineers can access production data, and only to operate or repair the Service.

No method of transmission or storage is 100 % secure. If we ever discover a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours, as required by GDPR Art. 33–34.

12. Cookies and similar technologies

Cookies and similar technologies are described separately in our Cookie Policy. Strictly necessary cookies are loaded by default. Marketing cookies are off until you give consent. Analytics cookies are off until you give consent in the EEA, the UK and Switzerland, where before your choice we collect only cookieless, non-identifying measurement (no cookies or device storage for PostHog or Google Analytics, no persistent identifiers); elsewhere they are on by default and you can switch them off at any time via the cookie banner, cookie settings or Global Privacy Control. Google Analytics’ tag uses Google Consent Mode and, whenever analytics cookies are off, sends only the cookieless signals described in Section 6.

13. Changes to this Policy

We may update this Privacy Policy when our practices, the law, or our subprocessors change. If a change is material, we will notify you (in-product or by email) at least 30 days before it takes effect. The “Last updated” date at the top of this page always shows the current version. Earlier versions are available on request.

14. Contact

Diglot OÜ — Republic of Estonia (registration in progress; registry code and registered address are added here once the Commercial Register entry is made) Privacy & data-protection requests: legal@diglot.ai General support: support@diglot.ai Billing: support@diglot.ai — we route the request to the Merchant of Record that handled your purchase

Estonian supervisory authority: Andmekaitse Inspektsioon — aki.ee.