Skip to content

Legal

Privacy Policy

Effective August 21, 2026

This page is about the data we hold on you — an account holder or API user. For how we handle the public third-party data our API surfaces, see the Terms of Service.

1. Scope

Diraz is an AI technology company; this Privacy Policy is about its platform and public APIs. It explains what personal data Diraz ("we", "us") collects about you when you register for, or make requests to, the Diraz platform — as an account holder, an organization member, or a visitor to our website.

It does not cover the public third-party data our Sourced API products surface (see the Terms of Service), which is not personal data we collect about you, and it does not cover any personal data you choose to submit as input to a computed product — you are the controller of that data, as explained in the Terms.

It also stops where the platform does. Personal data handled under a separate written agreement for work we do for you is governed by that agreement, and products Diraz operates separately publish their own privacy policies.

2. Information we collect

We collect the following categories of personal data:

  • Account information — your name, email address, and a securely hashed password (we never store your password in plain text). If you sign in with a third-party provider, we receive the profile information that provider shares with us.
  • Organization information — your organization's name, credit balance, and, once a payment method is completed on your account, payment records (amount, method, and status — not your raw card or account number, which is handled by our payment processor and never reaches our servers).
  • API usage metadata — which endpoint was called, when, its HTTP method and status code, how long it took, and how many credits it cost. We do not log or store the specific values you submit as input to a computed product (for example, an identity number you ask us to validate) — see "What we do not collect" below.
  • Session and security information — your session token, IP address, and browser/client user agent, used to keep you signed in and to detect abuse (for example, unusual sign-in patterns or automated bot traffic on our sign-up and login forms).
  • Support communications — anything you send to [email protected].

3. What we do not collect

When you call a computed product — a validator, parser, or calculator that takes an input you supply — that input is processed only to generate the response and is not written to our database or included in our usage logs. Our usage records (described above) capture that a call was made and what it cost, never the values inside it.

We do not sell personal data, and we do not use account or usage data to build advertising profiles.

4. How we use it

We use the information above to:

  • Operate your account, authenticate you, and enforce API keys, scopes, and rate limits;
  • Meter and bill for credit usage, and show you your own usage history;
  • Secure the Service — detect fraud, abuse, and automated attacks, including through bot-detection on our sign-up and login forms;
  • Respond to support requests you send us; and
  • Comply with our own legal and accounting obligations.

5. Retention

Detailed, per-call usage records (endpoint, timestamp, status, latency) are kept for 7 days and then deleted. Before deletion, each day's activity is summarized into a single daily total (requests and credits charged) that we keep indefinitely as your billing record — this lets us show you accurate long-term usage history without keeping an unbounded, per-call log of your traffic forever.

Account and organization information is kept for as long as your account is active, and for a reasonable period afterward to satisfy legal, accounting, or dispute-resolution needs. You may request deletion of your account at any time by contacting us — see "Your rights."

6. Sharing and disclosure

We do not sell your personal data. We share it only with:

  • Infrastructure providers who process it on our behalf to run the Service (for example, hosting and database providers), under obligations to protect it and use it only as we instruct;
  • A payment processor, to complete a transaction you initiate;
  • A bot-protection provider, to distinguish human sign-ups from automated abuse on our authentication forms; and
  • Anyone we are legally required to share it with, such as in response to a valid legal process.

7. Security

Passwords are hashed, never stored in plain text. API key secrets are shown to you once, at creation, and stored on our side only as a one-way hash — we cannot recover a lost key, only revoke and reissue one. Access to production data is limited to what operating the Service requires. No method of storage or transmission is perfectly secure, and we cannot guarantee absolute security.

8. Cookies

We use a session cookie to keep you signed in and to protect against cross-site request forgery. We do not use third-party advertising or cross-site tracking cookies. Disabling cookies in your browser will prevent you from staying signed in.

9. Your rights

Depending on where you are, you may have rights to access, correct, export, or delete your personal data, or to object to or restrict certain processing — including rights under Indonesia's Law No. 27 of 2022 on Personal Data Protection and, where applicable, the EU General Data Protection Regulation. To exercise any of these, contact us at [email protected]. We will respond within a reasonable time and may need to verify your identity first.

10. Children

The Service is not directed at, and we do not knowingly collect personal data from, anyone under 18. If you believe a child has provided us personal data, contact us and we will delete it.

11. Changes to this policy

We may update this Privacy Policy from time to time. If a change is material, we will make reasonable efforts to notify account holders before it takes effect. The effective date at the top of this page always reflects the version currently in force.

12. Contact

Questions about this policy, or requests concerning your personal data, can be sent to [email protected].