Skip to main content

Legal

Privacy Policy

Effective Date: August 5, 2026 · Last Updated: August 17, 2026

Diana Intelligence Corp. (“Diana,” “we,” “us,” or “our”) operates Diana Family (the “Service”), a family update service. A child uses the Diana Family iPhone app to share short, approved updates about their everyday life with the parents and family members they choose. Those family members receive the updates by text message (SMS) or WhatsApp and do not need the app.

This Privacy Policy covers two things: the Diana Family app and service, and the getdiana.com website you are reading it on. Most of it describes the Service — what it collects, how that information is used and protected, how long it is kept, and the controls available to the child and their family. Section 2 separately covers the website, which is a marketing site and follows different practices, including advertising measurement.

1. Who Uses Diana Family

  • The child: the person sharing updates. The iPhone app is their control surface for sign-in, permissions, photo selection, review, pausing, and deletion. Diana Family is intended for people age 13 and older, and a parent or guardian must be involved in setting up and supervising the account of anyone under 18. See Children and Teens below.
  • Parents and guardians: they may create the family and add a child, or connect later to a family created by the child. They can use the web dashboard, and they receive updates by SMS or WhatsApp.
  • Other family recipients: people the child chooses to receive updates. An account is optional for receiving them.

2. The getdiana.com Website

This website is a marketing and sign-up site. It is operated separately from the Diana Family app, and the practices in this section apply only to it. Nothing collected here is combined with a family's photos, updates, or app activity.

Information You Submit

Our waitlist, contact, newsletter, demo, and early-access forms collect what you type into them — typically your email address and, where the form asks, your name and phone number. We use it to reply to you, to add you to the waitlist or mailing list you asked for, and to tell you when the product is available.

Depending on the form, those submissions are stored in and processed by Airtable, HubSpot, and Customer.io, may be posted to our internal Slack, and product feedback is handled by Featurebase. We keep them until you ask us to delete them or unsubscribe.

Trackers This Site Loads

Pages on getdiana.com load the following third-party scripts, most of them after the page is idle or you first interact with it:

  • Google Tag Manager and Google Analytics: a Google Tag Manager container that loads Google Analytics 4 and manages our other measurement tags.
  • LinkedIn Insight Tag: loaded through that container, for LinkedIn campaign measurement and audience matching.
  • Meta pixel: loaded through that container, for the advertising measurement described below.
  • HubSpot:HubSpot's tracking script, which sets its own cookie and records page views and form activity for our sales and marketing follow-up.
  • PostHog: product analytics and session recording, described below.
  • Vercel Analytics: aggregate page-view and performance measurement from our hosting provider.

Each of these providers may set cookies or similar identifiers in your browser and receives your IP address and browser user agent as part of loading. Our blog pages do not load the marketing and advertising tags.

Analytics and Session Recording

We use PostHog to understand how the site is used. It records page views, the pages you arrive on and leave from, approximate device type, the referring site, and any campaign parameters in the link you followed (for example utm_source, fbclid, or gclid). PostHog also records browsing sessions on this site — every desktop session and a sample of mobile sessions — so we can see where the site is confusing. PostHog sets a cookie that is shared across getdiana.com subdomains, and campaign parameters may be carried over when you follow a link into the Diana app.

Advertising Measurement

On some pages, including our ad-driven reminders and early-access flows, we measure whether an advertisement led to a sign-up. This uses the Meta pixel in your browser together with Meta's server-side Conversions API. For those events we send Meta the event name and page address, the Meta advertising cookies set in your browser (_fbc and _fbp), your IP address and browser user agent, and — when you have submitted them to us — a one-way cryptographic hash of your email address and phone number rather than the values themselves. Meta uses this to attribute conversions and may use it for its own advertising purposes under its own policies.

This site does not currently show a cookie consent banner. You can limit this tracking by using your browser's cookie controls or tracking protection, by using Meta's own ad-preference settings, or by not submitting a form. If you would like us to delete information collected about you through the website, email privacy@getdiana.com.

3. Information We Collect

Account and Family Information

  • Account details: name, phone number, and, if you provide it, an email address. Sign-in uses a verified phone number with a one-time code, Sign in with Apple, or Facebook; some existing accounts use email and password.
  • Family profiles: the names, relationship labels, and optional profile photos of the people and pets in a family, plus the family code used to connect accounts. A phone number is only required for a family member who receives updates; the app does not ask for one when adding a child profile.
  • Settings and consent records: review mode, pause state, custom instructions, delivery channel choices, permission and consent history, and audit records of significant account actions.
  • Device notification tokens:Apple Push Notification service tokens for the child's registered devices, used to send review requests and reminders.

Photos

  • Photo collection begins only after the child grants Photos access and chooses at least one family member to receive updates. The child can pause all collection at any time.
  • Automatic moments: the app considers one candidate at a time from a rolling seven-day window, limited to photos that appear to come from the iPhone camera. Screenshots and photos used as profile references are skipped.
  • Manual moments: the child can select a specific photo to share. The picker hides and rejects screenshots.
  • On-device minimization: a selected photo is re-encoded on the device before it leaves the phone. Original file metadata is stripped and the image is reduced to a bounded size. Full-resolution originals and EXIF data are never uploaded.
  • On-device safety check:when Apple's Sensitive Content Warning or Communication Safety is enabled on the device, Apple's analysis runs before upload and flagged photos are removed locally without being sent to us.
  • Private quarantine: uploaded photos go to a private storage area that is not a shared media library. They are used only for safety analysis and to generate one update, then deleted on the schedule in Data Retention.

Location Context

  • Diana Family never requests live or background device location, and never collects location trails.
  • When a selected photo already has coordinates saved in it, those coordinates stay in the app's protected upload queue and then, after upload, in the temporary record for that photo for up to seven days. Turning off Photos or saved-place access removes them sooner.
  • The app asks Apple's geocoding service to turn those coordinates into coarse context — city and region, neighborhood, and up to five nearby points of interest — which may be used when drafting an update. Coordinates and street addresses are never included in what a family member receives.
  • The Service rejects standalone location uploads.

Calendar Context

  • Calendar access is optional and off unless the child grants it. Diana Family works without it, and the child can revoke it at any time in iOS Settings.
  • When it is granted, the app looks at events close in time to a selected photo and derives short, coarse context — such as a general activity or occasion — that may be used when drafting an update. That derived context is kept with the temporary record for the photo.
  • We do not upload or store a copy of the calendar itself, and we do not use attendees, invitee lists, notes, or event descriptions. Calendar details are never included verbatim in what a family member receives.

Contacts

When adding a family member, the child may use Apple's one-contact system picker. Diana Family receives only the display name, the phone number chosen, and an optional contact image for the single contact selected. We do not upload, read, or enumerate the device address book. Manual entry is always available instead.

Face Recognition References

  • A family member's profile photo showing one clear face also serves as that person's recognition reference, so Diana can tell who is in a later photo. There is no separate on/off switch: whenever a family member has a usable profile photo, recognition is active for that person, and it stops when the photo is removed.
  • We use Amazon Rekognition, which converts a face into a mathematical representation stored in a collection scoped to that one family. We store the returned face identifiers, the name the child confirmed, the family member it belongs to, and consent evidence (who confirmed it, when, the terms version, and the source).
  • Matching is deliberately conservative: only high-quality faces at a very high confidence threshold are considered, matches are only accepted within the same child's family, and Diana never guesses a name. Unknown faces do not enter the update sent to family.
  • Replacing or removing a profile photo, or removing the family member, deletes the stored face representation and invalidates any retained results for that person.

Messages, Replies, and Revisions

  • The generated update text, its approval or rejection history, and any change the child asks for before it is sent.
  • A family recipient's reply or emoji reaction to an update they received. Replies are shown only to the child in the app and are never used to generate future updates or sent to our analytics tools. Authorized staff may access them for support and debugging, as described in Storage and Security.
  • Delivery records for each message: the recipient, channel, timestamps, provider confirmations, and any classified failure reason. STOP, HELP, and START are handled as messaging commands and are not stored as replies.

Diagnostics and Product Analytics

  • Crash and error reporting (Sentry): enabled only in released builds of the app. It captures crashes, hangs, and a fixed set of normalized operational failures. Session replay, screenshots, view hierarchy, network capture, and attachments are disabled, and we do not attach an account, family, child, or device identity to these reports.
  • Product analytics (PostHog): enabled only in released builds. It records app lifecycle and screen activity, a closed set of product events (for example sign-in success, adding a family member, a permission decision, a review decision, or a pause change), and content-free performance measurements such as durations, byte counts, and error classifications. Once signed in, activity is associated only with an internal account identifier, which is reset on sign-out or deletion.
  • Masked session replay: replay in the app uses screenshot mode with all text inputs, images, and system views masked. Even masked replay can reveal screen structure, so access is limited to authorized product operators.
  • Names, phone numbers, email addresses, family codes, photos, locations, generated update text, revision requests, recipient replies, and face recognition data are never sent to these tools.

Optional Evaluation Snapshots

With a child's explicit opt-in, we may collect a one-time snapshot of their previous 30 days of photos to evaluate and improve how Diana selects and describes moments. These photos go through the same on-device minimization and safety checks, are stored in an isolated private area, and never produce an update, an approval request, a notification, or a message to any family member. Evaluation data expires on its own schedule and is removed sooner on cancellation or account deletion.

4. What We Do Not Collect

  • Live or background device location, location history, or location trails.
  • A copy of your calendar, or calendar attendees, invitee lists, notes, or event descriptions. Optional calendar access is described in Calendar Context above.
  • Your device address book, or contacts you did not explicitly select.
  • Your message history, or your conversations with anyone other than Diana. We see only a reply sent to a Diana update.
  • Full-resolution photo originals or their embedded metadata, and any inference about appearance, identity, or characteristics beyond the consented face matching described above.
  • Any advertising or profiling use of app data. Photos, extracted facts, updates, messages, and family information are never used for advertising, never used to build a profile of anyone, and never sold. The separate advertising measurement on the getdiana.com website is described in Section 2 and does not touch app data.

5. How We Use Information

  • Create and operate family accounts: verify phone numbers, connect a parent and child through a family code and matching verified number, and maintain family profiles and settings.
  • Generate updates: analyze a selected photo for safety and for the small set of neutral facts used to write a short update.
  • Support child review: send the child a notification to approve, reject, or request a change before an update is delivered.
  • Deliver approved updates: send messages by SMS or WhatsApp to the family members the child approved, and record delivery outcomes.
  • Send occasional reminders:if the app has not been used for a while, we may send the child a small number of push notifications, limited to daytime hours in the device's local time zone and at most once per day.
  • Maintain safety, consent, and security: keep consent and audit records, prevent abuse, and investigate security incidents.
  • Improve the Service: use aggregate, content-free analytics and opted-in evaluation data to improve reliability and quality.

We do not use Diana Family app data for advertising, profiling, or sale to third parties. Advertising measurement on the getdiana.com website is described in Section 2 and is kept separate from app data.

6. AI Processing

Diana Family uses third-party large language models, currently from OpenAI and Google, to review a photo for safety and to write the short update text. How this works:

  • Layered review:the minimized photo passes through Apple's on-device check (when enabled), then one structured safety and fact-extraction analysis on our servers. Photos with visible nudity are rejected and deleted, and automatically collected photos with nothing meaningful to say are deleted rather than shared.
  • Minimum necessary input: the safety analysis receives only the minimized image — never coordinates or geocoded context. The step that writes the family-facing update receives only the small extracted facts plus approved coarse context, never the raw photo record.
  • No model training: photos, extracted facts, and generated text are never used to train third-party AI models. Our providers operate under commercial API agreements that prohibit training on customer data, and we use their zero- or limited-retention configurations.
  • Isolation:each family's data is segregated by account and family identifiers, enforced in the database and again in server code. There is no cross-family access.
  • AI-generated content: updates are written by AI. They can contain mistakes, so treat them as a friendly summary rather than a record of fact. Diana Family is not a safety monitoring, location tracking, medical, or emergency service. In an emergency, contact your local emergency services directly.

7. Child Review and Family Controls

  • Review mode:the child chooses whether every update is reviewed before sending, only sensitive ones are, or new moments send automatically. Updates that use a saved person's name are treated as sensitive.
  • Review itself: a pending update is sent to the child by push notification. If they do not respond within 30 minutes, we send the approval request over their configured SMS or WhatsApp channel, where they can reply Y or N, or send an instruction to change the wording. Review never times out or sends by default, and automatic collection pauses while a decision is waiting.
  • Fixed audience: the recipients and the wording are frozen when the child approves. A later change cannot add a recipient to an already-approved update, and an opt-out or removed recipient is always honored.
  • Pause and permissions: the child can pause all collection in the app, and can change or revoke Photos access in iOS Settings at any time. Both are enforced on our servers, not just in the app.
  • Deletion: the child can request deletion of their data from inside the app.

8. Messaging Program

Diana Family sends transactional SMS and WhatsApp messages: phone verification codes, child-approved family updates, a one-time welcome message when a family member is first enabled to receive updates, and family account notifications. Message frequency varies based on family activity and settings. Message and data rates may apply.

Reply STOP at any time to stop receiving messages and HELP for help. Opting out prevents Diana Family from sending you updates but does not otherwise limit available account features. Consent to receive messages is not a condition of buying any goods or services, and these are not marketing messages.

9. Mobile Number Non-Sharing

Diana Intelligence Corp. does not sell, rent, or share mobile phone numbers with third parties or affiliates for their own marketing or promotional purposes.

Text messaging originator opt-in data and consent will not be shared with any third parties, except the service providers that help us deliver and support Diana Family messages, who are required to protect that information.

10. Data Retention

Diana Family is designed to keep sensitive material for the shortest time that still makes the product work.

  • Uploaded photos and their temporary records, including any coordinates saved in the photo: 7 days. Photos rejected by safety analysis are deleted immediately, with retries if the first deletion fails.
  • Generated posters: when a selected photo is used to build a poster or similar generated image that is part of an update, a copy of that photo remains inside the finished poster. The seven-day expiry above covers the raw uploaded photo, not the poster. Posters are kept with the update they belong to until the child or family is deleted, or until the child deletes that update.
  • Extracted facts about a photo: 14 days. Facts behind an update still awaiting review are kept until the child decides.
  • Generated updates and their approval history: kept until the child or family is deleted, so the family's history of what was shared remains available. Photo previews still disappear on the shorter schedules above.
  • Recipient replies and completed revision records: 365 days, or sooner if the child or family is deleted. The text of a change request is cleared as soon as it has been applied.
  • Face representations, names, and consent records: kept until the profile photo is replaced or removed, the family member is removed, or the account is deleted.
  • Evaluation snapshot data: the collection window closes after 30 days and all evaluation photos, results, and metadata expire within 90 days, or sooner on cancellation or deletion.
  • Account, family, consent, and audit records: kept while the account is active and, for consent and audit logs, longer as needed for security and compliance.
  • Aggregate analytics: de-identified, aggregate usage data may be retained indefinitely for service improvement.
  • After deletion:a deletion request removes the associated data from active production systems within 14 days, including stored photos, posters, and face representations. Residual copies can remain in encrypted backups until those backups age out on our provider's normal rotation. We do not use backups to restore deleted data, and anything restored from a backup for an unrelated reason is re-deleted.

11. Storage and Security

  • Hosting: data is hosted in the United States using Vercel (web application and durable processing) and Supabase (managed PostgreSQL database, authentication, and private file storage).
  • Encryption: data is encrypted in transit using TLS 1.2+ and at rest using AES-256.
  • Private storage: photos and family profile images live in private storage buckets addressed by opaque paths. They are never publicly readable, and any preview shown for review or support uses a short-lived signed link.
  • On-device protection: queued photos and app settings on the iPhone are written with complete file protection, and are cleared when the account changes or deletion is requested.
  • Access controls:database row-level security scopes every family's data, server code re-checks membership, role, consent, permission, pause, and deletion state on every operation, and access to production systems is limited to authorized personnel with multi-factor authentication.
  • Staff access: authorized Diana personnel may access photos, generated update text, and recipient replies when it is needed to respond to a support request, check quality, or debug a problem. Access is limited to staff who need it, requires multi-factor authentication, and any photo preview uses a short-lived signed link. We do not browse family content otherwise, and this access ends for content that has already expired or been deleted.

12. Data Sharing

We do not sell, rent, or share your personal information with third parties except as follows:

  • Sub-processors: we use service providers to deliver the Service — Vercel (hosting and durable processing), Supabase (database, authentication, and storage), Twilio (SMS and WhatsApp delivery, including verification codes), Apple (push notifications and on-device geocoding), Amazon Web Services (Rekognition face matching), OpenAI and Google (AI analysis and update text), Sentry (crash reporting), and PostHog (product analytics). Each is contractually bound to process data only as instructed and to maintain appropriate security.
  • Website advertising and analytics: for the getdiana.com website only, PostHog receives website analytics and session recordings, Vercel receives aggregate traffic measurement, HubSpot receives page and form activity, and Google, LinkedIn, and Meta receive the measurement and advertising events described in Section 2. Google, LinkedIn, and Meta are independent advertising businesses rather than sub-processors acting only on our instructions, and they use that data under their own policies.
  • Within the family:the point of the Service is to share approved updates with the family members the child selects. A recipient sees the update text and, where applicable, the associated photo. A recipient's reply is shown only to the child.
  • Legal requirements: we may disclose information if required by law, regulation, legal process, or governmental request.
  • Business transfers: in a merger, acquisition, or sale of assets, data may be transferred as part of that transaction, subject to the same privacy protections.

13. Your Rights and Choices

  • Access: you can request a copy of the personal data we hold about you.
  • Deletion: a child can request deletion in the app, and anyone can request deletion by contacting us at privacy@getdiana.com. Data is deleted from production systems within 14 days; residual copies in encrypted backups are removed as those backups age out on their normal rotation.
  • Correction: you can request correction of inaccurate personal data, and family profiles can be edited directly in the app.
  • Data portability: you can request an export of your data in a machine-readable format.
  • Opt-out: a recipient can reply STOP at any time to stop receiving messages. A child can pause collection, revoke Photos access in iOS Settings, remove a saved person, or delete the account.

To exercise any of these rights, contact us at privacy@getdiana.com.

California Residents (CCPA)

If you are a California resident, you have additional rights under the CCPA, including the right to know what personal information we collect and how it is used, the right to request deletion, and the right to non-discrimination for exercising your privacy rights. We do not sell personal information for money. The advertising measurement on the getdiana.com website described in Section 2 may constitute “sharing” for cross-context behavioral advertising under California law; Diana Family app data is never used this way. To opt out of that website measurement, use your browser's tracking protection or email privacy@getdiana.com.

European Residents (GDPR)

If you are located in the European Economic Area, you have rights under the GDPR including access, rectification, erasure, restriction of processing, data portability, and the right to object. Our legal basis for processing is performance of a contract (providing the Service), consent (photo access, saved-place context, face recognition references, and optional evaluation snapshots), and legitimate interests (securing and improving the Service). For the website, our legal basis for analytics, session recording, and advertising measurement is your consent where required, and otherwise our legitimate interest in understanding how the site performs. Where processing is based on consent, you may withdraw it at any time in the app, in iOS Settings, or through your browser's cookie controls.

14. Children and Teens

  • Diana Family is intended for people age 13 and older. We do not knowingly collect personal information from anyone under 13. If we learn that we have collected data from a person under 13, we will delete it promptly.
  • If the child is under 18, a parent or guardian must review this Policy, consent to their participation, and remain part of the family account. Setting up a family requires a verified phone number and, where the parent creates the family, an explicit consent record for the child's participation.
  • A parent or guardian can review the family's settings and recipients, and can request access to, correction of, or deletion of their child's information by contacting privacy@getdiana.com.
  • The child keeps meaningful control regardless: they choose what is shared, can require review before anything is sent, can pause collection, and can request deletion from inside the app.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy and updating the “Last Updated” date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

16. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

Diana Intelligence Corp.
Email: privacy@getdiana.com
Security Issues: security@getdiana.com