Privacy Policy
Last updated: August 17, 2026
This Privacy Policy explains how Diffui Inc. ("Diffui", "we", "us", or "our") collects, uses, and stores information when you use the service, including when you sign in with Google OAuth.
Information collected
When you sign in or use the service, we may collect:
- Basic account information returned by your sign-in provider, such as your email address, display name, and profile image.
- Information you submit in the product, such as prompts, generated outputs, project content, and settings you choose to save.
- Session and security data needed to keep you signed in and protect the service.
- First-party product analytics such as page views, referral attribution, MCP installations, and generation channel.
- Basic access log metadata such as IP address, user agent, request path, timestamp, and related operational diagnostics.
How information is used
Your information is used to:
- Authenticate your account and let you sign in with Google.
- Operate the service, save your work, and provide the features you request.
- Maintain service reliability, investigate abuse, prevent fraud, and debug operational issues.
- Administer billing or account-related actions if those features are used.
Analytics and tracking
We may keep standard server-side access log metadata for operational and security purposes. We may use the Meta (Facebook) Pixel and Google Tag Manager to measure visits and ad performance on public marketing pages and after you sign in or otherwise consent to cookies. Diffui Inc. does not use third-party ad pixels to track your in-app design or generation activity itself.
We also use short-lived first-party cookies to remember referral sources and an anonymous browser identifier. These let us measure page views, attributed signups, and aggregate product usage without sending that product analytics data to a third-party analytics platform. Referral cookies expire after seven days.
Diffui Inc. does not sell personal information in exchange for money. We do share limited personal information with advertising partners, and under the California Consumer Privacy Act (CCPA/CPRA) that may be considered "sharing" or a "sale": subject to your privacy choices below, we send hashed identifiers (a SHA-256 digest of your email address, name, and phone number) to Meta and Google, including directly from our servers, to measure and improve our ad campaigns. The raw values are not sent. You can opt out at any time through the cookie notice or the "Review or change your choice" link under Your privacy choices, and we honor the Global Privacy Control signal as an opt-out. Cookie consent on marketing pages is also described in our Terms of Service.
Your privacy choices
Which analytics and advertising tags run depends on where you are visiting from. We determine that from the country your network connection resolves to, and when we cannot determine it we apply the stricter option.
- European Economic Area and United Kingdom: analytics and advertising tags do not run until you accept them in the cookie notice. Declining is as easy as accepting, and nothing is pre-selected.
- United States: analytics and advertising tags may run by default, and the notice gives you a way to opt out. You can change that choice at any time through the cookie notice or the "Review or change your choice" link on this page.
- Everywhere else, and whenever the region cannot be determined, we apply the European opt-in rule.
We honor the Global Privacy Control signal. If your browser or extension sends it, we treat that as an opt-out in opt-out regions and no advertising or analytics tags run, without you having to interact with the notice. Your choice is stored in your browser, so clearing site data resets it to the default for your region.
These choices are passed to Google Tag Manager as Google Consent Mode v2 signals
(ad_storage, ad_user_data, ad_personalization, and
analytics_storage), which control whether the tags in that container may store or use data.
Sharing of information
Information may be shared when reasonably necessary to run the service or, subject to your privacy choices, to measure our advertising, such as with:
- Google, when you choose Google OAuth to authenticate.
- Infrastructure or hosting providers that process data on behalf of the service.
- Payment processors, if you make purchases or add billing information.
- Advertising and measurement partners (Meta and Google), which receive hashed identifiers (a SHA-256 digest of your email address, name, and phone number) for conversion measurement and ad attribution. This sharing is controlled by your cookie-consent choice, the "Do Not Sell or Share My Personal Information" opt-out, and the Global Privacy Control signal, as described under "Your privacy choices" above.
- Authorities or legal recipients when required by law or to protect the service from abuse or security threats.
Diffui Inc. does not sell personal information in exchange for money. The disclosure of hashed identifiers to advertising partners described above may qualify as "sharing" (or a "sale") of personal information under the CCPA/CPRA. You can opt out through the cookie notice, the "Review or change your choice" link on this page, or by enabling Global Privacy Control in your browser.
Retention
Account and project data may be retained for as long as needed to operate the service, comply with legal obligations, resolve disputes, and enforce security measures. Access log metadata may be retained for a limited period for security, auditing, and operational troubleshooting.
Your choices
You can choose not to sign in with Google by not using Google OAuth. If you want your account data deleted or need a copy of data associated with your access, contact Diffui Inc. through the same channel you used to obtain access to the service.
Changes
This Privacy Policy may be updated from time to time. Material changes will be reflected by updating the date at the top of this page.