Privacy Policy
Last updated 25 August 2026.
This policy explains what Disidea (disidea.dev) collects and what happens to it. The data controller is Painterner Limited.LTD, RM.1801 Easey Comm. Bldg., 253-261 Hennessy Road, Wan Chai, Hong Kong. Privacy questions go to privacy@disidea.dev.
What we collect
Account. Your email address. If you sign in with Google, we also receive your name, profile picture URL and Google account identifier. We do not receive your Google password.
What you write. Your threads and messages, the files in each thread's project, and the personal context you set for the models to read.
Billing. A Stripe customer identifier, your subscription status and billing period, and a ledger of credits spent. We never see or store your card number — Stripe handles the card and we only receive a reference.
Usage. For each model call: which model, what it cost, how many tokens, and whether it completed. This is how metering works, and it is tied to your account.
Technical. Standard server logs, and your IP address at the moment you create an account — kept for 24 hours and used only to rate-limit signups.
We do not use advertising cookies, analytics trackers, or third-party pixels. The only cookie is the one that keeps you signed in.
Sign-in and sessions
Your session cookie is HttpOnly, Secure and SameSite, and only a SHA-256 hash of it is stored on our side. A copy of our database does not hand anyone a working session.
Magic-link sign-in emails contain a single-use, short-lived token.
Where your content goes
To answer a question, we send the relevant part of your thread — your message, earlier answers in the thread, your personal context, and any project files a model reads — to the AI model providers you have selected. This is the core function of the product and it cannot be switched off while still using it.
Requests are routed through a model gateway operated by our parent company, which forwards them to the underlying providers (currently including OpenAI, Anthropic and Google for thread conversations, plus any separately configured utility provider used for titles and Scribe). Each provider handles data under its own terms.
We do not use your content to train any model, and we do not sell it. We cannot control whether an individual provider retains data sent to it; if that matters to you, choose your panel accordingly.
Who else processes your data
| Processor | What for | Where |
|---|---|---|
| Cloudflare | Hosting, database (D1), coordination (Durable Objects) | Global edge |
| Model gateway (Painterner) | Routing model requests, usage accounting | — |
| AI model providers | Producing answers | Per provider |
| Stripe | Payments and subscriptions | Global |
| Email provider | Sign-in links and service email | Global |
We do not transfer your data to anyone else, except where we are legally required to, or in a business transfer — in which case we would give you notice first.
How long we keep it
- Threads, projects and personal context — until you delete them. Deleting a thread also deletes its project files and its revision history.
- After a subscription ends — nothing is removed when you cancel. Threads remain for as long as the account does, and project files are kept for at least six months. Cancelling is not a deletion request; if you want your content gone, delete it or ask us.
- Your account — until you ask us to delete it. Deleting your account removes your content within 30 days, save for backups which age out within a further 30 days.
- Billing records — seven years, because tax law requires it. These are transaction records, not your content.
- Usage records — 12 months, for billing accuracy and dispute resolution.
- Signup IP addresses — 24 hours.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, or restrict how we use it. Every thread can also be exported as Markdown from inside the product at any time, without asking us.
Write to privacy@disidea.dev. We respond within 30 days. If you are in the EEA or UK, you may also complain to your local supervisory authority.
Security
Content travels over TLS. Sessions are stored hashed. Model-written code runs in a sandboxed frame on a separate origin, with no cookies, no access to your session and a restrictive content policy — so generated code cannot reach your account even if it tries.
No system is perfectly secure. If we discover a breach affecting your data, we will notify you and the relevant authority as required by law.
Children
The Service is not for anyone under 13, and we do not knowingly collect their data. If you believe a child has given us data, write to privacy@disidea.dev and we will delete it.
Changes
We will post any update here and change the date at the top. For material changes we will notify you by email or in the product before they take effect.
Contact
Painterner Limited.LTD
RM.1801 Easey Comm. Bldg., 253-261 Hennessy Road, Wan Chai, Hong Kong
privacy@disidea.dev