Privacy Policy
Last updated: 23 September 2026
1. Introduction
Diploria AI ("Diploria", "we", "us", or "our") is operated by Reef Digital Agency Pty Ltd (ABN 35 151 143 476), a company incorporated in New South Wales, Australia. We provide an AI visibility monitoring platform accessible at diploria.ai (the "Service").
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Service. By accessing or using Diploria, you agree to the terms of this Privacy Policy.
We are committed to complying with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where you are located in the European Economic Area or United Kingdom, we also comply with the General Data Protection Regulation (GDPR) and UK GDPR to the extent applicable.
2. Information We Collect
We collect information you provide directly to us, information generated through your use of the Service, and information from third-party services you connect to your account.
2.1 Account Information
When you register for an account, we collect your name, email address, and (if you sign in via Google OAuth) your Google profile information (name, email, and profile photo). We do not receive your Google password.
2.2 Brand and Prompt Data
To operate the Service, we store the brand names, keywords, prompts, and related configuration data you enter. This data is used solely to perform AI visibility polls on your behalf.
2.3 Poll Results
We store the results of AI engine polls run for your account, including response content, mention status, sentiment scores, and historical trend data. This data is associated with your account and used to generate the reporting you see within the platform.
2.4 Payment Information
Payments are processed by Stripe, Inc. We do not store your full credit card number, CVV, or bank account details on our servers. Stripe provides us with a tokenised representation of your payment method and billing information (such as your billing name, address, and last four card digits) sufficient to manage your subscription.
3. How We Use Your Information
We use the information we collect to:
- Create and manage your account and authenticate your identity.
- Run AI visibility polls against the brands and prompts you configure.
- Generate reports, dashboards, and analytics within the Service.
- Process payments and manage your subscription via Stripe.
- Send you transactional communications (e.g. receipts, account notifications, and service alerts).
- Respond to your support requests and enquiries.
- Improve, maintain, and secure the Service.
- Comply with our legal obligations.
We do not sell your personal information to third parties. We do not use your brand or prompt data to train AI models.
4. Third-Party Services
4.1 Stripe
We use Stripe to process subscription payments. Stripe acts as an independent data controller for the payment information it collects. Please review Stripe's privacy policy at stripe.com/au/privacy.
4.2 Google Analytics Integration
Diploria offers an optional integration with Google Analytics 4 (GA4) that allows you to see how much of your website traffic originates from AI-powered search engines and assistants, correlated with your brand's AI visibility score in the Diploria dashboard.
Scopes requested
analytics.readonly: read-only access to your Google Analytics property data. This is the minimum scope required to retrieve traffic data; Diploria does not request any write permissions.openidandemail: used to identify which Google account you connected, so Diploria can associate the integration with your Diploria account and display the connected account address in Settings.
What GA4 data is accessed
To allow you to select a property, Diploria calls the Google Analytics Admin API accountSummaries endpoint and reads the Google Analytics accounts and GA4 properties you can access, including their account and property names. After you select a property, Diploria reads the following fields from that property via the Google Analytics Data API: session counts, traffic source domains (session source), channel groupings (for example, Organic Search, Direct, and Referral), and conversion counts using either the conversions metric (Key Events) or eventCount. This data is accessed in read-only mode only.
Purpose of access
The GA4 data retrieved is used solely to display AI referral traffic trends within your own Diploria dashboard. Specifically, it is used to show you how much of your site's traffic comes from AI-powered tools and to correlate that with your brand's AI visibility scores over time. This feature exists to help you, the account holder, understand your own data.
What this data is not used for
- GA4 data is not used for advertising, remarketing, or targeting you or any third party.
- GA4 data is not used to train AI models.
- Diploria does not modify, write to, or delete any data in your Google Analytics properties.
Who we disclose Google user data to
Diploria does not sell, rent, or trade Google user data and does not disclose Google user data for advertising. We disclose Google user data only to the following named service providers where necessary to operate the Service:
- Replit, Inc. hosts the application and the API that calls the Google Analytics APIs on your behalf, on Google Cloud Platform infrastructure.
- Neon, Inc. provides the PostgreSQL database where GA4 metrics, the connected Google account email address, and encrypted Google OAuth access and refresh tokens are stored.
- Clerk, Inc. provides authentication for the Service and holds the email address associated with your Diploria account.
- OpenAI, L.L.C. receives the limited subset of aggregated GA4-derived data described below.
Where you have connected Google Analytics, Diploria includes aggregated GA4-derived figures in prompts sent to OpenAI's API to generate the written insight shown on the LLM Traffic page and in Insights. The information included is limited to aggregated session counts, conversion counts, referral source domain names such as chatgpt.com and perplexity.ai, and channel grouping names. These prompts never include your connected Google account email address, Google OAuth access or refresh tokens, or any individual user-level or event-level GA4 data.
This processing is performed solely to produce the written insight displayed back to the same Diploria user whose connected GA4 data was used. Under OpenAI's API data usage policies, data submitted through the API is not used to train OpenAI's models. Diploria does not use Google user data to develop, improve, or train any artificial intelligence or machine learning model.
Google user data is not sent to Anthropic, Google Gemini, Perplexity, xAI, or OpenRouter. It is not sent to DataForSEO, SerpAPI, or Stripe. The connected Google account email address is never sent to any of these providers, including OpenAI, and is used only to display the connected account in Settings.
We may disclose Google user data where required by valid legal process, to investigate or respond to a security incident, or to enforce or address a breach of our Terms.
Diploria's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
User control and revocation
The Google Analytics integration is entirely optional. You can disconnect your Google Analytics account at any time from the Settings → Integrations page within Diploria. Disconnecting removes Diploria's stored OAuth tokens and immediately stops any further syncing of your GA4 data. GA4 traffic snapshot data associated with a disconnected integration is deleted within 90 days, consistent with the account closure retention policy described in Section 6. You may also revoke Diploria's access directly from your Google Account permissions page.
4.3 AI Engine APIs
To deliver visibility polling and related analysis features, the Service sends configured prompts, search queries, and relevant brand or page context to the following AI engine providers: OpenAI, Anthropic, Google (Gemini), Perplexity, xAI (Grok), and OpenRouter. Diploria also uses DataForSEO and SerpAPI as search data providers; those providers receive prompt and search query data, not Google user data. Except for the limited disclosure of aggregated GA4-derived figures to OpenAI described in Section 4.2, these requests do not include Google user data. Each provider processes requests according to its own terms and privacy policies.
5. Data Storage & Security
Your data is processed and stored using Replit, Inc. hosting services. The application and API run as a Replit Autoscale Deployment on Google Cloud Platform infrastructure in the North America project geography. The Service's database is a Neon PostgreSQL database provisioned through Replit. We implement industry-standard technical and organisational measures to protect your personal information against unauthorised access, disclosure, alteration, and destruction. These measures include encrypted data transmission (TLS), encrypted storage for sensitive fields, access controls, and regular security reviews. Google OAuth access and refresh tokens are encrypted at rest using AES-256-GCM.
No method of transmission over the internet or method of electronic storage is completely secure. While we strive to protect your personal information, we cannot guarantee its absolute security.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. When an organization deletion is verified, we stop queued work, remove live account records and private files, and record downstream processor completion. Recovery backups expire within 90 days. A documented legal hold, regulatory requirement, dispute, or security investigation can delay that final expiry.
Aggregated, de-identified poll result data that cannot reasonably be used to identify you may be retained indefinitely for product improvement and benchmarking purposes.
7. Your Rights
Subject to applicable law, you have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete personal information.
- Delete your personal information (subject to our legal retention obligations).
- Restrict or object to certain processing of your personal information.
- Data portability: receive a copy of your data in a structured, machine-readable format (where applicable under GDPR).
- Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, submit a verified request below or contact us at [email protected]. We will respond within 30 days. If you are an EEA or UK resident and are dissatisfied with our response, you have the right to lodge a complaint with your local supervisory authority.
8. Cookies
We use essential cookies to run the service, keep you signed in and remember your preferences. These cannot be turned off.
We also use optional cookies for website analytics and advertising measurement, through Google Analytics 4, Google Tag Manager, Google Ads and Umami. Google Ads cookies, including the Google Ads conversion linker, let us see which ads and clicks lead to signups, so we can measure and improve our advertising. We do not use customer-connected GA4 data for advertising, remarketing or targeting.
How we ask for your consent depends on where you are:
- In the European Economic Area, the United Kingdom, Switzerland and Canada, optional cookies stay off until you choose Accept. Nothing is loaded before then.
- Elsewhere, including Australia, the United States and New Zealand, optional cookies are on by default. You can turn them off at any time using the Cookie settings link in our website footer, or Cookie preferences in Account Settings.
If your browser sends a Global Privacy Control signal, we treat it as an opt-out and do not set optional cookies, wherever you are.
To work out which rules apply, we check the country your connection appears to come from. We do not store your IP address for this purpose.
Turning optional cookies off does not affect your access to the service.
9. Children's Privacy
Diploria is not directed at children under the age of 16. We do not knowingly collect personal information from children under 16. If you believe we have inadvertently collected such information, please contact us at [email protected] and we will promptly delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where required by law, notify you by email or through a prominent notice within the Service. Your continued use of the Service after any changes constitutes your acceptance of the updated Policy.
11. Contact Us
If you have any questions, concerns, or complaints about this Privacy Policy or our privacy practices, please contact us at:
Reef Digital Agency Pty Ltd
ABN 35 151 143 476
New South Wales, Australia
Email: [email protected]
Website: reefdigital.com.au