DiraX Legal
Privacy Policy
Last updated: September 30, 2026
This Privacy Policy explains how Infaniti AI Inc. collects, uses, stores, and protects personal data when you use DiraX, our AI journaling product.
1. Data We Collect
We collect account information such as your email address and authentication identifiers, diary entries and diary metadata, goals, AI companion selections, chat messages, support requests, subscription and billing status, and settings or usage information generated while you use the product.
If you sign in with Google, we receive your Google account email, and your name and profile information if Google sends them, only to create and authenticate your DiraX account. We do not read your Gmail, Drive, Calendar, or other Google product data.
Diary entries may include sensitive information you choose to write, including emotions, relationships, health-adjacent reflections, or other personal topics. Please avoid entering information that you do not want processed by the service.
2. How We Use Data
We use your data to provide the journaling service, save and retrieve diary entries, analyze entries for sentiment and topics, generate AI comments, update goal and diary summaries, support companion chat, process subscriptions, provide support, maintain security, and improve product reliability.
We use optional analytics only after consent to understand aggregate product usage and improve the experience. Essential authentication, security, billing, and account operations do not depend on analytics consent.
3. AI Processing
To run companions, insights, and chat, diary text is processed by AI providers we hire for that work. Outputs such as comments, summaries, and chat replies may be stored so you can read them later.
We do not use your diary entries or interactions to fine-tune or train a model unless we introduce a separate, explicit opt-in consent flow in the future. That flow does not exist today.
4. Encryption And Access
Diary entries are encrypted in our database. Encryption keys are held as secrets and rotated. People on the team cannot open your journal as a browsing hobby. A page is decrypted only while the product is doing the work you asked for — saving, showing, commenting, insights, or chat — not as a standing human-readable archive for staff.
We treat personal identifiers carefully. Do not type government IDs, exact home addresses, bank details, or passwords into a journal. Keep the page on your days and feelings.
5. Service Providers
We use vendors in a few categories: cloud hosting and database, account sign-in, AI processing, payment processing, and optional product analytics after you consent. We do not run speech transcription or web-search add-ons in the product today.
6. Cookies And Analytics
We use strictly necessary cookies for authentication, security, and interface operation. These are required for the service to work.
PostHog analytics are optional and should only load after you consent through the cookie banner. PostHog session replay is disabled.
7. Retention And Deletion
We retain account, diary, chat, goal, subscription, and support data while your account is active and as needed to provide the service, comply with legal obligations, resolve disputes, and maintain security.
You can request account deletion from settings. Deletion removes or anonymizes user-owned application data except where limited retention is legally required, such as billing, tax, security, or compliance records.
8. Your Rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal data, and to withdraw consent for optional analytics.
To exercise privacy rights, contact support@infanitiai.com. We may need to verify your identity before fulfilling a request.
9. International Transfers
Our providers may process data in countries outside your location, including the United States. Where required, we rely on appropriate transfer mechanisms such as adequacy decisions, data processing agreements, standard contractual clauses, or equivalent safeguards.
10. Children And Vulnerable Users
DiraX is not intended for children under 13, or for users below the age at which they can lawfully consent to digital services in their jurisdiction. If you believe a child has provided data without appropriate consent, contact us.
11. Changes
We may update this policy as the product, providers, or legal requirements change. Material changes will be reflected by updating the date on this page and, where appropriate, providing additional notice.