da Vinci ("we", "us", "our") operates the da Vinci platform, an AI-powered personalised agent service. This Privacy Policy explains what data we collect, why we collect it, and how we use it.
By using the Platform, you agree to the collection and use of information as described in this policy.
When you sign in, we collect your name, email address, and profile picture as provided by your authentication provider (e.g. Google). We do not store your passwords.
During agent setup you answer questions about your preferences, interests, knowledge level, cultural context, and goals. These responses are stored and used to build and refine your personalisation profile.
We store your chosen delivery channel (email, WhatsApp, Telegram, SMS), your channel address (e.g. phone number or email), your preferred schedule, and your chosen content format.
If you rate or react to delivered content, those signals are stored and used to recalibrate your personalisation profile.
We may collect standard server logs including IP addresses, browser type, pages visited, and timestamps. This data is used for security and service improvement.
If an agent step asks you to upload or capture an image as part of onboarding, that image is stored in our secure cloud storage and used solely for personalisation purposes.
The primary use of your personal data is to generate personalised AI content. This works as follows:
1. Your onboarding responses and feedback signals are aggregated into a personalisation profile.
2. This profile is combined with the agent creator's instructions to form a system prompt — a set of instructions given to an AI language model.
3. The AI language model (currently Amazon Bedrock / Anthropic Claude) uses this prompt to generate the content delivered to you.
4. Your personal data is therefore transmitted to third-party AI providers as part of the prompt. By using the Platform, you consent to this transmission.
We do not use your data to train AI models. Your data is used exclusively to generate content personalised for you.
AI outputs are not reviewed by humans before delivery unless you are using an agent that explicitly states otherwise. You receive automated, AI-generated content directly.
To operate the Platform, we share data with the following categories of third-party services. We select providers that offer appropriate data protection guarantees:
| PROVIDER | PURPOSE | REGION |
|---|---|---|
| Google (Firebase) | Authentication, database, and file storage | US/EU |
| Amazon Web Services | Computing infrastructure and AI model access | US/EU |
| Anthropic (via Bedrock) | AI language model for content generation | US |
| Google (Gemini) | URL content fetching for agent sources | US |
| Twilio / Vonage | SMS and WhatsApp message delivery | US/EU |
| Telegram | Telegram message delivery | Global |
| SendGrid / SMTP | Email delivery | US |
When content is delivered to your chosen channel, your channel address is shared with the relevant delivery provider.
We retain your account and personalisation data for as long as your account is active.
If you delete your account, we will remove your personal data from our active systems within 30 days. Some data may be retained for up to 90 days in backups before permanent deletion.
Delivery logs and metadata may be retained for up to 12 months for security and debugging purposes.
Depending on your location, you may have the following rights regarding your personal data:
Right of access — you may request a copy of all personal data we hold about you.
Right to rectification — you may correct inaccurate data through your account settings or by contacting us.
Right to erasure — you may request deletion of your data. Requests will be fulfilled within 30 days subject to any legal retention obligations.
Right to data portability — you may request your data in a structured, machine-readable format.
Right to object — you may object to certain processing activities.
To exercise any of these rights, contact us via the Platform. We will respond within a reasonable timeframe and in any case within 30 days.
The Platform uses session cookies for authentication purposes. We do not use third-party advertising cookies.
We do not currently use any analytics trackers that follow you across other websites.
Our authentication provider (Google Firebase) may set its own cookies necessary for sign-in functionality.
The Platform is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected such data, contact us and we will delete it promptly.
Users aged 13–17 must have parental consent before using the Platform.
We implement reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, or destruction. These include: encrypted data transmission (HTTPS); cloud storage access controls; authentication via established providers.
However, no system is completely secure. We cannot guarantee absolute security and are not liable for unauthorised access resulting from circumstances beyond our reasonable control.
Because the Platform's core function is AI-driven personalisation, your personal preferences and responses are central to how the product works. We want to be transparent about this:
Your data shapes the AI prompt. What you tell us about yourself directly influences what the AI is instructed to produce. The more accurate your responses, the more relevant the output — but all outputs remain AI-generated and unverified.
Your data does not make you identifiable to AI providers. We transmit preference data and profile summaries, not your name, email address, or contact details, to AI model providers.
You can recalibrate at any time. If you want to reset your profile and start the personalisation process from scratch, you can do so from the subscription management screen.
You can delete your profile. Deleting your account removes your personalisation data. After deletion, no further AI outputs will be generated for you.
We may update this Privacy Policy from time to time. The most current version will always be available at this URL. Material changes will be communicated to registered users where practicable.
Your continued use of the Platform after changes are posted constitutes acceptance of the revised policy.
If you have questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us via the Platform.
We are committed to resolving any issues with your personal data and will respond to all reasonable requests.