Privacy Notice
Last updated: September 2, 2026
Dittor AI (the “Service”) is an AI-based mentoring service provided by Dailystack (the “Operator”). This Privacy Notice explains what information is collected and how it is used, shared, and retained when mentors, mentees, and other visitors use the Service.
The Service is in beta, and its features, AI models, or external services may change. If an important processing practice changes, this notice will be updated as well.
1. Who this notice applies to
In this notice, users include:
- Mentors: people who create, edit, and publish an AI persona and review mentee session briefs and conversations
- Mentees: people who converse with a mentor's persona and generate a session brief
- Visitors: people who visit the landing page or other parts of the Service
2. Information we collect or process
Depending on how the Service is used, we may process the following information.
2.1 Information provided by mentors
- Name and email address
- Supabase account ID and the Google or LinkedIn identity used to sign in
- Interview responses and the full interview conversation used to create an AI persona
- Working methods, mentoring philosophy, communication style, boundaries, and example cases
- Persona title, introductory copy, skills and instructions, and test scenarios
- Persona publication status, version, and creation and modification times
- Secret edit links and edit tokens used to edit a persona and review briefs
2.2 Information provided by or generated for mentees
- Questions and messages sent to a persona and the full conversation record
- A name or other information provided directly during the conversation
- AI-generated responses
- A session brief generated from the conversation
- Free-form feedback submitted about the brief
- Session creation time and associated persona information
Mentors or mentees may voluntarily enter sensitive or private information in free-text fields, including information about health, mental health, family or relationships, work, finances, or beliefs. The Service does not require this information. Users are encouraged not to enter sensitive information or another person's personal information when it is not necessary to use the Service.
2.3 Technical information processed automatically
- Random visitor identifiers and session identifiers
- Pages visited, request times, browser and device type, operating system, screen settings, language settings, and similar general usage information
- IP address and approximate country or city inferred from the IP address
- Service-operation metadata such as errors, response times, models used, and token counts
- Aggregated page-usage statistics generated by Vercel Web Analytics
The Operator does not directly store IP addresses with conversation records in the application database. Hosting and security providers such as Vercel may process network logs to provide the Service, respond to incidents, and maintain security.
2.4 Information generated or derived by AI
- Classification results about question type and response depth
- Results used to select relevant persona skills
- Intermediate processing results generated while producing responses
- Session briefs, summaries, hypotheses, and follow-up questions derived from conversations
- Persona drafts and test scenarios generated from mentor interviews
2.5 Subscription and payment information
When a mentor subscribes to a paid plan, the Service processes the selected plan, subscription status, PayPal payer and subscription identifiers, billing-cycle dates, transaction status, billing country, state or region, postal code, buyer type, and, for business buyers, legal business name and tax identification number. This information is stored with a transaction-time snapshot for tax, accounting, cancellation, refund, dispute, and support records. PayPal collects and processes payment-account and funding-source details on its own hosted pages. The Operator does not receive or store a user's full card or bank-account number.
3. How we use information
The Operator processes information to:
- Create, edit, store, and publish a mentor's AI persona
- Classify mentee questions and generate AI responses tailored to the persona
- Restore conversations and allow sessions to continue
- Generate session briefs and provide them to mentees and the relevant mentor
- Allow mentors to review briefs and related conversations submitted to their personas
- Start and manage paid subscriptions, unlock paid features, handle cancellations and refunds, and keep billing records
- Authenticate mentors through Google or LinkedIn and connect personas to the correct account
- Evaluate beta-service quality and improve prompts, user experience, and features
- Investigate errors, prevent abuse, manage security and capacity, and maintain service reliability
- Respond to inquiries and privacy requests and comply with legal obligations
4. Information shared with mentors and others
4.1 Information provided to the relevant mentor
When a mentee uses a specific mentor's persona, the following information may be provided to that mentor:
- The session brief
- The full conversation record up to the point when the brief was generated
- A name or other information the mentee entered directly in the conversation or feedback
- Session creation time and related persona information
This sharing is a core feature of the Service that helps the mentor prepare for an actual session. The mentee interface also explains that the conversation and brief are saved and shared with the relevant mentor.
4.2 Public persona information
When a mentor publishes a persona, public information such as the mentor's name, persona name, introductory copy, and philosophy line may be displayed to anyone through a unique URL.
5. AI services and external AI processing
5.1 Processing structure
The Service's AI features use multiple AI models and inference providers through Vercel AI Gateway. The company that developed a model and the infrastructure operator that processes a request may be different. The same model may also be processed by different providers depending on availability, performance, and Gateway routing settings.
The model families currently used are:
The list of models and providers may change based on service quality, availability, or cost. This notice will be updated if a change materially affects how personal information is processed.
5.2 Information that may be sent to AI processors
Depending on the AI feature, some or all of the following information may be sent to Vercel AI Gateway and the final inference provider:
- The user's current message and previous conversation history
- Mentor persona instructions, skills, introduction, and related settings
- AI-generated responses, intermediate processing results, and recent conversation context
- Information needed to classify questions or select relevant skills
- The full conversation record used to generate a session brief
- Mentor interview records, mentor name, and email address used to generate a persona draft
5.3 Retention and training by external providers
Vercel states that AI Gateway itself does not permanently retain prompts and outputs from model requests. However, final inference providers may temporarily cache or retain request content or metadata in logs under their own terms, security settings, and abuse-prevention policies.
Some providers state that API or enterprise requests are not used for model training by default. The Service does not guarantee that Zero Data Retention or training opt-out settings apply to every request across every provider. Users should therefore avoid entering unnecessary personal information, confidential information, or sensitive information in conversations.
Current provider policies are available in the following documents:
6. Sharing with service providers
The Operator may allow the following providers to process information as necessary to provide the Service.
The legal entity that contracts for or processes a particular AI Gateway model request may vary based on Vercel's and each provider's contractual arrangements, region, and request-routing path. The table lists the Republic of Korea or United States entities identified in the current official terms. If Vercel separately identifies the entity applicable to a particular request, that information takes precedence.
Where required by law, the Operator may provide information to law-enforcement authorities to the extent necessary under applicable law, a court order, or a valid government request.
7. Cookies, browser storage, and analytics
7.1 Visitor cookie
The Service uses an essential cookie named eai_vk, which contains a random UUID. It is used to restore and connect sessions from the same browser and is not used for advertising tracking.
- Retention period: up to 180 days
- Scope: all Service paths
- Security settings: HttpOnly, SameSite=Lax, and Secure in production
If the cookie is deleted or blocked, existing conversations may not be restorable and the browser may be treated as a new visitor.
7.2 Session storage
The browser's sessionStorage may store the page path, session ID, and session type needed to restore the current session. This information is generally deleted when the relevant browser tab or browser session ends.
7.3 Vercel Web Analytics
The Service uses Vercel Web Analytics to understand pages visited and general usage trends. Vercel states that this feature does not use third-party tracking cookies, distinguishes visitor sessions using a hash generated from requests, and discards the visitor-session identifier after 24 hours. The Operator does not use this information to build individual behavioral profiles or for personalized advertising.
8. Retention and deletion
The Service retains information for as long as necessary to fulfill the purposes for which it was collected and to provide and operate the Service.
- Visitor cookie
eai_vk: up to 180 days - Browser
sessionStorage: generally while the relevant tab or browser session remains active - Mentor information, personas, sessions, conversations, briefs, and feedback: while needed to provide the Service, review beta quality, or respond to related inquiries, or until a deletion request is processed
- Subscription and transaction records: for the subscription term and afterward for the period required by tax, accounting, consumer-protection, anti-fraud, and dispute-resolution obligations
- Logs, caches, and backups held by external service providers: for the periods set by the relevant provider's contract, security policy, and legal obligations
Some information may be retained for an additional limited period when required by law or needed for dispute resolution, security investigations, or backup recovery. In those cases, use of the information is limited to those necessary purposes.
9. International processing
The Service uses cloud and AI providers that operate globally. Personal information may therefore be processed on servers or by personnel outside the user's country of residence, where the level of privacy protection may differ from that in the user's country.
Data is transmitted through encrypted network connections while the Service is used and may be processed outside the user's country, including in:
- The United States and other regions where Vercel, Fireworks AI, OpenAI, Microsoft, and Amazon provide services
- Regions where PayPal and its payment, fraud-prevention, and customer-support infrastructure operate
- Regions where Google and Google Cloud provide services
- The region where the Supabase project and support infrastructure are located
- Overseas regions where Alibaba Cloud operates service and inference infrastructure
Because Vercel AI Gateway uses dynamic routing, the exact country in which an individual request is processed may not always be fixed. The fact that Qwen was developed in China also does not mean that a request is guaranteed to be processed only in a particular country.
10. User rights and choices
Subject to applicable law, users may request:
- Access to or a copy of their personal information
- Correction of inaccurate information
- Deletion or anonymization of personal information
- Restriction of or objection to certain processing
- Withdrawal of consent previously provided
11. Security
The Operator uses reasonable technical and administrative measures to protect personal information, including:
- Row Level Security on the database and server-only access keys
- Encryption in transit
- Random session identifiers and difficult-to-guess edit tokens
- Limiting access to personnel and service providers who need it for operational purposes
12. Changes to this notice
The Operator may revise this notice to reflect changes to Service features, AI models, providers, or legal requirements. If an important change is made, notice will be provided in an appropriate location in the Service and the “Last updated” date above will be revised.