How Corporate AI 365 handles personal data and customer code. Effective 16 August 2026.
This policy has not yet been reviewed by a lawyer. Everything below accurately describes how the product handles data, but it should be checked against the law of every jurisdiction you sell into before you rely on it.
Corporate AI 365 is operated by DirayahAI ("we", "us"), based in the United Arab Emirates. This policy explains what we collect, why, and what we do with it.
Sign-in is through Google, Microsoft or GitHub. We receive your email address, display name and the provider's account identifier. We never receive your password — there is no password field in this product.
When you connect a repository we take a point-in-time copy of its source files, and of any database schema you choose to upload. That copy is what the AI reasons over. We take structure, never the contents of your databases: if diagnosing something genuinely needs live data, the AI writes a read-only query for your own developer to run, and the result never comes back to us.
Issues, tasks, conversations, approvals and releases you create in the product. Technical logs for operating and securing the service. AI token consumption, so your plan's allowance can be measured and shown to you.
Payments are handled by our payment provider as merchant of record. We do not receive or store your card details — we hold only the plan you bought, its term, and the provider's reference for it.
| Purpose | Data | Basis |
|---|---|---|
| Providing the service you bought | Account, code copies, issues, tasks | Performance of a contract |
| Billing and tax records | Plan, term, provider reference | Legal obligation |
| Keeping the service secure and available | Technical logs | Legitimate interests |
| Service email — invitations, approvals, trial notices | Email address | Performance of a contract |
| Marketing email, if you ask for it | Email address | Consent, withdrawable at any time |
We use these sub-processors. Each does one job, and none receives more than that job requires.
| Sub-processor | What it does | What it sees |
|---|---|---|
| Railway | Hosting and managed database | All service data, at rest |
| Anthropic | AI analysis | The code excerpts and issue text needed to answer one request |
| OpenAI | AI analysis and embeddings | The same, plus code text when a repository is indexed |
| Resend | Service email delivery | Recipient address and message |
| DoDo Payments | Payments, as merchant of record | Your billing and card details, directly — not via us |
| Google / Microsoft / GitHub | Sign-in | Confirms who you are; we receive only the fields above |
If you supply your own AI provider key, your code goes to that provider under your agreement with them rather than ours. For many buyers that is the cleanest answer to this section.
We operate from the United Arab Emirates. Service data is held by our hosting provider, and AI requests are processed by the AI provider you are configured against — both of which may be outside the UAE. Where personal data leaves its originating jurisdiction we rely on the provider's standard contractual clauses.
If your procurement requires data to stay in a named region, tell us before you buy: it is a question about our hosting provider's region rather than about the product, and it is answerable.
Every record carries the identifier of the organisation it belongs to, and that filter is applied centrally at the database layer on every query rather than by each feature remembering to add it. Isolation is a property of the system rather than a convention a developer can forget.
Depending on where you live you may have the right to access, correct, delete, export or restrict the processing of your personal data, and to object to processing based on legitimate interests. Write to contact@dirayahai.com and we will respond within the period the applicable law sets.
Where we process data on behalf of your employer, they are the controller and we act on their instructions — in that case, ask them first and we will support them.
The application sets a session cookie so you stay signed in, and one that remembers your interface preferences. These are strictly necessary and cannot be turned off without breaking sign-in. We set no advertising or third-party tracking cookies.
We will post any change here and update the effective date. Where a change materially affects how we handle your data we will tell account holders by email before it takes effect.
Write to contact@dirayahai.com for anything in this policy, including a request to access, correct, export or delete your data. If you are in the UK or EU and are unhappy with our response, you may complain to your local supervisory authority.