Legal
Privacy policy
How account, membership, research workspace, billing and service-delivery data are handled.
These legal documents are published in English. Interface language preferences do not alter their meaning, scope or governing version.
- Effective date
- 23 July 2026
- Service operator
- The Diligence Room
Controller and scope
The Diligence Room operates The Diligence Room and controls the personal data used to provide the portal, Discord membership synchronization and related service notices.
Data we process
Discord supplies your user identifier, display name and, when Discord makes it available, email address. We store membership status, sessions, alert preferences, investment profile, watchlists, saved opportunities, private notes, pipeline activity and support or audit records.
To understand whether Launch Preview is useful, we aggregate daily product events such as sign-in, catalog use, saved opportunities, workspace use, intelligence views, watchlists and exports. We also store optional value feedback and purchase intent that you submit. We do not record document contents or private notes as product-event metadata.
Stripe supplies customer, subscription, invoice and payment-status identifiers. We do not store complete card details. Resend processes recipient and delivery metadata for service emails. Security logs may include truncated network and device information.
Purposes and legal bases
Account authentication, access control, billing, requested alerts and workspace features are processed to perform the service contract. Security, fraud prevention, reliability, source attribution and audit trails rely on our legitimate interests in operating a safe and accountable service.
Opportunity email alerts are optional and are enabled only after an affirmative choice in alert settings. You can withdraw that choice at any time without losing in-app alerts. Essential access, billing and security notices remain separate from marketing.
Providers and international transfers
We use Discord for identity and community access, Stripe for billing, Resend for transactional email, OVHcloud for hosting and AWS S3 for encrypted offsite backups. These providers process only the data needed for their role and may use infrastructure outside your country under their published transfer safeguards.
OpenAI features remain disabled unless clearly activated. When enabled in the future, members will be told what content is submitted and which controls apply before use.
Retention and security
Account draft snapshots are optional and member-scoped. They are available for 30 days and are separate from saved research and pipeline records. Expired draft contents are cleared by scheduled maintenance; version markers remain to prevent stale devices from recreating a removed snapshot. Removing a draft does not remove saved work.
Optional browser performance sharing is off by default and controlled in the footer. When enabled, only the metric name and value, public landing or portal surface, and a mobile or desktop category are sent. These reports contain no account identifier, private note, document identifier or page URL. Samples expire within seven days. You may withdraw permission at any time in the same control.
Active account and workspace data are retained while the account is active. Aggregated product events and export audit records are removed after 365 days. Billing and audit records are retained as required for accounting, disputes and security. Daily encrypted backups follow a short rolling retention policy. Expired sessions, failed delivery metadata and operational logs are periodically removed or minimized.
We use signed webhooks, encrypted transport, least-privilege credentials, isolated services, access logging, active-session limits and tested restore procedures. Session security may compare recent network and browser signals to identify probable account sharing; the Founder sees risk indicators rather than raw credentials. No system can guarantee absolute security.
Your choices and rights
You may update alert preferences, disable email alerts, leave Discord or request access, correction, deletion, restriction, portability or objection where applicable. Some records may be retained where law, security or an unresolved dispute requires it.
Send requests to members@thediligenceroom.cloud. You may also contact the data-protection authority responsible for your location.