Privacy & Data Policy
Last updated: 30 July 2026
Ask Diaz (“we”, “us”) is a service operated by Sevenoways Innovations, based in Ireland. This policy explains what personal data we collect, why, who we share it with, and the rights you have. We've written it in plain English on purpose. If anything is unclear, email us at hello@sevenoways.com.
What we collect
- Account details. Your email address and a securely hashed version of your password (we never store your actual password).
- Messages you ask us to check. When you paste a suspicious message, we send its text to our AI provider to analyse it. We do not keep the message unless our system is unsure and flags it for a human (Diaz) to review — in that case we store it only for as long as needed to review it.
- Email addresses you check for breaches. We send the address you enter to a breach-lookup service to see if it appears in known data breaches. We do not store the address after checking.
- Usage.A count of how many checks you've done this month (to apply your plan's limits) and basic technical logs.
- Payment details. If you subscribe, payment is handled by Stripe. We never see or store your card number — we only keep a Stripe customer reference and your plan.
What we do NOT do
- We never sell your data.
- We don't use tracking or advertising cookies.
- We don't publish your messages. The public “scam alerts” page only shows anonymous scam categoriesand counts — never anyone's actual message.
Who we share data with
We use a small number of trusted providers to run the service. They only process data on our behalf:
- OpenRouter — analyses the messages you submit (AI scam checking).
- XposedOrNot — the breach-lookup service for the email checker.
- Stripe — processes subscription payments securely.
- Our hosting provider (OVH, managed via xCloud) — hosts the website and database.
- Our email provider — used to send you service emails and alerts (where enabled).
Some of these providers are based outside the EU/EEA. Where that's the case, transfers are protected by appropriate safeguards such as the EU Standard Contractual Clauses.
Cookies
We use one essential cookie to keep you logged in. It's strictly necessary for the service to work, so it doesn't require consent. We don't use any advertising or analytics cookies. Your recent checks on the check page are stored only in your own browser (local storage), not on our servers.
How long we keep data
- Account & subscription data: while your account is active, and for a reasonable period afterwards for legal and accounting reasons.
- Checked messages: not retained, except messages flagged for human review, which are kept only until reviewed.
- Breach-check emails: not retained after the check.
Your rights (GDPR)
Under the GDPR you have the right to access, correct, or delete your personal data, to object to or restrict its processing, and to data portability. To exercise any of these, email hello@sevenoways.comand we'll respond within one month. You can delete your account at any time, which removes your account data.
You also have the right to complain to the Irish Data Protection Commission (dataprotection.ie) if you're unhappy with how we handle your data.
Security
Passwords are stored using strong one-way hashing (scrypt), the site runs over encrypted HTTPS, and card details never touch our servers. No system is perfectly secure, but we take reasonable steps to protect your data.
Children
Ask Diaz is intended for adults and is not directed at children under 16. We don't knowingly collect data from children.
Changes
We may update this policy from time to time. We'll change the “last updated” date above, and for significant changes we'll let you know.
Contact
Questions about your data? Email hello@sevenoways.com.