Privacy Policy
Last updated June 22, 2026
We take the privacy of your data seriously.
What We Collect
We collect data to operate, secure, support, and improve Dyad.
-
Telemetry Data (Opt-In)
With your consent, we collect limited telemetry data to help us monitor, maintain, and improve the reliability, performance, and security of Dyad, as well as to prevent abuse.
This telemetry may include:
- Feature usage and interaction events
- Error reports and crash diagnostics
- Model selection metadata
- Randomly generated identifiers
This telemetry is pseudonymous and does not include your chat messages, prompts, or code. We use PostHog to process desktop telemetry on our behalf.
-
Troubleshooting Logs (User-Initiated)
If you use Upload Chat Session, we may collect:
- Chat transcripts
- Selected portions of your codebase
This data is collected only with your explicit action, used solely for support and debugging, and deleted after approximately one month.
-
Service Operation Logs (Dyad Pro only)
When using Dyad Pro, your prompts and code are proxied through Dyad’s servers to reach hosted model providers. In limited cases, we may temporarily log portions of this content when necessary to:
- Investigate abuse or policy violations
- Diagnose outages, errors, or degraded performance
- Ensure the reliability and quality of the service
Access to this data is strictly limited, logs are retained only for as long as necessary for these purposes, and Dyad never uses your data to train our own models. Your data will not be used by model providers to train models except for specific models disclosed in the model UI as allowing provider training. This allows us to provide more cost-effective inference in certain cases.
How Your Data is Handled
-
Using the Free Version of Dyad (Desktop App) When using the free desktop version of Dyad, you provide your own API keys or connect to local models.
- If you use API keys, your prompts and code are sent directly to the model providers (e.g., OpenAI).
- If you use a local model, everything stays on your device. In both cases, your data never passes through Dyad's servers.
-
Using Dyad Pro (Paid Plan) Dyad Pro is a paid service that gives you access to hosted AI models via Dyad’s infrastructure. In this case, your prompts and code are proxied through Dyad servers before reaching the model providers. We only log content when necessary for abuse prevention and to monitor, maintain, and improve the reliability and performance of our service. Dyad never uses your data to train our own models. Your data will not be used by model providers to train models except for specific models disclosed in the model UI as allowing provider training. This allows us to provide more cost-effective inference in certain cases.
Full Privacy Policy
This policy applies to all products built and maintained by Dyad.
This policy applies to our handling of information about site visitors, prospective customers, and customers. We refer collectively to these categories of individuals as "you" throughout this policy.
This policy does not govern the privacy practices of apps you build with Dyad. If you build and publish an app with Dyad, you are responsible for providing any privacy notices or controls required for that app and its users.
What we collect and why
Here’s what we collect and why:
Identity and access
When you sign up for a Dyad product, we may ask for identifying information such as your name, email address.
We’ll never sell your personal information to third parties, and we won’t use your name or company in marketing statements without your permission either.
Billing information
If you sign up for a paid Dyad product, you will be asked to provide your payment information and billing address. Credit card information is submitted directly to our payment processor and doesn’t hit Dyad servers.
Website interactions
We use Umami Cloud for cookieless website analytics. Umami helps us understand aggregate website usage, such as pageviews, referrers, approximate country, browser, operating system, device type, and session duration.
Umami does not use cookies for our website analytics, and we do not use Umami for advertising or cross-site tracking. Umami may use request information such as IP address, user agent, and website ID to derive anonymous session metrics.
Cookies and marketing attribution
We use a small number of first-party cookies to understand which channels bring visitors to Dyad — for example, a marketing campaign, a search engine, or a link from another site. We do not use these cookies for advertising or cross-site tracking.
These cookies store a compact record of how you arrived — campaign parameters (UTM tags), the referring site or search engine, the landing page, and a timestamp — for your first visit and your most recent visit. They are retained for about 90 days. If you create an account, this attribution may be associated with your account so we can measure which channels lead to sign-ups.
If you are in the EEA or UK, these attribution cookies are only set after you accept them via our cookie banner; if you decline, they are not set. Your consent choice is itself stored in a cookie for about six months so we don't ask again. You can withdraw consent at any time by clearing the Dyad cookies in your browser.
Voluntary correspondence
When you email Dyad with a question or to ask for help, we keep that correspondence, including your email address, so that we have a history of past correspondence to reference if you reach out in the future.
Transactional emails
We use Mailgun to send transactional emails about your Dyad account, subscription, credits, cancellation, and referral rewards. Mailgun processes the email address and message content needed to deliver those emails on our behalf.
Email updates and subscriber status
We use ConvertKit to manage Dyad email updates and subscriber lists. When you create a Dyad account or subscribe to a paid plan, we may share your email address with ConvertKit and apply subscriber tags that reflect account or subscription status, such as new account signup, active Pro subscription, or unsubscribed subscription status.
We use this information to send product updates, onboarding emails, and relevant account or subscription-related communications. You can unsubscribe from marketing emails using the unsubscribe link in those emails. Transactional emails about your account, billing, credits, or service changes may still be sent where necessary to operate Dyad.
When we access or disclose your information
Dyad limits human access to your content to specific cases: when you ask us for support or debugging help, when we need to investigate abuse or security issues, when limited access is necessary to diagnose service reliability problems, or when we are required to respond to legal process (see "When required under applicable law" below). Access is limited to the people who need it for those purposes, and we look for root cause solutions as much as possible to avoid repeated manual access.
To help you troubleshoot or squash a software bug, with your permission. If at any point we need to access your content to help you with a support case, we will ask for your consent before proceeding.
To investigate, prevent, or take action regarding restricted uses. Accessing a customer’s account when investigating potential abuse is a measure of last resort. We want to protect the privacy and safety of both our customers and the people reporting issues to us, and we do our best to balance those responsibilities throughout the process. If we discover you are using our products for a restricted purpose, we will take action as necessary, including notifying appropriate authorities where warranted.
Aggregated and de-identified data. We may aggregate and/or de-identify information collected through the services. We may use de-identified or aggregated data for any purpose, including marketing or analytics.
When required under applicable law. Dyad is a U.S. company and its own infrastructure is located in the U.S. (some third-party processors may operate in the U.S. or the E.U.).
-
Requests for user data. Our policy is to not respond to government requests for user data unless we are compelled by legal process or in limited circumstances in the event of an emergency request. However, if U.S. law enforcement authorities have the necessary warrant, criminal subpoena, or court order requiring us to disclose data, we must comply. Likewise, we will only respond to requests from government authorities outside the U.S. if compelled by the U.S. government through procedures outlined in a mutual legal assistance treaty or agreement. It is Dyad’ policy to notify affected users before we disclose data unless we are legally prohibited from doing so, and except in some emergency cases.
-
Preservation requests. Similarly, Dyad’s policy is to comply with requests to preserve data only if compelled by the U.S. Federal Stored Communications Act, 18 U.S.C. Section 2703(f), or by a properly served U.S. subpoena for civil matters. We do not disclose preserved data unless required by law or compelled by a court order that we choose not to appeal. Furthermore, unless we receive a proper warrant, court order, or subpoena before the required preservation period expires, we will destroy any preserved copies of customer data at the end of the preservation period.
-
If we are audited by a tax authority, we may be required to disclose billing-related information. If that happens, we will disclose only the minimum needed, such as billing addresses and tax exemption information.
Finally, if Dyad is acquired by or merges with another company — we don’t plan on that, but if it happens — we’ll notify you well before any of your personal information is transferred or becomes subject to a different privacy policy.
Your rights with respect to your information
At Dyad, we strive to apply the same data rights to all customers, regardless of their location. Some of these rights include:
- Right to Know. You have the right to know what personal information is collected, used, shared or sold. We outline both the categories and specific bits of data we collect, as well as how they are used, in this privacy policy.
- Right of Access. This includes your right to access the personal information we gather about you, and your right to obtain information about the sharing, storage, security and processing of that information.
- Right to Correction. You have the right to request correction of your personal information.
- Right to Erasure / “To Be Forgotten”. This is your right to request, subject to certain limitations under applicable law, that your personal information be erased from our possession and, by extension, from all of our service providers. Fulfillment of some data deletion requests may prevent you from using Dyad services because our applications may then no longer work. In such cases, a data deletion request may result in closing your account.
- Right to Complain. You have the right to make a complaint regarding our handling of your personal information with the appropriate supervisory authority.
- Right to Restrict Processing. This is your right to request restriction of how and why your personal information is used or processed, including opting out of sale of your personal information. (Again: we never have and never will sell your personal data.)
- Right to Object. You have the right, in certain situations, to object to how or why your personal information is processed.
- Right to Portability. You have the right to receive the personal information we have about you and the right to transmit it to another party.
- Right to not Be Subject to Automated Decision-Making. You have the right to object to and prevent any decision that could have a legal or similarly significant effect on you from being made solely based on automated processes. This right is limited if the decision is necessary for performance of any contract between you and us, is allowed by applicable law, or is based on your explicit consent.
- Right to Non-Discrimination. We do not and will not charge you a different amount to use our products, offer you different discounts, or give you a lower level of customer service because you have exercised your data privacy rights. However, the exercise of certain rights may, by virtue of your exercising those rights, prevent you from using our Services.
Many of these rights can be exercised by signing in and updating your account information. Please note that certain information may be exempt from such requests under applicable law. For example, we need to retain certain information in order to provide our services to you.
In some cases, we also need to take reasonable steps to verify your identity before responding to a request, which may include, at a minimum, depending on the sensitivity of the information you are requesting and the type of request you are making, verifying your name and email address. If we are unable to verify you, we may be unable to respond to your requests. If you have questions about exercising these rights or need assistance, please contact us at [email protected]. If an authorized agent is corresponding on your behalf, we will need written consent with a signature from the account holder before proceeding.
Depending on applicable law, you may have the right to appeal our decision to deny your request, if applicable. We will provide information about how to exercise that right in our response denying the request. You also have the right to lodge a complaint with a supervisory authority. If you are in the EU or UK, you can contact your data protection authority to file a complaint or learn more about local privacy laws.
Data retention
We keep your information for the time necessary for the purposes for which it is processed. The length of time for which we retain information depends on the purposes for which we collected and use it and your choices, after which time we may delete and/or aggregate it. We may also retain and use this information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. Through this policy, we have provided specific retention periods for certain types of information.
Location of site and data
Our products and other web properties are operated in the United States. If you are located in the European Union, UK, or elsewhere outside of the United States, please be aware that any information you provide to us will be transferred to and stored in the United States. Where we transfer personal data of EEA or UK individuals to the United States, we rely on appropriate safeguards to protect that information.
Changes and questions
We may update this policy as needed to comply with relevant regulations and reflect any new practices. Whenever we make a significant change to our policies, we will refresh the date at the top of this page and take any other appropriate steps to notify users.
Have any questions, comments, or concerns about this privacy policy, your data, or your rights with respect to your information? Please get in touch by emailing us at [email protected] and we’ll be happy to try to answer them!
Adapted from Basecamp open-source policies / CC BY 4.0