DIKA DESIGN LTD, a company registered in England and Wales under company number 16251779, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Contact: hello@dika.design.
Effective 20 August 2026. We will tell you before a material change takes effect.
This policy explains what we do with personal data when you use Dika Studio. DIKA DESIGN LTD is the controller of that data. For questions about it, write to hello@dika.design.
1. What we collect
Because you gave it to us
- Account: name, email address, password (stored only as a hash), profile picture, and the language and interface preferences you set.
- Profile: anything you choose to put on a public creator profile, such as a biography, links, skills and pinned work. A profile is unlisted until you publish it.
- Company details: if you tell us your company's revenue band, we keep that answer to decide which plans apply to you.
- Content: designs, videos, uploaded files, brand assets, products, automations and anything else you create or upload.
- Support: the subject, your name and email address, and the messages in a support conversation. These are encrypted at rest.
- Voice cloning: if you clone your voice, we store a consent recording as evidence of that consent, together with the exact wording you agreed to, the time and your IP address. The training sample itself is deleted once the clone is made.
Because you used the product
- Product analytics: page views, clicks and feature use inside the signed-in application, together with your IP address, approximate location, device, operating system and browser, and, while you are signed in, your user and workspace. This runs only if you allow analytics cookies, and it is switched off entirely for anyone whose browser sends a Do Not Track or Global Privacy Control signal.
- Advertising measurement: if we show an in-product notice or promotion, whether it was displayed, clicked or dismissed. This runs only with marketing consent.
- Security and operations: sign-in attempts, sessions and devices, rate-limit counters, error reports and audit records of administrative actions. This is necessary to run the service safely and does not depend on consent.
- AI usage: which model you used, when, and what it cost, so we can meter and bill it. Prompts are not retained for our own purposes beyond what is needed to deliver the result and the usage record.
2. Why we use it, and on what basis
- To provide the product you asked for (accounts, editing, storage, AI features, sharing, support): performance of our contract with you.
- To take payment and keep tax records: performance of a contract, and a legal obligation for the records we must keep.
- To keep the service secure and working (abuse prevention, rate limits, audit trails, backups): our legitimate interest in running a service that is not abused, balanced against your rights.
- Product analytics and advertising measurement: your consent, given through the cookie banner and withdrawable at any time.
- Marketing email: your consent. Every marketing message carries an unsubscribe link and unsubscribing is honoured. Messages about your own account, your payments and your support requests are not marketing and are sent regardless.
3. Who else processes it
We use a small number of providers. They act on our instructions and only for the purposes above.
Infrastructure
- Amazon Web Services (AWS) hosts the application, the database and stored files, in the European Union (Frankfurt, eu-central-1).
- Cloudflare provides network protection, DNS and content delivery in front of our services. Requests to us pass through it.
Sign-in
- Google is offered as a sign-in provider. If you choose it, Google confirms your identity to us and we receive your name, email address and profile picture. We never receive your Google password.
Payments
- Stripe processes all payments. Card details are entered on Stripe's own pages and are never seen or stored by us.
Email
- Transactional and marketing email is sent from our own mail infrastructure. We do not use a third-party marketing email platform.
Support
- Zendesk may handle support conversations depending on how the desk is configured. When it is not in use, support runs entirely on our own systems.
AI providers
Generating text, images, video, speech or transcription sends your prompt, and any file you attach to it, to the provider that serves the model you chose. Which provider that is depends on the model, and you can see the model on screen before you run it. The providers we route to are:
- OpenAI, Google, Alibaba Cloud (Qwen / DashScope), DeepSeek, fal.ai and OpenRouter for text, image and video generation.
- ElevenLabs for speech synthesis and voice cloning, and Deepgram for transcription.
- BytePlus, Runway, Luma, Pika and Kling for video generation.
If you supply your own API key for a provider, that call is made on your own account and under your own contract with that provider. We relay the request and add nothing to it.
A live, always-current list of the providers we actually route to is published at Subprocessors.
4. Where it is processed
Our infrastructure runs in the European Union. Some providers, in particular AI providers, process data outside the UK and the EU, including in the United States. Where that happens we rely on the transfer mechanisms available to us, such as the UK International Data Transfer Addendum and the European Commission's standard contractual clauses.
5. How long we keep it
- Your account and content: while your account exists. When you ask us to delete your account there is a 30-day recoverable period, during which you can change your mind; after that it is permanently deleted.
- Billing records: kept as long as tax and accounting law requires, even after an account is deleted. This is the one category we cannot delete on request.
- Support conversations: kept while they are open and for a period afterwards so we can answer a follow-up, then deleted.
- Data export archives: deleted 7 days after they are ready, with a maximum of 5 downloads.
- API and integration usage records: 90 days.
- Analytics: aggregated over time; identifiable records are not kept indefinitely.
6. Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to someone else. You can also withdraw consent at any time, which does not affect what we did before you withdrew it.
The fastest route is in the product: Settings → Privacy lets you download a full archive of your data, change your consent, and start an account deletion. You can also write to hello@dika.design.
We answer every request within 30 days. If you are not satisfied you can complain to the UK Information Commissioner's Office at ico.org.uk, or to the data protection authority where you live.
7. Cookies
Cookies and similar storage are covered in the Cookie Policy. Nothing optional is set until you say yes, and you can change your answer at any time from the "Cookie settings" link in the footer.
8. Security
Access to production systems is restricted and audited. Support content, stored provider keys and encrypted storage folders are encrypted at rest. Passwords are stored as hashes and never in a readable form. Data export archives are encrypted with a passphrase only you hold, which means we cannot open them once they are written and cannot recover one if you lose the passphrase.
9. Children
The product is not for children under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, write to us and we will delete it.
10. Changes
We may update this policy. Material changes are versioned, listed on the legal page, and you will be asked to acknowledge them in the product.