Privacy Policy
This policy explains what information dylomo needs to provide the service, how model content is handled, and the choices you have when collaborating, sharing, using AI assistance, or closing your account.
Last updated September 18, 2026
1. What this policy covers
This policy applies when you visit dylomo, create or use an account, build or review a logic model, collaborate with other people, publish a read-only model, use an AI-assisted feature, manage a subscription, or contact Support.
If you use dylomo for an organization, that organization may also have privacy responsibilities for personal information placed in a model. Only include personal or confidential information when it is necessary, appropriate, and permitted for your work.
2. Information you provide
dylomo processes information you choose to provide, including:
- Account details such as your name, email address, profile image, sign-in method, and preferences.
- Program descriptions, model components, relationships, assumptions, indicators, notes, layouts, comments, and other model content.
- Collaboration details such as invitations, roles, and activity connected to a shared model.
- Support requests, feedback, and information you provide while resolving an account or product issue.
- Subscription and billing details such as plan, billing status, and payment-related identifiers. Payment card details are entered with the payment provider rather than stored in dylomo’s application database.
3. Information processed automatically
The service processes basic technical and security information needed to deliver requests, keep accounts signed in, diagnose failures, prevent abuse, and protect the service. This can include dates and times, browser or device information, network information, request status, and error details.
When error reporting is enabled, dylomo sends Sentry a limited diagnostic report identifying the failed operation, error category, app version, and time. These reports exclude model content, AI prompts, account details, page addresses, and raw error messages. During the initial public rollout, we may also use temporary, masked session recordings to investigate errors. Recordings show page layout and interactions around an error; text and form inputs are masked, media is blocked, and page addresses and network contents are excluded. As with other online service providers, Sentry receives network information when your browser connects to it.
dylomo uses essential cookies and browser storage for sign-in, security, preferences, and limited product state. When the cookie notice offers analytics, selecting Got it allows Google Analytics. Leaving the notice open keeps analytics off. You can also allow analytics or turn it off here at any time. Your choice is saved in this browser.
If you allow analytics, Google Analytics receives page categories, feature actions, browser and device information, and whether you have Free or Pro access. When you sign in, we use an internal account identifier to understand use across visits and devices. We do not send model content, email addresses, invitation tokens, or payment-card details in our analytics events. Advertising personalization is disabled.
Optional analytics is off in this browser.
4. Model and collaboration content
Model content is stored so you can return to it, revise it, collaborate, export it, and present it. Access is based on the model role and sharing controls selected by the owner.
People invited as editors or viewers can see the content available to their role. Changes, comments, invitations, and version information may identify the account involved so collaborators can understand what happened in the shared workspace.
You retain ownership of the model content you create. dylomo uses it only as needed to provide, secure, and support the service and to follow your sharing and feature choices.
5. AI-assisted features
AI assistance is used only when you choose an AI drafting or review action. The program details and model content needed for that request are sent to dylomo’s AI service providers so they can return the requested result.
Do not include sensitive personal information, confidential participant records, or restricted funder information in an AI request unless you have determined that doing so is permitted. Review the result before using it; AI output can be inaccurate or incomplete.
dylomo selects AI-processing options intended to limit provider retention and prevent submitted content from being used to train provider models. Provider terms and available controls can change, so these safeguards are reviewed as the service evolves.
6. Payments and subscriptions
Paid checkout and payment-card processing are handled by Stripe. dylomo receives the customer, subscription, transaction status, and billing information needed to activate paid access, manage renewals or cancellations, resolve payment issues, and keep required financial records.
Stripe processes payment information under its own privacy terms. dylomo does not receive or store the full payment-card number entered during hosted checkout.
7. How information is used
dylomo uses information to:
- Create, authenticate, secure, and support accounts.
- Save, display, revise, export, and share logic models according to your choices.
- Support collaboration, invitations, roles, comments, and component-edit history.
- Provide subscriptions, process billing events, and manage plan access.
- Complete an AI-assisted request when you choose one.
- Respond to support requests and product feedback.
- Prevent misuse, investigate failures, maintain reliability, and meet legal or accounting obligations.
8. Service providers
dylomo uses service providers to operate parts of the product. They receive only the information needed for their role and process it under their terms and agreements with dylomo.
- Google Firebase and Google Cloud: hosting, authentication, database, and application services. Provider privacy information (opens in a new tab)
- Google Analytics: optional measurement of visits and feature use, when you allow it. Provider privacy information (opens in a new tab)
- Stripe: checkout, subscription billing, and payment records. Provider privacy information (opens in a new tab)
- Sentry: receiving limited error reports to help diagnose application failures. Provider privacy information (opens in a new tab)
- OpenRouter and selected AI model providers: processing the AI-assisted request you choose to make. Provider privacy information (opens in a new tab)
10. Retention and deletion
Account information and model content are generally kept while your account is active or until you delete the model or account. Support and operational records are kept only as long as reasonably needed to resolve requests, maintain security, prevent abuse, and meet legal or accounting obligations.
Deleting a model removes the owner’s active copy and any public version created from it. Deleting an account removes models you own, removes your access to shared models, and removes or replaces personal attribution where shared records must remain understandable to other collaborators.
Some information may remain for a limited time in backups, security records, billing records, or deletion-processing records. Information is retained longer only where required for legal, tax, accounting, fraud-prevention, dispute, or security purposes.
11. Security
dylomo uses account authentication, role-based access controls, encrypted web connections, restricted service credentials, and monitoring and testing practices intended to protect the service and its data.
No online service can promise absolute security. Protect your sign-in method, review collaborator access, avoid publishing confidential model content, and contact Support if you believe an account or model has been accessed without permission.
12. Your choices and privacy rights
You can update profile details, manage collaborator roles, revoke a public link, delete models you own, cancel a paid subscription, and start account deletion from the available account settings.
Depending on where you live, you may also have rights to ask for access to, correction of, deletion of, or a copy of personal information, or to object to or restrict certain processing. We may need to verify your identity and may retain information where the law permits or requires it.
to ask a privacy question or make a request.
13. International processing
dylomo and its service providers may process information in countries other than the one where you live. Privacy protections can differ by location. Where required, appropriate contractual or legal safeguards are used for international transfers.
14. Children’s privacy
dylomo is intended for adults and organizations doing program planning, evaluation, grant, and related professional work. It is not directed to children, and children should not create accounts or submit personal information. Contact Support if you believe a child has provided personal information so the situation can be reviewed.
15. Changes and contact
This policy may be updated as the product, providers, or legal requirements change. The latest update date appears at the top of the page. Material changes will receive additional notice when appropriate.
to ask a privacy question or make a request.