Legal

Privacy Policy

Last updated: August 31, 2026

United States businesses only

Diurno HQ — Customer Intent Intelligence CRM is offered solely to businesses located and operating in the United States. It is not directed to or intended for individuals or entities outside the United States, and it is not intended for consumers or minors. By using the Service you represent that you are a United States-based business.

Diurno HQ builds Diurno HQ — Customer Intent Intelligence CRM on an ethos of honest, sourced research. This Policy explains what information the Service handles, how we use it, and the choices and rights you have. A defining principle is the boundary in Section 5: we pool only public facts about third-party companies, and we never pool a customer’s private data.

1. Who we are and what this Policy covers

This Privacy Policy explains how Diurno HQ (Diurno HQ,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with Diurno HQ — Customer Intent Intelligence CRM (the “Service”), a business-to-business sales-intelligence platform.

This Policy applies to three groups of people whose information the Service handles:

  • our customers — the businesses that subscribe to the Service;
  • the users who access the Service on a customer’s behalf; and
  • the individuals at third-party companies whose limited, public professional information the Service processes so that customers can research those companies.

This Policy is provided for transparency about how the Service handles information; it is not legal advice, and you should consult your own counsel regarding its application to your business.

2. United States only

The Service is offered solely to businesses located and operating in the United States. It is not directed to, intended for, or offered to individuals or entities located or operating outside the United States, and it is not intended for consumers or minors. By using the Service, customers and their users represent that they are United States-based.

Because the Service is designed for the United States market, this Policy is written around United States privacy law. See Section 13 for how we treat access from outside the United States.

3. Information we collect

We collect the following categories of information:

a. Account and authentication data

When you register and use the Service, we collect your name, your work email address, your organization, and account credentials (passwords are stored only in hashed form). To keep you signed in, the Service stores an authentication token in your browser’s local storage. This token is used only for authentication.

b. Workspace configuration and customer-entered data

We collect the information you configure and enter in the Service, such as your ideal-customer profile, personas, competitors, target-account lists, and any CRM, pipeline, notes, contacts, and hand-entered signals you record. We refer to this as your Customer Data. Your Customer Data is kept private to your tenant, as described in Section 5.

c. Public third-party company information

To research the companies our customers choose to monitor, we collect facts about those third-party companies from publicly available web sources — for example, hiring signals, technologies in use, funding events, news, and firmographic details. Every stored fact carries the public source URL it came from, and any claim we could not tie to a public source is labeled “needs verification.”

d. Public professional information about individuals

As part of researching third-party companies, we process limited, publicly available professional information about individuals who work at those companies — specifically their name, job title, and public professional profile links — sourced from the public web. We do not seek out home addresses, personal contact details, government identifiers, or the sensitive categories of personal information described in Section 11.

e. Usage and technical data

We collect the minimal technical and log data needed to operate, secure, and troubleshoot the Service. We keep cookies and browser storage to a minimum: a login token in local storage for authentication, as described above. We do not use third-party advertising trackers, we do not track you across other websites, and we do not build advertising profiles.

4. How we use information

We use the information described above to:

  • provide, operate, and maintain the Service and your workspace;
  • perform research on the third-party companies you choose to monitor and generate the intelligence, signals, and suggested outreach the Service is designed to produce;
  • authenticate you, secure the Service, and prevent fraud and abuse;
  • provide customer support and respond to your requests;
  • process billing and manage subscriptions;
  • monitor, improve, and develop the reliability and quality of the Service; and
  • comply with legal obligations and enforce our terms.

To generate research, we send queries and relevant public context to the AI research providers described in Section 7, which process them on our behalf to return results.

5. The shared public-intelligence corpus — and the private-data boundary

To research third-party companies efficiently, we maintain a shared corpus of public, web-sourced facts about third-party companies — for example, hiring signals, technologies in use, funding, and public professional profiles — each tied to a public source. This corpus is cached and reused across customers to power research. Maintaining a shared corpus of public company facts is standard practice for the sales-intelligence category; platforms such as 6sense, ZoomInfo, and Clay similarly pool a shared corpus.

The shared corpus pools only public facts about third-party companies. Its purpose is to reuse public knowledge about the market so that every customer benefits from research already done, without re-fetching the same public sources.

The shared corpus never includes a customer’s private data. Specifically, we do not pool, share, or reveal to any other customer:

  • your targeting or interest — the fact that you researched or monitored a given company is never disclosed to any other customer;
  • your notes;
  • your hand-entered signals; or
  • your CRM, pipeline, or contacts.

These are strictly tenant-private. In short: the corpus reuses public knowledge about the world; it never reuses your private knowledge about your pipeline. Your Customer Data is used only to provide the Service to you.

7. How we disclose information; subprocessors

We do not sell your personal information (see Section 8). We share information only as described here, and we engage service providers (subprocessors) who process information on our behalf under contracts that require appropriate confidentiality and security. Our subprocessors fall into these categories:

  • AI research providers (for example, Perplexity, OpenAI, and Anthropic), which process research queries and public context to help generate intelligence; and
  • Cloud hosting, database, and infrastructure providers (for example, Railway, Cloudflare, and Supabase), which host, store, and help secure the Service.

The providers named above are examples; our current list of subprocessors is available on request at contact@diurnohq.com. We may also disclose information to professional advisors, to comply with law or valid legal process, to protect our rights and the safety of others, and in connection with a merger, acquisition, or sale of assets (subject to this Policy).

8. We do not sell your personal information

Diurno HQ does not sell personal information for money, and we do not share personal information for cross-context behavioral advertising. We do not use third-party advertising trackers, and we do not disclose personal information to data brokers for their own marketing purposes. Information is used to provide and improve the Service, as described in this Policy.

9. Data retention

We retain your account and Customer Data for as long as your organization’s account is active and for a limited period afterward, so that we can support wind-down, meet legal and accounting obligations, and resolve disputes, after which we delete or anonymize it. Backups are retained for a limited period and then overwritten.

We retain public facts in the shared corpus for as long as they remain useful and supported by a public source, refreshing or re-sourcing them over time. Individuals may request removal of their public professional information as described in Section 11.

10. Security

We use reasonable administrative, technical, and organizational measures designed to protect information, including encryption of data in transit, token-based authentication, access controls on a least-privilege basis, and reputable hosting infrastructure. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. If you believe your account has been compromised, contact us promptly at contact@diurnohq.com.

11. Your choices and privacy rights

a. Account holders and their users

You can review and update much of your account information within the Service. You may also request access to, correction of, or deletion of your account information by emailing contact@diurnohq.com. If you use the Service under an organization’s account, some requests are controlled by that organization, and we may direct your request to it.

b. California residents (CCPA/CPRA)

Because some of our customers, users, or the individuals referenced in third-party company data may be California residents, we provide the following. Subject to verification and legal limits, California residents have the right to know and access the personal information we hold about them, to request deletion, to request correction, to opt out of the “sale” or “sharing” of personal information, to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights.

  • We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes that would trigger the right to limit.
  • Categories we collect include identifiers (such as name, work email, job title, and organization), professional or employment-related information (such as job title, employer, and public professional profile links), commercial information (such as subscription records), and limited internet or network activity needed to operate and secure the Service.
  • Sources are you and your organization, and publicly available web sources.
  • Purposes are those described in Section 4, and we disclose information to subprocessors for business purposes only, as described in Section 7.

To exercise these rights, email contact@diurnohq.com. We will take steps to verify your request by matching it to your account or to the public record referenced, and we will respond within the timeframes required by law. You may use an authorized agent to submit a request on your behalf.

c. Individuals featured in third-party company data

If you are an individual whose public professional information (such as your name, job title, or public professional profile link) appears in the Service, you can request access to, correction of, or removal of that information by emailing contact@diurnohq.com. We will locate the records associated with you and correct or remove them, subject to legal and operational limits, and we may keep a minimal record of your request so that we can continue to honor it.

12. Children

The Service is a business-to-business tool that is not directed to, or intended for, children. We do not knowingly collect personal information from anyone under 18 years of age, and the Service is not intended for consumers or for personal, family, or household use. If you believe a child has provided us personal information, contact us at contact@diurnohq.com and we will take appropriate steps to delete it.

13. International users — United States only

The Service is intended solely for businesses located and operating in the United States, and information is processed in the United States. The Service is not directed to, or offered to, individuals or entities outside the United States, including in the European Union, the European Economic Area, or the United Kingdom. This Policy is not designed to address, and we do not offer the Service under, the EU/UK General Data Protection Regulation or similar non-United States frameworks.

If you access the Service from outside the United States, you do so on your own initiative, and you must not use the Service if doing so is not permitted where you are located.

14. Changes to this Policy

We may update this Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page, and, for material changes, we will provide reasonable notice. Your continued use of the Service after changes take effect constitutes your acceptance of the updated Policy.

This Policy is governed by the laws of the State of Texas, United States, consistent with our Terms & Conditions.

15. Contact us

For any question about this Policy or about how we handle information — including access, correction, or removal requests, or to obtain our current list of subprocessors — email us at contact@diurnohq.com.