Where your data lives & who can touch it
Where Diggr stores data, who processes it, and — the question customers ask most — what happens to your own confidential sales information.
Last updated: 19 July 2026
This page is written to be read by anyone — you are welcome to show it publicly, and we are happy to provide it to customers or prospects on request.
Diggr keeps two kinds of data. A shared public directory of telecom companies and the professional people who work at them — public facts, sourced and cited, and holding no personal contact details at all (no email addresses, no phone numbers). And your private workspace — your own contacts, notes, meeting records, pipeline and plans. Your private workspace is isolated to your organisation at the database level, is never shared with another customer, and is never sold. Most of it — your pipeline, projects and notes list — never leaves the database for any AI processing at all. The one exception, stated plainly below, is the AI features you actively invoke: when you ask Diggr to research an account or prepare you for a meeting, the inputs for that result — which can include the text of your own meeting notes — are sent to our AI processing engine to generate your answer, and returned to you. That is the whole of it.
1. Where your data is stored
Your data lives in the European Union. Our database, file storage and login run on Supabase, hosted in Ireland (EU). This is where everything sits at rest — both the shared public directory and every customer’s private workspace. Our application and API run on Vercel; those servers process requests in transit and call the database and AI engines, but they do not store your data — it stays in the Ireland database.
2. Who else processes data
Every outside service Diggr relies on, what it does, its country, and — critically — whether it ever touches a customer’s private data or only public directory data.
- SupabasePrivate + public data
Primary database, file storage and login — holds the shared directory and every customer's private workspace
Location: Ireland (EU)
- VercelIn transit only
App and API hosting — runs the servers that read/write the database and call the AI engines; data passes through in transit, it is not stored here
Location: US company (EU data stays in the Ireland database)
- Google (Gemini)Private + public data
Text-AI engine for every AI feature — Intelligence reports, Meeting-prep, the Today memo, Next-Best-Contact, Momentum, outreach drafts and Country briefings
Location: US company, global infrastructure
- Bright DataPublic data only
Fetches a public professional profile by its URL (enrichment) — never receives your pipeline or notes
Location: Israel / US
- Brave Search / SerperPublic data only
Web search to resolve a name + company to a public profile URL
Location: US
- ResendEmail content only
Transactional email — feedback replies, teammate invites, notifications
Location: US
Anthropic (Claude) also appears in our systems, but it is not used for live customer requests — it enriches the public directory offline only, and never receives your workspace data. Each provider above is a standard vendor that publishes a Data Processing Agreement; we remain responsible for your data when these providers handle it on our behalf.
3. How your workspace stays separate from every other customer
- •Every private row carries the organisation that owns it, and the database enforces row-level securityso one customer’s session can only ever read its own rows. The fence is in the database, not just the app.
- •The public browser key can only reach data through those policies. Server actions that need elevated access run through a separate server-only key that never reaches the browser, and every read is scoped to the caller’s own organisation.
- •When an account is deleted, a purge routine removes that user across the private tables — including contacts, the enrichment store, and uploaded photos — so “delete” means gone, not hidden.
4. Your confidential data and AI — the precise answer
Exactly what happens to your private workspace data, feature by feature. Nothing here is softened.
Never sent to any AI engine
Your pipeline / deals, your projects, your notepad, and your engagement history with an account. The engagement rollup is computed by plain database logic — no AI is involved at all.
Sent to an AI engine only when you invoke that feature, and only the inputs needed for your result:
- Intelligence report (research an account)Sends your note text
Sends: Your own private meeting/interaction notes for that account, plus the public directory data
Engine: Google Gemini
- Meeting-prep (pre-meeting judgment)Sends your note text
Sends: Your most recent meeting notes for that account
Engine: Google Gemini
- Today memoNo note text
Sends: Your task titles and which accounts you researched, plus public news and events
Engine: Google Gemini
- Next-Best-ContactNo note text
Sends: The contact names at that account plus recent public news
Engine: Google Gemini
- MomentumNo note text
Sends: Task/status metadata and account scores (interaction dates only — not note text)
Engine: Google Gemini
- Outreach / LinkedIn-invite draftsNo note text
Sends: The target contact plus light account context
Engine: Google Gemini
- Country briefingNo note text
Sends: Nothing of yours — public directory data only
Engine: Google Gemini
Contact names are masked on every AI feature.Before any request leaves our servers, the contact-name fields are replaced with neutral tokens and restored only in your result — so the AI engine does not receive your contacts’ names.
The plain caveat we will not hide: two features — Intelligence reports and Meeting-prep — send the actual text of your notes to a third-party AI company (Google, which processes it on global infrastructure outside the EU) when you ask for them on that account. This is by design — the AI is more useful when it can weigh your own field intel — and it happens only for the account you are actively researching, only when you trigger it. If you typed a name into the free text of a note, that free text is sent as written. Every other feature sends only light metadata (task titles, which accounts, interaction dates), never your note bodies.
These calls are transient — sent to generate your result and returned. Diggr does not use your data to train any AI model, does not sell it, and does not expose it to another customer; we use our AI provider on terms under which your inputs are not used to train their models.
5. The short version
Your workspace is isolated to your organisation and never shared with another customer or sold. It is stored in the EU (Ireland). Your pipeline, projects and notes list are never sent to any AI engine. When you use an AI feature — researching an account or prepping for a meeting — the inputs for that result, which can include the text of your own meeting notes, are sent to our AI engine solely to generate your answer and returned to you; contact names are masked, and nothing is used to train any model. Our AI engine is Google Gemini; ask us and we will share this page.
This page describes how Diggr handles data as of 19 July 2026, and we keep it up to date. For the notice covering people in our public directory, see Privacy; for the terms of using Diggr, see the Terms. Questions: contact us at philippe@alcaras.co.