Where your data lives & who can touch it
Where Diggr stores data, who processes it, and - the question customers ask most - what happens to your own confidential sales information.
Last updated: 7 September 2026
This page is written to be read by anyone - you are welcome to show it publicly, and we are happy to provide it to customers or prospects on request.
Diggr is operated by Alcaras LLC, established in Sharjah, United Arab Emirates. That is the company that holds the data described here and the company you contract with. If the Diggr business is later carried on by an affiliated company or a successor, this page will name it.
Diggr keeps two kinds of data. A shared public directory of telecom companies and the professional people who work at them - public facts, sourced and cited, and holding no personal contact details at all (no email addresses, no phone numbers). And your private workspace - your own contacts, notes, meeting records, pipeline and plans. Your private workspace is isolated to your organisation at the database level, is never shared with another customer, and is never sold. Most of it - your pipeline, projects and notes list - never leaves the database for any AI processing at all. The one exception, stated plainly below, is the AI features you actively invoke: when you ask Diggr to research an account, prepare you for a meeting, or read a document you upload, the inputs for that result - which can include the text of your own meeting notes, and for the document reader the whole file - are sent to our AI processing engine to generate your answer, and returned to you. That is the whole of it.
1. Where your data is stored
Your data lives in the European Union. Our database, file storage and login run on Supabase, hosted in Ireland (EU). This is where everything sits at rest - both the shared public directory and every customer’s private workspace. Our application and API run on Vercel; those servers process requests in transit and call the database and AI engines, but they do not store your data - it stays in the Ireland database.
2. Who else processes data
Every outside service Diggr relies on, what it does, its country, and - critically - whether it ever touches a customer’s private data or only public directory data.
- SupabasePrivate + public data
Primary database, file storage and login - holds the shared directory and every customer's private workspace
Location: Ireland (EU)
- VercelIn transit only
App and API hosting - runs the servers that read/write the database and call the AI engines; data passes through in transit, it is not stored here
Location: US company (EU data stays in the Ireland database)
- Google (Gemini)Private + public data
Text-AI engine for every AI feature - Intelligence reports, Meeting-prep, the Today memo, Momentum, outreach drafts, Country briefings, and the document reader
Location: US company, global infrastructure
- Bright DataPublic data only
Opens company pages that block ordinary fetching - leadership pages, filings - so the shared directory can be built from the company's own site, and, only when you paste your own link during onboarding, reads that one LinkedIn profile to fill in your own user profile. Never used to add a person to the shared directory automatically, and never receives your pipeline or notes
Location: Israel / US
- Brave Search / SerperPublic data only
Web search to find a company's own pages, announcements, filings and event listings for the shared directory
Location: US
- ResendEmail content only
Transactional email - feedback replies, teammate invites, notifications
Location: US
- Zoho BooksBilling details only
Invoicing - when we bill a paying customer, the billing details for that invoice (the company name, and a billing contact's name and email) are created in our accounting system. It never receives your workspace data, your notes, or the directory
Location: Zoho Corporation, India
Anthropic (Claude) also appears in our systems, but it is not used for live customer requests - it enriches the public directory offline only, and never receives your workspace data. Zoho Books is listed because the invoicing is built, not because it is running: while early access is free, no invoice exists and nothing has been sent there. Each provider above is a standard vendor that publishes a Data Processing Agreement; we remain responsible for your data when these providers handle it on our behalf.
3. How your workspace stays separate from every other customer
- •Every private row carries the organisation that owns it, and the database enforces row-level securityso one customer’s session can only ever read its own rows. The fence is in the database, not just the app.
- •The public browser key can only reach data through those policies. Server actions that need elevated access run through a separate server-only key that never reaches the browser, and every read is scoped to the caller’s own organisation.
- •When an account is deleted, a purge routine removes that user across the private tables - including contacts, the enrichment store, and uploaded photos - so “delete” means gone, not hidden.
4. Your confidential data and AI - the precise answer
Exactly what happens to your private workspace data, feature by feature. Nothing here is softened.
Never sent to any AI engine
Your pipeline / deals, your projects, your notepad, and your engagement history with an account. The engagement rollup is computed by plain database logic - no AI is involved at all.
Sent to an AI engine only when you invoke that feature, and only the inputs needed for your result:
- Intelligence report (research an account)Sends your note or file text
Sends: Your own private meeting/activity notes for that account, plus the public directory data
Engine: Google Gemini
- Meeting-prep (pre-meeting judgment)Sends your note or file text
Sends: Your most recent meeting notes for that account
Engine: Google Gemini
- Today memoNo note or file text
Sends: Your task titles and which accounts you researched, plus public news and events
Engine: Google Gemini
- MomentumNo note or file text
Sends: Task/status metadata and account scores (activity dates only - not note text)
Engine: Google Gemini
- Outreach / LinkedIn-invite draftsNo note or file text
Sends: The target contact plus light account context
Engine: Google Gemini
- Country briefingNo note or file text
Sends: Nothing of yours - public directory data only
Engine: Google Gemini
- Document reader (drop a document into the Analyst)Sends your note or file text
Sends: The whole document you upload - a PDF is sent as the file itself, other formats as their full extracted text
Engine: Google Gemini
Contact names are masked wherever your contacts arrive as a list.On Intelligence reports, Meeting-prep, the Today memo, outreach drafts and LinkedIn invites, every contact-name field is replaced with a neutral token before the request leaves our servers, and the real name is put back only in your result - so the AI engine never receives your contacts’ names.
Masking cannot apply to a document you upload, and we will not pretend otherwise. The document reader sends what you uploaded, exactly as it stands. A name inside a sentence is just words to us, and it goes with the sentence.
The plain caveat we will not hide. Three features send your own words to a third-party AI company (Google, which processes them on global infrastructure outside the EU). Every one of them runs only when you trigger it, on the one thing you triggered it on:
- •Intelligence reports and Meeting-prep send the actual text of your notes for the account you are actively researching. This is by design - the AI is more useful when it can weigh your own field intel.
- •The document reader sends the whole document you drop into it. If it is a PDF, the file itself goes; other formats go as their full extracted text.
If you typed a name into the free text of a note, that free text is sent as written. Every other feature - the Today memo, Momentum, outreach drafts, Country briefings - sends only light metadata (task titles, which accounts, activity dates), never your note bodies.
A word about documents specifically.The document reader is the one feature where the thing you send is somebody else’s confidential file rather than your own working notes. Diggr will not decide for you whether a tender document or a customer deck may go to a US cloud AI provider - only you know what you signed. We tell you plainly that it does go, so that you can make that call before you drop the file.
These calls are transient - sent to generate your result and returned - with one exception we would rather state than have you discover.
The document reader keeps its result. The uploaded file itself is never stored: it is read in memory and discarded. But the cited fact cards the read produces - which include short verbatim quotes from your document - are kept in your own private area of our database, so that re-reading the same file is instant and free. Alongside them we keep the file’s name and a digital fingerprint of its contents - a one-way code that cannot be turned back into the document, and is only there so we recognise the same file if you upload it again. That kept result is yours alone, no other customer can reach it, and it is deleted when your account is deleted.
Diggr does not sell your data and does not expose it to another customer.
5. The short version
Your workspace is isolated to your organisation and never shared with another customer or sold. It is stored in the EU (Ireland). Your pipeline, projects and notes list are never sent to any AI engine, and nothing else is either until you press a button. When you do - researching an account, prepping for a meeting, or reading a document - the inputs for that one result are sent to our AI engine solely to generate your answer, and returned to you. That can include the text of your own meeting notes, and for the document reader it is the whole file you uploaded. Contact names are masked wherever your contacts arrive as a list; a document you upload goes as it stands. Our AI engine is Google Gemini; ask us and we will share this page.
This page describes how Diggr handles data as of 7 September 2026, and we keep it up to date. For the notice covering people in our public directory, see Privacy; for the terms of using Diggr, see the Terms. Questions: contact us at contact@getdiggr.com.