Skip to content
DIRI AI

DIRI AI legal

DIRI AI Cookie Policy

Version 1.2.1Effective 22 September 2026English version

1. What this Policy covers

Cookies are small values stored in a browser. Similar technologies include local storage, SDKs, pixels and device identifiers. This Policy explains technologies used on diriai.com and the DIRI AI application. The Privacy Policy explains the related personal-data processing.

2. Necessary technologies

The following inventory describes necessary technologies used by the service. DIRI AI checks it against deployed public, signup and authenticated routes after each material change:

Name or functionProviderPurposeMaximum/default lifetimeRequirement
__Host-diriai_sessionDIRI AIauthenticate and protect the signed-in sessionup to 8 hoursstrictly necessary; HttpOnly, Secure and SameSite=Lax in production
diriai_localeDIRI AIremember the language selected by the visitorup to 1 yearrequested functional preference; consent is used where local law requires it
diriai_demo_trialDIRI AIprevent repeated use of a separate public product demoup to 30 daysconditional and necessary only if that demo is enabled; it is not the paid seven-day Stripe trial
security/load-balancing values that may be set by Cloudflare or the hosting platforminfrastructure providerdeliver, protect and route the websiteprovider/session dependentonly values strictly necessary for the requested service load without consent; provider values may vary

Necessary infrastructure is not marketing analytics. Vercel hosting and Cloudflare DNS, routing or security do not make Vercel Web Analytics, Vercel Speed Insights or Cloudflare Web Analytics part of the optional analytics configuration.

3. Optional Google Analytics technology

Google Analytics 4 (GA4) is the only optional traffic-measurement provider covered by this Policy. The Google tag remains absent until a visitor on a supported English or Czech public marketing page on diriai.com or www.diriai.com affirmatively allows analytics. Refusal, Global Privacy Control and withdrawal keep or return the page to a tag-free state. DIRI AI uses Basic Consent Mode, not Advanced Consent Mode: no consent-state ping or other Google Analytics request is sent while consent is absent or refused.

Name or functionProviderPurposeMaximum lifetimeScope and control
diriai_marketing_analytics_consentDIRI AIremember the browser's analytics choice and versionaccepted: 365 days; rejected: 6 UTC calendar monthslocal storage on the visitor's device; contains the choice, time, locale, notice version and GA4 provider-configuration version
_gaGoogle Analyticsdistinguish a browser for traffic measurement365 days from first consent on the current hostfirst-party host cookie; not renewed on each page load; removed on withdrawal where browser controls permit
_ga_<measurement-id>Google Analyticspersist GA4 session state365 days from first consent on the current hostfirst-party host cookie; not renewed on each page load; removed on withdrawal where browser controls permit

The Google cookie domain is limited to the current host, so a cookie set on diriai.com is not configured for app.diriai.com. Automatic pageviews and Enhanced Measurement are off. DIRI AI sends manual pageviews and only these bounded events: campaign_landing, marketing_signup_selected and sample_report_selected.

The event payload may contain only an allowlisted public origin and normalized path, the normalized same-site referrer path when available, event name, language, an allowlisted CTA placement or plan, and allowlisted campaign source, medium and campaign values. Query strings, URL fragments, external referrer URLs, document titles, free text, names, emails, telephone numbers, account/customer/company identifiers, call content, recordings, transcripts, payment data, checkout/status tokens and User-ID are not permitted in the Analytics payload.

Before a choice, DIRI AI may keep only the first already-sanitized allowlisted campaign source, medium and name, capture time, state and random per-document binding in volatile JavaScript memory for the current page document. This handoff creates no cookie, local storage or session storage. Every utm_* parameter is removed from the visible browser address immediately. Client-side navigation that preserves the mounted page component can keep the first touch for at most 30 minutes; a full reload, new tab or duplicated tab discards it.

Campaign values are cleared on refusal, Global Privacy Control, withdrawal, invalid or expired consent, expiry or when analytics starts. A no-campaign marker may remain only in that page's volatile memory to prevent recapture during the same mounted document. No raw query, referrer, arbitrary key or provider request is stored or sent by this handoff.

When a consented request is sent, the browser and network necessarily expose technical information such as IP address, user agent, timestamp and protocol headers to Google. Google states that for EU, Swiss and UK traffic it uses IP addresses for coarse geolocation and discards them before logging; its documentation describes limited service uses and discard after use for other regions. This network processing means that a restricted zero-PII event payload is not a claim that no personal data is processed.

Google explains how it uses information from sites and apps using its services at https://policies.google.com/technologies/partner-sites.

4. Categories requiring a prior choice

The following categories must be off by default until the visitor makes a valid choice and an applicable effective release expressly includes them:

  • analytics and product measurement not strictly necessary to provide the requested service;
  • advertising, retargeting, conversion pixels and cross-site identifiers;
  • personalisation not requested by the visitor;
  • embedded third-party media or social features that read or write non-essential identifiers; and
  • any future experimentation, heatmap or session-replay technology.

The optional analytics configuration includes only GA4 traffic measurement. It excludes Umami, Vercel Web Analytics, Vercel Speed Insights, Cloudflare Web Analytics, advertising or conversion pixels, retargeting, session replay, heatmaps, advertising audiences, Google Ads links and Google Analytics advertising features. A configuration value or provider account cannot add an excluded provider or purpose.

Newsletter signup itself does not require an advertising cookie. A consent for email marketing does not automatically permit analytics or advertising cookies, and a cookie choice does not subscribe a visitor to email.

5. Consent design for non-essential technology

Where consent is required, the website must:

  1. block the technology before consent;
  2. offer Accept and Reject non-essential at the same level and with comparable prominence;
  3. explain purposes and vendors before the choice;
  4. avoid pre-ticked boxes, deceptive colours, bundled purposes and consent inferred from scrolling or closing the banner;
  5. record the notice version, locale, provider-configuration version, choice and time without exposing more data than necessary;
  6. provide a persistent Cookie settings control on every page where non-essential technology can be enabled, normally in the site footer; and
  7. make withdrawal as easy as acceptance and stop future collection after withdrawal.

The default interval is no more than 365 days for a positive choice and six UTC calendar months before asking again after refusal, unless a material processing change or deleted browser storage makes a new request appropriate. Global Privacy Control keeps optional analytics off.

6. Browser controls

Visitors can reject or withdraw through Cookie settings and can delete or block cookies through browser settings. Blocking a necessary session cookie will prevent sign-in. Browser controls may not stop server-side account, security or billing records; those are described in the Privacy Policy. A browser's generic "Do Not Track" signal is handled only where law or an implemented standard gives it a defined effect.

7. Provider, retention and transfer information

The Subprocessor List identifies Google Analytics 4 and Google Ireland Limited under the applicable Analytics account agreement and Data Processing Terms. DIRI AI uses one Analytics property with one web stream covering diriai.com and www.diriai.com. The property uses two-month user-level and event-level retention with reset on new activity off. Enhanced Measurement, Google Signals, advertising features, advertising personalisation, audiences, Google Ads links and User-ID are off. Google states that the retention setting does not affect standard aggregated reports; those remain subject to DIRI AI's purpose-limitation and deletion rules rather than being described as deleted after two months.

Google may process data where Google or its subprocessors maintain facilities. The applicable Google Analytics account agreement and Data Processing Terms govern this processing and include the applicable transfer terms.

8. Updates and contact

DIRI AI reviews cookies and network requests after material website changes. A material new category, provider or purpose requires an updated notice and renewed choice before it runs.

Questions or rights requests: privacy@diriai.com.

Version: 1.2.0. Effective date: 30 August 2026.

DIRI AI Cookie Policy | DIRI AI