Vision
Log inSupportInquire

Privacy Policy

Operator: Digital Divas LLC Country: United States Privacy contact: [email protected] Last updated: August 27, 2026 Effective date: The date this Privacy Policy is first posted

1. Scope

This Privacy Policy explains how Digital Divas LLC (“Digital Divas,” “we,” “us,” or “our”) collects, uses, discloses, retains, and deletes personal information through Vision, including its public website, inquiry forms, invitation emails, onboarding pages, assessments, private workspaces, applications, administrative tools, connected-platform features, media and messaging functions, analytics, and automation (collectively, the “Service”).

This policy applies to website visitors, inquiry contacts, prospective and current creators, agency and business contacts, applicants, contractors, employees, authorized workspace users, and other people whose information is processed through the Service.

It does not replace a privacy notice provided by a creator, agency, employer, customer, connected platform, or other organization that independently determines how it uses personal information.

2. Our privacy roles

Digital Divas may act as a business or controller for information used to operate the public website, respond to inquiries, administer invitations and accounts, conduct our own onboarding and assessments, secure the Service, manage contracts, and satisfy legal obligations.

When Digital Divas processes creator, customer, fan, conversation, media, or other workspace information on the instructions of a creator, agency, or business customer, we may act as that organization’s service provider or processor. That organization may be the business or controller responsible for responding to privacy requests and determining the purposes of processing. We may route a request to that organization and assist it as required by law or contract.

3. Personal information we collect

The information we collect depends on how a person interacts with the Service and the permissions granted.

A. Website, inquiry, and business-contact information

We may collect:

  • name, email address, telephone number, organization, job title, role, and social or business profile information;
  • whether a person is a creator, chatter, employee or contractor candidate, agency representative, technology partner, or other interested party;
  • business needs, expectations, account or team information, requested services, referral source, and the content of an inquiry;
  • scheduling, follow-up, proposal, negotiation, and relationship-management records; and
  • technical information associated with submitting a form, such as date, time, IP address, device information, and abuse-prevention signals.

B. Invitation and onboarding information

We may collect:

  • invitation recipient, inviter, onboarding type, invitation status, expiration, and acceptance information;
  • creator business history, goals, account context, working preferences, portrayal preferences, boundaries, schedule, time zone, and team expectations;
  • agency or prospective customer role, organization, use case, expected team size, desired outcomes, and implementation needs;
  • applicant, contractor, employee, or chatter experience, availability, shift preferences, time zone, qualifications, onboarding responses, and acknowledgments; and
  • simulated chat responses, assessment activity, completion data, scores, reviewer notes, and evaluation decisions.

Possession of an invitation may be treated as evidence that the recipient controls the invited email inbox. We still may require additional authentication before granting production access.

C. Account and authentication information

We may collect:

  • name, email address, account identifier, profile image, role, workspace, creator coverage, permissions, and account status;
  • identity-provider identifiers and the limited profile information authorized through Google or another approved sign-in provider;
  • passkey public-key credentials, authentication events, session identifiers, and security settings;
  • OAuth scopes, access credentials, and refresh credentials for connected services when authorized; and
  • login time, IP address, device and browser information, session activity, failed attempts, and security events.

Digital Divas does not receive or store your Google password. Sensitive access credentials are used only to operate authorized integrations and security controls.

D. Creator, customer, fan, conversation, and transaction information

Depending on workspace permissions and connected-platform access, we may process:

  • creator profiles, account identifiers, team assignments, customer or fan profiles, tags, notes, and relationship history;
  • messages, conversation status, drafts, compositions, delivery records, and authorized outbound communications;
  • subscriptions, purchases, sales, prices, tips, audience segments, transaction references, and performance analytics;
  • creator-to-chatter and creator-to-customer assignments, assignment history, workload, fit indicators, and operational status; and
  • information inferred from authorized activity to help organize accounts, identify opportunities, support continuity, or recommend actions.

Connected platforms may remain the authoritative source for messages, sales, posts, media, or other records.

E. Content, media, and artificial-intelligence information

We may process:

  • uploaded images, video, audio, text, prompts, reference material, generated outputs, edits, and download choices;
  • media identifiers, dimensions, file type, status, folder membership, thumbnails, avatars, sales or posting references, and processing metadata;
  • creator-approved profile information and reference material used to personalize authorized tools; and
  • prompts, source files, outputs, model-selection data, processing status, and error information needed to perform or troubleshoot requested generation and analysis.

Media and communications may reveal sensitive characteristics depending on what users choose to submit. Users should avoid including unnecessary government identifiers, health information, financial credentials, biometric identifiers, or other highly sensitive information. Vision may process images and identity-reference material for requested media features, but Digital Divas does not use that material to create biometric-identification templates unless separately disclosed and authorized.

F. Device, usage, telemetry, and security information

We may collect:

  • browser, operating system, device, application version, language, approximate location derived from IP address, and network information;
  • feature use, navigation, timestamps, job timing, queue activity, errors, crashes, performance observations, and diagnostic logs;
  • security, access-control, audit, fraud-prevention, and incident-response records; and
  • cookies, local-storage values, and similar technical information used for authentication, preferences, draft continuity, and security.

G. Contract, payment, and business records

We may collect contracts, invoices, payment status, commission or revenue-share records, tax-supporting records, account contacts, service history, and communications needed to administer a business relationship. Payment-card or banking information may be handled by a payment provider rather than stored directly by Vision.

4. Sources of personal information

We collect information:

  • directly from the person who visits, inquires, applies, onboards, authenticates, uploads content, communicates, or uses the Service;
  • from the creator, agency, employer, business customer, administrator, or team member who invites or authorizes the person;
  • from connected services when an authorized user grants access;
  • from service providers that support authentication, email delivery, hosting, security, payment, analytics, or requested media processing; and
  • automatically through the operation and security of the Service.

5. How we use personal information

We use personal information to:

  • respond to inquiries and evaluate prospective creator, agency, customer, employment, or contractor relationships;
  • send and administer invitation emails and onboarding sessions;
  • build authorized creator or team profiles and configure workspace permissions;
  • evaluate chatter or workforce assessments and support human review of fit, availability, and skill;
  • authenticate users, maintain sessions, enforce permissions, and prevent unauthorized access;
  • provide messaging, media, organization, analytics, automation, and connected-platform features;
  • maintain continuity across creator teams and support authorized customer relationships;
  • generate drafts, recommendations, profiles, classifications, matches, or other requested assistance;
  • deliver service, security, administrative, and relationship communications;
  • monitor reliability, debug failures, maintain infrastructure, and improve requested functionality;
  • detect abuse, investigate incidents, enforce agreements, and protect users and connected systems;
  • administer contracts, invoices, payments, commissions, and business records; and
  • comply with legal obligations and establish, exercise, or defend legal claims.

We may use deidentified or aggregated information for capacity planning, security, reliability analysis, and Service improvement. We do not attempt to reidentify information that has been deidentified except to test whether deidentification measures are effective or as otherwise permitted by law.

6. Artificial-intelligence and assisted decision-making

Vision may use artificial-intelligence and analytical tools to summarize authorized information, develop profiles, categorize media, draft communications, estimate performance, recommend creator-to-chatter matches, prioritize work, or support assessments.

These tools may produce inaccurate or incomplete results. Unless separately disclosed, they are intended to assist authorized human users rather than make final decisions that produce legal or similarly significant effects without human review. Employment, contractor, creator-management, customer, pricing, and publication decisions remain subject to authorized human judgment.

Private creator or customer content is not used to train a general-purpose artificial-intelligence model unless that use is separately disclosed and authorized. Third-party artificial-intelligence or media providers may process submitted material to perform a requested feature under their own terms and our applicable arrangements with them.

7. How we disclose personal information

We may disclose personal information as follows:

A. Within an authorized workspace

Information may be visible to the creator, agency, workspace owner, administrators, assigned chatters, reviewers, or other authorized team members according to role and creator coverage. An organization controls the access it grants to its personnel where it acts as the business or controller.

B. Service providers and processors

We may disclose information to providers that support hosting, storage, databases, authentication, email delivery, security, monitoring, customer support, payment processing, connected-platform integration, and requested artificial-intelligence or media processing. They may process information only for the services they provide, subject to applicable agreements and law.

C. Connected services and user-directed actions

When an authorized user connects an account or directs an external action, we disclose the information required to carry out that request to the connected platform or intended recipient. That service’s independent privacy notice governs its subsequent processing.

D. Legal, safety, and enforcement purposes

We may disclose information when reasonably necessary to comply with law, legal process, or a valid government request; protect rights, safety, and security; investigate fraud or abuse; enforce agreements; or establish, exercise, or defend legal claims.

E. Business transfers

Information may be transferred as part of a merger, financing, reorganization, sale of assets, acquisition, bankruptcy, or transfer of all or part of the Service, subject to applicable confidentiality and privacy obligations.

F. With consent or direction

We may disclose information for another purpose when the person or responsible organization directs or authorizes the disclosure.

8. Sales, targeted advertising, and tracking choices

Digital Divas does not sell personal information collected through Vision and does not share it for cross-context behavioral advertising. We do not use private creator or customer information to build advertising profiles for unrelated businesses.

Because Vision does not presently sell or share personal information for those purposes, the Service does not offer a sale-or-sharing opt-out link. If our practices change, we will update this policy and provide any required notice and choice before the new practice begins.

Vision does not presently respond differently to legacy browser “Do Not Track” signals because no uniform response standard applies. Where required by applicable law and relevant to our practices, we will recognize a legally valid universal opt-out mechanism, such as Global Privacy Control.

Third-party services linked to or connected with Vision may collect information under their own policies. Digital Divas does not control their independent tracking practices.

9. Retention and deletion

We retain personal information only for as long as reasonably necessary for the identified business, security, contractual, or legal purpose. We use category-specific periods or objective criteria and delete, deidentify, or aggregate information when the purpose expires.

Deletion may be suspended for a documented legal hold, preservation request, security investigation, fraud-prevention need, dispute, tax or accounting requirement, or other legal obligation. Information retained under an exception is limited to the exception’s duration and isolated from unrelated use where practical.

A. Inquiries, invitations, and onboarding

Inquiry and prospective-relationship records are retained while needed to respond, evaluate the opportunity, document the outcome, prevent abuse, and support a resulting relationship or legal obligation. Unnecessary materials should be deleted or deidentified when those purposes expire.

Invitation tokens expire or are revoked and are no longer accepted after the applicable invitation period. Limited invitation, consent, delivery, acceptance, and audit metadata may be retained longer to document authorization, prevent misuse, or resolve disputes.

Creator, agency, applicant, contractor, employee, and chatter onboarding or assessment records are retained while needed to evaluate or administer the applicable relationship and for any required employment, contractual, security, dispute, or legal period. Assessment access can be disabled immediately when the process ends.

B. Accounts, roles, and authentication

Approved accounts, roles, permissions, and creator coverage are retained while the account or business relationship is active. Access may be disabled immediately at offboarding. Limited administrative, security, consent, and audit evidence may be retained afterward for an applicable contractual, dispute, or legal period.

An active session expires after no more than 12 hours or after 2 hours of inactivity. A successful sign-in on another computer may invalidate the former active computer session. Expired session tokens are no longer accepted. Minimal session and sign-in metadata may be retained longer for security, audit, and fraud prevention.

Public-key passkey credentials are retained until removed, replaced, or the account is closed. OAuth access and refresh credentials are retained only while the connected account remains authorized and should be revoked or deleted after disconnection or offboarding.

C. Creator, customer, conversation, and transaction information

Creator assignments, customer records, conversation projections, compositions, audience selections, sales information, and related operational data are retained while needed to provide the Service and support the applicable creator or customer relationship.

When the relationship ends or an authorized deletion request is completed, local copies are deleted, deidentified, or reduced to the records still required for security, accounting, dispute resolution, legal compliance, or a documented legal hold.

Deleting a local Vision index, cache, or folder does not delete a connected platform’s copy unless the action expressly states that it performs a remote deletion. When Vision is instructed and authorized to delete remote information, it will send the request to the connected service and may record the outcome. The connected service’s retention rules remain independently applicable.

D. Media, thumbnails, avatars, and local organization

Vision may retain media identifiers, dimensions, status, folder membership, sales or posting references, and replaceable thumbnails or avatars while the source remains available and the local projection is useful for an active relationship. Full-resolution media may remain on a connected platform unless a feature requires local processing or authorized storage.

Reconciliation processes should remove or invalidate cached material after source deletion, moderation, authorization loss, or creator offboarding. Deleting a Vision folder removes local organization records but does not delete the underlying remote media unless the interface expressly identifies a remote-delete action.

E. Temporary media-generation uploads

Source files uploaded specifically for temporary media-generation processing may be retained for up to 7 days to complete, retry, or troubleshoot the requested job. They are then deleted unless the user separately saves the file to an authorized persistent media library or a legal hold applies. Generated outputs saved in a creator library follow the media-retention rules above.

F. Telemetry

Detailed operational telemetry used to diagnose recent failures and performance regressions may be retained for up to 30 days. Reduced or aggregated performance observations used for longer-term capacity and reliability analysis may be retained for up to 730 days, provided they are not used to reconstruct private content and direct identifiers are removed or minimized where practical.

G. Security, audit, tax, and business records

Security and audit events are retained for the period reasonably necessary to detect abuse, investigate incidents, demonstrate authorization, protect the Service, and satisfy contractual or legal requirements. Logs are reviewed periodically and are not retained indefinitely merely because storage is available.

Contracts, invoices, payment records, and records supporting tax returns are retained for the applicable limitations and recordkeeping periods. Ordinary federal tax-support records are generally retained for at least 3 years, employment-tax records for at least 4 years after the tax becomes due or is paid, whichever is later, and particular records longer where required. These periods do not justify retaining unrelated private content.

H. Backups

Deletion removes or deidentifies information from active systems within the time reasonably necessary to verify and complete the request. Copies in encrypted, access-restricted backups may remain until the ordinary backup-rotation cycle reaches them. Backup copies are not returned to active use except for disaster recovery. If a backup is restored, applicable deletion instructions must be reapplied before the restored information is used for ordinary business purposes.

We instruct relevant service providers to delete or return information when required by contract or applicable law.

10. Cookies and device storage

Vision may use secure cookies and limited browser or device storage for authentication, invitation exchange, interface preferences, draft continuity, and security controls. Sensitive API credentials should not be placed in ordinary browser storage. Responses containing sensitive or private information should use appropriate cache controls.

We do not presently use third-party behavioral-advertising cookies in the private Service. If a public website analytics or marketing tool is introduced, this policy and any required consent or preference controls must be updated before deployment.

11. Security

We use administrative, technical, and organizational safeguards designed for the nature of the information we process. These may include role-based access, creator-level permission boundaries, encryption in transit, restricted credentials, session controls, security logging, backups, and incident-response procedures.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Users are responsible for protecting their accounts, devices, invitations, and credentials and for promptly reporting suspected unauthorized access.

12. Privacy rights and requests

Depending on residence and applicable law, a person may have rights to:

  • know or access personal information;
  • correct inaccurate information;
  • obtain a portable copy;
  • request deletion;
  • opt out of specified processing;
  • limit certain uses of sensitive personal information;
  • withdraw consent where processing relies on consent; and
  • appeal a denied request.

Requests may be sent to [email protected]. We may verify identity, authority, residency, and the relevant account, workspace, creator, or business relationship before acting. An authorized agent may be required to provide written authority. We will not discriminate against a person for exercising an applicable privacy right.

If Digital Divas processes information solely for a creator, agency, employer, or business customer, we may direct the request to that organization and assist it as required. Rights are subject to applicable coverage thresholds, roles, exceptions, and retention obligations.

Where the California Consumer Privacy Act applies, we will provide the notices, request procedures, response periods, and appeal or opt-out mechanisms required by that law. The categories described in Section 3 identify the personal information we expect to collect, and Section 5 identifies the corresponding business purposes. We do not sell or share those categories for cross-context behavioral advertising.

13. Children’s information

The Service is limited to adults and is not directed to children. Users may not submit personal information or content involving a person under 18. If we learn that prohibited children’s information has been submitted, we may remove it, suspend access, and take other appropriate action.

14. Sensitive and regulated information

Vision is not designed as a healthcare, financial-account, identity-verification, or consumer-reporting service. Users must not intentionally submit or infer regulated health data, financial-account credentials, government identification numbers, consumer reports, or biometric-identification data unless Digital Divas has expressly approved the workflow and all required notices, consents, contracts, security controls, and deletion procedures are in place.

The Service may process private communications, creator media, and profile preferences that could reveal sensitive information. Such information must be limited to the authorized business purpose and protected according to workspace permissions and applicable law.

15. United States operation and international use

Digital Divas operates from the United States. Information may be processed in the United States and in other locations where approved service providers operate. Those locations may have privacy laws different from the person’s place of residence.

If the Service is intentionally offered in a jurisdiction requiring additional notices, contractual protections, transfer mechanisms, representatives, or consent, Digital Divas will provide the required supplement before relying on this policy alone.

16. Third-party services and links

The Service may link to or integrate with third-party services. Their privacy practices are governed by their own notices, and Digital Divas is not responsible for their independent processing. Users should review the privacy terms of a connected service before granting access or directing information to it.

17. Changes to this policy

We may update this Privacy Policy as the Service, legal requirements, and data systems change. Material changes will be identified by a revised date and accompanied by any notice or consent required by law.

We will not silently expand a retention promise or use previously collected personal information for a materially different purpose where additional notice or consent is required.

18. Contact

Questions, privacy requests, and deletion requests may be sent to:

Digital Divas LLC United States [email protected]

← Return to Vision