Privacy notice
Commercial evidence deserves clear boundaries.
Dileo separates private deal material from the limited commitments and financial events that must be public for an onchain transaction.
Last updated 21 August 2026 · Hackathon testnet release
Scope
This notice explains how the current Dileo prototype handles information when you browse a deal, verify a wallet, create a draft, upload evidence, review a Blueprint, confirm as a buyer, or interact with an X Layer Testnet contract.
Data we handle
- Wallet and session data
- Your public address, signed verification message, session timestamps, and deal-specific permissions. Dileo never asks for a seed phrase or private key.
- Deal information
- Business names, counterparties, amounts, dates, commercial terms, draft state, and workflow decisions entered for a financing request.
- Private evidence
- Uploaded PDFs, document hashes, extracted page text, attributable AI output, reconciliation results, and reviewer notes.
- Technical data
- Request and error information needed for security, abuse prevention, diagnosis, and reliable operation. Sensitive document text is not intended for application logs.
How information is used
- to verify wallet control and restore the correct private workspace;
- to extract, attribute, reconcile, and present commercial evidence;
- to enforce company, reviewer, buyer, and funding permissions for each deal;
- to create an exact public Blueprint only after human approval; and
- to protect, diagnose, and improve the prototype.
Dileo does not sell personal data, build advertising profiles, or use uploaded evidence to train a Dileo model.
Public blockchain records
Wallet addresses, Blueprint commitments, buyer confirmation, contribution amounts, transaction timing, escrow state, and lifecycle events may be permanently visible on X Layer. Blockchain records cannot generally be edited or deleted by Dileo.
Original PDFs, extracted text, contact details, raw analysis context, and private reviewer notes are stored offchain and are not intentionally written to the contract. Keeping evidence offchain does not make associated wallet activity anonymous.
Storage, providers, and security
Private application records are stored in wallet-scoped database rows and private object storage. AI processing receives the evidence required for the requested analysis. Wallet, RPC, database, storage, and AI providers process information only to supply their part of the service.
An essential HttpOnly cookie maintains a verified application session. Local browser storage remembers theme and limited interface state. The prototype does not use advertising cookies, so it does not display a consent banner solely for essential storage.
Access controls, document hashing, server-side authorization, rate limits, and secret separation reduce risk; no system can promise absolute security. Production requires formal retention schedules, deletion and access-request procedures, processor agreements, monitoring, incident response, and jurisdiction-specific controls.
Your choices
- Browse public opportunities and documentation without connecting a wallet.
- Disconnect your wallet or end the browser session when finished.
- Decline any signature or transaction you do not understand.
- Avoid uploading information that should not enter this test environment.
A production release will provide an identified operator, support channel, retention policy, data-rights process, and region-specific notices before accepting real customer evidence.