Privacy notice
Effective date: 2026-09-19 · Version 2026-09-19-v1
DiploDesk is operated by DiploDesk LP.
Information we use
When you use Google sign-in, we receive a Google account identifier and the name and verified email Google provides. We use the account identifier, not your email or affiliation, to identify your sign-in. We do not receive your Google password or request access to Gmail, contacts or Drive. We do not retain Google access or refresh tokens.
Your profile includes your first and last name and your self-reported mission/country or other affiliation. Designation and committee interests are optional. These details support your account and may help tailor future features; affiliation is not verified accreditation and does not give editorial or administrative permissions.
We also keep account status, permissions, session activity and security records. Server logs may include request paths, network addresses, timing and errors needed to operate and protect the service. Editorial actions retain the reviewer's name, decision, reason and account reference so published changes remain attributable.
Cookies and sign-in
Essential cookies support sign-in, request security and returning you to the page you were reading. The reader session uses a random browser token; only its digest is stored in the database. Reader sessions last up to 365 days and renew during continued use. Signing out or revoking sessions ends access earlier. Browser settings or cleared cookies may also end a session. We do not use an advertising or analytics integration in the current website.
Public proceedings and mission directories
DiploDesk separately archives information from public UN proceedings and mission directories, including speakers, diplomatic personnel and publicly listed contact details. Those records are distinct from reader accounts. Transcripts, summaries, country mentions and staffing changes may contain errors or lag behind the source. Staffing listing changes do not establish employment dates.
External services and access
Google handles federated sign-in. The website also loads fonts from Google, so your browser makes requests to Google's font servers. Following a recording or other external link takes you to that service, which has its own privacy practices. Authorized operators and infrastructure providers may access records needed to maintain and secure DiploDesk.
AI services process public proceeding text and related meeting context to produce corrections, summaries and country references. The current analysis pipeline does not send your reader profile or sign-in credentials to those models. AI-generated material should be checked against its cited source.
Retention and account deletion
Deleting your account is a soft deletion: access is disabled, sessions are revoked and sign-in links are disconnected, but your user record and profile details are retained. They are not automatically erased or purged. A later Google sign-in can create a new account; it does not restore the old one.
- Expired sign-in transactions become eligible for cleanup after 24 hours.
- Expired or revoked reader sessions become eligible after 30 days; active sessions are not removed by this cleanup.
- Disconnected identity safety fingerprints for deleted accounts become eligible after 24 hours. They prevent an already-started sign-in from recreating the account during deletion.
- Cleanup runs in bounded daily batches, so these are eligibility periods, not exact erasure deadlines.
Account deletion does not remove public source archives or rewrite past editorial decisions. Google's saved connection is managed separately in your Google Account settings.
Questions and requests
We may need to verify your identity before handling an account-related request. The available rights and obligations depend on applicable law; the account-deletion control alone is not a data-erasure request process. Changes to this notice will carry an updated version and effective date.