Legal

Privacy Policy.

Where you go in the mountains is your business. Here is exactly what we collect, why we collect it, and the choices you have, written to be read in one sitting.

Last updated: September 22, 2026Effective: October 1, 202613 sections
01

The short version

We never sell your data, we never use your trips or messages to train AI models, and your live location stays on your device unless you choose to share it.

This Privacy Policy explains how AI Outdoors LLC, the company that operates Diorite ("Diorite", "we", "us"), collects, uses and protects information when you visit diorite.ai, join our waitlist, or use the Diorite apps, web planner and wearable integrations (together, the "Service").

Mountain plans are personal. They reveal where you will be, when, and with whom. We built Diorite so that the least possible amount of that information ever leaves your phone, and so that what does is used only to make your plans better.

02

Information we collect

Information you give us. When you join the waitlist we collect your email address and, if you choose, your primary activity. When you create an account we collect your name, email, password (stored only as a salted hash), and optional profile details such as experience level, certifications and emergency contacts.

Trip information. Objectives, routes, dates, party members, gear lists, notes and questions you ask Diorite. This is the core of the Service and is stored in your account so you can plan across devices.

Device and usage information. App version, device model, operating system, crash logs, and aggregated feature usage. We do not use advertising identifiers and we do not embed third-party advertising or tracking SDKs.

Wearable data. If you connect a watch or fitness platform, we import only the activity metrics you approve (for example pace, distance and elevation) to calibrate your personal pace model.

03

Location and Field Mode

Field Mode runs on your device. Live GPS position, the breadcrumb track and the offline route model are processed locally and are not uploaded while you are moving.

After a trip, you may choose to sync your track to your account to improve your pace model and build trip history. Syncing is off by default and can be switched off at any time, which deletes previously synced tracks within 30 days.

Live location sharing with your party or an emergency contact only happens when you explicitly start a share, and it ends automatically when the trip is closed or the share expires.

04

How we use information

To provide the Service: generating briefs, gear plans and pace estimates, syncing across devices, and sending the alerts you subscribe to.

To keep people safe and the Service reliable: detecting abuse, debugging crashes, and evaluating the quality of briefs against our safety council scenarios using de-identified samples.

To communicate with you: waitlist invitations, product updates and, where permitted, occasional newsletters. Every marketing email has a one-click unsubscribe.

05

AI processing and model training

Diorite uses large language models, including models provided by Anthropic, to generate briefs and answer questions. When you ask Diorite something, the relevant trip context is sent to the model provider over an encrypted connection to produce the answer.

Our agreements with model providers prohibit them from using your content to train their models and require deletion after processing, subject to short abuse-monitoring windows.

We do not use your trips, messages or location to train any model, ours or anyone else’s. Improvements to Diorite come from public data, licensed data, and scenarios written and graded by our safety council.

06

How we share information

We do not sell or rent personal information, and we do not share it for cross-context behavioral advertising.

Service providers. We use carefully selected vendors for cloud hosting, database storage, email delivery, payment processing and AI inference. They may process data only on our instructions and under written contracts.

Your party. Trip details you choose to share are visible to the people you invite. You control what each trip shares and can revoke access at any time.

Legal and safety. We may disclose information if required by law, or if we believe in good faith it is necessary to protect someone’s life or safety, for example responding to a verified search and rescue request.

07

Retention

Waitlist emails are kept until you are invited and onboarded, or until you ask us to remove them. Account and trip data are kept while your account is active. When you delete your account, we delete your personal data from production systems within 30 days and from backups within 90 days.

Crash logs and usage analytics are retained for up to 13 months in aggregated or de-identified form.

08

Security

Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Access to production systems is limited to a small number of engineers, requires hardware security keys, and is logged.

No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by law. You can report a vulnerability to security@diorite.ai.

09

Your rights and choices

Wherever you live, you can access, correct, export or delete your personal information from the app settings or by writing to privacy@diorite.ai. We respond within 30 days.

If you are in the European Economic Area, the United Kingdom or Switzerland, you also have rights to restrict or object to processing and to lodge a complaint with your local supervisory authority. Our lawful bases are performance of a contract, legitimate interests (security and product improvement) and consent (marketing and optional data sharing).

If you are a California resident, you have the rights described in the CCPA, including the right to know, delete and correct, and the right not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined.

10

Cookies and similar technology

Our website uses only strictly necessary storage, such as remembering that you have already joined the waitlist. We do not use third-party advertising cookies or cross-site tracking pixels.

We measure site traffic with privacy-friendly, cookieless analytics that do not identify individual visitors.

11

International transfers

Diorite is based in the United States and has a team in Chamonix, France. Your information may be processed in the United States and the European Union. Where we transfer personal data out of the EEA or UK, we rely on the European Commission’s Standard Contractual Clauses and equivalent safeguards.

12

Children

The Service is not directed to children under 16, and we do not knowingly collect their personal information. Younger climbers may use Diorite only through a parent, guardian or guide service account. If you believe a child has provided us information, contact us and we will delete it.

13

Changes and contact

If we make material changes to this policy, we will notify you by email or in the app at least 14 days before they take effect.

Questions or requests can be sent to privacy@diorite.ai or by mail to AI Outdoors LLC, Attn: Privacy, c/o GB Registered Agents, Inc., 47 W. Belmont Dr., Hockessin, Delaware 19707, USA.

Questions about this document?

A real person on our team reads every message, usually within two business days.

privacy@diorite.ai