Legal

Privacy

Placeholder pending legal review. The substance below is accurate; the wording is not yet a contract.

What we collect

Two distinct categories, held to different standards. Account data — names, work email addresses, and workspace membership — is what you give us to use the product. Evidence is what the agent gathers from your systems during an investigation: log lines, approved query results, database metadata, configuration files and source code excerpts.

What never reaches us

Redaction runs at the agent, inside your network, before transmission. Connection strings, bearer tokens, API keys, payment card numbers and configurable personal-data patterns are removed at source. You can add your own patterns. Redacting on ingest would mean the data had already left your perimeter, which is why we do not do it that way.

Retention

Raw evidence expires well before the diagnosis that cites it — the defaults are 14 days for raw payloads and 90 days for redacted evidence records, both configurable. Incidents and their verdicts are retained longer because they are the accuracy record. You can delete a workspace and everything in it at any time.

Sub-processors

A current list of sub-processors is available on request and will be published here before general availability. We do not sell data, and we do not use customer evidence to train models shared with other customers.

Contact

Questions about this policy, or a data subject request: privacy@decim.dev.