Privacy policy
Decis processes only the information needed to provide the service and does not sell personal data.
Information we process
We process account email and sign-in information; connected health, training, nutrition, and calendar records; work-agent session information and the work records or summaries selected for sync; content you submit and responses; record type and source metadata needed for sync; service usage records; and subscription and billing status. Precise workout-route location from Apple Health is imported only with your explicit permission for that data type. Paddle processes payment details such as card numbers directly; Decis does not store them.
Google user data
When you sign in with Google, we receive your name, email address, and profile picture from your Google account and use them only to create and authenticate your Decis account. If you connect Google Calendar or Google Health as a data source, we access only the read-only data types you approve on the Google consent screen, use them solely to provide the features described in this policy, and store them encrypted. We do not sell Google user data, use it for advertising, or transfer it except as needed to provide these features. Decis's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke Decis's access at any time in Settings or at your Google Account permissions page.
How we use Google Calendar data
When you connect Google Calendar, Decis uses read-only access to retrieve your calendar list and event details returned by the Google Calendar API, which can include calendar names and identifiers; event titles, descriptions, start and end times, locations, recurrence, status and visibility; and organizer, attendee, conferencing, and attachment metadata. Decis uses this data to display your schedule, let you choose which calendars are included, classify events, compare meetings and scheduling patterns with your connected health and recovery records, and generate user-requested answers. Event data and OAuth credentials are encrypted in transit and at rest. We disclose data only to service providers acting on our behalf when necessary to operate these user-facing features. Decis does not create, modify, or delete events in Google Calendar, and does not use Google Workspace data to train or improve generalized AI or machine-learning models.
AI work-agent data
Connecting a work agent syncs work times, agent type, repository and branch, task context, and outcomes. With ‘Summarize with Decis AI,’ Decis stores a distilled work record and uses Google Cloud Vertex AI to summarize it. With ‘Summarize with this agent,’ the agent installed on your device summarizes the distilled record; its provider may process it under your account and settings. In that case, Decis receives only the summary and does not send it to Vertex AI. Neither mode uploads complete source session files, raw tool output, authorization headers, or recognized secrets.
How information is used
We use information to analyze your records, provide wellness insights, organize AI work sessions in Timeline, maintain connected-data sync, and handle account, subscription, and security issues.
Service providers
We use Supabase for authentication and databases, Vercel for hosting, and Paddle for payments. We may use AI infrastructure providers such as Google Cloud Vertex AI for answer generation, calendar-event classification, and the work-record summary method you select. We use PostHog (United States) for troubleshooting and service quality checks. We send each provider only the information needed for its function.
Service troubleshooting
We retain service usage records and related content for troubleshooting and quality checks. Authorized personnel access and use them only when, and to the extent, needed for those purposes.
Deleting a connected source
Deleting a connected source removes its synced data and connection credentials from Decis. For work agents, it also stops sync and removes the corresponding sessions and summaries. Original records in connected services such as Apple Health and Google Calendar, or in local agents, are not changed.
Permanently deleting your Decis account
Permanent account deletion removes your Decis account, service data, and connection credentials. Billing records are unlinked from the deleted account internally and retained as needed for fulfillment and legal obligations. Original records in connected services are not changed.
Retention and deletion
We retain information while your account and connections remain active, subject to the record retention terms in our Terms of service. Records without account identifiers used to confirm completed account deletion are kept for 30 days. Apple revocation credentials not needed for a pending deletion request are kept for 7 days. Billing records are retained as needed for fulfillment, disputes, and legal obligations. PostHog currently retains input content and responses used for troubleshooting and quality checks for 30 days; related metadata follows its event retention policy. Account or source deletion does not immediately delete these records; they expire under those retention periods.
Your choices
In Settings, you can stop connections, delete synced data, and change work-agent summary methods, language, and time zone. You can also request a copy of your records or permanently delete your account. The scope of source and account deletion is described above. Disconnecting Google Health, WHOOP, or Google Calendar keeps records already imported; deleting them is a separate request.
Security
We use encryption in transit and at rest, server-only credentials, access controls, and least-privilege practices. Connection credentials for external services are stored encrypted. No system can guarantee absolute security.
Security incident notification
If we confirm unauthorized access to or use of your information, we will promptly notify affected users as required by applicable law and, where required, the connected data providers and relevant authorities.
Operator and contact
- Operator
- Tab0 Inc.
- Privacy and billing support
- support@decis.me