Data handling
Trust
Where your data goes
Every tool runs two ways. Self-hosted, it runs on your machine and nothing is sent to Decosa. Hosted, your data travels encrypted to Decosa’s API server, where it is decrypted and processed by Decosa's API server, with the open models run by NEAR AI through OpenRouter, with Reka AI as the only fallback under Decosa's account. It is not used for training. The companies involved are named below.
Each tool below lists how long hosted data is kept and every call that leaves Decosa’s hosted service or your machine. The list is built from each tool’s stack.json and checked against the backend code; the hosted routing was last checked on 26 Sep 2026.
Decosa for Chrome has its own privacy policy.
- What this page proves
- What each tool sends, to whom, and what it keeps, as the hosted service runs today, built from each tool's own data-flow file.
- What it doesn't
- Anything you can check from outside. If your data can't leave your building, self-host the tool instead.
Level 1
Self-host: confidential
Your data stays on your machine. Decosa never receives it and there are no Decosa charges.
- Every tool has a self-host path: the same containers and pinned open-weight models, set up by one copy-paste prompt. Self-hosting or on a Mac Studio.
- 74 of 86 send nothing out by default, or talk only to a system you name (your model endpoint, your website, the site you test).
- 10 make public lookups with short identifiers, never your documents: Run the visit with a copilot, Check a brief before filing, Check a paper's citations, Keep a signed lab notebook, Tie out MD&A figures, Draft VEX for scanner findings, Check a lay summary's numbers, Draft a tariff classification memo, Check the other side's brief and Read a demand before the deadline. Each row says what it sends and, where possible, how to switch it off.
- 2 send some content out by default: Capture audit evidence from your admin screens and See what studies found for a supplement.
- Off unless you turn them on, with your own keys: outside services in Make a disclosed UGC ad and Find the songs in your mix (paid answer engines, fal renders). Each row below says what they receive.
Level 2
Hosted: processed by Decosa
Encrypted on the way, then decrypted and processed by Decosa's API server, with the open models run by NEAR AI through OpenRouter, with Reka AI as the only fallback under Decosa's account. Decosa's API server and the provider running the model can read what you send while they work on it.
- The path: your browser or client → Cloudflare (Decosa's network provider: it ends TLS for api.decosa.ai and carries the request over an encrypted tunnel) → Decosa's API server (runs the tool, signs the receipts) → the inference provider that runs the model (below). Each hop is encrypted (TLS, or the tunnel); each company decrypts what it handles.
- Processing: in memory. Decosa’s API server runs the tool and sends its model calls to NEAR AI through OpenRouter, with Reka AI as the only fallback, under Decosa’s account, with zero data retention required. Each call’s receipt names who served it. If that changes, this page and the badges change first.
- Not used for training by Decosa, and the model providers are held to no training and no retention. Receipts hold hashes and token counts, not your text.
- Retention is set per tool and listed below: most keep nothing after the request, some keep a run for an hour for exports, a few keep reports or renders.
- Outside services: hosted video in Make a story, a song or a music video, Make a disclosed UGC ad, Fill a form from your own papers, Capture audit evidence from your admin screens and See what studies found for a supplement is rendered by fal, which receives the prompts and media for that render. Some tools look up citations or identifiers in public services, or call a system you name; each is listed below.
- 35 tools handle patient, privileged or regulated records, so their hosted demo is for sample or public data only: self-host for real data.
Level 3
Sealed tier: paused at launch
End-to-end encrypted chat is off at launch. It comes back as a confidential tier that runs inside an attested enclave.
- It decrypted prompts on a model server Decosa operates. At launch outside providers run the hosted models, so there is no such server and the sealed endpoints are off.
- For patient, privileged or regulated data, self-host: nothing reaches Decosa or a provider.
- Why, and how it worked: Sealed tier. The pilot that replaces it: Confidential tier.
- Hosted video input, hosted renders other than UGC ads, live speech recognition, speaker separation, document reading, retrieval and the sealed tier are off at launch; their tool pages show recorded runs.
What we do not claim
- The hosted route is not end-to-end encrypted. Decosa’s API server decrypts your request to run the tool, and the provider decrypts the model call.
- The main model provider runs the model inside a TEE, but the hosted route as a whole is not confidential computing: Cloudflare, Decosa’s API server and the router handle the request outside an enclave, and Decosa doesn’t attest the provider’s enclave on each call.
- For patient data, privileged material or anything under a protective order, self-host. That is our recommendation on every such tool, and the hosted demos of those tools take sample data only.
Who processes hosted work
Decosa doesn't run the hosted models on its own GPUs at launch. These companies process hosted work for Decosa, each only for the part listed. A receipt names who served each model call.
| Company | What it does for Decosa | Policy |
|---|---|---|
| OpenRouter | Routes Decosa's hosted language-model calls to NEAR AI (Reka AI as the only fallback), requiring zero data retention and no data collection on every request. | Privacy |
| NEAR AI | Runs Qwen3.8-27B in FP8 inside a TEE (a hardware enclave) for the hosted API. | Privacy |
| Reka AI | The only fallback, when NEAR AI is unavailable: Qwen3.8-27B in FP8, keeping no prompts. | Privacy |
| fal | Renders images and video for UGC ads (the render prompt and inputs); keeps request data 30 days by default, and outputs sit on its CDN for at least 7 days. | Privacy |
| CourtListener (Free Law Project) | Legal citation lookups: gets citations and case names only, never your document. | — |
| NCBI (PubMed) | Paper and study lookups: gets identifiers and search terms only, never your document. | Privacy |
| Anthropic | The site guide's fallback: gets a question typed into the site guide (Ask Decosa), only when the guide's own model fails before answering. | Privacy |
The services that need no GPU run on Decosa's own server: the tools' checkers and lookups, music similarity and beat alignment, Kokoro and Chatterbox speech, and the browser that runs site checks.
The Ask Decosa guide
- The site guide asks what you do, answers from this site’s own pages (tools, metrics, docs, this page) and can open a page on this site for you. It never opens other sites, never runs a tool for you (you press Run), and does not browse.
- Your message and the matching page excerpts go to Decosa’s hosted open model (Qwen3.8-27B, through the same metered route as the hosted tools). If that is unavailable, a commercial provider (Anthropic) answers instead, under its API terms. Decosa does not send them anywhere else. Before either model sees your message, obvious identifiers (emails, phone numbers, dates, record numbers, a name after a title) are replaced.
- On a tool’s page, a question you ask the guide also carries what that page shows about your finished run (the verdict, the findings, the start of the draft, the time, the cost and the count of signed records), so it can explain the result. Nothing else of the page goes, and it isn’t stored either. If you paste your own made-up text and ask for a tool, the guide can open the tool with that text filled in under “Use your own”; the hand-off stays in your browser tab.
- We do not store conversation text. The server keeps only token counts, the model name, timings and cost per answer, plus rate-limit counters keyed by a hashed IP address. The conversation lives in your browser tab and is gone when you close it. We also count, per day, which tools the guide opened, explained or estimated, which profession was picked and the language: ids from fixed lists, never your words, your IP address or a session id. These counts tell us what people want built next.
- If no tool fits, the guide can draft a request for our team. Nothing is sent until you press Send on it. We then keep what the card shows (your role, what you want to get done, how and how often you do it today, the kind of data, and the guide’s preliminary read), with the same identifiers removed, plus an email only if you add one and tick the box. A person reads it and replies within 3 business days on a private status page (and by email if you gave one). We erase it 12 months after we close it, or sooner if you ask.
- Don’t paste patient data, privileged material or secrets into it. Ask about the product, not your case.
By tool
Hosted retention comes from each tool’s own facts. “Outside calls” are the only places data goes besides your machine or Decosa’s hosted service; model downloads at setup are not listed, since they carry none of your data.
- Hosted retention
Hosted demo is for sample or public data only. Audio and transcript live in server memory for the session and are dropped when it ends; paperwork PDFs are rendered on request and not stored. The receipt store keeps hashes of each model call, not the text.
Outside calls- NLM Clinical Tables, NLM RxNav and openFDAThe codes lane looks up a condition name and drug names (not the transcript or the note).Hosted and self-hostIdentifiers onlyOn by defaultTo switch it off: Block egress for the api container: the codes lane reports no match and the note is still written.
- Run an open model behind the OpenAI APIStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Hosted: prompts and answers are not stored; only the receipt (hashes, token counts, cost) is kept. Self-hosted: nothing leaves the machine unless you turn on the network profile.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Make a story, a song or a music videoStays localSelf-host: stays on your machineHosted: Decosa's hosted service + falHosted retention
Rendered files stay under /studio/media on the server; job status is kept in a file without tokens, and without the prompt once a job has started. Logs carry prompt hashes, never prompts. On fal (hosted video only): fal keeps request data (prompts and file links) for 30 days by default and serves uploaded and generated files from public CDN links until they are deleted [V: fal docs, Data Retention & Storage, read 29 Sep 2026]; Decosa downloads each result at once, and fal's no-storage and short-expiry options are not switched on yet.
Outside calls- fal (MiniMax H3 Max)Hosted video renders send the video prompt (text only) to fal, a partner GPU provider, under Decosa's account, billed at fal's list price with no markup; fal keeps request data 30 days by default. Songs and images render on Decosa's hosted service; self-hosted video renders locally with Wan2.1.HostedYour contentAlways
- Write the inspection reportStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Audio and transcript in memory for the session only; the report comes back in done and is not stored.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Nothing stored: transcript and translations live in memory for the session.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Make a tamper-evident meeting recordStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
The signed record is returned to you in done; the server keeps receipts (hashes), not the transcript.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Check your provider serves the model you pay forStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Signed reports are stored on the server and readable by anyone with the report id; a report of your endpoint records its URL and model name, never the key.
Outside calls- The endpoint you auditAbout 23-43 fixed probe prompts (not your data) and the provider API key you give, held in memory for one run. The probes bill your provider.Hosted and self-hostTo a system you nameAlways
- Make a disclosed UGC adStays localSelf-host: stays on your machineHosted: Decosa's hosted service + falHosted retention
Plans (brief, script, claims, receipt ids) are kept on the server as JSON so a render can refer to them; a rendered ad opens only through an expiring signed link given to the key that made it. No personal data is needed: presenters are invented. On fal (hosted video only): fal keeps request data (prompts and file links) for 30 days by default and serves uploaded and generated files from public CDN links until they are deleted [V: fal docs, Data Retention & Storage, read 29 Sep 2026]; Decosa downloads each result at once, and fal's no-storage and short-expiry options are not switched on yet.
Outside calls- fal (MiniMax H3 Max)Hosted renders send the director's shot prompts, two frames of the invented presenter (made on fal) and the house-voice voice-over audio to fal, a partner GPU provider, under Decosa's account; fal keeps request data 30 days by default and serves files from public CDN links until deleted.HostedYour contentAlways
- fal (MiniMax H3 Max)Only if you choose the H3 backend and set your own fal key; the default self-host render is local.Self-hostYour contentOnly if you turn it on
- Catch AI answers your sources don't backStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Nothing stored: text and sources live in memory for the request. The signed report carries hashes and character offsets, not your text.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Hosted demo is for sample or public data only. Transcripts and digests live in server memory for one hour (for export) and are never written to disk or logs.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Check a brief before filingLocal + lookupsSelf-host: local, plus lookupsHosted: Decosa's hosted serviceHosted retention
Hosted: the brief and excerpts live in memory; an uploaded file's text and a finished run are kept for one hour (for the export links), then dropped. Logs carry counts only.
Outside calls- Caselaw Access Project, CourtListener, LII, uscode.house.gov and eCFREach citation (for example 550 U.S. 544), never the brief, to check that the authority exists and to fetch its text. Case citations are answered first from a local index on our server; only its misses go out.Hosted and self-hostIdentifiers onlyOn by defaultTo switch it off: Offline mode sends nothing; case items are then left unverified.
- Pre-check promo claims for MLRStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Nothing stored: the piece and references live in memory for the request. The signed packet holds hashes, offsets, finding codes and receipt ids, never the copy.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Check if an open model can take over your promptStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Nothing stored: prompts, inputs and outputs live in memory for the request and come back to you in the sealed record. Strip each entry's text to share the record without your data; it still verifies.
Outside calls- Extra candidate endpoints you configureOnly if you list candidate models in DECOSA_MIGRATION_CANDIDATES: your examples then go to those endpoints.Self-hostTo a system you nameOnly if you turn it on
- Classify with a confidence you can act onStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Nothing stored: contexts and questions live in memory for the request. The signed record holds hashes of the context and questions plus the answers, not your text.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Answer a security questionnaireStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Nothing stored: the library and the questionnaire live in memory for the request. The review record holds hashes, source ids and statuses, never text.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Hosted: runs and screenshots are kept 24 hours (DECOSA_FLIGHT_TTL_S), then deleted. Self-host: you set the TTL; sealed records verify offline, so archive them yourself.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Run an end-to-end browser testStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Hosted: certificates and screenshots-as-thumbnails for 24 hours, then deleted. Self-host: as long as you set.
Outside calls- The site under testThe runner's browser loads the fixture app, saucedemo.com or https hosts your key verified (self-host: any host you list). Secrets are replaced by {{NAME}} before anything is recorded or sent to the model.Hosted and self-hostTo a system you nameAlways
- Build a model-risk evidence packStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Hosted: packs for the demo systems (synthetic) are stored; packs for your endpoint or suite are never stored, they go back to you. Self-host: nothing leaves the box.
Outside calls- The system you testYour suite's case texts go to the OpenAI-compatible endpoint you name (https and public on the hosted API).Hosted and self-hostTo a system you nameAlways
- Hosted retention
Hosted demo is for sample or public data only. None: transcripts, notes and audio stay in memory for one request; logs carry counts.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Hosted demo is for sample or public data only. Documents are held in memory for the request; the run (calls, log, no document text) for one hour, for the token or key that made it. Nothing is written to disk; logs carry counts only.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Log human edits and editor sign-offStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Open pieces 7 days, published ledgers 30 days, with the texts. Choose whether the public page shows the AI draft; its hash is always there. Self-host keeps everything on your box.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Check a police report against bodycamStays localSelf-host: stays on your machineHosted: demo data onlyHosted retention
Hosted demo is for sample or public data only. Nothing. Transcripts, reports and records live in memory for the request; logs carry counts and timings only. You keep the signed statement and record.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Hosted demo is for sample or public data only. The contract is held in memory for the request; the run (findings, changes, the redline) for one hour, for the token or key that made it. Nothing is written to disk; logs carry counts only.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Hosted demo is for sample or public data only. Records are held in memory for the request and the run (one hour, so the release can be rebuilt after the officer's decisions), for the token or key that made it. Nothing is written to disk; logs carry counts only.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Score an oral exam against a rubricStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Nothing stored: transcripts and records live in memory for the request or session and come back to you. The server keeps receipts (hashes), not text. For students under 18 the records keep hashes only.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Chart claim support in a patent specStays localSelf-host: stays on your machineHosted: demo data onlyHosted retention
Hosted demo is for sample or public data only. The application is held in memory for the request; the run (chart, issues, no specification) for one hour, for the token or key that made it. Nothing is written to disk; logs carry counts only.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
The prompt and lyrics are kept only while the job is queued; runs, certificates and the refusal log hold hashes, rules and settings. Rendered audio stays in the studio's media folder. Compared reference files are not kept.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Pre-check samples and lyricsStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
The audio and lyrics are held in memory for the request; the run (checklist and record, no audio) for one hour, for the token or key that made it. Nothing is written to disk; logs carry counts only.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Check split sheets and metadataStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Documents are held in memory for the request; the run (report and proposal) for one hour, for the token or key that made it. Nothing is written to disk; logs carry counts only.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Check a paper's citationsLocal + lookupsSelf-host: local, plus lookupsHosted: Decosa's hosted serviceHosted retention
The manuscript is held in memory for the request; the run (verdicts, issues, the text for exports) for one hour, for the token or key that made it. Nothing is written to disk; logs carry counts only.
Outside calls- Crossref, OpenAlex, Europe PMC, arXiv and doi.orgDOIs, identifiers and reference strings from the reference list, never the manuscript text, to find and read each cited work.Hosted and self-hostIdentifiers onlyAlways
- Keep a signed lab notebookLocal + lookupsSelf-host: local, plus lookupsHosted: Decosa's hosted serviceHosted retention
Demo notebooks expire after 14 days. Self-host keeps notebooks as append-only files in your data volume for as long as you set.
Outside calls- FreeTSA (freetsa.org), or the RFC 3161 time-stamp authority you setA 32-byte digest of the notebook's chain head, never the entries, to get a trusted timestamp.Hosted and self-hostA digest onlyOn by defaultTo switch it off: Set DECOSA_NOTEBOOK_TSA_URL to your own time-stamp authority.
- Check green claims in copyStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Nothing stored: copy and evidence live in memory for the request. The signed report holds hashes, offsets, verdicts, rule ids and receipt ids, never the copy.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Hosted demo is for sample or public data only. Nothing on the server. Transcripts, jackets and records live in memory for the request, and logs carry counts and timings only. You keep the signed record for two years (1784.44(a)).
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Dub a video in your own voiceStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Jobs, uploads and files are deleted after 24 hours. Logs hold ids, counts and timings, never text.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Pre-flight a synthetic-performer adStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
The upload and intermediate files are deleted when the run ends; the disclosed video and the report are kept for one hour, for the token or key that made the run. Logs carry counts only, never script text, names or the reviewer.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Turn a script into an animaticStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Hosted: the script, shot list, frames, voices and MP4 are kept 7 days so you can edit and re-render, then deleted. Frames and the MP4 open only through signed links that expire within hours and are given to the session or key that made the run. The signed record is public by design (anyone with its link can verify it): it holds hashes only and does not lead to your frames. Logs hold ids and counts, never script text.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Episode files are deleted after 7 days; until then they open only through signed links that expire within hours, given to the token or key that made the episode. The server keeps ids, hashes, settings and measurements, and the signed record; never script text in logs.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Make a music video for your trackStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
The track is kept 24 hours after upload so it can be rendered (longer only while a render is queued or running), then deleted. The run (hashes, analysis, lyric timings, captions, plan, record) is kept 7 days; the rendered videos stay in the studio's media folder and open only through signed links that expire within hours, given to the run's owner or its watch link. Logs hold ids, counts and hashes, never lyrics.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Hosted demo is for sample or public data only. Nothing stored: the case file lives in memory for the request. The signed report holds hashes, citations, verdicts and receipt ids, never case text; logs carry counts only.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Hosted demo is for sample or public data only. Nothing kept on the server. Files, policies and records live in memory for the request; logs carry counts only. You keep the signed file review with the claim file.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Hosted demo is for sample or public data only. Nothing on the server. Transcripts, call logs and records live in memory for the request, and logs carry counts and timings only. You keep the signed record with the recording for three years (12 CFR 1006.100(b)).
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Hosted demo is for sample or public data only. Nothing stored: the log lives in memory for the request. The signed pack holds hashes, ids, verdicts, clocks, receipt ids and the facts read from each notice (counts, yes/no fields, matched times and numbers), never the log or notice text itself; the timeline record goes back to you; logs carry counts only.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Hosted demo is for sample or public data only. Nothing stored but a cache of public EDGAR documents you asked for. Drafts and tables live in memory for the request; the signed record holds hashes, statuses and fact ids, never text; logs carry counts only.
Outside calls- SEC EDGAR (www.sec.gov)The CIK and accession number of a public filing you ask it to fetch, with a User-Agent naming the operator's contact address. Never your draft or tables.Hosted and self-hostIdentifiers onlyOn by defaultTo switch it off: Set DECOSA_TIEOUT_EDGAR=0, or send the document yourself.
- Hosted retention
Hosted demo is for sample or public data only. Nothing stored: the alert lives in memory for the request, and the review and the record go back to you. Logs carry the list, rule and decision, never names, dates of birth or numbers. You keep the records (10 years under 31 CFR 501.601).
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Hosted demo is for sample or public data only. Nothing on the server. Transcripts, call sheets, plan facts and records live in memory for the request, and logs carry counts and timings only. You keep the signed record with the recording until its retention dates.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Hosted demo is for sample or public data only. Nothing kept on the server. Denials, charts and packets live in memory for the request; logs carry counts only. You keep the signed packet with the claim.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Check if a video is made for kidsStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
An uploaded video is deleted when its run ends. Reports and records are kept in memory for one hour, for the token or key that made them. Logs carry run ids, statuses and counts, never titles, transcripts, names or links. You keep the signed review record.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Hosted demo is for sample or public data only. Nothing stored: the member file lives in memory for the request. The signed record holds hashes, verdicts and receipt ids, never note text; logs carry counts only.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Draft VEX for scanner findingsLocal + lookupsSelf-host: local, plus lookupsHosted: Decosa's hosted serviceHosted retention
Nothing kept but advisory text: reports, SBOMs and evidence bundles live in memory for the request; logs carry counts only. The image never reaches the API: the collector runs on your machine.
Outside calls- OSV.dev and NVD (NIST)Vulnerability ids (CVE, GHSA) to fetch advisory text, from the API and from the collector; never the report, the SBOM, the evidence or the image.Hosted and self-hostIdentifiers onlyOn by defaultTo switch it off: Set DECOSA_VEX_OFFLINE=1 and run the collector with --offline; load advisories with the import command or send them in the request. DECOSA_VEX_NVD=0 turns NVD alone off.
- Hosted retention
Hosted demo is for sample or public data only. Nothing kept on the server. Complaints and records live in memory for the request; logs carry counts and decisions only. You keep the signed records in the MDR event file.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Hosted demo is for sample or public data only. Nothing stored: the SSP and artefacts live in memory for the request. The signed index holds hashes, statuses and receipt ids, never artefact text; logs carry counts only.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Check a lay summary's numbersLocal + lookupsSelf-host: local, plus lookupsHosted: Decosa's hosted serviceHosted retention
Nothing stored: the study record, the draft and the result live in memory for the request, and logs carry counts only. A registry record fetched by NCT number is cached for a day. The signed record holds hashes, statuses and receipt ids, and the text of each sentence.
Outside calls- ClinicalTrials.gov (US National Library of Medicine)The NCT number you ask it to fetch. Never your draft, your inputs or unpublished results.Hosted and self-hostIdentifiers onlyOn by defaultTo switch it off: Set DECOSA_LAYSUMMARY_FETCH=0, or send the study record yourself as "study".
- Hosted retention
Hosted demo is for sample or public data only. Nothing kept on the server. Notices, account data and files live in memory for the request; logs carry counts only. You keep the signed record with the dispute, at least two years (12 CFR 1005.13(b)).
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Stage a listing photo with disclosureStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Uploads live in a temporary folder for the run and are deleted when it ends. A disclosed pair (the original, the staged image and the record) is kept for 30 days on a public page, because the label links to it: download the pair to host it on your own listing site. Runs are kept in memory for one hour for the token or key that made them. Logs carry ids, verdicts and counts, never images or instructions.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Write a due-diligence red-flag memoStays localSelf-host: stays on your machineHosted: demo data onlyHosted retention
Hosted demo is for sample or public data only. Nothing stored: the documents live in memory for the request. The signed record holds hashes (documents, index, quotes) and receipt ids, never document text; logs carry counts only.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Draft a tariff classification memoLocal + lookupsSelf-host: local, plus lookupsHosted: Decosa's hosted serviceHosted retention
Nothing stored: the description lives in memory for the request. Logs carry counts and timings only.
Outside calls- rulings.cbp.gov and hts.usitc.govOnly the one-time download of the public ruling set and the HTS (scripts/tariff_fetch.py): search terms (heading numbers, product words) and ruling numbers, never a product description. The hosted service calls no outside data sources: retrieval and the model run on Decosa's hosted service.Self-hostIdentifiers onlyOn by defaultTo switch it off: Copy rulings.jsonl, manifest.json and hts/ from another machine into DECOSA_TARIFF_DATA and skip the fetch.
- Hosted retention
Hosted demo is for sample or public data only. Nothing stored: the report lives in memory for the request. The signed record holds each number's status, cell and expected value, table hashes and receipt ids, never the report text; logs carry counts and timings only.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Nothing stored: the sheet, the label and the result live in memory for the request, and logs carry counts only. The signed record holds hashes, statuses, flags, the extracted fields and the translations.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Hosted demo is for sample or public data only. Nothing stored: files and page images live in memory for the request (the sample packet's reader output is cached in memory by file hash). The signed record holds hashes and receipt ids, never record text or the patient's name; logs carry counts only.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Hosted demo is for sample or public data only. Nothing kept on the server. Documents and packets live in memory for the request; logs carry counts only. You keep the signed packet with the claim.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Quote a job from a walkthrough videoStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
The video and its clip are deleted when the run ends. The report, with its keyframes, is kept in memory for one hour for the token or key that made it. Logs carry run ids and counts, never titles, narration or line text. You keep the exports and the signed record, which holds hashes and numbers only.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Turn an expert video into an SOPStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
The recording and its clip are deleted when the run ends. The report, with its keyframes, is kept in memory for one hour for the token or key that made it. Logs carry run ids and counts, never titles, narration or step text. You keep the exports and the signed record, which holds hashes only.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Check generated product imagesStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Images are held in memory and a temporary folder for the run and deleted when it ends; an approved image is kept with the run for one hour for the token or key that made it, so you can download it. Consent decisions on the demo go to a private in-memory ledger. Logs carry ids, verdicts and counts, never images or product facts.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Hosted demo is for sample or public data only. Nothing kept on the server. Reports, audio, scans and records live in memory for the request (the bundled samples' transcripts are cached by hash); logs carry counts and the case summary only. You keep the signed records with the case.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Compare safety sections across labelsStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Nothing stored: the documents live in memory for the request. The signed record holds document hashes, sections, each flag's place, kind and triage and the receipt ids, never the label text; logs carry counts and timings only.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Find accessibility fixes for a shopStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Nothing is stored: pages, screenshots and images live in memory and a private browser profile for the audit and are dropped when it ends. The result and its signed record are returned to you, not kept. Logs carry counts and ids, never URLs, alt text or page text.
Outside calls- The shop's own pages (the URLs you list)GET and HEAD requests from the headless browser to the domain the key verified (hosted) or the hosts you list (self-host). Every other request method is blocked.Hosted and self-hostTo a system you nameOn by defaultTo switch it off: Paste the HTML (synthetic: true) or use the sample shop instead of URLs.
- Fill a form from your own papersStays localSelf-host: stays on your machineHosted: Decosa's hosted service + Qwen3.8-27B on Decosa's servers, Decosa's document reader, Decosa's translation modelsHosted retention
Hosted runs keep the filled PDF, the source sheet and the signed record for 24 hours, readable only with your key or demo token, then delete them; 'Delete this run now' deletes them at once. Logs carry counts and ids, never answers or document text.
Outside calls- Qwen3.8-27B on Decosa's serversBox labels and options; your papers as numbered lines with Social Security, card, IBAN and routing numbers withheld; form text the injection patterns did not settle. Signature, ID and bank boxes are never sent. On our demo web form, also a screenshot when a widget needs it.HostedYour contentAlways
- Decosa's document reader (on Decosa's servers)Scanned PDF pages and photos of your papers, to find blanks and read text.HostedYour contentOn by defaultTo switch it off: Use fillable or text PDFs and text papers.
- Decosa's translation models (only if you pick another language)Field labels, reasons and the cited lines of your documents, for a review in your language. Never the values typed into the form.HostedYour contentOn by defaultTo switch it off: Choose English as the review language.
- The form's own siteThe browser loads the form's pages and assets from its own host (plus hosts you allow). Nothing is sent to it until you press Submit: every POST, form navigation, fetch, beacon and websocket is held while the agent works.Hosted and self-hostTo a system you nameOn by defaultTo switch it off: Paste the form's HTML instead of a URL (hosted), or do not press Submit.
- Turn a client call into notesStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
The call audio is held in memory only and dropped as soon as the transcript is made; its hash and the time go into the signed record. Nothing is written to disk. The memo, transcript and signed record are returned to you; the server keeps receipts (hashes), not the text.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Check the other side's briefLocal + lookupsSelf-host: local, plus lookupsHosted: Decosa's hosted serviceHosted retention
Hosted: the filing lives in memory; an uploaded file's text and a finished run are kept for one hour (for the export links), then dropped. Answers from the public sources (the citation queried, public opinion text; never the filing) are cached on disk for 7 days. Logs carry counts only.
Outside calls- Caselaw Access Project, CourtListener, LII, uscode.house.gov and eCFREach citation (for example 550 U.S. 544) and, before a citation is called not found, the case name; never the filing's text. Case citations are answered first from a local index on our server; only its misses, and quotations of recent cases, go to CourtListener.Hosted and self-hostIdentifiers onlyOn by defaultTo switch it off: Offline mode (DECOSA_PREFLIGHT_OFFLINE=1) sends nothing; case items are then left not checkable unless you supply the opinions.
- Check their discovery responsesStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Nothing stored: the responses live in memory for the request. The signed record holds the document hash, each flag's category, place and rule ids and the receipt ids, never the response text; logs carry counts and timings only.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Hosted demo is for sample or public data only. Nothing written to disk. The letter, charts and result live in memory; a finished run is kept one hour so its downloads work, then dropped. Logs carry counts only. The signed record holds hashes, not chart text.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Check a prior auth before you send itStays localSelf-host: stays on your machineHosted: demo data onlyHosted retention
Hosted demo is for sample or public data only. Nothing kept on the server. Policies, charts and results live in memory for the request; logs carry counts only. You keep the signed record with the request.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Hosted demo is for sample or public data only. Nothing stored: the jottings, the photo or the dictation live in memory for the request. The signed record holds hashes of each jotting and sentence and receipt ids, never text; logs carry counts only.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Capture audit evidence from your admin screensSends content outSelf-host: sends content outHosted: demo data onlyHosted retention
Hosted demo is for sample or public data only. Hosted demo: runs on made-up consoles are kept one hour for the session that made them, then deleted. Your own runs stay on your machine: the spec, the evidence packs and the signing key live where you run the helper.
Outside calls- The model you choose for setup and repairs (your own server, or the hosted gateway)Screenshots and the element table of the admin screens the agent opens during setup or a repair; never passwords; never during quarterly runs.Hosted and self-hostYour contentOn by defaultTo switch it off: Use a self-hosted model server (DECOSA_LLM_ROUTE=direct), or reuse an approved spec and run quarterly only.
- Put the visit into your EHR as draftsStays localSelf-host: stays on your machineHosted: demo data onlyHosted retention
Hosted demo is for sample or public data only. The hosted check keeps nothing: the visit lives in memory for the request, logs carry counts only. The agent's signed record holds hashes of the patient identifiers, never their text, and stays with the practice.
Outside calls- Decosa's model gateway (Qwen3.8-27B)Screens of the EHR form and the visit's values for each step, when the agent uses our hosted model. Needs a BAA first; the hosted demo is synthetic only.HostedYour contentOnly if you turn it on
- Your EHR (the tab you have open)The drafts, typed into your own session; nothing is signed or sent.Hosted and self-hostTo a system you nameAlways
- Read a demand before the deadlineLocal + lookupsSelf-host: local, plus lookupsHosted: demo data onlyHosted retention
Hosted demo is for sample or public data only. Nothing kept on the server: the package lives in memory for the request; logs carry counts only. You keep the signed record with the claim file.
Outside calls- CourtListener (Free Law Project)A case citation (volume, reporter, page and the case name) when the local citation index doesn't have it; never the letter.Hosted and self-hostIdentifiers onlyOn by defaultTo switch it off: Set DECOSA_PREFLIGHT_CL_OFF=1 (self-host prompt sets it) to use the local index only.
- Hosted retention
Hosted demo is for sample or public data only. Nothing kept on the server: the contract, request and policies live in memory for the request; logs carry counts only. You keep the signed record for the E&O file.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Check a bank-detail change before you payStays localSelf-host: stays on your machineHosted: demo data onlyHosted retention
Hosted demo is for sample or public data only. Nothing kept on the server: the email and vendor file live in memory for the request; logs carry counts only. You keep the signed records.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Turn a family interview into a filmStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
The interview, photos, transcript and films stay in your private Studio project until you delete it or she takes her consent back with her link (which deletes everything). Her consent entry expires after three years. Logs hold ids, counts and hashes, never her words.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Make a music video starring youStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
The consent clip, face references, track and videos stay in your private Studio project until you delete it or the performer takes consent back with their own link (which deletes their references and videos). The consent entry expires after one year. Logs hold ids, counts and hashes.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Make a film of your story togetherStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
The consent clip, face references, track and videos stay in your private Studio project until you delete it or the performer takes consent back with their own link (which deletes their references and videos). The consent entry expires after one year. Logs hold ids, counts and hashes.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Hosted retention
Hosted demo is for sample or public data only. Drafts, page images, photos and videos are kept for two hours on the server that made them, then deleted (Delete now removes a render at once). The signed record holds hashes and receipt ids, never record text, names or photos; logs carry counts, timings and ids only. The hosted demo takes synthetic matters only.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Find the themes in your interviewsStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Nothing kept on the server: audio and text live in memory for each request, and logs carry counts and timings only. The study lives in your browser until you export it; the recording is dropped after transcription and only its hash is kept in the record.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- Find the songs in your mixStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
Your mix and track files are deleted when the run ends. The chaptered .m4a is kept for one hour for download, or until you delete it. The song list and the signed cue sheet (no audio) stay in memory for 24 hours.
Outside calls- AudD (audd.io)A compressed copy of the mix, only if you set your own AudD token (DECOSA_CUE_AUDD_TOKEN) on a self-hosted server.Self-hostYour contentOnly if you turn it on
- Reply to a review without breaking patient privacyStays localSelf-host: stays on your machineHosted: Decosa's hosted serviceHosted retention
None: the review and the reply live in memory for the request. The signed record holds the review's SHA-256, never its text.
Outside callsNone. Nothing goes anywhere but your machine (self-host) or Decosa’s API server and its model provider (hosted).
- See what studies found for a supplementSends content outSelf-host: sends content outHosted: Decosa's hosted service + NCBI E-utilitiesHosted retention
The hosted service keeps the PMIDs each search returned for 7 days, keyed by a SHA-256 of the search term, so repeat searches are fast. Titles and abstracts live in memory for the request; the signed record holds each abstract's SHA-256, not its text.
Outside calls- NCBI E-utilities (PubMed, eutils.ncbi.nlm.nih.gov)The search words (the supplement and the outcome, in a PubMed query) and the PMIDs to fetch. PubMed returns public records: titles and abstracts.Hosted and self-hostYour contentAlways
For agents and scripts
The same facts are in /api/catalog.json and /use-cases/<id>.json under data_handling: self_host.level (always confidential) and self_host.leaves (nothing, identifiers or content), hosted.level (operator-processed), hosted.demo_only, hosted.third_parties, hosted.retention, and external_calls. See For AI agents.
Privacy requests, such as a copy of your data or deleting it: email privacy@decosa.ai.