Company
Privacy policy
Effective 11 October 2026. Decosa, Inc., a Delaware corporation.
This policy covers decosa.ai, the Decosa API and the tools on this site. Each tool's own handling, including what it keeps and for how long, is on where your data goes. The Chrome extension has its own policy.
The short version
- We collect what we need to run Decosa: your email if you buy credits, your API keys' usage, and what you send to a tool.
- We don't sell your data, show ads, use tracking cookies or train models on your data.
- A short list of outside companies handles data for us; section 5 names each one and what it sees.
- You can ask to see, fix, export or delete your data: write to privacy@decosa.ai.
1. Who is responsible
Decosa, Inc. (2261 Market Street STE 96574, San Francisco, CA 94114) decides how this data is used. Privacy questions and requests: privacy@decosa.ai.
2. What we collect
- When you visit. Our hosts see standard request data: IP address, browser, the page and the time. We run no analytics or advertising scripts.
- API keys. For each key: its id, a hash of the key (never the key itself), the name you gave it, the tools you picked and daily usage counts.
- Using a tool or the API. What you send so the tool can run, and its result. Each call also leaves a signed record: the model route, the time, usage counts, the cost, and hashes of the input and output. What each tool keeps, and for how long, is on where your data goes.
- Buying credits or a plan. Your email, the payment processor's customer id, and your credit ledger (purchases, usage and the record behind each debit). Card details go to the payment processor; we never see your full card number.
- The site guide. We don't keep what you type to it. We keep usage counts, timings and cost per answer, and rate-limit counters keyed by a hashed IP address. If you send our team a request through it, we keep that request.
- Forms, comments and requests. What you type, your email if you give it, and a salted hash of your IP address to stop abuse.
- Email. The messages you send us and our replies.
3. What we don't do
- We don't sell or rent personal data, or share it for advertising.
- We don't use your content to train models.
- We don't use analytics, advertising or cross-site tracking cookies.
4. Why we use it
- To run the tools and the API you ask for, and to bill for them (our contract with you).
- To keep the service safe, apply limits and stop abuse (our legitimate interest in a working, fair service).
- To answer you, and to send account emails such as sign-in links and low-balance notices.
- To learn what to build next, from counts that don't include your words.
- To meet legal duties, such as tax records, and to answer lawful requests.
Where the law asks us to rely on your consent, we ask first, and you can withdraw it at any time.
5. Who else handles it
These companies handle personal data for us, and we let them use it only for the job listed. This list is current as of 11 October 2026. The first rows are the model providers that serve hosted model calls (the same list as where your data goes); we add any new one here, by name, before it handles your data.
| Company | What it does for us | What it sees | Where | Status |
|---|---|---|---|---|
| OpenRouter | Routes Decosa's hosted language-model calls to NEAR AI (Reka AI as the only fallback), requiring zero data retention and no data collection on every request. | Hosted model calls: the prompt Decosa's API server sends and the answer, in transit and in memory, with zero data retention required. | United States | In use |
| NEAR AI | Runs Qwen3.8-27B in FP8 inside a TEE (a hardware enclave) for the hosted API. | Hosted model calls: the prompt Decosa's API server sends and the answer, in transit and in memory, with zero data retention required. | United States (in a TEE) | In use |
| Reka AI | The only fallback, when NEAR AI is unavailable: Qwen3.8-27B in FP8, keeping no prompts. | Hosted model calls: the prompt Decosa's API server sends and the answer, in transit and in memory, with zero data retention required. | See its policy | In use |
| Vercel | Hosts decosa.ai and its server routes (the site guide, key and credit pages). | Page requests, IP addresses, and what you send through those routes. | United States | In use |
| Cloudflare | Runs our DNS and the encrypted connection to our API at api.decosa.ai. | API requests and IP addresses in transit. | Global network | In use |
| Stripe | Takes payments, issues invoices and receipts, and works out sales tax. | Your name, email, billing address and card details. We never see your full card number. | United States | In use |
| Google Workspace | Our email (support@, privacy@ and the other inboxes). | The emails you send us. | United States | In use |
| SendGrid (Twilio) | Sends our emails: sign-in links, replies to requests, low-balance notices. | Your email address and the message. | United States | In use |
| Anthropic | Answers the site guide when our own model is unavailable. | Your guide message, with obvious identifiers removed, and excerpts of our pages. | United States | In use |
| fal | Renders images and video for UGC ads, the only hosted renders on at launch. | The prompts and media for that render. It keeps request data 30 days by default. | United States | In use |
| OpenAI and xAI | Answer the questions our search-visibility tools ask answer engines. | Those questions, which are about a brand, not about you. | United States | Off today |
| Upstash | Would hold the site guide's rate-limit counters. | Counters keyed by a hashed IP address. | United States | Not in use yet |
The Decosa API, its tools, ledgers and signed records run on our own servers in California. Some tools look things up in public sources (for example case law or medical literature): those lookups carry search terms, not your files, and where your data goes lists them per tool. We may also disclose data when the law requires it, or to a buyer if Decosa is sold, under this policy.
6. How long we keep it
- Tool inputs and results: as stated for each tool on where your data goes.
- API key records: while the key exists; usage counts as long as we need them for billing and abuse checks.
- Credit ledgers, invoices and payment records: as long as tax and accounting law requires.
- Requests to our team: 12 months after we close them, or sooner if you ask.
- Email: as long as we need it to help you, then deleted.
7. Cookies and browser storage
decosa.ai sets only the first-party cookies below. They are needed for the features that use them, so there is no cookie banner. None is set when you just read a page.
| Cookie | What it does | Scope | Lasts |
|---|---|---|---|
| decosa_keys | Remembers which API keys this browser created and how many it made today, so it can list them and apply the daily limit. | Sent only to /api/keys. Not readable by page scripts. | 1 year |
| decosa_billing | Keeps you signed in to your credits account after a checkout or an emailed sign-in link. | Not readable by page scripts. | 1 year, or until you sign out |
| decosa_site | Remembers the preview password on preview copies of the site. It isn't used on the public site. | Not readable by page scripts. | 30 days |
Some pages also keep things in your browser's own storage, on your device only: the names and ids of keys you made (not the keys), your Studio projects, drafts, the guide conversation for the open tab, and settings such as reduced motion. Clearing your browser's site data removes them. Checkout happens on the payment processor's own pages, which set their own cookies under its policy.
8. Your rights
Wherever you live, you can ask us to show you, correct, export or delete your personal data, or to stop using it for something. Write to privacy@decosa.ai. We may need to confirm it's you, and we answer within 30 days. Some records, such as invoices, we must keep by law; we tell you if that applies.
- California. You have the rights to know, delete and correct, and not to be treated differently for using them. We don't sell or share personal information for cross-context advertising, and we don't use sensitive personal information to infer things about you.
- EU, EEA and UK. You also have the rights to restrict and object to processing and to data portability, and you can complain to your data protection authority.
9. Children
Decosa is for adults. We don't knowingly collect personal data from children under 13, or let anyone under 18 hold an account. Stories with children are paused in Studio. If you think a child has given us personal data, write to privacy@decosa.ai and we will delete it.
10. Security
Connections are encrypted (HTTPS). We keep hashes of API keys, not the keys, and limit who on our side can reach your data. Every metered call leaves a signed record you can check yourself. No system is perfectly secure: if you find a problem, please tell us at security@decosa.ai (see security).
11. Where your data is
We are based in the United States, and our servers and most of the companies above are there. If you use Decosa from elsewhere, your data is handled in the United States, with the safeguards the law requires for such transfers.
12. Changes
When we change this policy, we update the effective date at the top. For a change that matters, we tell you by email (if we have yours) or on the site before it takes effect.