Legal

Privacy Policy

Last updated August 5, 2026

This Privacy Policy explains how Decisive (“Decisive”, “we”, “us”, or “our”) collects, uses, shares, and protects information when you use our website at decisive.rocks, our application at app.decisive.rocks, and related features (together, the “Service”). It works alongside our Terms of Service.

In short: your team’s content is yours. We process it to run the workspace and the features you choose to use, we rely on a small set of trusted providers to do that, and we don’t sell your data.

1. Information we collect

Account information

When you sign up, we collect your email address (used to identify your account) and basic profile details you provide, such as a display name and avatar image. We do not store passwords: sign-in is passwordless, using either a one-time code sent to your email or your Google account.

If you choose “Continue with Google”, Google confirms your identity to us and shares your email address and basic profile information (such as your name and profile picture). We never receive your Google password, and we request no access to your Gmail, Drive, or any other Google service. Google’s own handling of that sign-in is governed by its privacy policy; you can review and revoke Decisive’s access at any time in your Google account settings.

Workspace content

We store the content you and your team create in a workspace, including chat messages, tasks, documents, discussions, comments, reactions, and uploaded file attachments. This content is provided by you and shared with the members of your workspace.

Integration data

If you connect integrations, we process the data needed to make them work. For GitHub, this includes repository content and metadata accessed under the permissions you grant. For Slack, this includes the messages in channels the bot has been invited to when it is mentioned there, and the Slack profile email used to match a Slack account to a member of your workspace - see “Slack integration” below. If your workspace provides its own AI provider API key, we store it encrypted and use it to make AI requests on your behalf.

Billing information

When you subscribe to a paid plan, payment is processed by our payment provider, Stripe. Stripe collects and processes your payment details (such as card or other payment information) and billing address directly; we do not receive or store full payment card numbers. We receive limited billing records from Stripe, such as your plan, subscription status, the last digits and type of your payment method, and invoices, so we can manage your subscription.

Voice, video & transcripts

When you use huddles or the voice AI agent, we and our real-time communication providers process audio and video streams, and may generate captions, transcripts, and synthesized AI voice as part of the feature.

Usage, device & log data

Like most online services, we and our providers automatically collect technical information such as IP address, browser and device type, pages and features used, timestamps, and diagnostic logs. We use this to operate, secure, debug, and improve the Service. For the same purposes we use product analytics, which record which pages and features are used.

We also use session replay: our analytics provider records a reconstruction of your browsing session - the pages you view, your clicks, scrolling, and navigation - so we can diagnose bugs and improve how the Service works. Because a replay reconstructs the page as it appeared to you, it can include content displayed on screen, such as task titles, document text, messages, and the names of people in your workspace. What you type into form fields is masked before it leaves your browser and is never recorded - including passwords, API keys, and email addresses entered into forms - and we do not record network request contents or browser console output. Replays are stored by our analytics provider and are accessible only to us.

Cookies & local storage

We use cookies and similar browser storage (including local storage and IndexedDB) to keep you signed in, remember preferences, support offline and real-time editing of documents, and keep the Service secure. We do not use third-party advertising cookies.

2. How we use information

  • to provide, maintain, and operate the Service and its features;
  • to authenticate you and keep your account and workspace secure;
  • to power AI features you use, including generating responses, summaries, and code changes;
  • to enable integrations you connect, such as GitHub and Slack;
  • to respond to support requests and communicate with you about the Service;
  • to monitor, debug, prevent abuse of, and improve the Service; and
  • to comply with legal obligations and enforce our Terms.

Where required by law, we rely on the following legal bases: performance of our contract with you (to provide the Service), our legitimate interests (to secure and improve the Service), your consent (where requested), and compliance with legal obligations.

3. AI processing

When you use AI features, relevant workspace content is sent to AI providers to generate a response, and, for voice features, to speech-to-text and text-to-speech providers. Anthropic (Claude) is the default and handles AI features unless your workspace chooses otherwise. A workspace admin may additionally enable another provider for specific features - OpenAI (GPT) for what your AI teammates think with in chat - in which case content for those features is sent to that provider instead. Where your workspace uses its own provider API key, requests are made under your own account with that provider and are also subject to that provider’s terms and privacy practices. We do not use your content for AI training, and we rely on our AI providers’ commitments not to train their models on data submitted through their business APIs.

4. Code & repository data

If you connect a GitHub repository, our build and coding-agent features may clone your repository into a secure cloud environment to run, edit, preview, and propose changes, and may send relevant code to AI providers to generate those changes. Proposed changes are delivered as pull requests for your review. Your source code remains in your own GitHub repository, and you can disconnect the integration at any time.

5. Slack integration

If a workspace admin connects Slack, we store your Slack team’s id and name, the bot’s user id, the granted scopes, and an access token for the bot - encrypted at rest, and readable only by our servers. When someone mentions the bot in a channel it has been invited to, we receive that mention and the surrounding messages (the thread, or the last few messages in the channel), together with the Slack profile email of the person asking, which is used to match them to a member of the connected workspace. That content is processed to answer or to file a task, including by sending it to our AI providers, and is not stored by us beyond what the bot writes into your workspace - such as a task it creates - which is then workspace content like any other.

The bot only ever sees channels it has been explicitly invited to; it cannot enumerate or read the rest of your Slack workspace, direct messages, or files. How much of your Decisive workspace it may say back out in Slack is an admin setting that starts at nothing. Disconnecting it in Settings → Slack revokes the token and deletes the connection. Slack’s own handling of the messages and profile data in your Slack workspace is governed by Slack’s privacy policy and your agreement with them.

6. How we share information

We do not sell your personal information. We share information only as needed to run the Service: with the members of your workspace; with the service providers (sub-processors) listed below; in connection with a merger, acquisition, or sale of assets (with notice where required); and when required by law or to protect rights, safety, and the integrity of the Service.

Sub-processors

We rely on the following providers to operate the Service. They process data on our behalf:

ProviderPurpose
SupabaseAuthentication, database, file storage, and real-time sync
CloudflareHosting, serverless functions, cloud containers for the coding/voice agents, real-time media, and bot prevention
Anthropic (Claude)AI assistant, summaries, code generation, and other AI features
OpenAI (GPT)AI assistant replies, where a workspace admin has enabled OpenAI for that feature
GitHubSource-control integration (repository access, branches, pull requests)
SlackSlack app - messages in channels the bot is invited to, and the replies and tasks it posts back, where a workspace connects it
LiveKitReal-time audio and video for huddles
ElevenLabsVoice assistant and huddle transcription - speech-to-text, the spoken conversation itself, and text-to-speech (AI voice responses)
StripePayment processing, billing, and tax calculation
MailgunTransactional and product email delivery
PostHogProduct analytics, session replay, and diagnostics

This list may change as the Service evolves; we will keep it up to date here. Some providers process data in the United States and other countries.

7. Data retention

We retain your information for as long as your account and workspace are active and as needed to provide the Service. When you delete content, your account, or your workspace, we delete or anonymize the associated data within a reasonable period, except where we must retain it to comply with legal obligations, resolve disputes, or enforce our agreements. Residual copies may persist in routine backups for a limited time before being overwritten.

8. Security

We take technical and organizational measures to protect your information, including encryption in transit, encryption of sensitive credentials (such as AI provider API keys and connected-account tokens) at rest, and database-level access controls that isolate each workspace’s data. Our architecture, tenant-isolation model, and vulnerability-reporting process are described in detail on our Security page.

No method of transmission or storage is completely secure. A workspace admin can export the workspace’s full contents at any time, and we recommend keeping your own copy of anything critical.

9. Your rights

Depending on where you live, you may have rights to access, correct, delete, export, or restrict the processing of your personal information, and to object to certain processing or withdraw consent. You can update much of your profile and content directly in the app. A workspace administrator can download the workspace's full contents at any time from Settings → Export, without asking us - no plan requirement and no request form. To delete your account or workspace, or to exercise any of these rights, contact us at [email protected] and we will action the request as required by applicable law. If a workspace administrator controls your workspace, some requests may need to be directed to them.

If you are in the European Economic Area, the United Kingdom, or Switzerland, you also have the right to lodge a complaint with your local data protection supervisory authority.

10. International transfers

We and our providers operate globally, and your information may be processed in countries other than your own, including the United States. Where required, we rely on appropriate safeguards for such transfers.

11. Children

The Service is not directed to children, and you must be at least 16 years old (or the age of digital consent in your jurisdiction, if higher) to use it. We do not knowingly collect personal information from children below that age.

12. Billing & refunds

Paid-plan payments are processed by our payment provider, Stripe, which handles your payment and billing information. Decisive Network, Inc. is the seller of record, and Decisive does not store full payment card details. Our billing, cancellation, and refund terms - including that subscriptions can be cancelled anytime, remain active until the end of the paid period, and that payments are non-refundable except where required by law - are set out in our Terms of Service.

13. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

14. Data controller & contact

The Service is operated by Decisive Network, Inc., a Delaware corporation with its registered office at 2810 N Church St STE 89498, Wilmington, DE 19802, United States, which is the data controller responsible for personal data processed through the Service. Questions about your privacy or this policy, and any of the requests described in “Your rights” above, can be sent to [email protected].