Privacy Policy
Last updated: August 12, 2026
This Privacy Policy describes how DecimalAI LLC (“DecimalAI,” “we,” “us”) collects, uses, and shares information when you use the DecimalAI platform, our website at decimal.ai, and our APIs and SDKs (collectively, the “Service”).
If you have questions or want to exercise any of the rights described below, email us at hello@decimal.ai.
1. Information we collect
1.1 Account information
When you sign up, our authentication provider (Clerk) collects your email address, name, and profile image from your chosen OAuth provider (Google, GitHub, etc.). We sync this information to our database to attribute traces, manage workspace membership, and send transactional emails.
1.2 Workspace and billing
We store the name of your organization, your plan tier, billing contact email, and Stripe customer identifier. Payment card information is collected and stored by Stripe and is never visible to us.
1.3 Agent traces and platform usage
Our core product ingests agent execution traces from your applications via our SDK. These traces may include:
- Prompts and responses from large language model (LLM) calls
- Tool invocations, span metadata, error messages
- Manifest versions (prompts, model identifiers, skill references)
- Evaluation scores and verdicts
You decide what to send to DecimalAI. We recommend redacting personally identifiable information from prompts and outputs before ingestion when possible. We provide a sample redaction utility in our SDK documentation.
1.4 Logs and diagnostics
We collect server-side request logs (IP, user agent, endpoint, response code, latency) and, if enabled, error events via Sentry. These are used to operate and improve the Service.
1.5 Product analytics and cookies
We use PostHog for product analytics on the application at app.decimal.ai, to understand which features are used and where people get stuck. PostHog sets a first-party cookie on the .decimal.ai domain containing a randomly generated identifier, so the same browser is recognised across visits. We have configured it to record no session replays and to attach a person profile only to signed-in users; for those, the identifier we send is the opaque account ID, never your email or name. Page URLs, referrer, and UTM parameters are collected as event properties.
Our marketing website at decimal.ai uses Framer’s built-in analytics, which is cookieless: it derives a daily visitor count by hashing IP address and user agent with a secret that rotates and is deleted every day, and creates no persistent identifier. It reports aggregate pageviews, referrers, countries, and devices, and cannot identify an individual. The marketing site additionally carries the Google tags described below, which do set cookies.
We also use Google Analytics and Google Ads, loaded through Google Tag Manager, to measure our own advertising — specifically, to tell which visits and sign-ups came from an ad we paid for, and to show our ads to people who have already visited us. These set Google advertising and analytics cookies on the .decimal.ai domain, including one that stores the click identifier from the ad you arrived through.
For visitors in the European Economic Area, the United Kingdom, and Switzerland, these tags start in a consent-denied state: they send only aggregate, cookieless signals unless and until you affirmatively consent. Elsewhere they are active by default. You can opt out at any time via Google’s opt-out add-on, your browser’s cookie controls, or Google My Ad Center.
We do not sell personal information. Our use of Google Ads remarketing may qualify as sharing personal information for cross-context behavioural advertising under California law; to opt out, email us at hello@decimal.ai or use the Google controls above. To opt out of product analytics, block the cookie in your browser or email us at hello@decimal.ai and we will exclude your account.
2. How we use information
- To operate the Service — ingest, store, and display your traces; run evaluations; detect regressions.
- To bill — meter usage against your plan and process subscription payments via Stripe.
- To communicate — send transactional emails (receipts, quota warnings, security alerts) and lifecycle emails (welcome, activation tips). You can opt out of non-essential lifecycle emails at any time.
- To improve the Service — analyze aggregated, de-identified usage patterns. We do not train AI models on your trace contents.
- To meet legal obligations — tax records, fraud prevention, lawful requests.
3. AI model training
We do not train DecimalAI models on customer trace contents. When you enable LLM-judge evaluations, prompt and response text from your traces is sent to the LLM provider you have configured (OpenAI, Anthropic, Google Gemini, etc.) under that provider’s terms. Each provider has its own policy on training; you should review and configure those providers’ accounts to opt out of training where applicable.
4. Subprocessors
We share data with the following third-party services to operate the platform. Each is contractually bound to data-protection terms and processes data only on our behalf.
| Subprocessor | Purpose | Data shared |
|---|---|---|
| Google Cloud Platform | Hosting (Cloud Run, Cloud SQL, Cloud Storage, Secret Manager) | All platform data, encrypted at rest |
| Clerk | Authentication | Email, name, OAuth identifiers |
| Stripe | Payment processing | Billing contact, plan, subscription state |
| Resend | Transactional email delivery | Recipient email, message content |
| Sentry (optional) | Error tracking | Server-side error context, sanitized |
| PostHog | Product analytics on app.decimal.ai | Pages viewed, referrer and UTM parameters, a cookie identifier, and — for signed-in users — the opaque account ID. No session replays, no email or name. |
| Framer | Marketing site hosting and cookieless analytics for decimal.ai | Page requests; visitor counts derived from a daily-rotating hash of IP and user agent, with no persistent identifier |
| Google (Analytics, Ads, Tag Manager) | Advertising measurement and remarketing across decimal.ai and app.decimal.ai | Pages viewed, referrer and UTM parameters, ad click identifier, approximate location and device, and cookie identifiers. Consent-denied by default in the EEA, UK, and Switzerland. |
| LLM providers you configure | Eval-judge calls | Prompt/response text from your traces, only when LLM-judge eval is enabled |
We keep the list above current as our subprocessors change, and will make reasonable efforts to update it in advance. Customers under a data processing agreement receive notice of new subprocessors as set out in that agreement.
5. Data retention
- Traces and platform data — we aim to delete these according to your plan’s retention window (Free 14 days, Core 30 days, Pro 90 days, Enterprise 365 days); see your billing page for the value on your current plan. In all cases they are deleted no later than 12 months.
- Account and workspace records — kept until you delete your account, then deleted within 30 days.
- Billing records — retained for 7 years to comply with US tax law.
- Server logs — retained for 90 days then deleted.
6. Your rights
Depending on where you live, you may have the following rights:
- Access — request a copy of the personal information we hold about you.
- Correction — ask us to fix inaccurate data.
- Deletion — ask us to delete your account and associated data.
- Portability — receive your trace data in a machine-readable format.
- Opt-out — unsubscribe from non-essential email at any time.
To exercise any right, email hello@decimal.ai from the address on your account. We may ask you to verify your identity before we act, and we may decline requests that are manifestly unfounded or excessive, or charge a reasonable fee to handle them.
We aim to respond within the period the applicable law allows — generally one month under UK and EU rules, and 45 days under California’s — and we may extend that where the law permits, for example where a request is complex or you have made several. We will tell you if we need the extension.
Portability covers the data we hold about you at the time of your request, in a structured, commonly used format. It does not extend to data already removed under the retention windows in section 5, to backups, or to data we would have to rebuild or reverse-engineer to produce.
7. Security
We use industry-standard practices to protect your data: TLS for all traffic, encryption at rest for customer LLM provider credentials (Fernet AES-128-CBC + HMAC-SHA256), least-privilege IAM for our cloud resources, and audit logging of consequential mutations. See our Security page for our vulnerability disclosure policy.
8. International transfers
Our infrastructure is hosted in the United States on Google Cloud Platform. If you access the Service from outside the US, you understand that your information will be processed in the United States.
9. Children
The Service is not directed to children under 16. We do not knowingly collect personal information from anyone under 16.
10. Changes to this policy
We may update this policy from time to time. Changes are posted here with a new “Last updated” date, and for material changes we will make reasonable efforts to notify the workspace billing contact by email.
11. Contact
DecimalAI LLC
1209 North Orange Street
Wilmington, DE 19801
Email: hello@decimal.ai