Privacy Policy
Last updated: August 5, 2026
At Decodeme Suite, privacy is not a feature — it is a foundational principle. We handle sensitive communication data, and we take that responsibility seriously. This policy explains in detail how we protect your data, what consents we require, and the technical and organizational measures we implement.
Data Protection Layers
Your data is protected by multiple security layers, from the moment it enters our platform to the moment it is deleted.
All data is encrypted both in transit and at rest using industry-standard protocols.
- TLS 1.3 for all data in transit between your browser and our servers
- AES-256 encryption for all data at rest in our databases
- End-to-end encryption for analyzed texts — not even our team can read your messages
- Encryption keys are rotated regularly and managed through a dedicated key management service
Strict access policies ensure only authorized processes interact with your data.
- Role-based access control (RBAC) for all internal systems
- Multi-factor authentication required for any infrastructure access
- Zero-trust architecture — every request is verified regardless of origin
- Audit logs for all data access events, reviewed regularly
Our infrastructure is designed with security-first principles at every level.
- Hosted on Google Cloud infrastructure, SOC 2 Type II certified
- Network isolation with private subnets and strict firewall rules
- Automated vulnerability scanning and dependency auditing
- Regular penetration testing by independent security firms
Your texts are processed by AI with strict privacy boundaries.
- Texts are processed in isolated, ephemeral sessions — no cross-user data mixing
- AI models are never trained or fine-tuned on user data
- Analysis results are generated in real time and not stored unless you explicitly save them
- No third-party AI providers have access to your raw text data
Information We Collect
We collect only the minimum data necessary to provide our services. We do not collect data from third-party sources.
Account Information
To create and manage your account, authenticate your identity, and communicate with you.
- Full name
- Email address
- Authentication credentials (hashed, never stored in plain text)
Communication Data
To provide communication analysis, generate insights, and build your analysis history.
- Texts submitted for analysis
- Analysis results (if you choose to save them)
- Conversation partner profiles you create
Usage Data
To improve the platform, personalize your experience, and detect technical issues.
- Feature usage patterns
- Session duration
- Language preference
Optional Data
To provide personalized recommendations and track your communication improvement journey.
- Cognitive game scores
- Coaching progress
Consents
We operate on a consent-first model. You are always in control of what data we process and how.
Required Consents
Terms of Service & Privacy Policy
You must accept our Terms of Service and this Privacy Policy to use the platform. This covers the basic data processing needed to provide our core services.
AI-Powered Communication Analysis
By submitting text for analysis, you consent to its processing by our AI systems. Texts are processed in ephemeral sessions and are not retained unless you explicitly save the results.
Optional Consents
Activity Notifications
Receive notifications about your analysis activity, streaks, and coaching recommendations. You can enable or disable this at any time from your profile settings.
Anonymous Usage Analytics
Allow us to use anonymized, aggregated usage patterns to improve the platform. No individual data is ever identifiable.
You can withdraw any optional consent at any time from your profile settings. Withdrawing required consents will result in account deactivation. Previously processed data based on valid consent remains lawful.
How We Use Your Information
We use your information exclusively to:
- Provide and improve our communication analysis services
- Generate personalized coaching recommendations based on the COM-B behavioral model
- Personalize your experience on the platform
- Send you relevant notifications about your activity (with your consent)
- Detect and prevent security threats and abuse
- Comply with legal obligations
We will NEVER:
- Sell your data to third parties
- Share your data with advertisers
- Use your texts to train or improve AI models
- Profile you for purposes unrelated to the service
- Transfer your data to countries without adequate protection without safeguards
Your Rights
Under GDPR, CCPA, and applicable data protection laws, you have the following rights:
- Right of Access — Request a copy of all personal data we hold about you
- Right to Rectification — Correct any inaccurate or incomplete data
- Right to Erasure — Request permanent deletion of your data (completed within 30 days)
- Right to Data Portability — Export your data in a standard, machine-readable format
- Right to Restrict Processing — Limit how we process your data in certain circumstances
- Right to Object — Object to data processing based on legitimate interests
- Right to Withdraw Consent — Revoke any consent at any time without affecting prior processing
- Right to Lodge a Complaint — File a complaint with your local data protection authority
You can exercise most of these rights directly from your profile settings. For requests that require manual processing, contact us at privacy@decodeme.ai and we will respond within 30 days.
Data Retention
We retain data only as long as necessary for the purposes described in this policy.
| Data Type | Retention Period |
|---|---|
| Original message | Encrypted and deleted after 72 hours |
| De-identified analysis | Retained while your account is active |
| Account information | Retained while your account is active |
| Usage analytics (anonymized) | Retained for up to 24 months |
| All data upon account deletion | Permanently deleted within 30 days |
Regulatory Compliance
Decodeme Suite is designed to comply with major data protection regulations:
- GDPRGDPR (General Data Protection Regulation) — EU
- CCPACCPA (California Consumer Privacy Act) — US
- SOC 2 Type IISOC 2 Type II — Google Cloud infrastructure security standards
- HIPAA available on request for healthcare organizationsHIPAA available on request for healthcare organizations
Sub-Processors
Third-party services that process personal data on behalf of Decodeme.
Transferências Internacionais de Dados
Alguns dos nossos sub-processadores estão localizados fora do Brasil. Todas as transferências internacionais são realizadas com base em mecanismos adequados nos termos dos Art. 33 a 36 da LGPD.
Os Estados Unidos não possuem decisão de adequação da ANPD. As transferências para processadores norte-americanos são amparadas por Cláusulas Contratuais Padrão (SCC), nos termos do Art. 33, II da LGPD.
| Processador | País | Base legal (LGPD) | Finalidade |
|---|---|---|---|
| Amazon Web Services (AWS) | EUA | Art. 33, II — SCC | Hospedagem, armazenamento, infraestrutura |
| OpenAI | EUA | Art. 33, II — SCC | Análise de comunicação e detecção de riscos psicossociais |
| Anthropic | EUA | Art. 33, II — SCC | Processamento de linguagem natural — análise complementar |
| MongoDB Atlas | EUA | Art. 33, II — SCC | Banco de dados principal |
| Slack Technologies | EUA | Art. 33, II — SCC | Integração de comunicação organizacional |
Análise Psicossocial NR-1🇧🇷 Brasil
Aplicação territorial: Esta seção aplica-se exclusivamente a organizações e trabalhadores no território brasileiro, sujeitos à NR-1 (Portaria MTE nº 1.419/2024) e à LGPD (Lei nº 13.709/2018). Se a sua organização não opera no Brasil, esta seção não é aplicável.
Dados tratados
Para cumprir a NR-1, o Decodeme processa comunicações de trabalho a fim de identificar indicadores de risco psicossocial (esgotamento, estresse, conflitos interpessoais). Esses dados constituem dados sensíveis na acepção do Art. 5º, X da LGPD (dados referentes à saúde / estado psicológico inferido).
Base legal
O tratamento fundamenta-se no cumprimento de obrigação legal (LGPD Art. 11, II, a), uma vez que a NR-1 impõe às empresas a obrigação de identificar e gerenciar riscos psicossociais no Programa de Gerenciamento de Riscos (PGR). O consentimento individual complementar (Art. 11, I) pode ser obtido separadamente pela plataforma.
Finalidade
Geração de evidências para o PGR da organização; elaboração de planos de ação corretiva; geração do inventário de riscos e plano de ação do PGR; relatório de impacto à proteção de dados (RIPD) nos termos do Art. 38 da LGPD.
Período de retenção
Os registros de análise psicossocial NR-1 são conservados por 5 anos (1 825 dias) a partir da data de geração, conforme recomendação de arquivamento do PGR. Cada organização pode configurar um período distinto respeitando o mínimo legal.
Direitos do titular
Nos termos do Art. 18 da LGPD, o titular pode solicitar acesso, correção, portabilidade, eliminação e revogação do consentimento. Para exercer esses direitos, entre em contato com o Encarregado (DPO) pelo endereço abaixo.
Data Protection Officer (DPO)
If you have questions about how your personal data is processed, wish to exercise your data protection rights, or want to report a privacy concern, you can contact our Data Protection Officer directly.
dpo@decodeme.aiContact & Data Protection Officer
For privacy inquiries, data requests, or to report a concern, write to us at privacy@decodeme.ai