Decret / Legal
Privacy Policy
Effective September 10, 2026 · Version 2026-09-10
What we process, what providers receive, and how to exercise your rights.
1. Who is responsible
The controller is Sorenor, LLC, a Delaware limited liability company. Our primary application and database infrastructure is hosted in the United States. Hosting location does not change our identity or remove applicable European data-protection obligations, including for transfers between the EU and the US described in section 6.
Sorenor, LLC, trading as Decret2810 N Church St STE 90277, Wilmington, DE 19802, USA
Registration: Delaware limited liability company, file 10762175, formed September 8, 2026
[email protected] · [email protected]
Contact [email protected] about personal data, access, correction or deletion. This policy covers the website, accounts, company workspaces, AI research, MCP connections and operational communications. It is an information notice, not a request for blanket consent.
If an organization instructs us to process personal data on its behalf, the parties’ roles and obligations depend on the actual processing and an applicable data-processing agreement. The standard preview does not include a separately negotiated agreement for processing third-party personal data in customer files. Do not upload that data before the required arrangements have been agreed.
2. Information we collect
- Account and security information: name, email address, password hash, email-verification status, session identifiers, session expiry, IP address and user-agent information where available, and the version and time of Terms acceptance. We use the self-hosted Better Auth software; it is not a hosted identity provider receiving your credentials.
- Company workspace information: company name, website address, description, documents, document names, text, sizes, versions and metadata you supply or authorize an external agent to supply. Entering a website address does not automatically make us fetch the website.
- Research and history: questions, selected perspectives, conversation history, generated responses, source citations, captured company context, research progress and diagnostic information, and usage and cost-accounting records.
- Agent connections: key name, permissions, creation, expiry, revocation and activity information, a key hash, and an encrypted recoverable copy of the key where supported. An agent using the key can read or modify the records permitted by its scope.
- Communications and transactions: messages you send us, authentication emails and delivery status, support and rights requests, withdrawal notices and receipts, and subscription and payment identifiers and status. Payment-card details entered into Stripe’s checkout are processed by Stripe; we do not see or store full card details.
- Device and service operation: HTTP requests, network and device information, security events and technical logs handled by the application and infrastructure providers. Browser storage also holds preferences, custom boards, favorites and temporary interaction state.
- Public-source information: names, professional biographical information, writings, statements, quotations, source metadata and attributions concerning people represented in the source library and AI perspectives. We obtain this from selected public materials and published third-party accounts, not from private access to those people.
Name, email and authentication details are needed to create and secure an account. Submitting questions and company content is voluntary, but features that need that information cannot operate without it. Avoid information that is unnecessary for your question, sensitive personal data and material you lack authority to share.
3. Why we use information
We use account information to create and authenticate accounts, provide requested features, preserve history, administer usage limits and send essential service messages. For an individual contracting with us, we rely on contractual necessity where processing is objectively necessary for that contract. For business contacts who are not themselves the contracting party, we may rely on our legitimate interest in administering that business relationship.
We process network, security and diagnostic information to prevent misuse, protect accounts, investigate incidents, troubleshoot failures and maintain the Service. Our legitimate interests are running a reliable and secure service and protecting users and our legal rights. We assess those interests against the rights and interests of affected people. Legally required records and disclosures are processed to comply with the applicable obligation.
We use relevant prompts, company context and prior conversation material to perform the AI research you request. Public-source material supports retrieval, citation and discussion of publicly expressed professional ideas, based on our legitimate interest in providing that research functionality, subject to applicable rights and objections. Public availability does not remove data-protection or intellectual-property rights.
We do not sell personal data, use it for targeted advertising, or add private company documents to the shared public-source library. Decret does not train its own foundation model on workspace content. We do not use customer workspace content for unrelated product evaluations without the customer’s request or permission. Limited access for support, security and troubleshooting may be necessary. The separate processing rights of model providers are described below.
Where a processing activity requires consent, we will request it separately and explain how to withdraw it. Acceptance of the Terms is not used as a universal legal basis for personal-data processing.
4. What goes to the AI provider
MiniMax receives the information needed to generate a response. Depending on the question and research steps, this can include your prompt, company profile, relevant document content, captured document pages or excerpts, prior conversation context, selected public-source passages and intermediate tool results. Do not assume that only your latest question is transmitted.
Our current text-generation integration uses the MiniMax API operated under terms published by Nanonoble Pte. Ltd. and its affiliates. MiniMax’s published API terms permit certain uses of inputs and outputs to operate, maintain, develop and improve its services. Its privacy policy also describes retention and uses of deidentified or anonymized information. We have not established a dedicated zero-retention or blanket no-training arrangement for this preview.
Review the MiniMax API Terms and MiniMax API Privacy Policy before submitting confidential material. We cannot promise that deleting information from Decret immediately deletes provider copies, or that providers use information exclusively on our instructions. Contact us before submitting information that requires contractual restrictions beyond those available for the Service.
Public-library search embeddings are produced on our own server using a local model. That local retrieval step does not itself send your query to another embedding service. Generating an answer still involves the MiniMax processing described above.
Decret produces informational analysis for your review. It does not itself make legally binding decisions about you or automatically execute its recommendations. You should not use its output as the sole basis for decisions with legal or similarly significant effects.
5. Service providers and other recipients
| Recipient | Role in the Service | Information involved |
|---|---|---|
| Amazon Web Services | Application and database hosting, storage, backups and infrastructure operation. | Data stored by the Service and infrastructure metadata. |
| Cloudflare | Network delivery, security, HTTPS termination, tunnel and inbound email routing. | Requests, IP/device information, traffic and security metadata, and messages forwarded to our support mailboxes. |
| MiniMax | AI text generation and associated provider processing. | Prompts and relevant context described in section 4. |
| Resend | Transactional email, including verification, password recovery and request confirmations. | Recipient address, email content, service metadata and delivery events. Open and click tracking are disabled for our sending domain. |
| Apple iCloud Mail | Operator mailboxes receiving forwarded support, privacy and other service correspondence. | Correspondence, sender information and attachments you send. |
| Stripe | Payment checkout, subscriptions, fraud prevention and payment administration. | Billing and payment data supplied at checkout. We receive the identifiers, subscription/payment status and related information needed to administer your purchase. |
Providers may use their own subprocessors and may act as independent controllers for some purposes, such as their own security, legal or account administration. Their policies and applicable contractual arrangements govern those activities. The list above does not mean that every provider receives every category of your information.
The operator and authorized personnel may access data where reasonably necessary for service operation, support, security and legal obligations. Company workspaces are scoped to the account and are not made public by default. A person or agent you give access to may receive the data its credentials permit, under that client’s separate terms.
We may disclose information where legally required, to protect legal rights or safety, or in a lawful transfer of the business, subject to applicable safeguards and notice. We do not treat a business transfer as permission to disregard this policy or applicable law.
6. Locations and international transfers
Our primary application, database and backup storage are in AWS US East (Northern Virginia). Operating and support access is limited to authorized US personnel. Cloudflare and other providers operate internationally. MiniMax and Resend describe US data storage, and their affiliates or subprocessors may process data in other countries. Selecting a sending region for email is not a promise of data residency in that region.
Relevant provider materials include the AWS data-protection arrangements, Cloudflare DPA, Resend DPA and MiniMax’s international-transfer disclosures. Those documents describe mechanisms including standard contractual clauses or other safeguards in the circumstances they cover. They are not a representation that Decret has verified a separately negotiated processing and transfer arrangement for every possible category of customer-uploaded data.
Contact [email protected] for information about the arrangements relevant to your data or to request an available copy of applicable safeguards. Do not submit third-party personal data requiring a customer processing agreement until the required arrangements have been agreed. Your use of the Service is not treated as blanket consent to otherwise unlawful international transfers.
7. Retention and deletion
- Accounts and workspace records: retained while you keep the account or until you delete the relevant records, subject to a specific legal or security need. Sessions expire after up to 30 days. Verification links expire after one hour; password-reset links after 30 minutes. Expiry prevents use of a link and is not a promise that every related provider log is erased at that instant.
- Conversation context: a saved conversation may preserve document snapshots and quotations from the time of the question. Deleting or changing the current document does not rewrite prior research. Delete the relevant conversations as well if you want that saved context removed from the active account. Shared snapshots are removed when no remaining conversation needs them.
- Account deletion: removes account-linked records from the active database, including company records, conversations, credentials, connection keys and usage records. Copies in backups, external providers or necessary legal records are subject to their separate retention.
- Backups: encrypted daily backups are configured for 30-day expiry. Provider lifecycle cleanup can complete later. Backups are for recovery and are not an immediately editable live account. If restoration is necessary, deletion requests must be reapplied before restored records resume ordinary use.
- Technical records: application container logs rotate by size. Account-linked security and usage records remain with the account unless needed for a particular incident or legal obligation. We do not retain raw model reasoning in ordinary public progress events.
- Email and support: account emails are processed by Resend under its retention terms; its standard plans currently describe 30-day email/log retention and separate backup retention. We keep correspondence and request records as needed to resolve the matter and address applicable legal, accounting or dispute requirements. We review retained correspondence for continuing need rather than promise immediate erasure of inbox copies.
- Public materials: source-library records are maintained while relevant to the Service, subject to accuracy, objection, rights and removal review. They are independent of a particular customer account.
When a specific retention obligation or legal claim requires us to keep information longer, we limit it to what is necessary for that purpose. We cannot recall information you or an authorized agent exported, or control independently retained copies held by other recipients. Contact us if a deletion request needs to address those additional copies.
9. Security and your choices
We use HTTPS, encrypted primary storage and backups, account-scoped access controls, protected application secrets and limited administrative access. Passwords are stored as hashes. Recoverable MCP keys are encrypted at rest. The Service is not end-to-end encrypted against the operator or the providers that must process content to deliver it.
No system can guarantee absolute security. Keep your password and keys private, choose the least access your agent needs and revoke unused keys. Do not upload secrets or regulated sensitive records. Report a suspected security incident to [email protected].
You can edit company information, remove documents, delete conversations, revoke connection keys, export account content and delete the account in Settings → Data. Revoking a connection does not delete data already obtained by an external client.
10. Your data-protection rights
Subject to the conditions and exceptions in applicable law, you may request access and a copy, correction, erasure, restriction, applicable portability, or object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it without affecting the lawfulness of earlier processing. These rights can apply to information about you in public-source records as well as account data.
Write to [email protected]. We may need proportionate information to verify your identity and locate the records. We will respond within the legally required period, generally one month under the GDPR, and explain any lawful extension, restriction or refusal. We will not require unnecessary identity documents or unlawfully penalize you for exercising your rights.
You may complain to your competent data-protection authority — the European Data Protection Board member list links every EU authority — and exercise available judicial remedies. Contacting us does not waive those rights.
If your organization is responsible for personal data that it has lawfully instructed us to process under a separate agreement, a request may need to be handled through that organization. We will assist as required by the applicable arrangement and law.
11. Age limits and policy changes
The Service is for adults aged 18 and over. We do not knowingly offer accounts to children. Contact us if you believe a child has supplied personal data so we can investigate and take appropriate action.
We may revise this notice when practices or legal requirements change. The date above identifies the current version. We will give at least 30 days’ notice of material changes through the Service or an appropriate account communication, and obtain separate consent where the law requires it. A policy update does not make an incompatible earlier use lawful.