Effective September 16, 2026
DecisionLedger AI™ ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the DecisionLedger platform and related services, including our website, our web application, and the DecisionLedger AI mobile app for iOS and Android.
We collect information in the following categories:
Section 2 describes in detail what the mobile app accesses on your device, what it sends to us, and what it does not collect.
We publish a mobile app, "DecisionLedger AI", for iOS and Android. The app is another way to reach the same account and the same workspace data described elsewhere in this policy. It is not a separate service, it does not create a separate account, and it does not collect a separate category of data for its own purposes. This section describes what the app accesses on your device and what leaves your device.
The app asks for each of the following at the moment you use the feature that needs it, never at launch. Declining any of them leaves the rest of the app working.
Every photograph taken or selected in the app is re-encoded on your device before it is uploaded. Re-encoding writes a new image from the decoded pixels, so no EXIF metadata block survives, including the precise GPS coordinates that a phone camera embeds in a photograph by default. We therefore do not receive the location at which a photograph was taken.
There is one exception, and it is a timestamp rather than a location. For a safety hazard photograph, the app reads the original capture time from EXIF before the re-encode and sends it as a separate field, because the interval between when a hazard was photographed and when the report reached us is part of the safety record. No other EXIF value is read or retained.
Where a hazard occurred is recorded only from the site and location description you type into the report yourself.
If you allow notifications, the app obtains a push token from Expo, the service that delivers our mobile notifications, and registers that token with us together with your device's operating system, operating system version, device model, and the version of the app. We use this to route notifications to the right device, to show you which devices are registered, and to retire a token that is no longer valid.
Notification payloads are content-free by default. A push carries a generic banner and an identifier; the app then fetches the actual content over an authenticated, encrypted connection. This is deliberate: a mobile push relays through Expo's servers and then Apple's or Google's, so the notification itself is not the place for the substance of your work.
Signing out retires that device's push token, so a signed-out phone stops receiving another account's notifications.
All of this travels over HTTPS. The app has no unencrypted endpoint.
You may optionally require Face ID, Touch ID, a fingerprint, or your device passcode to reopen the app. The check is performed entirely by your device's operating system, which returns only a pass or fail result to the app. Your biometric data is never available to the app, never stored by us, and never transmitted. Only the fact that the lock is switched on is saved, and it is saved in your device's secure keystore.
A related setting, on by default, asks the operating system to block screenshots and screen recording of the app and to hide its preview in the recent-apps switcher. This is a protection applied on your device; it sends us nothing.
So the app remains usable without a connection, it keeps a local copy of data you have already viewed and queues changes you make while offline until they can be sent. Both are encrypted at rest on the device using AES-256, with the key held in the platform keystore (the iOS keychain or the Android keystore). Sign-in tokens and your workspace selection are held in the platform secure store and are deleted from the device when you sign out.
You can request deletion of your account and its associated data at decisionledgerai.com/account-deletion, which is linked from the Settings screen of the app and is also reachable without installing it. Retention and deletion timelines are described in section 6.
We use your information to:
We do not sell your personal data. We share data only with the following categories of service providers, under strict contractual obligations:
If you configure external AI provider API keys (e.g., Anthropic, OpenAI) for optional cost reconciliation, the platform may contact those providers' usage APIs to retrieve aggregate token counts and billing metadata. No personal data, decision inputs, or model outputs are transmitted in these calls.
We may also disclose information if required by law, subpoena, or governmental request, or to protect the rights and safety of DecisionLedger AI, our users, or the public.
We do not use customer data to train, fine-tune, or improve AI models. All AI inference is performed via Amazon Bedrock within our AWS VPC. No customer data - including decision inputs, model outputs, prompts, or completions - leaves the data boundary or is shared with model providers for training purposes. This applies to all AI features including the assistant, evaluator, narratives, and classification services, whether reached from the web application or the mobile app.
We implement industry-standard security measures to protect your data:
AI assistant conversations are stored encrypted at rest within your tenant's isolated data partition. Conversation content is subject to PII redaction before transmission to AI models. Users may apply per-conversation confidentiality policies:
No conversation content is used for AI model training. All AI inference runs via Amazon Bedrock within our VPC.
We retain your account information and decision data for the duration of your subscription. Following account termination, we retain data for 30 days to allow export, after which it is permanently deleted. Audit logs are retained according to your plan tier (30 days for Starter, 180 days for Professional, custom for Enterprise). Anonymized analytics data may be retained indefinitely for service improvement.
AI assistant conversations are retained for the duration of your subscription unless you apply a per-conversation zero-retention policy, which permanently deletes the conversation and all messages after your specified retention period (1–365 days). Conversations marked with the "restricted" confidentiality policy are accessible only to the conversation owner and are excluded from any administrative access.
Depending on your jurisdiction, you may have the right to:
To exercise any of these rights, contact us at privacy@decisionledgerai.com, or, to request deletion of your account, use our account deletion page.
Our Service is hosted in the United States (AWS us-west-2 region). If you access the Service from outside the United States, your data will be transferred to and processed in the United States. We implement appropriate safeguards, including Standard Contractual Clauses where required, to ensure your data is protected in accordance with applicable law.
The Service is not intended for individuals under 16 years of age. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 16, we will take steps to delete it promptly.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA/CPRA). For details on your rights and how to exercise them, please see our California Privacy Rights page.
For customers who require a formal data processing agreement, our Data Processing Agreement (DPA) describes our obligations as a data processor, sub-processor list, security measures, and breach notification procedures. Administrators may sign the DPA electronically through the Confidentiality Settings in the admin dashboard.
DecisionLedger AI operates as a Business Associate under HIPAA when processing data for healthcare Covered Entities. Customers who are HIPAA Covered Entities or Business Associates may execute a Business Associate Agreement (BAA) through the admin dashboard.
When a BAA is in effect and the healthcare domain is enabled for your tenant:
We do not use Protected Health Information to train AI models. All AI processing for healthcare tenants runs via Amazon Bedrock within our AWS VPC. For breach notification procedures, see our HIPAA Breach Notification Procedure document available upon request.
We use cookies and similar technologies to operate the Service. For details on the types of cookies we use and how to manage them, please see our Cookie Policy. The mobile app uses no cookies or similar technologies for analytics, advertising, or cross-app tracking.
We may update this Privacy Policy periodically. We will notify you of material changes by email or through the Service at least 30 days before they take effect. The "Effective" date at the top of this page indicates when the policy was last revised.
If you have questions or concerns about this Privacy Policy, please contact us at privacy@decisionledgerai.com.