Privacy Policy

    Effective September 16, 2026

    DecisionLedger AI™ ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the DecisionLedger platform and related services, including our website, our web application, and the DecisionLedger AI mobile app for iOS and Android.

    1. Information We Collect

    We collect information in the following categories:

    • Account Information: Name, email address, organization name, and role when you create an account
    • Usage Data: Pages visited, features used, session duration, and interaction patterns
    • Decision Data: Scenarios, model inputs, outputs, and configurations you create within the platform
    • Integration Data: Data synchronized from connected systems (HRIS, ERP, etc.) as configured by you
    • Payment Information: Billing details processed securely through Stripe; we do not store full card numbers
    • Device and Log Data: IP address, operating system, access timestamps, and, depending on how you reach the Service, either your browser type (web) or your device model, operating system version, and app version (mobile)
    • Photographs, Files, and Documents: Images and files you choose to upload, such as a photograph attached to a safety hazard report or a document attached to an AI assistant conversation

    Section 2 describes in detail what the mobile app accesses on your device, what it sends to us, and what it does not collect.

    2. The DecisionLedger AI Mobile App

    We publish a mobile app, "DecisionLedger AI", for iOS and Android. The app is another way to reach the same account and the same workspace data described elsewhere in this policy. It is not a separate service, it does not create a separate account, and it does not collect a separate category of data for its own purposes. This section describes what the app accesses on your device and what leaves your device.

    2.1 Device Access the App Requests

    The app asks for each of the following at the moment you use the feature that needs it, never at launch. Declining any of them leaves the rest of the app working.

    • Camera: so you can photograph a workplace hazard as evidence on a safety report, or photograph something to place on a whiteboard. The camera is opened only when you tap a control that takes a photo. The app has no background camera access and does not record video or audio.
    • Photo library: so you can attach a picture you already have to a safety report, a whiteboard, or an AI assistant conversation. The app receives only the item you select in the system picker. It does not enumerate, index, or scan your library.
    • Files and documents: so you can attach documents to an AI assistant conversation, through the operating system's own file picker. The app receives only the files you select. Accepted types are PDF, DOCX, XLSX, CSV, TXT, Markdown, and images, limited to 5 files of 10 MB each per message.
    • Notifications: so we can tell you about work assigned to you. See section 2.3.
    • Face ID, Touch ID, or equivalent device biometrics: optional, and used only to unlock the app on your own device. See section 2.6.

    2.2 Photographs and Location Metadata

    Every photograph taken or selected in the app is re-encoded on your device before it is uploaded. Re-encoding writes a new image from the decoded pixels, so no EXIF metadata block survives, including the precise GPS coordinates that a phone camera embeds in a photograph by default. We therefore do not receive the location at which a photograph was taken.

    There is one exception, and it is a timestamp rather than a location. For a safety hazard photograph, the app reads the original capture time from EXIF before the re-encode and sends it as a separate field, because the interval between when a hazard was photographed and when the report reached us is part of the safety record. No other EXIF value is read or retained.

    Where a hazard occurred is recorded only from the site and location description you type into the report yourself.

    2.3 Push Notifications and Device Information

    If you allow notifications, the app obtains a push token from Expo, the service that delivers our mobile notifications, and registers that token with us together with your device's operating system, operating system version, device model, and the version of the app. We use this to route notifications to the right device, to show you which devices are registered, and to retire a token that is no longer valid.

    Notification payloads are content-free by default. A push carries a generic banner and an identifier; the app then fetches the actual content over an authenticated, encrypted connection. This is deliberate: a mobile push relays through Expo's servers and then Apple's or Google's, so the notification itself is not the place for the substance of your work.

    Signing out retires that device's push token, so a signed-out phone stops receiving another account's notifications.

    2.4 What the App Sends to Us

    • Account identity: your name, email address, and account identifier, read from the sign-in token issued by AWS Cognito
    • Workspace selection: the identifier of the workspace you are working in, sent with each request so the correct tenant's data is returned
    • Content you create or change: decisions, tasks, notes, whiteboards, safety hazard reports, AI assistant messages, and the photographs and files you attach to them. This is the same content the web application handles, described in section 1.
    • Electronic signature ink: when you sign a document in the app, we record the path your finger or stylus drew, meaning the position and timing of each point and, on hardware that reports it such as an Apple Pencil, the pressure. The ink is stored with the signed document and covered by its tamper-evident seal. It is evidence that the signature was drawn rather than pasted, and it is not used for any other purpose.

    All of this travels over HTTPS. The app has no unencrypted endpoint.

    2.5 What the App Does Not Collect

    • No location. The app contains no location library, requests no location permission, has no background location access, and receives no location from photographs (see section 2.2).
    • No advertising identifier, and no advertising. The app contains no advertising SDK, serves no advertisements, and does not read your device's advertising identifier. We do not sell or share personal data for advertising or cross-app tracking.
    • No third-party analytics or attribution SDK. The app embeds no analytics, attribution, or tracking library. The activity figures the app displays are computed by our own API from data already in your workspace.
    • No crash or diagnostic reporting. The app includes an error-reporting library, but it ships with no reporting endpoint configured, so no crash report, stack trace, or diagnostic event is transmitted from the app to anyone. If we enable this in a future release, we will update this policy before doing so.
    • No contacts, calendar, microphone, health, or fitness data. The app requests none of these and contains no code that reads them.

    2.6 Biometric App Lock and Screenshot Protection

    You may optionally require Face ID, Touch ID, a fingerprint, or your device passcode to reopen the app. The check is performed entirely by your device's operating system, which returns only a pass or fail result to the app. Your biometric data is never available to the app, never stored by us, and never transmitted. Only the fact that the lock is switched on is saved, and it is saved in your device's secure keystore.

    A related setting, on by default, asks the operating system to block screenshots and screen recording of the app and to hide its preview in the recent-apps switcher. This is a protection applied on your device; it sends us nothing.

    2.7 Data Stored on Your Device

    So the app remains usable without a connection, it keeps a local copy of data you have already viewed and queues changes you make while offline until they can be sent. Both are encrypted at rest on the device using AES-256, with the key held in the platform keystore (the iOS keychain or the Android keystore). Sign-in tokens and your workspace selection are held in the platform secure store and are deleted from the device when you sign out.

    2.8 Deleting Your Account from the App

    You can request deletion of your account and its associated data at decisionledgerai.com/account-deletion, which is linked from the Settings screen of the app and is also reachable without installing it. Retention and deletion timelines are described in section 6.

    3. How We Use Your Information

    We use your information to:

    • Provide, maintain, and improve the Service
    • Process your decision models and deliver analytics results
    • Manage your account, subscriptions, and billing
    • Send service-related communications and updates
    • Deliver notifications about work assigned to you, on the web and on mobile
    • Monitor platform performance, uptime, and security
    • Comply with legal obligations and enforce our Terms of Service

    4. Data Sharing and Third Parties

    We do not sell your personal data. We share data only with the following categories of service providers, under strict contractual obligations:

    • Amazon Web Services (AWS): Cloud infrastructure, compute, storage, and database services (us-west-2 region)
    • AWS Cognito: Authentication and identity management
    • Stripe: Payment processing and subscription management
    • PostHog: Product analytics (anonymized usage data only). Used by the website and web application; the mobile app contains no analytics SDK.
    • AWS Bedrock: AI language model inference (Claude models via AWS Bedrock) for assistant, evaluation, and narrative features. All AI processing runs within our AWS VPC - no decision data, model inputs, or AI-generated outputs leave the AWS cloud boundary. No customer data is stored or used for model training.
    • Expo: Mobile push notification delivery and over-the-air updates for the mobile app. Push tokens and the content-free notification banners described in section 2.3 pass through Expo on their way to Apple and Google; the content of your notifications does not.
    • Sentry: Application error monitoring and performance tracing. PII scrubbing enabled; only sanitized error metadata is transmitted. In the mobile app this library is present but has no reporting endpoint configured, so the app transmits nothing to it (see section 2.5).
    • Zoom: Video conferencing integration for committee meetings and board sessions. OAuth scope limited to meeting creation and participant management.

    If you configure external AI provider API keys (e.g., Anthropic, OpenAI) for optional cost reconciliation, the platform may contact those providers' usage APIs to retrieve aggregate token counts and billing metadata. No personal data, decision inputs, or model outputs are transmitted in these calls.

    We may also disclose information if required by law, subpoena, or governmental request, or to protect the rights and safety of DecisionLedger AI, our users, or the public.

    4.1 AI Model Training and Data Use

    We do not use customer data to train, fine-tune, or improve AI models. All AI inference is performed via Amazon Bedrock within our AWS VPC. No customer data - including decision inputs, model outputs, prompts, or completions - leaves the data boundary or is shared with model providers for training purposes. This applies to all AI features including the assistant, evaluator, narratives, and classification services, whether reached from the web application or the mobile app.

    5. Data Security

    We implement industry-standard security measures to protect your data:

    • Encryption at rest: AES-256 encryption for all stored data
    • Encryption in transit: TLS 1.2+ for all data transfers
    • Row-Level Security (RLS): Tenant isolation at the database level across all tables
    • Immutable audit logs: S3 Object Lock ensures audit trails cannot be altered or deleted
    • Access controls: Role-based access control with multi-tier permission levels
    • PII scanning: Automated detection and classification of personal data in model inputs
    • On-device encryption: Data cached on a mobile device, and changes queued while offline, are encrypted at rest with a key held in the platform keystore (see section 2.7)

    5.1 AI Assistant Data

    AI assistant conversations are stored encrypted at rest within your tenant's isolated data partition. Conversation content is subject to PII redaction before transmission to AI models. Users may apply per-conversation confidentiality policies:

    • Zero-Retention: Permanently deletes the conversation and all messages after the user-specified retention period (1–365 days)
    • Restricted Access: Limits access to the conversation owner only, with audit logging on every access

    No conversation content is used for AI model training. All AI inference runs via Amazon Bedrock within our VPC.

    6. Data Retention

    We retain your account information and decision data for the duration of your subscription. Following account termination, we retain data for 30 days to allow export, after which it is permanently deleted. Audit logs are retained according to your plan tier (30 days for Starter, 180 days for Professional, custom for Enterprise). Anonymized analytics data may be retained indefinitely for service improvement.

    AI assistant conversations are retained for the duration of your subscription unless you apply a per-conversation zero-retention policy, which permanently deletes the conversation and all messages after your specified retention period (1–365 days). Conversations marked with the "restricted" confidentiality policy are accessible only to the conversation owner and are excluded from any administrative access.

    7. Your Rights

    Depending on your jurisdiction, you may have the right to:

    • Access the personal data we hold about you
    • Request correction of inaccurate data
    • Request deletion of your personal data
    • Export your data in a portable format
    • Object to or restrict certain processing activities
    • Withdraw consent where processing is consent-based

    To exercise any of these rights, contact us at privacy@decisionledgerai.com, or, to request deletion of your account, use our account deletion page.

    8. International Data Transfers

    Our Service is hosted in the United States (AWS us-west-2 region). If you access the Service from outside the United States, your data will be transferred to and processed in the United States. We implement appropriate safeguards, including Standard Contractual Clauses where required, to ensure your data is protected in accordance with applicable law.

    9. Children's Privacy

    The Service is not intended for individuals under 16 years of age. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 16, we will take steps to delete it promptly.

    10. California Privacy Rights

    If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA/CPRA). For details on your rights and how to exercise them, please see our California Privacy Rights page.

    11. Data Processing Agreement

    For customers who require a formal data processing agreement, our Data Processing Agreement (DPA) describes our obligations as a data processor, sub-processor list, security measures, and breach notification procedures. Administrators may sign the DPA electronically through the Confidentiality Settings in the admin dashboard.

    11.1 HIPAA and Protected Health Information

    DecisionLedger AI operates as a Business Associate under HIPAA when processing data for healthcare Covered Entities. Customers who are HIPAA Covered Entities or Business Associates may execute a Business Associate Agreement (BAA) through the admin dashboard.

    When a BAA is in effect and the healthcare domain is enabled for your tenant:

    • All plugin executions enforce strict PHI detection covering the HIPAA Safe Harbor 18 identifiers
    • Automated breach detection monitors for unauthorized access patterns and alerts administrators
    • HIPAA-specific audit events are generated for every plugin execution in healthcare mode
    • Minimum data retention of 6 years applies per 45 CFR §164.530(j)
    • Session idle timeout is configurable (recommended: 15 minutes)
    • All data is encrypted at rest (AES-256) and in transit (TLS 1.2+)

    We do not use Protected Health Information to train AI models. All AI processing for healthcare tenants runs via Amazon Bedrock within our AWS VPC. For breach notification procedures, see our HIPAA Breach Notification Procedure document available upon request.

    12. Cookies

    We use cookies and similar technologies to operate the Service. For details on the types of cookies we use and how to manage them, please see our Cookie Policy. The mobile app uses no cookies or similar technologies for analytics, advertising, or cross-app tracking.

    13. Changes to This Policy

    We may update this Privacy Policy periodically. We will notify you of material changes by email or through the Service at least 30 days before they take effect. The "Effective" date at the top of this page indicates when the policy was last revised.

    14. Contact

    If you have questions or concerns about this Privacy Policy, please contact us at privacy@decisionledgerai.com.