Security & privacy
Last updated 27 September 2026
Two things matter when you trust a tool with real work: that your data is held carefully, and that the “debate” is genuine rather than theatre. This page answers both, directly and without spin.
Is my data private and secure?
Yes. Your data travels over TLS (encrypted in transit) and is stored encrypted at rest in the EU. Decidi says exactly what it keeps, never sells your content, and never uses your work to train AI models. We are also upfront about what we don’t yet have — there are no formal certifications like SOC 2 to imply.
Data security & privacy posture
Encryption
Everything you send to Decidi travels over TLS, so it is encrypted in transit. At rest, your account records, decision history and uploaded files are stored encrypted by our hosting provider. There is no point in the flow where your brief crosses the network in the clear.
Where your data lives
Account data, chat threads, councils and credit ledgers are stored in Supabase, hosted in the European Union region. Everything we keep, and the reason for each item, is listed in the privacy policy.
Files you upload
Files you attach — photos, screenshots, documents — are used to do the work you attached them to, and to build the deliverable from it later. The text of a document is kept with its decision or conversation; images are read for the run and not kept. They are not shared. Documents in your library are drawn on across your conversations until you remove them, and are erased when you do.
We do not train on your data
We do not use your content to train any model. We do not sell your prompts, files, transcripts or verdicts. They reach the model providers through their APIs, to return an answer, and are handled there under each provider’s own API terms.
Who else touches your data
We use established providers under their data-protection terms. The services that handle your data, and the only reason each one does:
- Frontier-model providers — OpenAI, Anthropic, Google and xAI, reached through the FastRouter gateway. They receive your chat messages, your brief, the text of what you attach and the relevant parts of your library and of what Decidi remembers about you, to return each contribution and the verdict. Perplexity, reached the same way, receives the brief for the live web research that grounds the facts which move. When you ask for a video, the request goes to a video model from ByteDance through the same gateway.
- Supabase — stores your account and everything listed above, in the European Union (eu-north-1), and signs you in.
- Vercel — hosts and serves the application.
- Sentry — receives error reports, so a fault is found and fixed. A report carries the error, the page and the model involved — not your briefs or verdicts.
- Google Analytics — measures page views and traffic sources so we can see how people find and move through the site. It never receives your briefs, transcripts or verdicts.
- Meta — the Meta pixel records that a visit happened, so we can tell which advertisements brought someone here. It never receives your briefs, transcripts or verdicts, and advertising signals stay switched off unless you accept them in the cookie banner.
- Lemon Squeezy — processes payments; it handles your card details so we never do.
- Resend — delivers the email we send you. A message telling you a run has finished quotes the opening of your brief, so you can tell which run it was.
- Twilio — carries the support phone line, and holds a voicemail if you leave one.
- Google sign-in — if you choose to sign in with Google, Google confirms who you are to us.
We do not sell or share your content with anyone else. We do run measurement tags — Google Analytics and the Meta pixel — so we can see which pages and which advertisements bring people here. They record that a visit happened; they never receive your briefs, transcripts or verdicts, and advertising signals stay switched off unless you accept them in the cookie banner.
Access controls
Access to production data is restricted to the small number of people who operate the service, and only when needed to run or support it. Authentication protects your account, and every request is scoped to the account that made it.
Payment security
Payments are handled by Lemon Squeezy, which acts as the merchant of record for Decidi — it is the seller on your receipt, charges in US dollars, and calculates, collects and remits any sales tax or VAT due in your country. Full card details never reach Decidi’s servers. Your card details are entered with the processor, not with us — full card numbers, CVV and PIN never touch Decidi’s servers. We receive confirmation that a payment succeeded, its reference and amount, and the status of your subscription; any billing details you enter for an invoice are kept with it.
Requesting deletion
You can remove a decision or a conversation from your history at any time. It leaves your account at once and its shared link stops working. A document you remove from your library is erased at once. Anything Decidi remembers about you that you remove is erased at once. To have a removed item erased from our systems, or to erase your whole account, email support@decidi.ai. We erase your decisions, conversations, documents and what Decidi remembers about you, and keep only the billing records the law requires us to keep.
Data retention
Your decisions, conversations and documents are kept in your account until you remove them, so you can reopen and download them. The text of an attached document is kept with the decision or conversation it belongs to. We hold the billing records the law requires, and nothing more than we need to run the service.
What we don’t yet claim
We’d rather be honest than impressive. Decidi is an early-stage product and does not currently hold formal security certifications — no SOC 2, no ISO 27001, no HIPAA. We will not imply compliance we don’t have. Formal certification and features like customer-managed retention and audit logging are on the roadmap as the product and customer base grow. If your use genuinely requires a specific certification today, tell us and we’ll be straight with you about where we are.
Model transparency
A debate is only worth something if the minds are actually distinct. Here is exactly how the Multi-Agent Team works under the hood.
Multiple distinct, live models
A council can include several different underlying models — real, live API models, not one model wearing different hats. They are accessed through the FastRouter gateway and assigned round-robin, so an N-mind debate genuinely spans different providers: OpenAI, Anthropic, Google and xAI. When four minds argue, you are typically hearing four different frontier models reason independently.
Every contribution is attributed
Each contribution shows which model produced it. Nothing is anonymised into a single voice — when GPT, Claude, Gemini or Grok speaks, the debate names it, so you can weigh a point knowing where it came from.
Personas are a lens, shown alongside the model
Personas are distinct expert system-prompts — a security red-teamer, a CFO, a devil’s advocate — layered onto a model to give it a deliberate point of view. The persona shapes the lens; the model does the reasoning. Both are shown together, so you always know that a given argument is, for example, the CFO lens running on one specific model.
The three levels map to model tiers
The depth you choose selects the calibre of models in the pool:
- Quick — fast, lively, low-cost models for brainstorms and first passes.
- Standard — strong reasoning models for everyday rigour, the sensible default.
- Deep — the flagship frontier models at full depth, for decisions that genuinely matter. Deep is a Pro feature.
Higher levels draw from more capable — and more expensive — models, which is why Deep sits on the Pro plan rather than being something you can pay a little extra for on a lower one.
Cost is metered from real usage
We do not invent a price. Decidi is sold as a plan and metered underneath: each run draws on the real token usage of the models that actually contributed, plus the orchestration and the audit we run on top. Your plan shows how much of the month is left, a build-out shows its estimate before you commit, and the charge reflects what was genuinely consumed — a run that produces no answer is not charged.
When a model is unavailable
If a model is briefly unavailable, the debate says so and continues with the rest of the council, rather than fabricating a response on that model’s behalf. A missing voice is shown as missing — we would rather give you an honest four-mind debate than a faked five-mind one. If the model appointed to chair or to audit cannot be reached, a model from another lab takes its place, and the page names the one that did the work.
Model outputs may contain errors, even when several models agree. Decidi is built to surface disagreement rather than hide it — where the minds diverge, you see the divergence, because that tension is often the most useful part of the decision. The verdict is a synthesis to think with, not a guarantee to act on.
Security & privacy questions
Is my data private and secure?
Yes. Your data travels over TLS (encrypted in transit) and is stored encrypted at rest in the EU. What we keep is listed in full in the privacy policy — your email, your conversations, the runs you make and their transcripts, the text of documents you attach, what Decidi remembers about you, and the usage needed to meter your plan — and we do not sell your content or use it to train models.
Does Decidi train AI models on my work?
No. We do not use your content to train any model. We do not sell your prompts, files, transcripts or verdicts. They reach the model providers through their APIs, to return an answer, and are handled there under each provider’s own API terms.
Where is my data stored?
Account data, decisions and credit ledgers are stored in Supabase in an EU region (eu-north-1). Payments are handled by Lemon Squeezy, which acts as the merchant of record for Decidi — it is the seller on your receipt, charges in US dollars, and calculates, collects and remits any sales tax or VAT due in your country. Full card details never reach Decidi’s servers.
Does Decidi have SOC 2 or ISO 27001 certification?
Not yet. Decidi is an early-stage product and does not currently hold formal security certifications such as SOC 2, ISO 27001 or HIPAA. We say so plainly rather than implying compliance we don’t have. Formal certification is on the roadmap as the product matures.
How do I delete my data?
You can remove a decision or a conversation from your history at any time. It leaves your account at once and its shared link stops working. A document you remove from your library is erased at once. Anything Decidi remembers about you that you remove is erased at once. To have a removed item erased from our systems, or to erase your whole account, email support@decidi.ai. We erase your decisions, conversations, documents and what Decidi remembers about you, and keep only the billing records the law requires us to keep.
Decidi is decision support, not regulated professional advice. For decisions that genuinely require a licensed lawyer, accountant or other professional, Decidi will tell you so — it is built to surface issues and sharpen your thinking, not to replace qualified advice where the law requires it.
See it for yourself
Start in chat — free, no card, no account. Bring in the specialists and the full Multi-Agent Team when a decision earns it.