Skip to content
Decipler
Privacy Terms Open the app

Legal & privacy

Privacy Policy

This policy explains what personal data Decipler handles, why it is needed, where it may be shared, and the choices available to you.

Effective date: July 19, 2026 • Version: Public Beta
Important privacy summary

If you sign in, your journal entries, protection settings, and custom website list are synced to your Decipler account. Community posts are shared with other users. Direct messages are visible to their participants. Your locally saved SOS contacts are not included in account sync.

On this page Who we are Data we handle How we use data Sharing and service providers Retention Your rights and deletion

1. Who we are

Decipler is a digital-boundary, journaling, community-support, and accountability service operated under the public project identity Decipler Project. The individual contributors behind the project are not publicly identified for safety and privacy. For privacy questions or requests, email [email protected].

This policy applies to decipler.com, the Decipler web app, Android app, Windows app, and related backend services.

2. Personal data we handle

Account and authentication data

We process your name, email address, optional nickname and profile photo, account creation and last-seen times, and authentication records. Passwords are stored as one-way salted hashes, not as readable passwords. When you use Google Sign-In, Decipler receives basic identity information such as your verified email address, name, and Google account identifier or token claims needed to authenticate you. We do not receive your Google password.

Device and technical data

We process a generated device identifier, device label, platform, browser or app user-agent information, theme and sync settings, session records, timestamps, and security or diagnostic information. Our infrastructure providers may also process IP addresses, request logs, and similar network data needed to deliver and protect the service.

Protection and activity data

When you are signed in, Decipler may sync selected protection categories, custom website domains, protection status, approval requests and reasons, and activity events. Activity events can include the event type, category, selected website or domain, protection changes, blocked attempts, timestamps, and limited journal metadata such as mood and word count.

Journal data

Journal entries—including their text, mood, category, word count, and timestamps—are stored on your device and synced to the Decipler backend when you use a signed-in account. Journal text is not posted to the community unless you separately choose to copy and publish it there.

Community, profile, and messaging data

Your nickname, profile photo, community posts, comments, and their timestamps may be visible to other Decipler users. Direct messages and their timestamps are available to the sender and recipient. Authorized administrators and hosting personnel may access stored content only when reasonably necessary for service operation, safety, abuse response, legal compliance, or technical support.

Information kept locally

Your SOS support-contact list and local activity history are saved in local app or browser storage and are not part of the current account-state sync. Android protection uses an on-device VPN interface to inspect website domain lookups for filtering; allowed DNS requests are currently forwarded to Cloudflare's 1.1.1.1 public DNS resolver, while Decipler does not route the rest of your internet traffic through a Decipler server. Windows protection stores a local block configuration and updates the Windows hosts file with administrator permission.

Support and voluntary communications

If you email us, we receive your email address and the information you include. If you voluntarily support development, we process the information needed to respond and coordinate that support. Decipler does not currently sell paid feature access through the app.

3. How and why we use personal data

We use personal data to:

  • create and authenticate accounts, including Google Sign-In and email verification;
  • sync journals, settings, custom website lists, and supported features across devices;
  • provide website protection, accountability approvals, progress information, community posts, and direct messages;
  • operate, secure, troubleshoot, and improve the public beta;
  • prevent misuse, enforce our Terms of Use, and respond to support requests; and
  • comply with applicable laws and protect users, Decipler, and others.

Depending on the activity and applicable law, processing is based on your consent, steps needed to provide the service you request, legitimate interests in operating and securing Decipler, or legal obligations. You may withdraw consent where consent is the applicable basis, but some features may then stop working.

4. How data is shared

We do not sell personal data or use it for third-party behavioral advertising. We may disclose limited data to:

  • Other users: community profile information, posts, and comments you publish; direct messages only to their participants.
  • Google: for Google Sign-In and, where enabled, delivery of verification emails through Google email services.
  • Cloudflare: for website delivery, domain routing, security, and resolution of allowed Android DNS requests through the 1.1.1.1 public resolver.
  • Railway and database infrastructure providers: for hosting the API, database, logs, and related service operations.
  • GitHub: for distribution of the Windows installer when you choose to download it.
  • Authorities or affected parties: when reasonably necessary to comply with law, respond to valid legal process, investigate abuse, or protect rights and safety.

These providers may process data in regions outside your own. We use providers for limited service purposes and remain responsible for handling personal data in accordance with applicable law.

5. Local storage, cookies, and external links

Decipler uses browser or app local storage for your session token, device identifier, theme, settings, locally cached journals, local activity, SOS contacts, and other app state. Google Sign-In and infrastructure providers may use cookies or similar technologies needed for authentication, security, and delivery. Decipler does not currently include third-party advertising trackers.

The app links to external recovery resources and hotlines. Their privacy practices are governed by their own policies, and Decipler does not control those sites.

6. Data retention

  • Email verification codes are held temporarily and normally expire after 10 minutes.
  • Normal app sessions expire after approximately 30 days and may be revoked sooner when you log out.
  • Account data and synced content are generally retained while your account is active and for as long as reasonably needed to provide, secure, and document the service.
  • Provider logs and backups may remain for a limited period under the provider's operational retention schedule.

When a valid deletion request is completed, we will delete or de-identify account data that is no longer needed, subject to legal, security, fraud-prevention, dispute, backup, and recordkeeping requirements. Community content may be de-identified where deletion would otherwise disrupt conversations involving other users.

7. Security

We use reasonable technical and organizational safeguards, including HTTPS in transit, one-way password hashing, hashed server-side session tokens, application-level encryption for stored journal content and direct messages, access-controlled administration, and limited production API configuration. No online service is completely secure, especially during beta testing. Keep your device and account credentials secure, and contact us promptly if you suspect unauthorized access.

8. Your choices, rights, and account deletion

Subject to applicable law, you may ask to access, correct, obtain a copy of, object to certain processing of, or delete or block your personal data. You may also withdraw consent where processing relies on consent and lodge a complaint with the data-protection authority that applies to you.

To request account and data deletion, email [email protected] using your registered email address with the subject Delete my Decipler account. We may ask for reasonable verification before acting to protect your account. You can remove local-only data by clearing Decipler's app/browser storage or uninstalling the app, but doing so does not automatically delete synced server data.

9. Children and younger users

Decipler is not designed for children under 13. Users under 18 should use Decipler only with the involvement and permission of a parent or legal guardian. Do not submit another person's sensitive information without authority to do so.

10. Changes to this policy

We may update this policy as the beta changes. Material updates will be posted on this page with a revised effective date and, when appropriate, an in-app notice. Continued use after an update is subject to the revised policy, but we will request consent again when required by law.

11. Contact

Privacy contact and data-request channel: [email protected]
Website: https://decipler.com
Public operator identity: Decipler Project

Return to Decipler Read Terms of Use
Decipler

Privacy Policy · Terms of Use · Contact

2026