PRIVACY POLICY Last updated: August 25, 2026 1. WHO CONTROLS DECODE DATA This Privacy Policy explains how Said Mabchour, an individual operating DeCode from Morocco (“DeCode,” “we,” “us,” or “our”), collects, uses, shares, stores, protects, and deletes personal information in connection with the DeCode software. DeCode is the product and brand name of the service. It is not represented as a separate incorporated company unless accurate incorporation information is later published and used consistently. Privacy contact: hello@decodeai.net 2. SCOPE This Policy applies to personal information processed through: - https://decodeai.net; - DeCode accounts; - AI chat and coding assistance; - image generation; - voice and realtime features; - file and web-assisted tools; - the Roblox Studio Assistant; - subscription and billing access; - support and reporting channels; - safety and abuse systems; and - connected-service features when enabled and deliberately authorised. This Policy does not replace the privacy notices of third parties, including Creem and external AI, identity, hosting, or sign-in providers. 3. ELIGIBILITY AND AGE-RELATED INFORMATION DeCode may record information needed to confirm eligibility to use the service, such as an age-eligibility confirmation, the applicable policy version, and the time of confirmation. DeCode does not ordinarily require a government-issued identity document or facial scan solely to create a normal DeCode user account. Creem may separately perform merchant, business, representative, beneficial-owner, identity, tax-residency, bank-account, and compliance verification for the DeCode operator during Creem onboarding or account review. Creem controls that merchant-verification process under its own Privacy Notice and Merchant Terms. It is separate from ordinary DeCode user registration and does not mean DeCode requires those records from ordinary users. 4. ACCOUNT INFORMATION PROVIDED BY USERS DeCode may process: - name; - email address; - profile image; - authentication provider; - language and locale; - interface preferences; - signup reason; - eligibility confirmation; - account status; - subscription or entitlement status; and - user-selected settings. 5. USER CONTENT User Content may include: - prompts and messages; - conversation history; - uploaded files; - uploaded and generated images; - generated files; - code and scripts; - Roblox project context; - voice input and transcripts; - realtime conversation content; - tool instructions; - feedback; - information deliberately supplied through an enabled connector; and - other content deliberately submitted by the user. 6. SUPPORT, SAFETY, AND LEGAL INFORMATION DeCode may process support messages, refund requests, cancellation requests, privacy requests, abuse reports, copyright or trademark complaints, explanations, relevant attachments, Creem order or Transaction references, security information, enforcement appeals, and communications with DeCode. Users should not send full payment-card numbers, card security codes, passwords, API keys, recovery codes, or unnecessary identity documents to DeCode support. 7. AUTOMATICALLY COLLECTED INFORMATION DeCode and its Providers may automatically process: - IP address and network information; - browser and operating-system information; - device type and user agent; - locale, language, and time zone; - session and authentication activity; - request identifiers; - selected model, feature, and reasoning settings; - token or Credit usage; - image usage; - voice or realtime duration; - tool activity; - timestamps; - rate-limit information; - error and diagnostic data; - security and abuse events; - policy-consent records; and - approximate region inferred from network or infrastructure information. DeCode does not ordinarily require precise GPS location for normal service use. 8. AUTHENTICATION DeCode may use Firebase Authentication and related Google infrastructure. Depending on the selected sign-in method, Google, Microsoft, or another identity provider actually shown in the current sign-in interface may process the sign-in request. DeCode may receive an account identifier, name, email, profile image, verification status, and sign-in-provider information. Authentication providers process information under their own terms and privacy policies. DeCode may store limited access and security claims needed to distinguish an ordinary user from an operator or authorised product or billing tester. Public registration is not limited to that tester list. DeCode may still block an account that fails eligibility, security, abuse, or legal checks. Email and verification codes An email-and-password signup may generate an email-verification link. Login, deletion, password reset, or another sensitive action may use a short-lived email link or six-digit code. DeCode stores a protected representation of a code, its creation and expiry times, the number of failed attempts, and the account and email needed to verify the request. Current login and deletion codes expire after ten minutes and are limited to five incorrect attempts. Email verification and login-code sending are also subject to rate limits. Passkeys For eligible email-and-password accounts, DeCode may store a passkey credential identifier, public key, signature counter, device or password-manager name, supported transports, backup status, and created and last-used times. The private key remains with the user’s device or password manager. A local biometric or device-unlock method is handled by that device or platform; DeCode does not receive or store a biometric template. Registration and sign-in challenges are short-lived and are deleted or invalidated after use or expiry. Authenticator app DeCode supports time-based one-time-password multi-factor authentication through Firebase for accounts with a verified email address. During setup, Firebase and the user’s chosen compatible Authenticator app process the QR code or manual secret and current six-digit code. DeCode may receive factor identifiers, display information, enrolment time, and multi-factor status needed to show and manage the factor. A current Authenticator code and re-authentication may be required before adding or removing a security method. Device sessions DeCode may keep an account-session record containing a random installation identifier, browser, operating system, device type and name, locale, time zone, user agent, coarse location derived from infrastructure headers or time zone, authentication time, status, and last-active time. This allows the user to review active sessions and disconnect a device or all devices. A disconnected session must sign in again. Memory Memory is a General Chat setting that stores a bounded summary of durable information such as preferences, recurring goals, ongoing projects, and working style. It is enabled by default for a new account. When enabled, relevant parts of the summary may be sent with a General Chat request and the AI may propose a revised summary. Memory is not used by the Roblox Assistant or other tool-driven requests in the current Product. The user can view, edit, clear, save, or turn Memory off in Settings. When it is off, DeCode does not read or update the summary, but the existing summary remains stored until the user clears it or deletes the Account. Memory is not intended to contain passwords, authentication secrets, payment information, precise financial or health information, or other highly sensitive information. DeCode asks the AI not to infer or save such information, but users should still review the summary and remove anything they do not want retained. 9. AI CHAT AND CODE PROCESSING To provide a requested AI response, DeCode may send the current prompt and relevant context to the selected AI Provider. This may include relevant conversation history, system and safety instructions, model settings, files or images needed for the request, code or project context, tool context, formatting preferences, and limited technical metadata. External AI Providers process information under their own agreements, API settings, retention controls, security measures, and legal obligations. Different Providers may apply different retention or model-improvement practices. Users should avoid submitting confidential, personal, copyrighted, biometric, or sensitive information unless they are authorised to do so and the information is necessary for the requested feature. 10. IMAGE GENERATION DATA When image generation is used, DeCode may process image prompts, uploaded reference images, selected settings, generated images, moderation classifications, Provider request identifiers, usage records, and reporting or enforcement information. When image generation is enabled, DeCode’s server sends the raw user-supplied image prompt to Creem’s Moderation API before calling the image-generation Provider. The request body contains the prompt and a non-sensitive internal generation identifier in Creem’s optional external_id field. It does not include the DeCode Account identifier. DeCode does not send uploaded reference images or generated image bytes to that Creem moderation endpoint. Creem returns a moderation-result identifier, the echoed prompt and external identifier, an “allow,” “flag,” or “deny” decision, and usage information. DeCode uses the decision to allow further safety checks or block the request. DeCode stores a server-only verification record containing the moderation environment, endpoint host, credential class, Creem moderation-result identifier, internal generation identifier, decision, and time. The verification record does not contain the prompt or API key. This server-side moderation data flow is separate from Creem’s checkout and Merchant-of-Record processing. Image generation is subject to DeCode safety rules, AI-provider rules, and applicable payment-partner requirements. The feature is not intended for face swaps, deceptive deepfakes, unauthorised likeness use, impersonation, non-consensual imagery, or intellectual-property infringement. Otherwise safe image generation may depict clearly fictional, generic, or invented human characters. DeCode’s image-identity controls are designed to block requests involving a recognizable real person’s face or likeness, face swaps, deepfakes, face manipulation, identity transfer or preservation, deceptive impersonation, and related harmful uses. 11. VOICE AND REALTIME DATA When voice or realtime features are used, DeCode and the selected Provider may process microphone audio, transcripts, conversation context, selected synthetic voice, generated audio, session identifiers, session duration, usage records, errors, and safety findings. DeCode does not provide a feature intended to create a reusable clone of a real person’s voice. Provider-side audio retention may depend on the Provider, feature, account configuration, and applicable agreement. 12. VIDEO GENERATION Video generation is not part of the public paid service unless DeCode updates its product description, Provider disclosures, safety controls, Privacy Policy, Terms, Acceptable Use Policy, and payment-compliance information before launch. 13. ROBLOX STUDIO ASSISTANT When the Roblox Studio Assistant is used, DeCode may process user instructions, code, scripts, selected project context, plugin or bridge session information, tool results, errors, usage records, and safety findings. The feature is intended for projects the user owns or is authorised to modify. 14. FILES AND WEB-ASSISTED TOOLS When a user uploads a file or asks DeCode to perform a web-assisted task, DeCode may process the file, selected portions of it, extracted text or metadata, the user’s instructions, tool results, citations, and technical information needed to complete the request. Users are responsible for ensuring that they have a lawful basis and sufficient rights to submit files or other information for processing. 15. CONNECTED SERVICES Some connector interfaces may appear as “in development,” “coming soon,” or unavailable. A Provider name appearing in the interface does not necessarily mean the connector is active. Before an active connector accesses third-party data, DeCode should require authentication, identify the Provider, show requested permissions where supported, require deliberate user authorisation, and provide a disconnection method where supported. Connected Providers independently process information under their own terms and privacy policies. 16. CREEM CHECKOUT AND BILLING Eligible DeCode purchases completed through Creem are processed by Armitage Labs OÜ (“Creem”) as Merchant of Record and contractual reseller. Creem enters into the resale Transaction with the Buyer, collects and processes the payment, issues the Buyer invoice, handles applicable indirect transaction taxes, and provides related payment administration. Information entered into Creem’s Checkout Solution is provided directly to Creem. Under Creem’s current Privacy Notice, Creem may process Buyer and Transaction information such as: - customer name; - billing email; - billing address; - payment details; - order details; - IP address, device identifiers, and related checkout log or device information; and - Creem Customer Portal account and communication information where those services are used. Creem may disclose Buyer information to its payment service providers and other recipients described in its Privacy Notice. DeCode does not select or make claims about Creem’s payment-provider subprocessors through this Policy. DeCode does not intentionally receive or store complete payment-card numbers, card security codes, or payment-account credentials entered in Creem’s Checkout Solution. Creem and the payment service providers it uses process those payment details within their own systems. 17. BILLING DATA RECEIVED BY DECODE To connect a completed Creem purchase to the correct DeCode Account and manage the Product, DeCode may receive or store a limited subset of Creem checkout, API, dashboard, or webhook information, such as: - the DeCode Account or request reference used to associate the purchase; - Creem customer, checkout, order, Transaction, subscription, product, price, refund, or dispute identifiers where present; - customer email, name, or country where Creem includes them in a checkout or subscription event; - selected Product or Paid Plan; - order or Transaction amount, amount paid or refunded, currency, tax amount or tax country where present, and payment status; - subscription status, billing period, renewal, scheduled-cancellation, cancellation, pause, trial, or expiry state; - refund or dispute status and reason where present; and - webhook event identifier, type, mode, and timestamps. DeCode may use this information to activate paid access, assign Credits, prevent duplicate benefit grants, show subscription status, support cancellation, investigate payment problems, assist with refund requests, prevent fraud, maintain records, and reconcile Creem billing state. DeCode does not need complete payment credentials for those purposes and does not claim to receive every field Creem may process. The fields actually retained should be limited to what the deployed integration needs for entitlement, support, fraud prevention, reconciliation, and legal or accounting obligations. Redeem codes and Credit records When a user submits a redeem code, the browser sends it to an authenticated server function. DeCode normalises the code and looks up a SHA-256 hash rather than permitting the client to read the redeem-code collection. For a successful redemption, DeCode records the Account, Credit amount, one-time redemption status and time, and a ledger entry, then updates the Account’s purchased-Credit balance. It also keeps the amount redeemed in the Account’s cumulative Credit record. An invalid, inactive, or already-used code does not change the balance. Each code can be redeemed once across all Accounts. The service does not currently use the redeem-code record itself to identify a named recipient, and it does not automatically prevent the same Account from redeeming a different valid code. Redeemed Credits are internal usage units, not payment credentials or cash. Their records may be used for balance accuracy, fraud and campaign-abuse prevention, support, accounting of Product usage, and enforcement. 18. CREEM AND DECODE DATA-PRIVACY ROLES DeCode controls personal information it processes to operate DeCode Accounts, deliver and support the Product, manage entitlements, maintain its limited billing references, and fulfil DeCode’s own legal obligations. Creem’s Privacy Notice states that Creem may act as a controller, a joint controller with a Merchant, or a processor on a Merchant’s behalf, depending on the particular processing purpose. Creem acts in its own Merchant-of-Record and Buyer-contract roles when it runs the Checkout Solution and Customer Portal, processes payments, issues invoices, handles indirect taxes, prevents financial crime or fraud, manages Transactions, and fulfils its own accounting, regulatory, dispute, and legal obligations. Creem’s DPA applies only where Creem processes specified personal data on DeCode’s behalf as processor. Its current annex describes Merchant sub-account user data and Buyer name, email address, and IP address for AI-based statistics. This Policy does not treat the DPA as applying to all payment, tax, invoice, fraud, or Merchant-of-Record processing and does not assign Creem one privacy role for every activity. Creem’s current Privacy Notice is available at https://www.creem.io/privacy and its DPA at https://www.creem.io/dpa. Deleting a DeCode Account does not automatically delete information Creem controls, jointly controls, or must retain under its own legal obligations. Creem applies the retention rules described in its Privacy Notice according to the relevant data and processing purpose. 19. CREEM CUSTOMER SERVICES AND SUPPORT Creem provides a Checkout Solution and Customer Portal as its “Customer Services.” Following a successful purchase, Creem may provide the Buyer access to the Customer Portal to manage supported subscription, payment-method, personal-information, invoice, and support actions. DeCode may receive or provide limited Product information reasonably necessary to resolve a technical issue, refund investigation, cancellation problem, fraud issue, or payment dispute. 20. SAFETY MODERATION DeCode may use automated and Provider-based moderation systems to evaluate supported prompts, image requests, uploaded images, voice instructions, code requests, requested actions, account patterns, and limited technical metadata. A meaningful safety flag may contain an account identifier, timestamp, request identifier, policy category, estimated severity, flagged user-submitted content or excerpt, feature involved, enforcement status, and limited technical metadata. Normal conversations are not routinely sent to the DeCode operator for manual review merely because they exist. A flagged case may be reviewed by an authorised administrator when reasonably necessary to investigate a report, harmful output, moderation failure, intellectual-property complaint, security incident, fraud, or legal obligation. 21. PURPOSES OF PROCESSING DeCode may process personal information to: - create and secure accounts; - authenticate users and maintain sessions; - provide and manage passkeys, multi-factor authentication, verification codes, login alerts, and session-revocation controls; - provide requested AI, image, voice, file, web, Roblox, and connected-service features; - store history and Memory where enabled; - meter usage and enforce Credits; - validate one-time redeem codes and maintain accurate Credit balances; - activate and administer subscriptions; - provide billing access; - handle support, cancellation, refund, privacy, and abuse requests; - detect and prevent fraud, security incidents, and policy abuse; - moderate content and enforce policies; - diagnose failures and improve reliability; - communicate account, billing, security, or policy messages; - comply with law; and - establish, exercise, or defend legal claims. 22. LEGAL BASES Depending on the user’s location and the activity involved, DeCode may rely on performance of a contract, legitimate interests in operating and securing DeCode, consent where required, compliance with legal obligations, and protection of users, rights, and systems. Where consent is required for a particular optional feature or non-essential tracking technology, DeCode will request that consent before the relevant processing where required by law. 23. SERVICE PROVIDERS DeCode may use categories of Providers including: - Google Firebase and Google Cloud for authentication, hosting, databases, storage, server functions, security, and operational logs; - external AI Providers for chat, reasoning, coding, image generation, speech processing, synthetic voice, and realtime interaction; - Cloudflare or similar security Providers for anti-bot, network, and security controls; - Creem for Merchant-of-Record checkout, payment, indirect-tax, invoice, refund, dispute, subscription, Customer Portal, related support, and pre-generation image-prompt moderation when image generation is enabled; - email Providers for verification, password reset, account, billing, security, and support messages; and - user-authorised connector Providers where a connector is active and deliberately authorised. The exact Provider list may change as DeCode’s infrastructure changes. Material privacy-impacting changes will be reflected in this Policy where required. 24. DATA SHARING DeCode does not sell ordinary user personal information for money and does not intentionally share ordinary account information with advertising networks for behavioural advertising. DeCode may share information: - with Providers necessary to deliver a requested feature; - with Creem for Transaction, subscription, indirect-tax, invoice, refund, dispute, fraud-prevention, Customer Services, billing matters, and the limited image-prompt moderation described in Section 10; - with an authorised reviewer for a flagged safety case; - with professional advisers where reasonably necessary to protect legal rights; - in response to valid legal process; - to prevent fraud, security incidents, exploitation, or serious harm; - during a lawful business transfer; or - at the user’s direction. 25. MARKETING If DeCode sends optional marketing communications, it will provide any consent or opt-out controls required by applicable law. Creem may separately process marketing information under the legal bases and controls described in its own Privacy Notice. DeCode will not treat Creem Transaction data as permission for unrelated DeCode marketing where separate consent is required. 26. COOKIES AND BROWSER STORAGE DeCode may use cookies, local storage, session storage, service-worker caches, authentication tokens, and device/session identifiers to support authentication, security, preferences, checkout access, and core application functions. Creem may use its own cookies, payment tokens, log data, device data, and similar technologies when a user opens Creem’s Checkout Solution, Website, or Customer Portal. More details appear in Creem’s Privacy Notice at https://www.creem.io/privacy. DeCode’s Cookie Policy describes the technologies used on DeCode-controlled pages and should not be read as controlling Creem’s separate interfaces. 27. DATA RETENTION Retention depends on the purpose and the system involved. Typical DeCode retention may include: - account profiles, conversations, files, generated content, preferences, and usage state while the Account exists, unless deleted earlier where controls are available; - Memory while the Account exists, including while Memory is switched off, unless the user clears it earlier; - active passkey and Authenticator factor records until the user removes the factor or deletes the Account, subject to Provider records and security retention; - device-session records while needed to show activity, recognise revocation, investigate security incidents, or operate the Account; - redeem and Credit-ledger records while the Account or the underlying code record is needed for balance integrity, one-time enforcement, support, fraud prevention, or legal claims; - safety records ordinarily up to 180 days, unless needed longer for repeated abuse, investigation, dispute, security, or law; - support, refund, cancellation, privacy, copyright, and abuse records for a reasonable period after closure; - short-lived verification codes until expiry; - billing references and financial records for the period required by accounting, fraud, dispute, payment, and legal obligations; and - logs and backups according to Provider rotation and backup schedules. Information may be retained longer where reasonably necessary for fraud, security, legal claims, legal holds, or compliance. Creem and other Providers apply their own retention rules to information they control. Creem’s published retention rules are described in its Privacy Notice and may differ according to whether the data is contractual, accounting, customer-due-diligence, dispute, or other data. 28. ACCOUNT DELETION Where available, users may delete a DeCode Account through account settings. Deletion may require re-authentication or another ownership check. The current flow requires the exact confirmation phrase “DELETE ACCOUNT.” An email-and-password account must also verify its current password. An account using another sign-in provider must enter a six-digit code sent to the account email within ten minutes and before the attempt limit is reached. After successful confirmation, DeCode disables the Account while deletion is running, revokes DeCode sessions and Firebase refresh tokens, deletes the Firebase authentication account, and removes DeCode-controlled profile, Memory, preferences, session, connector, conversation, message, project, generated-content, stored-file, Credit, operational billing-profile, order-reference, refund-reference, support-request, and related account records included in the deletion process. Deleting a DeCode Account does not automatically cancel a Creem subscription or close the Buyer’s separate Creem Customer Portal account. The user should cancel an active subscription and verify its status before deleting the Account. The deletion process covers DeCode-controlled operational records associated with the Account. It does not delete Creem-controlled records. DeCode may also retain or segregate the minimum record it is required to keep for billing, accounting, tax, refund, dispute, fraud, security, backup, enforcement, or legal reasons. Deletion is therefore not a promise that every record held by DeCode, Creem, or another Provider will be erased immediately or at the same time. 29. USER RIGHTS Depending on applicable law, users may have rights to request access, correction, deletion, restriction, objection, withdrawal of consent, portability, or to complain to a data-protection authority. DeCode may verify account ownership before fulfilling a privacy request. Requests may be sent to hello@decodeai.net. Rights relating to information Creem controls should also be exercised directly with Creem where appropriate. Creem’s Privacy Notice lists support@creem.io as its privacy contact. Where Creem acts as DeCode’s processor for a particular request, Creem’s DPA provides for the request to be handled through DeCode as controller. 30. SECURITY DeCode may use authenticated access, Firebase security rules, server-side secrets, signed Creem webhook verification, event deduplication/idempotency controls, rate limits, restricted storage paths, session controls, content moderation, abuse reporting, and limited administrator access. Redeem-code records are server-only, and the stored code identifier is a hash. Email and deletion verification codes are stored as protected representations and compared using server-side checks. Passkey private keys and device biometrics remain outside DeCode. No online service can be guaranteed completely secure. Users should use strong authentication practices and should not share passwords, API keys, recovery codes, or sensitive billing credentials. 31. CREEM WEBHOOK AND API DATA Creem’s official webhook service can send checkout, subscription, refund, and dispute events to a Merchant server. Those payloads may contain the limited customer, checkout, order, Transaction, Product, subscription, refund, dispute, status, amount, currency, country, period, and event information described in Section 17. Creem APIs may make corresponding customer, order, Transaction, subscription, and Customer Portal information available to an authenticated Merchant. DeCode should verify Creem webhook signatures before processing an event and may store the minimum event identifiers and state needed to determine entitlement, prevent duplicate grants, reconcile duplicate or out-of-order events, and support billing issues. DeCode does not need to store the entire webhook payload for those purposes. 32. INTERNATIONAL PROCESSING DeCode and its Providers may process information in Morocco, the United States, the United Kingdom, the European Economic Area, and other countries where Providers or subprocessors operate. Those countries may have different privacy laws. Where required, appropriate contractual, legal, or organisational safeguards may be used for international transfers. 33. AUTOMATED DECISIONS AND SAFETY CONTROLS Automated systems may block or restrict a prompt, image request, voice instruction, code request, tool action, suspicious account activity, or payment-related benefit grant. Serious account-level enforcement decisions may be reviewed by an authorised human administrator where reasonably available and appropriate. DeCode is not intended to provide automated high-impact decisions about people in employment, credit, housing, insurance, medical access, or similar regulated contexts. 34. CHILDREN AND MINORS Where DeCode is operated as an 18+ service, it is not knowingly designed or marketed for minors. If DeCode reasonably believes that an Account is operated by a person who does not satisfy the stated eligibility requirement, it may restrict or close the Account and handle the associated data in accordance with applicable law. 35. CHANGES TO THIS POLICY DeCode may update this Policy when features, Providers, payment arrangements, safety practices, data flows, or law changes. Material changes will be communicated where required. The Legal Center should display the current version and effective or “Last updated” date. 36. CONTACT Operator: Said Mabchour Product: DeCode Country: Morocco Privacy and support email: hello@decodeai.net Website: https://decodeai.net