This Privacy Policy explains how Decisive (“Decisive”, “we”, “us”, or “our”) collects, uses, shares, and protects information when you use our website at wemachines.com, our application at app.wemachines.com, and related features (together, the “Service”). It works alongside our Terms of Service.
In short: your team’s content is yours. We process it to run the workspace and the features you choose to use, we rely on a small set of trusted providers to do that, and we don’t sell your data.
1. Information we collect
Account information
When you sign up, we collect your email address (used to identify your account) and basic profile details you provide, such as a display name, avatar and banner image. We do not store passwords: sign-in is passwordless, using either a one-time code sent to your email or your Google account.
If you choose “Continue with Google”, Google confirms your identity to us and shares your email address and basic profile information (such as your name and profile picture). We never receive your Google password, and signing in asks for nothing beyond that basic profile. Google Calendar is the only other Google service we ever request, it is entirely optional, and it is requested only if you connect it yourself in Settings → Google (see “Google Calendar integration” below). We never request your Gmail, your Drive, or your files. Google’s own handling of that sign-in is governed by its privacy policy; you can review and revoke Decisive’s access at any time in your Google account settings.
Workspace content
We store the content you and your team create in a workspace, including chat messages, tasks, documents, discussions, comments, reactions, and uploaded file attachments. This content is provided by you and shared with the members of your workspace.
Integration data
If you connect integrations, we process the data needed to make them work. For GitHub, this includes repository content and metadata accessed under the permissions you grant. For Slack, this includes the messages in channels the bot has been invited to when it is mentioned there, and the Slack profile email used to match a Slack account to a member of your workspace - see “Slack integration” below. For Google Calendar, this includes the events on the calendar you connect - see “Google Calendar integration” below. If your workspace provides its own AI provider API key, we store it encrypted and use it to make AI requests on your behalf.
Billing information
When you subscribe to a paid plan, payment is processed by our payment provider, Stripe. Stripe collects and processes your payment details (such as card or other payment information) and billing address directly; we do not receive or store full payment card numbers. We receive limited billing records from Stripe, such as your plan, subscription status, the last digits and type of your payment method, and invoices, so we can manage your subscription.
Voice, video & transcripts
When you use huddles or the voice AI agent, we and our real-time communication providers process audio and video streams, and may generate captions, transcripts, and synthesized AI voice as part of the feature.
Usage, device & log data
Like most online services, we and our providers automatically collect technical information such as IP address, browser and device type, pages and features used, timestamps, and diagnostic logs. We use this to operate, secure, debug, and improve the Service. For the same purposes we use product analytics, which record which pages and features are used.
We do not use session replay. Our analytics record which pages and features are used, not a reconstruction of your screen. We previously did use session replay, and stopped on August 14, 2026: a replay reconstructs the page as it appeared to you, so it could include your workspace's content and the names of people in it, and the person who agreed to analytics in their browser is not the person that content belongs to. All recordings made before that date have been deleted at our analytics provider.
Cookies & local storage
We use browser storage (local storage and IndexedDB) to keep you signed in, remember preferences, and support offline and real-time editing of documents. Your sign-in session is held in local storage, not in a cookie. We do not use third-party advertising cookies and we do not track you across other websites.
One cookie needs your permission, and it is the analytics described above: PostHog stores an identifier so repeat visits count as one person rather than many. We ask before setting it, and nothing is set until you accept - decline and analytics never start. A second cookie records that answer so you are not asked again; it holds nothing but your choice and is set either way. Both are set on wemachines.com, so one answer covers the marketing site and the app, and your choice is remembered for six months.
The remaining cookies are strictly necessary, so they are not part of that choice and cannot be used to identify you elsewhere: a short-lived cookie that stops the GitHub and Spotify connection flows from being hijacked, and, where your workspace runs an app, a cookie on that app's own address that tells the app who you are. Neither can be read by page scripts.
You can change your mind at any time: use at the bottom of any page here, or Settings → Profile → Analytics in the app. Turning analytics off also clears what has already been stored in your browser. Blocking cookies in your browser works too, though the sign-in and editing features above rely on browser storage and will not work without it.
Booking a call loads Calendly, and the sign-in screen loads Cloudflare Turnstile to tell people from bots. Both are third parties that may set their own cookies, and both load only at the moment you use them.
2. How we use information
- to provide, maintain, and operate the Service and its features;
- to authenticate you and keep your account and workspace secure;
- to power AI features you use, including generating responses, summaries, and code changes;
- to enable integrations you connect, such as GitHub, Slack, and Google Calendar;
- to respond to support requests and communicate with you about the Service;
- to monitor, debug, prevent abuse of, and improve the Service; and
- to comply with legal obligations and enforce our Terms.
Where required by law, we rely on the following legal bases: performance of our contract with you (to provide the Service), our legitimate interests (to secure and improve the Service), your consent (where requested), and compliance with legal obligations.
3. AI processing
When you use AI features, relevant workspace content is sent to AI providers to generate a response, and, for voice features, to speech-to-text and text-to-speech providers. AI requests are routed through OpenRouter, our AI gateway, to the model's own provider. Decisive's built-in AI runs on models we select (from Anthropic); a workspace admin or member may point specific features - coding runs, app builds, what an AI teammate thinks with - at another model from the catalog, in which case content for those features is sent to that model's provider instead, and the picker names who that is. We do not use your content for AI training, and we rely on our AI providers' commitments not to train their models on data submitted through their business APIs.
4. Code & repository data
If you connect a GitHub repository, our build and coding-agent features may clone your repository into a secure cloud environment to run, edit, preview, and propose changes, and may send relevant code to AI providers to generate those changes. Proposed changes are delivered as pull requests for your review. Your source code remains in your own GitHub repository, and you can disconnect the integration at any time.
5. Slack integration
If a workspace admin connects Slack, we store your Slack team’s id and name, the bot’s user id, the granted scopes, and an access token for the bot - encrypted at rest, and readable only by our servers. When someone mentions the bot in a channel it has been invited to, we receive that mention and the surrounding messages (the thread, or the last few messages in the channel), together with the Slack profile email of the person asking, which is used to match them to a member of the connected workspace. That content is processed to answer or to file a task, including by sending it to our AI providers, and is not stored by us beyond what the bot writes into your workspace - such as a task it creates - which is then workspace content like any other.
The bot only ever sees channels it has been explicitly invited to; it cannot enumerate or read the rest of your Slack workspace, direct messages, or files. How much of your Decisive workspace it may say back out in Slack is an admin setting that starts at nothing. Disconnecting it in Settings → Slack revokes the token and deletes the connection. Slack’s own handling of the messages and profile data in your Slack workspace is governed by Slack’s privacy policy and your agreement with them.
6. Google Calendar integration
Connecting Google Calendar is optional and is never requested at sign-in. If you connect it
in Settings → Google, we ask Google for a single scope, https://www.googleapis.com/auth/calendar.events, which lets
us view and manage events on your calendar and nothing else. We do not request access to
your Gmail, your Drive, your contacts, your files, or your calendar’s sharing and account
settings. The resulting access and refresh tokens are stored encrypted at rest and are
readable only by our servers.
We use that access only to carry out what you ask your AI teammates to do: read your upcoming events, work out when you are free, and create, update or cancel an event on your behalf. To do that, the relevant event details are sent to our AI providers to generate the response, exactly as described in “AI processing” above. We do not copy your calendar into our database, and we do not read it in the background. Disconnecting in Settings → Google deletes the stored tokens; you can also revoke access at any time from your Google account settings.
Limited Use. Decisive’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google user data - raw, aggregated, or derived - to develop, improve, or train generalized or foundational artificial intelligence or machine learning models, and the AI providers that process it are bound by their business-API commitments not to train their models on it either. Google user data is used solely to provide and improve the calendar features you have chosen to use, is never sold, and is never transferred or used for advertising.
7. How we share information
We do not sell your personal information. We share information only as needed to run the Service: with the members of your workspace; with the service providers (sub-processors) listed below; in connection with a merger, acquisition, or sale of assets (with notice where required); and when required by law or to protect rights, safety, and the integrity of the Service.
Sub-processors
We rely on the following providers to operate the Service. They process data on our behalf:
| Provider | Purpose |
|---|---|
| Supabase | Authentication, database, file storage, and real-time sync |
| Cloudflare | Hosting, serverless functions, cloud containers for the coding/voice agents, real-time media, and bot prevention |
| OpenRouter | AI gateway - routes every AI request to the selected model's provider |
| Anthropic (Claude) | Decisive's built-in AI - summaries, code generation, and other AI features |
| Other AI model providers | AI features a workspace has pointed at a model from the catalog - the picker names the provider; content for those features goes to that provider |
| GitHub | Source-control integration (repository access, branches, pull requests) |
| Slack | Slack app - messages in channels the bot is invited to, and the replies and tasks it posts back, where a workspace connects it |
| Sign-in with Google, and Google Calendar - the events on the calendar you connect, where you connect one | |
| LiveKit | Real-time audio and video for huddles |
| ElevenLabs | Voice assistant and huddle transcription - speech-to-text, the spoken conversation itself, and text-to-speech (AI voice responses) |
| Stripe | Payment processing, billing, and tax calculation |
| Mailgun | Transactional and product email delivery |
| PostHog | Product analytics and diagnostics (no session replay) |
| Calendly | Call scheduling - the name, email, and details you enter when you book a call with us |
This list may change as the Service evolves; we will keep it up to date here. Some providers process data in the United States and other countries.
8. Data retention
We keep workspace content for as long as the workspace is active, because it is the workspace. Three things clear themselves on a 14-day schedule, by design and visibly in the product: chat messages, counted from when a thread was last active; huddles, counted from when the call started; and completed tasks, counted from when the task was moved into a done status, so moving it back out starts the window again. Documents, discussions, pages and everything else stay until someone deletes them. The rest is kept only as long as it has a purpose:
| Data | Kept for |
|---|---|
| Chat messages, huddles, completed tasks | 14 days |
| Other workspace content and account profile | Life of the workspace or account |
| Diagnostic and request logs | 30 days |
| Product analytics | 12 months |
| Support correspondence | 3 years from the last message |
| Billing and tax records | 7 years, as tax law requires |
| Backups | Overwritten on a rolling 30-day cycle |
When you delete content, your account, or your workspace, we delete or anonymize the associated data across our systems and instruct our sub-processors to do the same, within 30 days. The exceptions are the records above that we are required to keep, principally billing and tax records, and anything we must retain to resolve a dispute or enforce our agreements. Deleted data may persist in backups until that cycle overwrites them, and is not restored to live systems in the meantime.
9. Security
We take technical and organizational measures to protect your information, including encryption in transit, encryption of sensitive credentials (such as AI provider API keys and connected-account tokens) at rest, and database-level access controls that isolate each workspace’s data. Our architecture, tenant-isolation model, and vulnerability-reporting process are described in detail on our Security page.
No method of transmission or storage is completely secure. A workspace admin can export the workspace’s full contents at any time, and we recommend keeping your own copy of anything critical.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, export, or restrict the processing of your personal information, and to object to certain processing or withdraw consent. You can update much of your profile and content directly in the app. A workspace administrator can download the workspace's full contents at any time from Settings → Export, without asking us - no plan requirement and no request form. To delete your account or workspace, or to exercise any of these rights, contact us at [email protected] and we will action the request as required by applicable law. If a workspace administrator controls your workspace, some requests may need to be directed to them.
If you are in the European Economic Area, the United Kingdom, or Switzerland, you also have the right to lodge a complaint with your local data protection supervisory authority.
11. International transfers
We and our providers operate globally, and your information may be processed in countries other than your own, including the United States. Where personal data leaves the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where the UK GDPR applies), agreed with each provider that receives it, and on an adequacy decision where one covers the destination. Several of our providers are additionally certified under the EU-US Data Privacy Framework. You can request details of the safeguards that apply to a specific provider at [email protected].
12. Children
The Service is not directed to children, and you must be at least 16 years old (or the age of digital consent in your jurisdiction, if higher) to use it. We do not knowingly collect personal information from children below that age.
13. Billing & refunds
Paid-plan payments are processed by our payment provider, Stripe, which handles your payment and billing information. Decisive Network, Inc. is the seller of record, and Decisive does not store full payment card details. Our billing, cancellation, and refund terms - including that subscriptions can be cancelled anytime, remain active until the end of the paid period, and that payments are non-refundable except where required by law - are set out in our Terms of Service.
14. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
15. Who is responsible for your data
The Service is operated by Decisive Network, Inc., a Delaware corporation with its registered office at 2810 N Church St STE 89498, Wilmington, DE 19802, United States.
Which role we play depends on the data, and the distinction matters if you are exercising a right:
- We are the controller for the data we hold to run Decisive as a business: your account and profile, billing records, support correspondence, product analytics, and the diagnostic logs described above. Requests about that data come to us.
- We are a processor for the content inside a workspace - the messages, tasks, documents, comments and files your team creates, and the personal data they may contain. The organisation whose workspace it is controls that content; we process it on their instructions to provide the Service, and our Terms of Service incorporate a Data Processing Agreement setting out that relationship. If your workspace belongs to your employer or client, a request about workspace content is best directed to them, and we will support them in answering it.
That Data Processing Agreement already applies to your workspace, with nothing to sign; a copy, countersigned if you need it, comes from [email protected]. Questions about your privacy or this policy, and any of the requests described in “Your rights” above, can be sent to the same address.