Privacy Policy
Last updated: August 10, 2026
Local-first by design
1. Data controller
deˆrozic (“we”, “us”) operates decli at decli.dev and associated subdomains. Contact: privacy@decli.dev · product: hello@decli.dev.
2. What we collect
Account data: email, name, and profile photo from Google Workspace sign-in; optional display handle.
Phone (SMS login): if you use SMS one-time codes, we process your phone number via Twilio Verify to authenticate you. Codes are short-lived; we store the verified number with your account identity.
Billing: we are not collecting payment card data in the public beta. When paid plans ship, card data will be handled by a PCI-compliant processor; we will never store full card numbers on decli servers.
Usage: optional product analytics (page views, feature usage) without third-party ad cookies. See our Cookies Policy.
Local data: CLI configs, integration tokens, desk packs, and iTerm exports remain on your device unless you explicitly enable encrypted cloud backup.
3. How we use data
Authenticate sessions, operate desk pack/recover features, provide support, and improve the product. We do not use your integration data to train third-party AI models.
4. Third-party services
decli connects to services you configure (GitHub, ClickUp, etc.) directly from your machine. Those interactions are governed by each provider's privacy policy.
5. Security
Credentials use OS keychain integration or AES-256-GCM local encryption. Data in transit uses TLS 1.3. See our Security page for details.
6. Your rights
Access, export, correct, or delete your account data at any time. EU/UK users have GDPR rights; California users have CCPA rights. Email privacy@decli.dev to exercise them — we respond within 30 days.
7. Retention
Account data is retained while your account is active. Backups you delete are purged from our vault within 30 days. Local CLI data is yours to wipe instantly via decli auth logout.