Privacy Notice
This notice explains what information Svart Works Inc. (“Svart Works,” “we”) collects when you use the DecryptAds web application, REST API, and MCP endpoint (the “Service”), why we collect it, how we use and share it, and the choices and rights available to you.
Effective date: May 2, 2026 · Last updated: June 18, 2026.
1. Who we are
Svart Works Inc. operates DecryptAds, a programmatic supply chain transparency and ad fraud investigation tool. For most uses of the Service, Svart Works acts as a data “controller” for account and Service operations data, and as a data “processor” (or “service provider”) for content you submit on behalf of your organization. Where an enterprise agreement, Order Form, or Data Processing Addendum (“DPA”) applies, that document controls.
Controller of record: Svart Works Inc., a Delaware (USA) corporation, Wilmington, Delaware, United States. General privacy contact: privacy@decryptads.com.
2. What we collect
We collect or generate the following categories of data:
- Account data — name, work email, organization, role, password hash, MFA factors, SSO claims (when SSO is configured), and basic profile preferences.
- Authentication and access data — session cookies, API keys (hashed), MCP tokens, login timestamps, and audit-log events for sensitive actions.
- Submissions — files and text you upload or paste, including ads.txt / app-ads.txt / sellers.json / buyers.json / adagents.json content, OpenRTB bid requests and responses, impression and bid logs, SupplyChain JSON, and similar declarations and telemetry.
- Crawled public data — declarations we fetch from public URLs at your direction (for example,
/ads.txt,/app-ads.txt,/sellers.json,/.well-known/adagents.json) and metadata associated with those fetches. - Derived data — parsed records, indices, hashes, fingerprints, clusters, validators’ output, scores, snapshots, and diffs computed from Submissions and crawled data.
- Service operations data — request logs, IP addresses, user agents, timing, error and security events, and rate-limit counters.
- Communications — messages you send by email to our sales, support, partnerships, or hello addresses, and any attachments.
3. Why we use it
- Operate the Service — authenticate users, run crawls, parse and store declarations, compute analytics, render dashboards, fulfill API and MCP requests, generate exports.
- Secure the Service — detect and prevent abuse, fraud, and security incidents; enforce rate limits and acceptable-use policy; maintain audit trails.
- Improve the Service — debug, monitor, build and refine investigation logic, validators, fingerprints, and risk indicators using aggregated and de-identified data.
- Communicate — service announcements, security notices, billing, and (with consent or as permitted by law) product updates.
- Comply with law — meet legal, regulatory, and contractual obligations, including responses to lawful requests.
Lawful bases (UK / EU / Swiss residents). Operating the Service and providing accounts: performance of a contract with you (GDPR Art. 6(1)(b)). Securing the Service, preventing abuse, and improving the Service through aggregated / de-identified data: legitimate interests (Art. 6(1)(f)). Service announcements and security notices: legitimate interests or contract; marketing emails: consent (Art. 6(1)(a)) where required. Compliance with law and lawful requests: legal obligation (Art. 6(1)(c)). Analytics and risk indicators target hostnames and infrastructure, not natural persons; we do not use Submissions to build behavioral profiles of identifiable end-users, and we do not make solely automated decisions producing legal or similarly significant effects on individuals.
4. How Submissions are handled
Files and text you upload or paste — together with derivatives we compute from them — are processed to deliver the analyses you request. By submitting data on pages where this notice is referenced, you confirm that you have the right to share that data and that you have not included personal information, login credentials, payment data, or other sensitive content.
- Submissions are stored in our hosting infrastructure and may be retained for the life of your account or as required to operate the feature you used (for example, snapshot diffs and historical analytics). See § 6 Retention.
- We may share aggregated, de-identified, or fingerprint-style derivatives (for example, schain topology hashes, cluster signatures, anonymized risk indicators) with the broader transparency and ad-fraud community to support investigation work, unless your Order Form prohibits this. We treat such derivatives as “de-identified” under California Civil Code § 1798.140(m), do not attempt to re-identify them, and contractually prohibit recipients from doing so.
- We do not sell Submissions, and we do not use them to build behavioral profiles of identifiable end-users.
- We are not responsible for the contents of Submissions you provide.
Inadvertent personal information. If a Submission contains personal information that should not have been included (for example, a contact email pasted into a comment field), contact privacy@decryptads.com. We will work with the submitting customer to delete or minimize that data, subject to legal hold and audit requirements.
5. Sharing
We share data only as needed:
- Service providers — hosting, storage, observability, email, payment, and similar vendors acting on our behalf under contractual confidentiality and security commitments.
- Your organization — admins of your tenant may see audit logs, API key usage, and account activity associated with your use of the Service.
- Transparency community — aggregated, de-identified, or fingerprint-style derivatives, as described above, when permitted by your contract.
- Legal and safety — to comply with law, lawful requests, court orders; to enforce our Terms; or to protect rights, property, or safety.
- Corporate transactions — in connection with a merger, acquisition, financing, or sale of assets, with notice and protections required by law.
A current sub-processor list and DPA terms are available to enterprise customers on request from privacy@decryptads.com.
6. Retention
We retain personal data only as long as needed for the purposes set out above, then delete or de-identify it. Indicative defaults (subject to legal holds, contractual commitments in your Order Form / DPA, and applicable law):
- Account data — for the life of your account; up to 24 months after account closure for billing, dispute, and audit purposes.
- Authentication and access data — session cookies expire when you log out or after seven (7) days from sign-in (rolling while you remain active); API key and MCP token records persist for the life of the credential and up to 12 months after revocation for audit.
- Audit logs of sensitive actions — at least 12 months and up to 24 months.
- Submissions and crawled public data — for the life of your account or for the duration the underlying feature requires (snapshot history, diff baselines, fingerprints). On account closure, Submissions are deleted within 90 days unless retained as aggregated / de-identified derivatives or required by law.
- Derived data (aggregated / de-identified) — may be retained indefinitely for Service operation and improvement, in accordance with the no-re-identification commitment in § 4.
- Service operations / request logs — typically 30 to 90 days; security incident records up to 24 months.
- Communications — typically 24 months from last contact.
7. Security
We use technical and organizational measures including encryption in transit, role-based access, audit logging, and infrastructure hardening to protect data. No system is perfectly secure; you are responsible for protecting your account credentials and API keys, and for limiting Submissions to data you are authorized to share.
Breach notification. If we determine that a security incident has resulted in unauthorized access to or disclosure of personal data we control, we will notify affected customers and (where required) regulators without undue delay, consistent with applicable law and any DPA in place.
8. Your rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you and obtain a copy;
- Correct inaccurate or incomplete personal data;
- Delete or erase personal data, subject to legal retention requirements;
- Restrict or object to certain processing (including direct marketing);
- Port your personal data in a structured, commonly used, machine-readable format;
- Withdraw any consent you previously gave (without affecting the lawfulness of processing before withdrawal);
- Lodge a complaint with your local data protection or privacy supervisory authority.
To exercise these rights for personal data we control, contact privacy@decryptads.com. We will respond within the timeframes required by applicable law (generally within 30 to 45 days) and will not discriminate against you for exercising these rights.
For Submissions and other data we process on behalf of an enterprise customer, please direct requests to that customer’s administrator; we will support them in responding under our DPA.
9. Cookies
The public marketing pages are static HTML and do not set authentication cookies. When you sign in to the DecryptAds web application, we set a first-party signed session cookie so the browser can stay logged in. The cookie may appear in your browser under the name session. We do not currently use third-party analytics, advertising, or tracking cookies on the marketing site or in the app.
session— first-party HTTP-only session cookie (SameSite Lax). It holds your signed-in state and expires when you log out or after seven (7) days from sign-in (rolling while you remain active).
10. Children
The Service is intended for business and research use. It is not directed to children. We do not knowingly collect personal information from children under 13 (or under 16 in jurisdictions where that is the applicable threshold under the EU General Data Protection Regulation or other law). If you believe we may have collected personal information from a child, contact privacy@decryptads.com and we will delete it.
11. US privacy supplemental notice (CCPA / CPRA)
This section provides additional disclosures for California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, “CCPA”), and applies to comparable rights under other US state privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, and Oregon) where those laws apply.
- Categories of personal information we collect. Identifiers (name, email, organization, IP address, account / API key identifiers); commercial information (plan, billing); internet or other electronic network activity (request logs, usage and audit events); professional or employment-related information (role, organization); inferences drawn from the foregoing for security and product analytics.
- Categories of sources. You; your organization’s administrators; your devices and browsers; identity providers (when SSO is used); public web sources we crawl at your direction (these typically do not contain personal information about you).
- Business or commercial purposes. Operate, secure, and improve the Service; account, billing, and audit; product analytics; legal and compliance; communicate with you. See § 3 for the full list.
- Categories of recipients. Service providers (hosting, observability, email, payment); your organization’s administrators; the transparency community (only aggregated / de-identified derivatives, where permitted); legal, safety, and corporate-transaction recipients as described in § 5.
- Sensitive personal information. We do not use or disclose sensitive personal information for purposes that require offering a right to limit under CCPA § 1798.121.
We do not sell or share your personal information. We do not sell personal information for monetary or other valuable consideration, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA.
Your CCPA rights. California residents may request to know, access, correct, delete, or limit certain processing of their personal information, and may exercise these rights through an authorized agent (we may verify the agent’s authority and your identity). We will not discriminate against you for exercising these rights.
Submit a request to privacy@decryptads.com. For Submissions and other data we process on behalf of an enterprise customer, contact that customer’s administrator; we will support them in responding under our DPA.
12. EU / UK / Swiss supplemental notice
For individuals in the European Economic Area, the United Kingdom, and Switzerland, the lawful bases on which we process personal data are summarized in § 3. Categories of personal data, recipients, retention periods, and rights are described in §§ 2, 5, 6, and 8 of this notice.
- Controller. Svart Works Inc. is the controller for account, authentication, audit, and Service-operations data, and for direct communications with you.
- Processor. For Submissions and crawled / derived data uploaded or directed by an enterprise customer, Svart Works acts as a processor on behalf of that customer (the controller). The customer’s instructions, Order Form, and DPA control.
- International transfers. Where personal data is transferred from the EEA, UK, or Switzerland to other countries, we use safeguards required by applicable law, including standard contractual clauses and UK addenda where relevant. Further detail is available to enterprise customers in our DPA.
- Supervisory authority. You may lodge a complaint with the data protection or privacy supervisory authority in your country of residence, place of work, or place of the alleged infringement.
Where this notice and any separate enterprise DPA conflict on a point relating to your organization’s data, the DPA controls.
13. Changes to this notice
We may update this notice as the Service or applicable law changes. Material changes will be communicated via the Service or by email to account holders. The “Last updated” date above reflects the most recent change.
14. Contact
Privacy questions or requests: privacy@decryptads.com. General contact options live on the Contact page; Terms of Service covers acceptable use.
Postal: Svart Works Inc., a Delaware (USA) corporation, Wilmington, Delaware, United States. Please include “Privacy Request” in the subject line so we can route the message to the right team.