Privacy Notice
This notice explains what information Svart Works Inc. (“Svart Works,” “we”) collects when you use the DecryptAds web application, REST API, and MCP endpoint (the “Service”), why we collect it, how we use and share it, and the choices and rights available to you.
Effective date: May 2, 2026 · Last updated: August 21, 2026.
Why we offer free access (and what we do not do with your data)
Some users ask how a free tier is possible if we do not sell data. DecryptAds is funded by paid Enterprise, Team, Pro, and Legal contracts — not by monetizing free or researcher accounts. Restricted free access helps the transparency community investigate public supply-chain declarations; at the quotas we set, it costs us little to operate and is not a substitute for selling personal information.
We do not sell your personal information. We do not share account data, Submissions, or usage data with advertisers, data brokers, ad networks, or other third parties for their own marketing, profiling, or commercial reuse. We do not use your personal information to build cross-site advertising profiles.
We do not use third-party analytics, advertising, or tracking cookies on our public site or in the app (see § 9 Cookies).
1. Who we are
Svart Works Inc. operates DecryptAds, a programmatic supply chain transparency and risk investigation tool. For most uses of the Service, Svart Works acts as a data “controller” for account, authentication, audit, and Service-operations data, and as a data “processor” (or “service provider”) for Submissions you provide on behalf of your organization. Our processing of Submissions as a processor is governed by the data-processing terms in our Terms of Service, which apply to every account, including free and self-serve accounts. Enterprise customers may also sign a separate Data Processing Addendum (“DPA”), which controls to the extent it conflicts with those terms.
Controller of record: Svart Works Inc., a Delaware (USA) corporation, Wilmington, Delaware, United States. General privacy contact: privacy@decryptads.com.
2. What we collect
We collect or generate the following categories of data:
- Account data — the username and email address you register, a hashed password, and MFA factors. If your organization uses single sign-on, we also receive the SSO claims your identity provider sends, and enterprise accounts may include an organization name. We do not require a legal name or profile biography to use the Service.
- Billing and contract data (enterprise customers) — organization name, billing-contact name and email, and invoicing, purchase-order, and remittance records needed to bill and take payment. Enterprise billing is handled through contracts and bank transfer; where a third-party payment provider is used, that provider processes the payment details and we receive only limited transaction and plan information, not full payment credentials.
- Authentication and access data — session cookies, API keys (hashed), MCP tokens, login timestamps, and audit-log events for sensitive actions.
- Submissions — files and text you upload or paste, including ads.txt / app-ads.txt / sellers.json / buyers.json / adagents.json content, OpenRTB bid requests and responses, impression and bid logs, SupplyChain JSON, and similar declarations and telemetry.
- Crawled public data — declarations and related public metadata we fetch at your direction (for example
/ads.txt,/app-ads.txt,/sellers.json,/.well-known/adagents.json), and public app-store listing and permission metadata for apps you look up. - Derived data — parsed records, indices, hashes, fingerprints, clusters, validators’ output, scores, snapshots, diffs, and geographic / counterparty-risk signals we compute from Submissions and crawled data.
- Service operations data — request logs, IP addresses, user agents, timing, error and security events, rate-limit counters, signup IP, and Terms / Privacy acceptance records (timestamp, account id, IP, document version hashes).
- Communications — messages you send by email to our sales, support, partnerships, abuse, or hello addresses, and any attachments.
3. Why we use it
- Operate the Service — authenticate users, run crawls, parse and store declarations, compute analytics, render dashboards, fulfill API and MCP requests, generate exports.
- Secure the Service — detect and prevent abuse and security incidents; enforce rate limits and acceptable-use policy; maintain audit trails.
- Improve the Service — debug, monitor, build and refine investigation logic, validators, fingerprints, and risk indicators using aggregated and de-identified data.
- Communicate — to send you (a) service announcements, security notices, and billing and account messages, which are part of providing the Service; and (b) product and feature updates and related communications (for example newsletters, feature announcements, research, and offers). You can opt out of category (b) at any time via the unsubscribe link in each such message or by emailing support@decryptads.com; this does not stop service, security, billing, or account messages. Where the law requires consent for messages that constitute direct marketing under applicable law, we rely on the basis described in the lawful-bases section below.
- Comply with law — meet legal, regulatory, and contractual obligations, including responses to lawful requests.
Lawful bases (UK / EU / Swiss residents). Operating the Service and providing accounts: performance of a contract with you (GDPR Art. 6(1)(b)). Securing the Service, preventing abuse, and improving the Service through aggregated / de-identified data: legitimate interests (Art. 6(1)(f)). Service announcements, security notices, and billing/account messages: performance of a contract or legitimate interests (Art. 6(1)(b), (f)). Product and feature updates and related communications to our own users: our legitimate interest in informing users about features and related offerings (Art. 6(1)(f)), or, where required by applicable law (including ePrivacy/PECR and equivalent rules), consent (Art. 6(1)(a)); in every case we provide an opt-out (unsubscribe) in each product and feature update message and honor it. Compliance with law and lawful requests: legal obligation (Art. 6(1)(c)). Analytics and risk indicators target hostnames and infrastructure, not natural persons; we do not use Submissions to build behavioral profiles of identifiable end-users, and we do not make solely automated decisions producing legal or similarly significant effects on individuals.
4. How Submissions are handled
Files and text you upload or paste, together with derivatives we compute from them, are processed only to deliver the analyses you request, as your processor and on your instructions.
By submitting data on pages where this notice is referenced, you confirm that you have the right and authority to share that data with us for processing under your instructions, and that you will not include login credentials, payment-card data, government-identification numbers, or special-category / sensitive personal data. Because impression and bid logs commonly contain online identifiers (for example IP addresses or advertising IDs), we process any such identifiers strictly as your processor, solely to perform the analysis you request, and not for our own purposes.
- Submissions are stored in our hosting infrastructure and may be retained for the life of your account or as required to operate the feature you used (for example, snapshot diffs and historical analytics). See § 6 Retention.
- We may share aggregated or de-identified derivatives, for example schain topology hashes and cluster signatures that do not identify a natural person, with the broader transparency community to support investigation work, unless your Order Form prohibits it. We treat these as “de-identified” under California Civil Code § 1798.140(m), do not attempt to re-identify them, and contractually require recipients not to. Where such a derivative could still relate to an identifiable person, we treat it as pseudonymized under the GDPR and share it only in that form.
- We do not sell Submissions, and we do not use them to build behavioral profiles of identifiable end-users.
- As the party that decides what to submit, you are responsible for the lawfulness of your Submissions and for holding any rights, notices, or consents needed to provide them. We process Submissions on your behalf and are not the controller of that content.
Inadvertent personal information. If a Submission contains personal information that should not have been included (for example, a contact email pasted into a comment field), contact privacy@decryptads.com. We will work with the submitting customer to delete or minimize that data, subject to legal hold and audit requirements.
4a. Personal data in public declarations and the corpus
Some files we crawl, and some Submissions, contain business-contact personal data about people other than you, for example a named contact in a sellers.json or adagents.json entry, an OWNERDOMAIN / CONTACT line, or an email inside a free-text comment.
Because this data is generated by the public advertising supply chain rather than provided to us by the individual, Svart Works acts as a controller for it and processes it to provide supply-chain transparency and anti-abuse analytics, on the basis of our legitimate interests, and those of the transparency community, in a trustworthy advertising supply chain (GDPR Art. 6(1)(f)). Because it comes from public sources rather than from the individual directly, we rely on the disproportionate-effort exemption in GDPR Art. 14(5)(b) for individual notice.
A person whose business-contact data appears in the corpus may ask us to access, correct, or remove it at privacy@decryptads.com or support@decryptads.com; we will honor such requests unless retention is required for security, fraud-prevention, or legal reasons.
5. Sharing
We do not sell your personal information. We do not share account data, Submissions, or usage data with advertisers, data brokers, ad networks, or other third parties for their own marketing, profiling, or commercial reuse. We do not use your personal information to build cross-site advertising profiles, and we do not permit service providers to use your personal information for their own unrelated purposes.
We share personal data only in the narrow cases below, and only as needed to run, secure, or legally operate the Service:
- Service providers (processors) — infrastructure and tools that process data solely on our instructions (for example hosting, email delivery, bot-prevention such as hCaptcha on signup, and payment processing for enterprise customers who pay via a third-party payment provider), under confidentiality and security commitments. They are not permitted to sell your data or use it for advertising.
- Your organization — admins of your tenant may see audit logs, API key usage, and account activity associated with your use of the Service.
- Third-party services you query at your direction — for example Google’s Chrome UX Report (CrUX) API, which we call server-side to return site-performance metrics you request. It receives only the hostname being analyzed, never your account identity or Submissions.
- Transparency community — only aggregated, de-identified, or fingerprint-style derivatives (not your account identity or raw Submissions as personal data), as described in § 4, when permitted by your contract.
- Legal and safety — to comply with law, lawful requests, or court orders; to enforce our Terms; or to protect rights, property, or safety.
- Corporate transactions — in connection with a merger, acquisition, financing, or sale of assets, with notice and protections required by law.
A current sub-processor list and DPA terms are available to enterprise customers on request from privacy@decryptads.com.
6. Retention
We retain personal data only as long as needed for the purposes set out above, then delete or de-identify it. Indicative defaults (subject to legal holds, contractual commitments in your Order Form / DPA, and applicable law):
- Account data — for the life of your account; up to 24 months after account closure for billing, dispute, and audit purposes.
- Authentication and access data — session cookies expire when you log out or after seven (7) days from sign-in (rolling while you remain active); API key and MCP token records persist for the life of the credential and up to 12 months after revocation for audit.
- Audit logs of sensitive actions — at least 12 months and up to 24 months, including after account closure when needed for security, fraud prevention, or dispute resolution (for example, signup acceptance records and abuse-related events).
- Billing, invoice, and tax records — retained as required by tax and accounting law, typically up to seven (7) years, independent of account-closure timelines.
- Communications — typically 24 months from last contact.
- Derived data (aggregated / de-identified) — may be retained indefinitely for Service operation and improvement, in accordance with the no-re-identification commitment in § 4.
- Submissions and crawled public data — retained for the life of your account or for as long as the feature you used requires (for example snapshot history and diff baselines). On account closure, raw Submissions are deleted within 90 days; only non-personal derived artifacts (such as hashes and fingerprints) persist beyond that, under the no-re-identification commitment in § 4.
- Service operations / request logs — typically 30 to 90 days; security and abuse-related records (including signup IP and related investigation data) up to 24 months after the relevant event or account closure.
7. Security
We use technical and organizational measures including encryption in transit and at rest, role-based access, audit logging, and infrastructure hardening to protect data. Account data we retain is minimized; for most users that is a username and email address. No system is perfectly secure; you are responsible for protecting your account credentials and API keys, and for limiting Submissions to data you are authorized to share.
Breach notification. If we determine that a security incident has resulted in unauthorized access to or disclosure of personal data we control, we will notify affected customers and (where required) regulators without undue delay, consistent with applicable law and any DPA in place.
8. Your rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you and obtain a copy;
- Correct inaccurate or incomplete personal data;
- Delete or erase personal data, subject to legal retention requirements;
- Restrict or object to certain processing, including direct marketing — you can opt out of product and feature update emails at any time via the unsubscribe link in any such message or by emailing privacy@decryptads.com or support@decryptads.com;
- Port your personal data in a structured, commonly used, machine-readable format;
- Withdraw any consent you previously gave (without affecting the lawfulness of processing before withdrawal);
- Lodge a complaint with your local data protection or privacy supervisory authority.
To exercise these rights for personal data we control, contact privacy@decryptads.com. Signed-in accounts (including free-tier) can download a copy under Account → Profile. We will respond within the period required by applicable law (for example, 45 days under the CCPA and one month under the GDPR, each extendable as those laws allow).
For Submissions and other data we process on behalf of an enterprise customer, please direct requests to that customer’s administrator; we will support them in responding under our DPA.
9. Cookies
The public marketing pages are static HTML and do not set authentication cookies. When you sign in to the DecryptAds web application, we set a first-party signed session cookie so the browser can stay logged in. The cookie may appear in your browser under the name da_session (or legacy session on older host-only cookies). We do not currently use third-party analytics, advertising, or tracking cookies on the marketing site or in the app. Signup may load hCaptcha (Intuition Machines, Inc.), which can set its own cookies or local storage in a third-party context solely to provide bot protection; see hCaptcha’s privacy policy for details.
da_session(and legacysession) — first-party HTTP-only session cookie (SameSite Lax). It holds your signed-in state and expires when you log out or after seven (7) days from sign-in (rolling while you remain active).
10. Children
The Service is intended for business and research use. It is not directed towards children. We do not knowingly collect personal information from children under 13 (or under 16 in jurisdictions where that is the applicable threshold under the EU General Data Protection Regulation or other law). If you believe we may have collected personal information on or about a child, please contact privacy@decryptads.com and we will delete it immediately.
11. US privacy supplemental notice (CCPA / CPRA)
This section provides additional disclosures for California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, “CCPA”), and applies to comparable rights under other US state privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, and Oregon) where those laws apply, and to additional states as their consumer-privacy laws take effect (for example Vermont, effective 2028).
- Categories of personal information we collect. Identifiers (name, email, organization, IP address, account / API key identifiers); commercial information (plan, billing); internet or other electronic network activity (request logs, usage and audit events); professional or employment-related information (role, organization); inferences drawn from the foregoing for security and product analytics.
- Categories of sources. You; your organization’s administrators; your devices and browsers; identity providers (when SSO is used); public web sources we crawl at your direction (these typically do not contain personal information about you).
- Business or commercial purposes. Operate, secure, and improve the Service; account, billing, and audit; product analytics; legal and compliance; communicate with you. See § 3 for the full list (for personal data about others that may appear in the corpus see § 4a).
- Categories of recipients. Service providers (hosting, observability, email, payment); your organization’s administrators; the transparency community (only aggregated / de-identified derivatives, where permitted); legal, safety, and corporate-transaction recipients as described in § 5.
- Sensitive personal information. We do not use or disclose sensitive personal information to infer characteristics or for any purpose that requires offering a right to limit under CCPA § 1798.121. Where a Submission contains sensitive personal information, for example precise geolocation in a bid log, we process it solely as your processor, on your instructions, and not for our own purposes.
We do not sell or share your personal information. We do not sell personal information for monetary or other valuable consideration, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA. Because we do not sell or share personal information, there is nothing to opt out of; we nonetheless treat a Global Privacy Control (GPC) signal as a valid opt-out request where the law requires.
Your CCPA rights. California residents may request to know, access, correct, delete, or limit certain processing of their personal information, and may exercise these rights through an authorized agent (we may verify the agent’s authority and your identity). We will not discriminate against you for exercising these rights.
Submit a request to privacy@decryptads.com. For Submissions and other data we process on behalf of an enterprise customer, contact that customer’s administrator; we will support them in responding under our DPA.
12. EU / UK / Swiss supplemental notice
For individuals in the European Economic Area, the United Kingdom, and Switzerland, the lawful bases on which we process personal data are summarized in § 3. Categories of personal data, recipients, retention periods, and rights are described in §§ 2, 5, 6, and 8 of this notice.
- Controller. Svart Works Inc. is the controller for account, authentication, audit, and Service-operations data, and for direct communications with you.
- Processor. For Submissions and crawled / derived data uploaded or directed by an enterprise customer, Svart Works acts as a processor on behalf of that customer (the controller). The customer’s instructions, Order Form, and DPA control.
- International transfers. Where personal data is transferred from the EEA, UK, or Switzerland to other countries, we use safeguards required by applicable law, including standard contractual clauses and UK addenda where relevant. Further detail is available to enterprise customers in our DPA.
- Supervisory authority. You may lodge a complaint with the data protection or privacy supervisory authority in your country of residence, place of work, or place of the alleged infringement.
Where this notice and any separate enterprise DPA conflict on a point relating to your organization’s data, the DPA controls.
13. Changes to this notice
We may update this notice as the Service or applicable law changes. Material changes will be communicated via the Service or by email to account holders. The “Last updated” date above reflects the most recent change.
14. Contact
For privacy questions or requests, please contact: privacy@decryptads.com. General contact options live on the Contact page; Terms of Service covers acceptable use.
Postal: Svart Works Inc., a Delaware (USA) corporation, Wilmington, Delaware, United States. Please include “Privacy Request” in the subject line so we can route the message to the right team.