Privacy Notice

This notice explains what information Svart Works Inc. (“Svart Works,” “we”) collects when you use the DecryptAds web application, REST API, and MCP endpoint (the “Service”), why we collect it, how we use and share it, and the choices and rights available to you.

Effective date: May 2, 2026 · Last updated: August 21, 2026.

Why we offer free access (and what we do not do with your data)

Some users ask how a free tier is possible if we do not sell data. DecryptAds is funded by paid Enterprise, Team, Pro, and Legal contracts — not by monetizing free or researcher accounts. Restricted free access helps the transparency community investigate public supply-chain declarations; at the quotas we set, it costs us little to operate and is not a substitute for selling personal information.

We do not sell your personal information. We do not share account data, Submissions, or usage data with advertisers, data brokers, ad networks, or other third parties for their own marketing, profiling, or commercial reuse. We do not use your personal information to build cross-site advertising profiles.

We do not use third-party analytics, advertising, or tracking cookies on our public site or in the app (see § 9 Cookies).

1. Who we are

Svart Works Inc. operates DecryptAds, a programmatic supply chain transparency and risk investigation tool. For most uses of the Service, Svart Works acts as a data “controller” for account, authentication, audit, and Service-operations data, and as a data “processor” (or “service provider”) for Submissions you provide on behalf of your organization. Our processing of Submissions as a processor is governed by the data-processing terms in our Terms of Service, which apply to every account, including free and self-serve accounts. Enterprise customers may also sign a separate Data Processing Addendum (“DPA”), which controls to the extent it conflicts with those terms.

Controller of record: Svart Works Inc., a Delaware (USA) corporation, Wilmington, Delaware, United States. General privacy contact: privacy@decryptads.com.

2. What we collect

We collect or generate the following categories of data:

3. Why we use it

Lawful bases (UK / EU / Swiss residents). Operating the Service and providing accounts: performance of a contract with you (GDPR Art. 6(1)(b)). Securing the Service, preventing abuse, and improving the Service through aggregated / de-identified data: legitimate interests (Art. 6(1)(f)). Service announcements, security notices, and billing/account messages: performance of a contract or legitimate interests (Art. 6(1)(b), (f)). Product and feature updates and related communications to our own users: our legitimate interest in informing users about features and related offerings (Art. 6(1)(f)), or, where required by applicable law (including ePrivacy/PECR and equivalent rules), consent (Art. 6(1)(a)); in every case we provide an opt-out (unsubscribe) in each product and feature update message and honor it. Compliance with law and lawful requests: legal obligation (Art. 6(1)(c)). Analytics and risk indicators target hostnames and infrastructure, not natural persons; we do not use Submissions to build behavioral profiles of identifiable end-users, and we do not make solely automated decisions producing legal or similarly significant effects on individuals.

4. How Submissions are handled

Files and text you upload or paste, together with derivatives we compute from them, are processed only to deliver the analyses you request, as your processor and on your instructions.

By submitting data on pages where this notice is referenced, you confirm that you have the right and authority to share that data with us for processing under your instructions, and that you will not include login credentials, payment-card data, government-identification numbers, or special-category / sensitive personal data. Because impression and bid logs commonly contain online identifiers (for example IP addresses or advertising IDs), we process any such identifiers strictly as your processor, solely to perform the analysis you request, and not for our own purposes.

Inadvertent personal information. If a Submission contains personal information that should not have been included (for example, a contact email pasted into a comment field), contact privacy@decryptads.com. We will work with the submitting customer to delete or minimize that data, subject to legal hold and audit requirements.

4a. Personal data in public declarations and the corpus

Some files we crawl, and some Submissions, contain business-contact personal data about people other than you, for example a named contact in a sellers.json or adagents.json entry, an OWNERDOMAIN / CONTACT line, or an email inside a free-text comment.

Because this data is generated by the public advertising supply chain rather than provided to us by the individual, Svart Works acts as a controller for it and processes it to provide supply-chain transparency and anti-abuse analytics, on the basis of our legitimate interests, and those of the transparency community, in a trustworthy advertising supply chain (GDPR Art. 6(1)(f)). Because it comes from public sources rather than from the individual directly, we rely on the disproportionate-effort exemption in GDPR Art. 14(5)(b) for individual notice.

A person whose business-contact data appears in the corpus may ask us to access, correct, or remove it at privacy@decryptads.com or support@decryptads.com; we will honor such requests unless retention is required for security, fraud-prevention, or legal reasons.

5. Sharing

We do not sell your personal information. We do not share account data, Submissions, or usage data with advertisers, data brokers, ad networks, or other third parties for their own marketing, profiling, or commercial reuse. We do not use your personal information to build cross-site advertising profiles, and we do not permit service providers to use your personal information for their own unrelated purposes.

We share personal data only in the narrow cases below, and only as needed to run, secure, or legally operate the Service:

A current sub-processor list and DPA terms are available to enterprise customers on request from privacy@decryptads.com.

6. Retention

We retain personal data only as long as needed for the purposes set out above, then delete or de-identify it. Indicative defaults (subject to legal holds, contractual commitments in your Order Form / DPA, and applicable law):

7. Security

We use technical and organizational measures including encryption in transit and at rest, role-based access, audit logging, and infrastructure hardening to protect data. Account data we retain is minimized; for most users that is a username and email address. No system is perfectly secure; you are responsible for protecting your account credentials and API keys, and for limiting Submissions to data you are authorized to share.

Breach notification. If we determine that a security incident has resulted in unauthorized access to or disclosure of personal data we control, we will notify affected customers and (where required) regulators without undue delay, consistent with applicable law and any DPA in place.

8. Your rights

Depending on your jurisdiction, you may have the right to:

To exercise these rights for personal data we control, contact privacy@decryptads.com. Signed-in accounts (including free-tier) can download a copy under Account → Profile. We will respond within the period required by applicable law (for example, 45 days under the CCPA and one month under the GDPR, each extendable as those laws allow).

For Submissions and other data we process on behalf of an enterprise customer, please direct requests to that customer’s administrator; we will support them in responding under our DPA.

9. Cookies

The public marketing pages are static HTML and do not set authentication cookies. When you sign in to the DecryptAds web application, we set a first-party signed session cookie so the browser can stay logged in. The cookie may appear in your browser under the name da_session (or legacy session on older host-only cookies). We do not currently use third-party analytics, advertising, or tracking cookies on the marketing site or in the app. Signup may load hCaptcha (Intuition Machines, Inc.), which can set its own cookies or local storage in a third-party context solely to provide bot protection; see hCaptcha’s privacy policy for details.

10. Children

The Service is intended for business and research use. It is not directed towards children. We do not knowingly collect personal information from children under 13 (or under 16 in jurisdictions where that is the applicable threshold under the EU General Data Protection Regulation or other law). If you believe we may have collected personal information on or about a child, please contact privacy@decryptads.com and we will delete it immediately.

11. US privacy supplemental notice (CCPA / CPRA)

This section provides additional disclosures for California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, “CCPA”), and applies to comparable rights under other US state privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, and Oregon) where those laws apply, and to additional states as their consumer-privacy laws take effect (for example Vermont, effective 2028).

We do not sell or share your personal information. We do not sell personal information for monetary or other valuable consideration, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA. Because we do not sell or share personal information, there is nothing to opt out of; we nonetheless treat a Global Privacy Control (GPC) signal as a valid opt-out request where the law requires.

Your CCPA rights. California residents may request to know, access, correct, delete, or limit certain processing of their personal information, and may exercise these rights through an authorized agent (we may verify the agent’s authority and your identity). We will not discriminate against you for exercising these rights.

Submit a request to privacy@decryptads.com. For Submissions and other data we process on behalf of an enterprise customer, contact that customer’s administrator; we will support them in responding under our DPA.

12. EU / UK / Swiss supplemental notice

For individuals in the European Economic Area, the United Kingdom, and Switzerland, the lawful bases on which we process personal data are summarized in § 3. Categories of personal data, recipients, retention periods, and rights are described in §§ 2, 5, 6, and 8 of this notice.

Where this notice and any separate enterprise DPA conflict on a point relating to your organization’s data, the DPA controls.

13. Changes to this notice

We may update this notice as the Service or applicable law changes. Material changes will be communicated via the Service or by email to account holders. The “Last updated” date above reflects the most recent change.

14. Contact

For privacy questions or requests, please contact: privacy@decryptads.com. General contact options live on the Contact page; Terms of Service covers acceptable use.

Postal: Svart Works Inc., a Delaware (USA) corporation, Wilmington, Delaware, United States. Please include “Privacy Request” in the subject line so we can route the message to the right team.