No data sale or ads
We do not sell personal data or use Sense content for targeted advertising.
Product privacy & data policy
This policy explains what Sense processes across the web app, connectors, browser extension, public shares, and Atlassian app — and the controls that keep that data yours.
Effective July 17, 2026 · Operated by Decionis, Inc.
We do not sell personal data or use Sense content for targeted advertising.
Connectors are optional, scope-limited, and can be disconnected or revoked.
Core judgment records use hashes, findings, and receipts instead of retaining raw draft text.
Sense is the judgment layer powered by Decionis. This Sense Product Privacy & Data Policy applies to the Sense website, playground, dashboard, APIs, optional connectors, browser extension, public verification surfaces, and Sense for Jira & Confluence.
It complements the broader Decionis Privacy Policy. The public Customer Data Processing Addendum applies when Decionis processes Customer Personal Data on a customer's behalf. If another customer agreement applies, that agreement controls for the customer workspace data it covers.
01
Decionis, Inc. operates Sense. For account, website, security, support, and relationship data, Decionis determines why and how the data is processed. For content placed in a customer-managed workspace, Decionis generally processes that data on the customer's instructions as a service provider or processor.
This policy covers information submitted directly to Sense and information Sense is permitted to read from an optional connection. It does not govern the privacy practices of Google, Microsoft, Notion, Slack, Atlassian, or another third-party service you choose to connect.
02
We process identifiers such as user, organization, workspace, device, and session IDs; account contact details when provided; membership and authorization scopes; connector status; and operational audit metadata.
When you request a review, Sense processes the draft, excerpt, goal, rule, decision, or other artifact needed to produce the requested verdict. The deterministic contradiction path does not send that artifact to an external large-language-model provider.
Sense creates content hashes, extracted claims, verdicts, contradiction findings, evidence summaries, work items, decision receipts, ledger records, verification records, and related activity metadata. If you save or share a result, these derived records are associated with your workspace.
With your authorization, Sense processes the source identifiers, metadata, and limited content needed for the connected feature. We may also process request, browser, device, IP, diagnostic, and security-log data needed to operate, protect, and troubleshoot the service. Support messages are processed when you contact us.
03
04
A first review can create a guest device and session token without an account. Submitted draft text is processed to return a result and is not retained as raw artifact text. Saved results retain the evidence summary, content hash, findings, and any ledger or verification records you choose to create.
Google Workspace, Microsoft, Notion, Slack, Atlassian, and other connectors begin only after an explicit authorization. OAuth credentials are kept in an encrypted server-side token vault and are not returned in connector API responses. A connector receives only the permissions shown during consent.
The Sense Forge UI reads current Jira or Confluence metadata through Atlassian-hosted APIs. The Forge UI does not transmit Jira issue body content or Confluence page body content to Sense and requests no product write scope.
A separate, optional Sense OAuth connector can synchronize recent Jira issue keys, summaries, status, priority, type, and update metadata, and Confluence page title, space, version, update metadata, URL, and a content excerpt. Confluence excerpt text is converted to a private content hash before Sense event storage; Jira and Confluence source text is not returned in connector API responses. Disconnecting the connector stops new synchronization and lets you revoke the authorization.
On supported work surfaces, the extension reads page metadata and short excerpts needed for a feature you invoke or enable. Secret-like values and common personal identifiers are redacted in the browser, URLs are stripped of query strings and fragments, and content is truncated before transmission over HTTPS to your configured Sense API. Extension settings, encrypted session credentials, and tab-capsule payloads are stored locally. The extension contains no advertising or third-party tracking technology.
Verification pages, Decision Packs, project shares, ledger shares, and judgment records are created only when an authorized user shares or mints them. Public views are designed to omit organization identifiers and private evidence hashes. Share links can be revoked by an authorized workspace user.
05
Sense keeps account and workspace records for as long as the account or customer relationship is active and as needed to provide the selected features. Derived decision and ledger records may remain until an authorized user deletes them or the applicable workspace retention rule removes them. Temporary and guest data is retained only as needed for the session, product continuity, security, and applicable retention controls.
Disconnecting a connector prevents future synchronization but does not automatically erase derived records previously created in the workspace. OAuth tokens are revoked, deleted, or made unusable when the connection or service no longer requires them. Security, billing, and legal records may be retained where law or legitimate operational requirements require it.
For Sense for Jira & Confluence, an authenticated Forge pre-uninstall event immediately revokes or disables credentials bound to the Atlassian cloud site and schedules connector records and Atlassian-derived events, work items, memory, and sessions for deletion within 30 days. A verified reinstall during that window cancels the scheduled deletion. Unrelated Sense projects, ledgers, devices, and other connector data are not removed by an Atlassian uninstall. See the Customer DPA for the contractual terms.
06
We do not sell or rent personal data, share it with data brokers, or use Sense content for cross-context behavioral advertising. We disclose data only to service providers that help us operate hosting, security, communications, support, and related business functions; to a customer workspace's authorized users; when you direct us to share it; or when required for law, safety, rights protection, or a corporate transaction.
Sense may process data in countries other than the one where you live. Where required, Decionis uses contractual and organizational safeguards for international transfers.
07
Sense uses safeguards designed for the sensitivity of the data, including HTTPS/TLS in transit, encrypted credential storage, least-privilege authorization, tenant-aware access controls, secret redaction, content hashing, and security logging. No service can guarantee absolute security, so we also monitor and improve these controls as the product evolves.
If you believe you have found a security issue, contact security@decionis.com and do not include live credentials or sensitive customer data in the initial report.
08
We may need to verify your identity and authority over the relevant workspace before completing a request. You may also have the right to complain to your local data-protection authority. Sense is a business productivity service and is not directed to children under 16; we do not knowingly collect their personal data.
09
We may update this policy as Sense changes. We will revise the effective date and provide additional notice when a material change requires it.
Privacy requests
privacy@decionis.com