our privacy commitment
at decoy, we believe privacy is a fundamental human right. we've built our platform with privacy at its core, not as an afterthought. this means we collect only what we need, we don't track you, and we give you control over your information.
introduction
this privacy policy describes how WhosAt LLC, the company that operates Decoy ("Decoy," "we," "us," or "our"), handles your information when you use our privacy and identity platform, including the Decoy app, our website at decoys.me, and related services (collectively, the "services"). WhosAt LLC is the data controller responsible for your information.
privacy principles
our approach to privacy is guided by these core principles:
- data minimization: we first ask whether identifiable data is necessary. if it is not, we do not collect it; if it is, we limit the fields and retention period
- on-device processing: where practical, sensitive processing happens on your device instead of on decoy's backend
- protecting identity: where the service does not need to know who you are, we prefer random identifiers, keyed hashes, aggregation, or deidentification over directly identifying information
- no tracking: we don't track your behavior across the web or build advertising profiles
- no sale of data: we never sell your personal information to anyone
- user control: you decide what information to share and can delete it anytime
- transparency: we're clear about what we collect and how we use it
- security first: we use technical and organizational safeguards appropriate to the data and the way it is processed
what is personal data at decoy?
we treat any data that relates to an identified or identifiable individual, or that decoy can reasonably link to one, as "personal data." a hash or pseudonymous identifier may still be personal data if it remains linkable to a person. we call information deidentified only when direct and indirect identifiers—including full ip addresses and linkable account or device identifiers—have been removed so the information can no longer reasonably identify a person.
information decoy handles
it is important to distinguish information you save with decoy from information decoy can read. we use three data categories, followed by a separate explanation of agent access.
encrypted user data
encrypted user data is information you enter into the vault or autofill features, such as usernames, passwords, passkeys, TOTP secrets, secure notes, custom fields, names, addresses, email addresses, phone numbers, and other account details you choose to save.
this information is encrypted on an authorized client before it is stored by decoy's backend. decoy stores and synchronizes the resulting ciphertext, but does not receive a readable copy and does not hold the unwrapped vault key required to decrypt it. you provide encrypted user data to the product, but you do not disclose its readable contents to decoy.
recovery bundles are stored in encrypted, wrapped form together with the salt, nonce, version, and KDF iteration count needed by an authorized client to attempt recovery. decoy does not receive the recovery secret or the unwrapped private key.
published encryption and recovery parameters
for the current version of decoy's recovery format:
- vault content is protected with AES-256-GCM using a randomly generated 256-bit vault key held by authorized clients
- the recovery key-encryption key is derived on the client using PBKDF2-HMAC-SHA-256 with 600,000 iterations, a random 32-byte salt, and a 32-byte derived key
- the recovery bundle is encrypted using AES-256-GCM with a random 12-byte nonce and a 128-bit authentication tag
- where access is granted to an authorized agent, key material is wrapped to that agent's registered public key using RSA-OAEP with SHA-256; the agent unwraps and uses it in its own environment
these parameters describe the current versioned formats and may be strengthened in later versions. stored records include the format version and parameters necessary for compatible authorized clients to decrypt them. changing parameters does not give decoy the recovery secret, vault key, or readable vault content.
service data
service data is the limited information decoy can read or generate while operating the services. it may include:
- an account identifier and authentication records
- a hashed account or forwarding-email identifier where used by the service
- device type, operating-system and app version, and registered device or push-notification identifiers
- decoy email addresses and their status
- dates, timestamps, item counts, storage size, feature settings, and subscription status
- ip address and server or security logs where necessary for authentication, abuse prevention, reliability, or troubleshooting, subject to the retention principles below
- agent names, public keys, requested permissions, approved resources, grant duration, token status, revocation state, and access records
we retain only the service data reasonably necessary to operate, secure, support, and improve the services or comply with law. service data does not include the readable contents of encrypted user data.
email delivery data
email is not the same as vault storage. to receive, filter, forward, send, and deliver disposable email, decoy and its infrastructure providers process message contents and attachments, sender and recipient addresses, message headers, routing information, delivery state, spam and abuse signals, and timestamps.
stored message bodies may be encrypted, but email necessarily exists in readable form at parts of the delivery pipeline. we minimize access and retention, but do not describe email transport as zero-knowledge.
authorized agents and connected apps
when you approve an agent or connected app, decoy may deliver encrypted content or key material wrapped to that agent. decoy's backend does not decrypt the vault content, but the authorized agent may decrypt and use the information covered by its grant. the agent is therefore a trusted recipient chosen by you.
what we don't collect or use
to be clear about what we don't do:
- we don't collect browsing history outside our platform
- we don't receive readable copies of encrypted user data from a conforming client
- we don't require health or financial information for a basic account; if you deliberately save sensitive information in your vault, decoy stores it as ciphertext
- we don't use persistent identifiers to track you across websites
- we don't create user profiles for advertising purposes
how we use your information
we use your information only for these purposes:
to provide our services
- create and maintain your account
- provide customer support
to improve our services
- analyze how our platform is used (in aggregate)
- identify and fix technical issues
- develop new features
- conduct internal research and development
to communicate with you
- respond to your inquiries
- send important service notifications
- provide security alerts when necessary
for security and fraud prevention
- protect our platform from abuse
- detect and prevent fraud
- enforce our terms of service
- comply with legal obligations
we will never use your data for purposes beyond those described here without your explicit consent.
how we protect your information
security isn't just a feature—it's fundamental to how we operate.
technical safeguards
- TLS encryption for data in transit
- client-side authenticated encryption for supported vault and autofill content; decoy's backend does not hold the unwrapped vault key needed to read that content
- encryption at rest and access controls for other stored data
- secure oauth 2.0 authentication
- internal security review, testing, and vulnerability remediation
- secure infrastructure with industry-standard protections
organizational safeguards
- strict access controls (employees access only what they need)
- privacy-by-design in all development
- incident-response and security-review procedures
limits of vault encryption
- authorized devices hold keys that can decrypt vault content
- an agent you approve for secret access may receive encrypted content or wrapped key material and decrypt it in the agent's environment; that agent is a trusted recipient
- email is not equivalent to vault content and must be processed in readable form during receipt, filtering, forwarding, sending, and delivery
- operational metadata such as identifiers, timestamps, routing information, permission records, and security logs may not be end-to-end encrypted
recovery
decoy cannot restore a vault solely from a forgotten master password. recovery requires a recovery key or another authorized device that retains the necessary key material. decoy stores recovery material in wrapped form but cannot use it without the user's recovery secret.
your role
- use strong, unique passwords
- enable two-factor authentication if available
- keep your login credentials confidential
- report suspicious activity immediately
data retention
we retain personal data only for as long as necessary for the purpose for which it was handled, or as required by law. when setting a retention period, we first ask whether identifiable information needs to be retained at all. if retention is necessary, our policy is to use the shortest feasible period and then delete or deidentify the information.
- encrypted user data: while your account is active, until you delete the item, or until account deletion is completed. decoy cannot read this ciphertext
- service data: only while needed to operate and secure the account, provide support, prevent abuse, satisfy financial or legal obligations, or resolve disputes
- email delivery data: only while needed for delivery, user-requested storage, abuse prevention, troubleshooting, or applicable legal requirements
- support communications: until the request is resolved and for the limited follow-up or legal period that applies
- aggregated or deidentified data: may be retained longer because it is no longer reasonably linkable to an individual
when you request account deletion, we begin deleting or deidentifying account-linked personal data, subject to operational backup cycles and information we must retain for security, fraud prevention, dispute resolution, financial reporting, or other legal obligations. where we must retain a record, we limit it to what is necessary and separate or deidentify it where feasible.
sharing your information
we share your information only in these limited circumstances:
service providers
we use service providers for functions such as hosting, email delivery, analytics, authentication, notifications, and customer support. they process information as needed to provide those services, subject to their agreements with us and applicable law.
legal requirements
we may disclose information when required by law, such as:
- in response to valid legal process (subpoenas, court orders)
- to protect rights, property, or safety
- to prevent fraud or abuse
- to comply with regulatory requirements
where legally permitted and appropriate, we may notify you of a legal request concerning your information.
our website uses limited analytics and browser storage to understand use of the site, remember session state, and measure signups or downloads. we do not use this information for advertising or to build profiles of your activity across unrelated websites.
your privacy rights
you have control over your information. depending on your location, you may have additional rights under applicable law.
access your information
request a copy of the personal information we hold about you.
correct your information
update inaccurate or incomplete information through your account settings or by contacting us.
delete your information
request deletion of your account and eligible personal information, subject to the retention limits described above.
request your information
request a copy of eligible account data. available formats and feature coverage may vary until we publish a documented vault-export format.
opt out of communications
unsubscribe from marketing emails anytime (service emails may still be sent).
revoke permissions
review and revoke connected-device and agent permissions.
object to processing
object to how we process your information for specific purposes.
lodge a complaint
contact your local data protection authority if you have concerns we haven't addressed.
to exercise your rights:
email us at [email protected] or use your account settings. we may verify your identity before fulfilling a request and will respond within the period required by applicable law.
international data transfers
our service providers may process information in countries other than your own. we handle international transfers as required by applicable law.
children's privacy
our services are not directed to children under 13 (or the equivalent minimum age in your jurisdiction). we do not knowingly collect information from children. if we learn that a child provided personal information in violation of this section, we will take appropriate steps to delete it.
parents: if you believe your child has provided us with information, contact us immediately at [email protected].
california privacy rights
if you're a california resident, you have additional rights under the california consumer privacy act (ccpa):
right to know: what personal information we collect, use, and share
right to delete: request deletion of your personal information
right to opt-out: we don't sell personal information, so there's nothing to opt out of
right to non-discrimination: we won't discriminate against you for exercising your rights
european privacy rights
if you're in the european economic area, uk, or switzerland, you have rights under the gdpr:
- right to access, rectification, erasure, and data portability
- right to restrict or object to processing
- right to withdraw consent
- right to lodge a complaint with your supervisory authority
our legal basis for processing includes:
- performance of contract with you
- your consent (which you can withdraw)
- our legitimate interests (balanced against your rights)
- legal compliance
changes to this privacy policy
we may update this privacy policy to reflect changes in our practices or for legal reasons. when we make material changes:
- we'll post the updated policy with a new effective date
- we'll notify you via email or platform notification
- where required, we will ask for consent before applying a change
if a security incident requires notice, we will notify affected users and authorities as required by applicable law.
contact us
for privacy inquiries:
- data controller: WhosAt LLC
- email: [email protected]
- website: https://www.decoys.me/privacy
we will respond as required by applicable law.
last updated: august 11, 2026
© 2026 decoy. all rights reserved.