1. Who operates this service
DecaCap Builders is a service name used by Ryan Stephens, an individual operator based in Austin, Texas, United States. Use the Support page or ryanking@ryanliketheking.com for privacy questions or requests.
2. Information the service handles
- Verified identity: the email address and display name supplied by Sign in with ChatGPT.
- Account content: optional biography, saved workflow state, role and model settings, and account preferences.
- Provider credentials: cloud API keys you choose to save. Keys are encrypted before durable storage and are never returned to the browser after saving.
- Private files: uploaded source files plus extracted text and file metadata needed for Workbench document distribution.
- Feedback and operations: feedback or support requests you submit, rate-limit records, and security audit events.
- Discovery aggregates: daily counts of public knowledge-page views and defined conversion actions, grouped by page, referral host, source, medium, campaign, and target. The service does not retain a raw per-visitor discovery history, advertising identifier, IP address in the report, or search query.
- Subscription records: plan and status information if paid subscriptions are activated; payment-card details are handled by the payment provider, not stored by DecaCap Builders.
3. How information is used
Information is used to authenticate you, enforce access, save workflows, run requests through cloud providers you select, distribute imported text within your chosen workflow, measure whether public documentation leads to useful actions, respond to feedback and support, prevent abuse, investigate failures, and meet legal obligations. DecaCap Builders does not sell personal information or use it for targeted advertising. A Google Search Console CSV imported into the administrator report is parsed only in that browser session and is not uploaded to or stored by DecaCap.
4. AI providers and infrastructure
When you execute a box, the prompt, selected system instructions, and any support material you explicitly distribute are sent to the provider assigned to that box under your provider account. Provider handling is governed by that provider’s terms and privacy policy. Hosting, database, and object-storage vendors process information only as needed to operate the service.
5. User-owned local models
The local companion address, pairing token, model files, prepared datasets, adapters, and training logs remain on the user's device. Local inference and training requests travel directly between the browser and the loopback companion. DecaCap's hosted server does not receive the pairing token or local model artifacts.
6. Retention, backups, and deletion
Account data is retained while your account exists and as needed for security, dispute resolution, tax, or legal compliance. Operational logs are ordinarily retained for 90 days; minimized billing and transaction records may be retained for up to seven years where reasonably needed for accounting, disputes, or law. Encrypted backups use a 90-day rolling retention period and are removed through the backup lifecycle after expiry. Deleting an account removes active service data listed below; encrypted backup copies age out under that schedule and are isolated from ordinary product use. You can export account metadata and permanently delete your DecaCap Builders account from Account settings. Deletion removes saved workflows, encrypted provider keys, uploads and extracted text, hosted training-preparation records, feedback and support requests tied to your account email, audit events tied to your account, and the local app profile, subject to the limited billing/legal retention above. Local companion files remain under your control on your own computer and must be removed there. Provider-side records remain subject to the provider’s policy.
7. Security
The service uses server-side authorization, tenant ownership checks, encrypted provider-key storage, same-origin mutation checks, rate limits, restricted file types and sizes, security headers, and audit records. No internet service can promise absolute security. Report suspected exposure through Support without including the secret itself.
8. Your choices and requests
You may access the data shown in Account, export account metadata, delete saved provider keys and files individually, disable automatic local learning, remove the browser-stored pairing configuration, or delete the account. Use Support for correction, access, deletion, or accessibility requests that the interface does not resolve.
9. Children
The service is not directed to children under 13 and does not knowingly collect their personal information. Users must also satisfy the minimum age required by the identity and AI providers they choose.
10. Changes
Material changes will be reflected by a new effective date and, when appropriate, an in-product notice. Continued use after an effective update means the revised policy applies going forward.