Effective September 14, 2026 · THD Agentic Systems LLC
This Privacy Policy describes how THD Agentic Systems LLC (“Cloud Decoded,” “we”) collects, uses, and protects information in connection with the Cloud Decoded platform. It applies to workspace owners and any users they invite. It does not apply to the infrastructure data your agents process (CI/CD logs, IaC files, cluster state) except as described in Section 3 below.
We collect:
When an agent runs, it processes only what's needed for that specific task — log excerpts, config file contents, PR diffs, or resource state from the systems you've connected. Every piece of that text passes through a redaction layer before it reaches any LLM provider: API keys, credentials, and PII patterns are stripped first, regardless of provider. Data is sent to the LLM provider you configure (Anthropic or OpenAI) under that provider's own API terms — it is not used to train Cloud Decoded's own models, and we do not control or guarantee a specific provider's training-data policy beyond what that provider states for API traffic.
We use the information above to:
We share information with a limited set of sub-processors necessary to run the Service: the LLM provider you configure (Anthropic or OpenAI), Stripe for billing, and our infrastructure/hosting providers. A current sub-processor list is available on request.
Audit log entries are retained indefinitely and never modified once written — this is a security requirement, not a default we can turn off. Cancelling a subscription does not immediately delete your data; it archives it, so a subsequent deletion request can be honored unambiguously. To request deletion of your workspace's credentials and personal data, contact privacy@theclouddecoded.com once your subscription is cancelled — we will confirm once your credentials and contact information have been purged. Billing and audit records may be retained after deletion where required for legal, accounting, or security-audit purposes.
Every table in our database is scoped by workspace with row-level security enforced at the database layer. Connected-system credentials are encrypted at rest and decrypted only for the duration of the specific call that needs them. Full detail is on the Security page.
Depending on your location, you may have rights to access, correct, or delete your personal information, or to object to certain processing (for example, under GDPR or CCPA). To exercise any of these rights, contact privacy@theclouddecoded.com. Enterprise customers with specific data-processing requirements should request a Data Processing Agreement.
The Service is intended for business use and is not directed at individuals under 18. We do not knowingly collect information from anyone under 18.
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated effective date on this page.
Questions about this policy: privacy@theclouddecoded.com