Decipher Privacy Policy
Privacy Policy
Effective July 26, 2026
Decipher Credit Solutions, Inc. (“Decipher,” “we,” “us,” or “our”) provides a cloud-based origination and underwriting platform used by lenders and other financial-services organizations.
This Privacy Policy explains how we collect, use, protect, share, retain, and delete information through the Decipher platform, our websites, and integrations with services such as Google, Microsoft, Plaid, financial institutions, accounting systems, and other authorized providers.
1. Information We Collect
Depending on how Decipher is used, we may collect:
- Names, business contact information.
- Device, browser, IP address, login, audit, security, and platform-usage information.
- Information received from services that a user or customer connects to Decipher.
Connected accounts and integrations
When a user connects an email, bank, accounting, or other third-party account, Decipher may access information permitted by the user or the user’s administrator.
Depending on the integration, this may include:
- Contact information, messages, attachments, recipients, and message metadata.
- Business information and related financial records.
- User data needed to authenticate the user and maintain the connection.
Users enter their credentials directly with the applicable provider. Decipher does not receive or store the user’s Google, Microsoft, bank, accounting-system, or other third-party password.
Decipher may store secure OAuth or access tokens needed to maintain an authorized connection.
2. How We Use Information
We use information to:
- Provide, operate, secure, and support the Decipher platform.
- Process credit applications and support underwriting, closing, and related workflows.
- Synchronize authorized email, financial, accounting, and other pre-authorized connected-account information.
- Allow users to view, associate, compose, send, reply to, organize, and retain business communications.
- Classify, summarize, validate, and organize documents and data.
- Provide customer-requested artificial-intelligence and automation features.
- Detect fraud, misuse, security incidents, and technical problems.
- Improve the reliability and performance of the Decipher platform.
We only access connected-account information for features authorized by the user, the user’s organization, or the applicable Decipher customer.
3. Google and Microsoft Email Data
When a user connects Google Workspace, Gmail, Microsoft 365, Outlook, or Exchange Online, Decipher accesses email data only through permissions approved during the provider’s authorization process.
Decipher may use authorized email data to:
- Synchronize only incoming and outgoing messages related to applicants.
- Display email within Decipher.
- Send, reply to, or forward messages at the user’s direction.
- Associate messages and attachments with credit applications, companies, contacts, or other records.
- Search, classify, summarize, or extract information for customer-requested workflows.
Decipher requests only the permissions reasonably necessary to provide the enabled features.
Decipher’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
Decipher does not use Google or Microsoft email data:
- For advertising or marketing profiles.
- For unrelated surveillance or monitoring.
- To sell or rent user data.
- To train generalized artificial-intelligence models made available to unrelated customers or third parties.
4. Financial and Accounting Integrations
Decipher may use providers of business financial-data or accounting integrations to obtain information authorized by an applicant, user, or customer.
The user completes authentication directly with the applicable provider or financial institution. Information received through these integrations is used to support the applicable credit application, underwriting, verification, monitoring, or servicing process.
Decipher does not sell information received from financial institutions, accounting systems, or similar integrations.
5. Artificial Intelligence
Decipher may use artificial intelligence and automated processing to classify documents, extract information, summarize communications, identify missing information, detect inconsistencies, and support customer workflows.
Connected email, financial, and customer data may be processed only to provide the applicable Decipher service or customer-requested feature.
Decipher does not use connected Google or Microsoft mailbox data to train generalized models for unrelated customers.
AI-generated information may be incomplete or inaccurate and should be reviewed by an authorized person before it is used for a material lending, credit, legal, or compliance decision.
6. How We Share Information
We may share information:
- With the Decipher customer and its authorized users.
- With requested customer-selected integrations.
- When required by law, regulation, court order, or valid legal process.
- To investigate fraud, misuse, cybersecurity incidents, or threats to users or the platform.
Service providers may use information only to perform services for Decipher and must protect it under appropriate confidentiality and security obligations.
Decipher does not sell personal information or connected-account data. We do not use connected email or financial data for targeted or cross-context behavioral advertising.
7. Security
Decipher maintains administrative, technical, and organizational safeguards designed to protect information, including:
- Encryption in transit and encryption of sensitive data at rest.
- Role-based and least-privilege access controls.
- Tenant-level data separation.
- Protection of OAuth tokens and other credentials.
- Security monitoring, logging, and audit trails.
- Vulnerability management, backups, and incident-response procedures.
- Employee confidentiality and vendor-security requirements.
Decipher hosts its cloud platform using Amazon Web Services and maintains a security program designed around recognized industry standards, including SOC 2 controls.
No system can guarantee absolute security. Users should promptly report suspected unauthorized access or security incidents.
8. Data Retention and Deletion
We retain information only as long as reasonably necessary to:
- Provide the Decipher services.
- Follow customer instructions and contractual retention requirements.
- Maintain applicants, servicing, audit, security, and compliance records.
- Comply with legal obligations.
Users or authorized administrators may disconnect an integration through Decipher or revoke access through the applicable provider.
After access is revoked:
- Decipher will stop obtaining new information through that authorization.
- The applicable access token will be deleted, disabled, or rendered unusable.
- Previously synchronized information may remain when it forms part of a customer’s applicant file, communication record, audit trail, backup, or legal retention requirement.
Users may request deletion through their organization’s Decipher administrator or by contacting Decipher. Because Decipher generally processes information on behalf of its customers, some requests may need to be reviewed or approved by the applicable customer.
Information retained solely in backups will be removed through the normal backup-retention cycle.
9. Privacy Rights
Depending on applicable law, individuals may have the right to request:
- Access to their personal information.
- Correction of inaccurate information.
- Withdrawal of consent.
When Decipher processes information on behalf of a customer, requests should generally be submitted first to that customer.
Decipher may verify a requester’s identity and authority before completing a request.
10. Customer Responsibilities
Decipher customers are responsible for:
- Providing required privacy notices and obtaining necessary authorizations.
- Ensuring they have the right to submit and process information through Decipher.
- Managing user permissions and removing access when no longer needed.
- Configuring integrations and retention requirements appropriately.
- Using information obtained through Decipher in compliance with applicable law.
11. Children’s Privacy
Decipher is a business platform and is not directed to children. We do not knowingly allow children under 13 to create Decipher accounts or connect personal accounts to the platform.
12. Changes to This Policy
We may update this Privacy Policy as our services, integrations, or legal obligations change. The updated policy will be posted on this page with a revised effective date.
Material changes will be communicated when required by law or applicable provider requirements.
13. Contact Us
Questions or privacy requests may be submitted to:
Decipher Credit Solutions, LLC
10411 Motor City Drive, Suite 750
Bethesda, Maryland 20817
info@deciphercredit.com
Phone: 301-710-5447
