Privacy Policy
Last updated: 30 November 2025
This Privacy Policy describes how DecompilerAI Akin Yilmaz (“we”, “our”, “us”) collects, uses, and protects your personal data when you use DecompilerAI at decompiler.ai.
1) Controller Information
- Controller: DecompilerAI Akin Yilmaz
- Address: Industriestraße 59, 50389 Wesseling, Germany
- Email: support@decompiler.ai
2) Data We Collect
| Data Category | Examples | Purpose | Legal Basis (GDPR) |
|---|---|---|---|
| Account Information | Email, username, profile picture, hashed password (e.g., SHA-256) | Account creation, login (including Google Login), profile management | Art. 6(1)(b) – Contract performance |
| Uploaded Content | Programs / files you upload, related decompilation tasks | Providing and operating the neural decompiler service for your requests | Art. 6(1)(b) – Contract performance |
| Metadata of Uploaded Files | Architecture, file size, file format, and other technical characteristics that do not describe program behaviour | Service operation, capacity planning, improving performance and reliability without using the actual program behaviour | Art. 6(1)(f) – Legitimate interest |
| Chat and Interaction Data | Messages you send via the interface, prompts, configuration choices | Providing the Service, showing history, support and troubleshooting, preventing abuse | Art. 6(1)(b), Art. 6(1)(f) |
| Security Data | Device fingerprint, IP address, login and access logs | Cybersecurity, abuse and fraud prevention, ensuring service integrity | Art. 6(1)(f) – Legitimate interest |
| Payment Data | Transaction ID, PayPal metadata, SEPA payment information (processed by payment providers; we do not store card data) | Billing, subscription management, refunds, fraud prevention, tax compliance | Art. 6(1)(b), Art. 6(1)(f) |
| Cookies & Browser Storage | Session cookies, security cookies, authentication tokens in localStorage | Session management, authentication, security, preventing unauthorized access | Art. 6(1)(b), Art. 6(1)(f) |
3) Data Sources
We collect data:
- Directly from you when you create an account, upload files, use chat features, or contact us.
- Automatically through your use of the Service (e.g., cookies, localStorage, device fingerprinting, IP address, logs).
- From third-party providers such as Google (for Google Login) and payment providers (e.g., PayPal, SEPA payment institutions).
4) Use of Data
- Provide, operate, and maintain the DecompilerAI Service, including decompilation and related features.
- Authenticate and secure user accounts and sessions.
- Process payments, manage subscriptions, and handle refunds.
- Ensure cybersecurity, prevent abuse, fraud, and illegal activities.
- Use automated and manual checks to protect the Service, investigate notices or complaints, enforce our Terms, protect third-party rights, and comply with applicable law.
- Improve the Service using technical metadata and independent benchmarks, without using the behaviour of your uploaded programs or chat messages for training.
- Use third-party AI services (for example, OpenAI) to post-process and improve the decompilation result and related outputs for your specific requests, as part of providing the Service.
We treat uploaded files with confidentiality. We do not use your uploaded files, their behaviour, or your chat content to train, fine-tune, or evaluate our models beyond the real-time processing required to provide results to you. Evaluation and long-term improvement of our systems are performed using independent benchmark datasets and technical metadata.
Important: If you are bound by strict confidentiality obligations (for example, NDAs, export control rules, or internal policies), you must ensure you are permitted to upload the relevant code or data to cloud services and third-party processors before using the Service.
5) Data Retention
- Account data: retained for as long as your account is active. Upon account deletion, we delete or anonymize personal data that is no longer required, subject to legal retention obligations.
- Uploads: kept as long as they remain in your account. You can delete uploads via
decompiler.ai/upload. If you delete your account viadecompiler.ai/profile, your uploads are deleted as part of account deletion. - Metadata of uploaded files: may be retained in anonymized or aggregated form after deletion of the original files, for service improvement and statistics, without identifying you or describing program behaviour.
- Payment records: retained for as long as required by applicable German tax and commercial laws (typically up to 10 years).
- Security logs and fingerprints: retained for as long as necessary to ensure the security, stability, and integrity of our Service and to investigate and prevent abuse or attacks, and generally not longer than 12 months unless a longer retention is required in a specific case (for example, for evidence purposes).
6) Sharing of Data
We share personal data only where necessary and with appropriate safeguards, in particular with:
- Google (Google Login and reCAPTCHA): for optional sign-in via your Google account and for spam and abuse prevention on forms. In this context, Google may process technical and interaction data such as IP address, browser and device information, and security-related signals. See Google’s Privacy Policy at https://policies.google.com/privacy.
- Payment providers: such as PayPal and SEPA payment institutions, for processing payments and refunds. See PayPal’s Privacy Policy at https://www.paypal.com/webapps/mpp/ua/privacy-full.
- AI service providers: such as OpenAI, for AI-assisted processing of uploaded or decompiled code, chat content, and related text as part of providing the Service for your requests. For this purpose, we may transmit portions of your uploads, decompiled code, and chat content to such providers, under appropriate contractual and data protection safeguards.
- Hosting and infrastructure providers: we use reputable third-party hosting providers (for example, with data centres in the EU/EEA) to store and process data necessary to operate the Service.
- Professional service providers: such as email providers, security service providers, and similar processors acting on our instructions.
- Authorities and legal recipients: where required to comply with legal obligations or to protect our rights or the rights of others.
7) International Transfers
If personal data is transferred outside the EU/EEA (for example, when using providers based in the United States or other third countries), we ensure that appropriate safeguards are in place, such as adequacy decisions by the European Commission or Standard Contractual Clauses.
8) Your Rights (GDPR)
As a data subject under the GDPR, you have in particular the following rights:
- Right of access (Art. 15) – to obtain confirmation whether we process your personal data and access to that data.
- Right to rectification (Art. 16) – to have inaccurate or incomplete personal data corrected.
- Right to erasure (Art. 17) – to request deletion of your personal data under certain conditions.
- Right to restriction of processing (Art. 18) – to request that we restrict the processing of your personal data.
- Right to data portability (Art. 20) – to receive personal data you provided in a structured, commonly used, machine-readable format and to transmit it to another controller.
- Right to object (Art. 21) – to object to processing based on our legitimate interests, on grounds relating to your particular situation.
- Right to withdraw consent (Art. 7(3)) – where processing is based on your consent, you can withdraw it at any time with effect for the future.
- Right to lodge a complaint with a supervisory authority – you can lodge a complaint with your local data protection authority if you believe your rights have been violated.
To exercise your rights, please contact us at support@decompiler.ai. You are also free to contact your competent data protection authority directly.
9) Cookies & Local Storage
We use cookies and browser storage (such as localStorage) only to the extent necessary to provide and secure the Service.
- Essential cookies: used for session management, authentication, and security (for example, keeping you logged in or protecting against cross-site request forgery).
- Authentication in localStorage: we may store authentication tokens or similar technical identifiers in your browser’s localStorage for secure login and session handling.
We do not use analytics, tracking, or marketing cookies. If this changes in the future, we will update this Privacy Policy and, where required, ask for your consent before setting any non-essential cookies.
10) Security
We implement appropriate technical and organizational measures to protect personal data against loss, theft, misuse, and unauthorized access. These measures include, among others, encryption in transit, access controls, logging, device fingerprinting for security purposes, and regular security monitoring. No system is perfectly secure, but we work continuously to keep risk at an appropriate level for a service of this kind.
11) Age Limit
Our products and services are intended for entities and persons who have reached the age of majority under the laws applicable to them. Younger persons may only use our products and services with the consent and under the responsibility of their parents or legal guardians.
12) Changes
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated “Last updated” date. We encourage you to review this Privacy Policy periodically to stay informed about how we process your personal data.