Privacy Policy
Last updated: August 15, 2026
Direx Engine is a desktop application published by Decursa ("we," "us," "Decursa"). This page explains what happens to your data when you use it: what stays on your own computer, what reaches our servers, and why. If you only read one section, read the next one.
What happens on your machine
Direx Engine is built so your files never have to leave your computer. When you connect a folder, a network drive, or a cloud account, the app reads what's there and builds a local search index right on your machine, running only while Direx Engine is open. Thumbnails, extracted text, and file metadata are generated locally too.
None of that content, the files themselves, their text, their previews, is uploaded to a Decursa server. If you connect Google Drive or Microsoft OneDrive, the access tokens for that connection are also stored locally, encrypted at rest, in the same local database. We don't keep a copy of your Drive or OneDrive credentials on our servers, because indexing happens on your machine, not ours, so we never need one.
Direx Engine also keeps short operational notices locally, like a note that a storage connection needs to be reconnected. These stay on your machine and are deleted automatically after seven days, the same as everything else in this section.
What we access on Google Drive and OneDrive, and why
If you connect Google Drive, Direx Engine only ever sees the
folders you explicitly choose (the drive.file scope,
granted through Google's own folder picker): enough to list and
read the files inside those folders, and nothing else in your
Drive. In practice the app only ever reads what's there; it doesn't
create, edit, rename, or delete anything. Microsoft OneDrive
access, through Microsoft's Files.Read scope, works
the same way, minus the folder picker. Neither connection is used
for anything beyond building your local search index.
What reaches our servers
Accounts, sign-in, and billing are handled entirely by Clerk, our identity provider - we never see or store your password, and Clerk Billing (built on Stripe) handles payment details directly, so we never see your card number either. See Clerk's privacy policy for what they hold on our behalf.
Our own server stores one more thing: if you post or vote on the community suggestions board, that post or vote is linked internally to your Clerk account ID, so we can enforce posting limits and let you remove your own posts - it's never linked to your email, and never shown publicly with your identity attached. If you delete your Clerk account, we're notified automatically and clean that up: your votes are deleted outright, and any posts you made stay up (they're useful to other users) but are stripped of any connection back to you.
That's the full list. Your files, their content, and your storage-provider tokens aren't part of it, for the reasons above.
Third parties we rely on
- Clerk, for accounts, sign-in, and billing (Clerk Billing, built on Stripe).
- Google, for sign-in and Drive access, if you choose to connect it.
- Microsoft, for OneDrive access, if you choose to connect it.
We don't sell your data, and we don't hand it to anyone for their own marketing.
If you're bringing this into a team or a company
Direx Engine is built today around a single person and their own machine. If several people on a team each use it, each of them runs their own local install and indexes their own files; there isn't yet a shared server deployment, an admin console, or single sign-on. That's worth knowing if you're evaluating it for a company rather than yourself. If you have procurement or security questions we haven't answered here, email us directly and we'll work through them.
How we protect what we do hold
OAuth tokens are encrypted at rest with industry-standard encryption before they ever touch disk. The credential that proves you're on a paid plan is a key signed by Clerk and checked locally by the app; the local app has no way to mint that key itself, so a paid tier can't be self-granted by editing files on your own machine. Passwords, where Clerk uses them, are handled entirely on Clerk's side - we never see or store one ourselves.
Your controls
You can disconnect Google Drive or OneDrive from inside Direx Engine at any time; that clears the local token immediately. You can also revoke access directly from your Google Account or Microsoft Account settings. To delete your account and everything we hold about it, sign in and delete it from your account page - it's immediate, and we automatically clean up your community board data at the same time (see above).
Update checks
The app occasionally checks updates.decursa.com for a newer version. That request logs your country (derived from your IP address, not stored alongside anything that identifies you), platform, and app version, purely so we can see install and update trends. It doesn't touch your files or your account.
Children
Direx Engine isn't directed at children, and we don't knowingly collect data from anyone under 13.
Changes to this policy
If this changes in a way that matters, we'll update the date at the top, and for anything significant, we'll try to tell existing users directly.
Contact
Questions about this policy: info@decursa.com.