Devstiny

Privacy Policy

Effective August 21, 2026

1. Overview

This Privacy Policy describes what information Devstiny (“we”, “us”) collects from you when you use the Service, how we use it, and your choices. We collect as little as possible and do not sell your data.

2. Information we collect

Account data: username, hashed password, optional email address, avatar image (stored as base64 in our database). We do not require a real name or email to create an account.

Usage data: the prompts you type to generate apps, run status and timing, token cost, and error information. This is used to operate the Service and measure costs.

Generated app content: the source code and assets produced for your projects are stored in GitHub repositories under a private organization you do not have direct access to, and deployed via Vercel under our account.

Billing data: if you subscribe or purchase credits, Stripe processes your payment card. We receive a Stripe customer ID and subscription status; we never see your full card number.

Uploaded files: images or files you attach to a prompt are temporarily stored in Vercel Blob and deleted after the run completes.

Server logs: standard HTTP request logs (IP address, user agent, timestamp) retained for up to 30 days for security and debugging purposes.

3. How we use your information

  • To generate, deploy, and maintain your apps.
  • To charge you the correct number of credits and process payments.
  • To detect abuse, enforce rate limits, and protect the Service.
  • To measure and improve the quality and cost of generation.
  • To communicate important changes to the Service (if you have an email on file).

We do not use your prompts to train AI models. We do not share your data with advertisers.

4. Third-party services

We use the following sub-processors to operate the Service:

  • Anthropic — AI model provider. Your prompts are sent to Anthropic's API to generate app code. Anthropic's data handling is governed by their API usage policy.
  • GitHub — stores generated app source code in private repositories.
  • Vercel — hosts the Devstiny dashboard and deploys generated web apps.
  • Neon — hosts our PostgreSQL database containing account and run data.
  • Stripe — processes payments. Subject to Stripe's privacy policy.

5. Data retention

Account data is retained until you delete your account. Run data (prompts, cost, status) is retained indefinitely for operational and billing audit purposes. Uploaded files are deleted after run completion. Server logs are retained for 30 days.

6. Security

Passwords are stored as scrypt hashes. All data is transmitted over TLS. Our database is not publicly accessible. We apply the principle of least privilege to internal service credentials.

No system is perfectly secure. If you discover a vulnerability, please report it to us privately rather than publicly disclosing it.

7. Children

The Service is not directed at children under 16. If you believe a child has created an account, contact us and we will delete it promptly.

8. Your rights

You may request a copy of data we hold about you, correction of inaccurate data, or deletion of your account and its associated data. To exercise these rights, use the feedback button in the dashboard or email us.

If you are in the EU or UK, you also have the right to lodge a complaint with your local data protection authority.

9. Changes

We will update this page when our practices change and update the effective date above. For material changes we will provide additional notice where required by law.

10. Contact

Questions about your privacy? Use the feedback button in the dashboard or email the address on file for the Service.

Terms of ServicePrivacy PolicyHome