Privacy Policy
1. Who we are
getdev.ai ("we", "us") is the controller of the personal data you provide. We are Kynosura, Inc., a corporation incorporated in the State of Delaware, United States, with its principal office at 651 N Broad St, Suite 206, Middletown, DE 19709, USA. For privacy questions: [email protected].
We are a US company, and members in the European Economic Area, the United Kingdom and California have specific rights described in section 7.
2. What data we collect
| Category | What | Source | |---|---|---| | Account data | Email, GitHub ID, GitHub login, display name, avatar URL, handle | You + GitHub OAuth | | Profile data | Bio, location, links, availability, preferences | You | | Subscription data | Stripe customer ID, subscription status, billing dates | Stripe | | Content you publish | Ships (titles, taglines, descriptions, URLs, screenshots, tags, dates) | You | | Usage data | Ships you appreciate, ships you flag, views of your profile | Platform interaction | | Analytics data | Aggregated page views, traffic sources, country codes (no IP addresses retained) | Server logs (transient) | | Audit data | Records of significant actions you take (sign-up, publish, cancel) | Platform |
What we don't collect:
- We don't collect your IP address beyond the moment of request (Cloudflare passes country code, the rest is discarded).
- We don't track your activity on other websites.
- We don't fingerprint your device beyond what Stripe does for fraud prevention.
- We don't access your GitHub repositories beyond the moment of OAuth (no long-lived tokens stored).
- We don't sell your personal information, and we don't share it for cross-context behavioural advertising.
3. Why we collect it
| Data | Purpose | Legal basis (EEA / UK) | |---|---|---| | Account, profile, content | To provide the service | Contract (Art. 6(1)(b)) | | Subscription data | To process payments and manage your subscription | Contract | | Aggregated analytics | To operate, secure, and improve the service | Legitimate interest (Art. 6(1)(f)) | | Audit data | To detect abuse and comply with law | Legitimate interest + legal obligation | | Email for transactional notifications | To deliver service-related messages | Contract |
4. Who we share it with
These are the processors we use today:
| Processor | Purpose | Location |
|---|---|---|
| Railway | Infrastructure hosting (web, api, worker, database, cache) | EU — Netherlands (europe-west4) |
| Cloudflare | DNS, CDN, DDoS protection, R2 image storage, email routing | Global edge; EU region for stored objects |
| Stripe | Payment processing, subscription management | US, with EU/UK entities for local customers |
| GitHub | Sign-in (OAuth). We receive your profile; we store no access token | US |
| Google | Destination inbox for mail sent to our support addresses | US |
We don't sell your data. We don't share it with advertisers. We don't share it for marketing analysis.
If we add a processor — for example an email-delivery provider, an error-tracking service, or a model provider used to draft ship descriptions — we will update this page before that processor handles member data.
We may disclose data when legally required (court order, statutory obligation) — see our Transparency report at getdev.ai/transparency.
5. How long we keep it
| Data | Retention | |---|---| | Active member account data | While your account is active | | After voluntary cancellation | Profile private immediately. All personal data anonymised at 30 days | | Payment and invoice records | 7 years, to meet US tax and accounting requirements | | Audit log entries | 2 years from event date; cancellation events kept indefinitely (with actor anonymised after deletion) | | Aggregated analytics (no PII) | Indefinitely | | Backup snapshots | 30 days |
6. Where your data is stored, and international transfers
Our application servers and primary database run in the European Union (Railway, Netherlands), and stored images sit in Cloudflare's EU region. We are a US company, so our staff access that data from the United States, and some processors (Stripe, GitHub, Google, Cloudflare's global edge) process data in the US.
For transfers of EEA and UK personal data to the United States we rely on the European Commission's and the UK government's adequacy decisions for the EU-US and UK-US Data Privacy Framework where the recipient is certified, and on Standard Contractual Clauses with the UK Addendum otherwise, together with supplementary technical measures such as encryption in transit and at rest.
7. Your rights
If you are in the EEA or the UK, under GDPR and UK GDPR you have the right to: access your data (we provide a JSON export via your dashboard); rectify inaccurate data (most fields you can edit directly); erase your account and personal data; restrict processing; object to processing based on legitimate interest; receive your data in a portable, machine-readable format; and withdraw consent where we rely on it. You are not subject to automated decision-making with legal or similarly significant effect — we don't do that.
If you are a California resident, under the CCPA as amended by the CPRA you have the right to know what personal information we collect and why, to request deletion, to request correction, to receive a portable copy, and to opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights.
Wherever you are, you can export or delete your data from your dashboard.
To exercise any right: email [email protected] or use the relevant button in your dashboard. We respond within 30 calendar days (usually much faster), free of charge except in exceptional cases. We may need to verify your identity before acting on a request.
8. Cookies and similar technologies
See our Cookie Policy at getdev.ai/cookies.
9. Children's privacy
The service is not for children under 16. We don't knowingly collect data from anyone under 16. If you believe we have, contact us and we'll delete it.
10. Changes
We update this policy from time to time. Material changes: email notice 30 days in advance.
11. Contact and complaints
- Privacy questions: [email protected]
- We are not required to appoint a Data Protection Officer at our size. Privacy requests go to the address above and are handled by the founder.
- If you are in the EEA or the UK and think we have handled your data badly, you can complain to your national supervisory authority — in the UK, the Information Commissioner's Office at https://ico.org.uk/make-a-complaint. We would like the chance to resolve it directly first.
- If you are in the US, you may also contact your state attorney general.
Effective date: 2026-08-20. Last updated: 2026-08-20.