1. Introduction
This Privacy Policy describes how DevlogKit ("we," "us," or "our") collects, uses, and shares personal information when you use our website and services (collectively, the "Service"). By using the Service, you agree to this policy and to our Terms of Service.
2. Information we collect
2.1 Account and profile
When you register or sign in, we collect information such as your name, email address, and credentials. Authentication and account data may be processed by our identity provider (Supabase).
2.2 Billing
If you subscribe to a paid plan, our payment processor (Stripe) collects payment method and billing details. We receive limited billing metadata (for example subscription status and customer identifiers) needed to provide the Service.
2.3 Content you provide
We store content you upload or create in the Service, such as media files, project details, drafts, outreach contacts, and settings. This may include personal information if you include it in your content.
2.4 Connected accounts
If you connect third-party accounts (for example Google for YouTube or Gmail, Bluesky), we receive tokens and profile information as permitted by those connections to perform the features you enable.
2.5 Technical and usage data
We may collect logs, diagnostics, and usage information to operate, secure, and improve the Service (for example IP address, browser type, timestamps, and error reports). We do not use third-party advertising cookies on the core application for cross-site tracking; if we add analytics or marketing pixels, we will update this policy.
3. How we use information
We use information to:
- Provide, maintain, and improve the Service;
- Process subscriptions and communicate about your account;
- Run features you request (including AI-assisted generation and publishing integrations);
- Detect, prevent, and address fraud, abuse, and security issues;
- Comply with legal obligations and enforce our terms;
- Communicate service-related notices and, where permitted, product updates.
4. Legal bases (EEA, UK, and similar regions)
Where GDPR or similar laws apply, we rely on one or more of the following: performance of a contract with you; legitimate interests (for example security and product improvement), balanced against your rights; consent where we ask for it (for example optional marketing); and legal obligation where required.
5. How we share information and subprocessors
We share information with service providers that process data on our behalf under appropriate agreements. Categories include:
| Category | Typical providers | Purpose |
|---|---|---|
| Authentication and database | Supabase | Accounts, application data |
| Payments | Stripe | Billing and subscriptions |
| Media storage | Cloudflare R2 | Storing uploaded files |
| AI | OpenAI | Generating content you request |
| Transactional email | Postmark | Sending system and outreach-related email |
| Background jobs | Inngest | Processing asynchronous tasks (for example uploads) |
| OAuth platforms | Google, Bluesky, and other OAuth providers (as you connect) | Features you enable |
We may also disclose information if required by law, to protect rights and safety, or in connection with a business transaction (for example merger) subject to appropriate safeguards.
6. Retention
We retain information for as long as your account is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Backup copies may persist for a limited period. You may request deletion as described below, subject to legal exceptions.
7. Security
We implement administrative, technical, and organizational measures designed to protect personal information. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
8. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, or export your personal information, object to or restrict certain processing, and withdraw consent where processing is consent-based. California residents may have additional rights under the CCPA/CPRA (including knowing categories of data collected and requesting deletion, subject to exceptions).
To exercise rights, contact us at [email protected]. We may verify your request. You may also lodge a complaint with your local data protection authority (EEA/UK).
9. International transfers
We may process information in the United States and other countries where we or our providers operate. If we transfer personal data from the EEA, UK, or Switzerland, we use appropriate safeguards such as Standard Contractual Clauses where required.
10. Children
The Service is not directed to children under 13 (or the age required by local law). We do not knowingly collect personal information from children. If you believe we have, contact us and we will take appropriate steps.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and change the "Last updated" date. Where required, we will provide additional notice.
12. Contact
For privacy questions or requests, contact [email protected].