Privacy Policy
Last updated: September 7, 2026
Our Commitment to Your Privacy
DevSpec is a developer productivity platform. We understand that you share project data, code, and technical information with us. We treat your data with the utmost care and confidentiality.
1. About DevSpec
DevSpec ("we", "our", or "us") is an AI-powered developer productivity platform. We provide intelligent development sessions through AI technology to help you plan, build, and ship software more effectively.
This Privacy Policy explains how we collect, use, disclose, and protect your personal information, including sensitive personal data, when you use our service.
2. Information We Collect
Account Information
When you create an account, we collect:
- Email address
- First name
- Display name and profile preferences
- Authentication data via our identity provider (Clerk)
Session Data
During your sessions, we collect and store:
- Your messages and questions
- AI-generated responses
- Session transcripts
- Files you upload (documents, images)
- Voice recordings (if you use voice input)
Context and Memories
To provide continuity across sessions and give you contextual assistance, we build a "context" about you and your projects that may include:
- Your display name and preferences
- Projects, repositories, and databases you've connected
- Code patterns, architecture decisions, and technical preferences
- Development goals and action items from your sessions
- Topics, frameworks, and technologies you work with
Your Control: You can view, export, or delete all of this context data at any time through your Privacy Settings. Deleting your context gives you a fresh start - the AI will treat you as a new user.
Usage Information
We automatically collect:
- Session dates and duration
- Feature usage (voice, text, file uploads)
- Usage for billing purposes
- Error logs for debugging
Payment Information
Payment processing is handled by Stripe. We do not store your full credit card details. We receive only confirmation of successful payments and subscription status.
3. How We Use Your Information
To Provide Support
- Process your messages through AI to generate supportive responses
- Build and maintain context so the AI remembers you across sessions
- Transcribe voice messages for text-based processing
- Generate voice responses when requested
To Improve Our Service
- Debug issues and monitor performance
- Analyze aggregate usage patterns (not individual conversations)
We do NOT use your conversations, context, or personal information to train AI models.
4. AI Provider Data Sharing
Important: To provide AI-powered support, certain data is sent to third-party AI providers. Here is exactly what each provider receives:
Anthropic (Claude) - Primary AI Provider
Receives:
- Your display name
- Your messages in the current session
- Your project context (repositories, code patterns, technical preferences)
- Session transcripts for context updates and memory extraction
- Any files you upload (images, documents, code)
Mistral AI - Code Search Embeddings
When your repositories are indexed for semantic search, receives:
- Code and file snippets from repositories you connect (to compute search embeddings)
- No conversations, personal information, or account details are sent
Voyage AI - Search Embeddings for Session Transcripts and Search Re-ranking
So that past sessions can be found by meaning, and so that code and action-item search return the most relevant results first, receives:
- Text of session transcripts (to compute search embeddings)
- The text of a code search query together with the code snippets it matched, to order them by relevance (re-ranking)
- The text of an action-item search query together with the titles and descriptions of the action items it matched, to order them by relevance (re-ranking)
- No account details are sent
OpenAI - Search Embeddings for Project Knowledge
So that action items, memories and documents can be found by meaning, receives:
- Text of action items, memories and uploaded documents you choose to make searchable (to compute search embeddings)
- No personal information or account details are sent
Deepgram - Voice Transcription
If you use voice input, receives:
- Audio recordings of your voice messages only
- No personal information or context is sent
Google Cloud Text-to-Speech - Voice Responses
If you use voice responses, receives:
- The AI's response text only (to convert to speech)
- No personal information about you is sent
AI Training Data Assurance
Your conversations are NOT used to train AI models. All our AI providers have explicit policies excluding API data from model training:
- Anthropic: API data excluded from training under Commercial Terms
- OpenAI: API data not used for training since March 2023
- Mistral AI: we have opted out of model training on API data
- Voyage AI: we have opted out of model training on API data
- Deepgram: Zero-retention defaults for real-time transcription
- Google Cloud: Text-to-Speech API data is not used to train models
Provider Data Retention
AI providers typically retain API data for up to 30 days for abuse monitoring and service improvement, then delete it. This is standard practice for AI services and is separate from model training. Your data stored in DevSpec is retained until you delete it.
5. Other Third-Party Services
| Service | Purpose | Data Shared |
|---|---|---|
| Clerk | Authentication | Email, name, login activity |
| Stripe | Payments | Billing info (processed by Stripe directly) |
| Supabase | Database & Storage | All application data (encrypted at rest) |
| Hetzner | Hosting | Server logs, performance metrics |
| Turbopuffer | Search index hosting (EU region, Ireland) | Search embeddings and text snippets of your connected code, session transcripts, action items, memories and uploaded documents; no account details |
| Inngest | Background Processing | Job metadata, session IDs (not content) |
6. Organizations
DevSpec is built around organizations. Every person has one, and teams create more. An organization owns the work its members do in DevSpec: its projects, its rooms (sessions) and the messages in them, its action items, memories, artifacts, uploaded files and the search indexes built from its connected repositories.
Rooms are shared by design
Everyone in a room sees everything said in it, by people and by agents. You see the organizations and projects you belong to and the rooms you are in, and nothing outside them.
The organization pays for the work done in its projects. Its Owners and Admins manage members, billing and settings and can see the balance, spend and each member's usage. An Owner can export everything the organization owns and can delete the organization (section 9).
7. Data Security
Your Data is Protected at Every Layer
Isolation is enforced at the organization and project boundary. A member reaches only the organizations and projects they belong to, and a room only if they are in it; one organization's data is never mixed into another's.
We implement robust security measures to protect your data:
- Encryption in transit: All data transmitted over TLS/HTTPS
- Encryption at rest: Database and file storage encrypted using AES-256
- Access follows membership: Database policies and application checks limit every read and write to the organizations, projects and rooms the person belongs to
- Authentication: Secure login through an industry-leading provider (Clerk) with optional two-factor authentication
- Stored files and downloads: Files live in private storage and are served only through short-lived signed links issued after an access check
- Access controls: Database access is restricted to essential infrastructure operations. We do not read your rooms in the course of operating the service; they are processed by the AI providers described in section 4
8. Data Retention
- Work data (rooms and messages, action items, memories, artifacts, uploaded files, code indexes): kept by the organization that owns it until it deletes it or the organization is deleted. Deleting an organization removes its projects, rooms, files and search indexes.
- Account data (sign-in, profile, preferences, notifications, saved connections and tokens): kept while your account is open and removed when you close it. Messages and work you contributed stay with the organizations they belong to, attributed to "Former member".
- Inactive accounts: an account unused for two years is closed after notices 30, 7 and 1 day before, unless it is the only owner of an organization; then we email instead and leave it open.
- Payment records: an organization's payment history and ledger are kept after the organization is deleted or an account is closed, for at least seven years, to meet financial record-keeping obligations.
- Exports you request: available to download for 7 days, then removed.
- Logs: request and application logs are kept for 30 days.
- AI provider retention: up to 30 days by providers, then deleted (section 4).
9. Your Rights and Controls
Who is responsible for what
For the work done in an organization (rooms, action items, memories, artifacts, files and code indexes) the organization is the controller and DevSpec processes that data on the organization's instructions. For your account and identity data (sign-in, profile, preferences, notifications, connections) DevSpec is the controller. A request about an organization's records goes to that organization; DevSpec acts on the organization's instruction. A request about your account comes to us.
Four controls, in the product:
Export Your Data
Settings → Data & Privacy → Request my export. A zip with your profile and preferences, your memberships, every message you wrote with the room it was in, your notifications, your usage and ledger entries in dollars, and the files you uploaded. It is prepared in the background; we tell you when it is ready and the download works for 7 days. Large exports arrive in numbered parts.
Close Your Account
Settings → Data & Privacy → Close my account. Your sign-in, saved connections and tokens, preferences and notifications are removed and you cannot sign in again. Messages and work you contributed to your organizations stay, shown as "Former member". A workspace that only you own, with nobody else in it, is deleted with your account, and the confirmation names it. If you are the only owner of an organization that has other members, transfer ownership first.
Export Your Organization's Data
Settings → Organization → Request the organization's export(Owners only). A zip with every project and repository record, action items with their history, memories, artifacts as markdown, uploaded documents, every room with every participant's messages and attachments, discussion points, plans, polls, goals, features, automations, members and roles, and the ledger. Prepared in the background, ready within minutes, downloadable for 7 days.
Delete Your Organization
Settings → Organization → Delete organization(Owners only). The organization's projects, rooms, files, search indexes and its sign-in group are removed for everyone in it; its payment history is kept. Your only organization cannot be deleted on its own: closing your account is the way to remove it.
GDPR & CCPA Rights
Under applicable privacy laws, you also have the right to:
- Access - Request details about what data we hold
- Rectification - Correct inaccurate data
- Portability - Receive your data in a standard format
- Restriction - Limit how we process your data
- Objection - Object to certain processing activities
For your account data, use the controls above or email us atprivacy@devspec.aifor access, rectification, restriction or objection; we answer within 30 days. For an organization's records, ask an Owner or Admin of that organization: they can export or correct them, and we act on their instruction.
10. Cookies & Analytics
Essential Cookies (Always Active)
We use minimal cookies required for the service to function:
- Authentication cookies - Required to keep you logged in (Clerk)
- Session cookies - Required for security and database access
- Preference cookies - Remember your settings (e.g., sidebar state)
Analytics (Optional, Requires Consent)
With your consent, we collect first-party performance measurements (Core Web Vitals) to keep the app fast. We do not currently use any third-party analytics service; if we adopt one in the future, it will sit behind the same consent and this policy will be updated first.
What analytics collects:
- Page load and responsiveness timings (Core Web Vitals)
- The page the measurement came from
- General device info (browser type, connection speed)
What analytics NEVER collects:
- Your conversations or messages
- Personal information (name, email, etc.)
- Anything you share in your sessions
- Your personal context or memories
You can change your analytics preference anytime in Privacy Settings.
We do not use advertising cookies, tracking pixels, or sell data to advertisers.
For detailed information about specific cookies we use, see our Cookie Policy.
11. International Data Transfers
Your data may be processed in countries outside your residence, including the United States, where our AI providers are located. We ensure appropriate safeguards are in place for international transfers, including Standard Contractual Clauses where required by GDPR.
12. Age Requirements
DevSpec is intended for adults. You must be at least 18 years old to use this service. We do not knowingly collect personal information from anyone under 18.
13. AI Output Disclaimer
Important: DevSpec provides AI-generated suggestions, code, and analysis. While designed to be helpful, AI output may contain errors or inaccuracies. Always review AI-generated content before using it in production. DevSpec is a productivity tool, not a substitute for professional judgement and thorough testing.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email and/or through the app. Your continued use after changes constitutes acceptance.
15. Contact Us
For privacy questions, data requests, or concerns, contact us:
- Email: privacy@devspec.ai
- Privacy Settings: Manage your data
By using DevSpec, you acknowledge that you have read and understood this Privacy Policy. Your trust means everything to us - we are committed to protecting your privacy and the sensitive information you share.