close

Privacy Policy

Last updated: August 2026

Overview

This policy explains what data Devkeepr collects, why, and what rights you have over it. It covers both the Devkeepr desktop application and this website.

We collect the minimum we need to run the service. We do not sell your data, and we do not use it for advertising.

Who Is Responsible for Your Data

The data controller is Eser Deniz, a sole trader (entrepreneur individuel) registered in France under SIRET 80104033800023, with registered address at 10 chemin du bergeron, 27930 Huest, France, trading as Devkeepr.

For any privacy question or request, contact support@devkeepr.app.

Using Devkeepr Without an Account

The desktop application is free to download and use with no usage limits. You do not need an account to use its free features.

Everything the application manages on your machine — your projects, file paths, scripts, terminal output, and agent sessions — stays on your device. We never receive it.

What We Collect

Account Information

When you create an account, we store your name, email address, and a hashed password. If you enable two-factor authentication, we also store your 2FA secret and recovery codes in encrypted form.

Legal basis: performance of our contract with you.

Billing Information

Payments are processed by Paddle, which acts as the merchant of record. We never receive or store your card details.

From Paddle we receive and store your billing name and email, your subscription status, renewal dates, and transaction records. Team owners may also set a separate billing email address.

Legal basis: performance of our contract with you, and our legal obligation to keep accounting records.

Devices

When you activate a licence on a device, we record a device identifier, a device name, the app and OS version, the timezone, the IP address last seen, and when it was last active.

We use this to enforce device slot limits on your plan and to help you recognise your own devices when managing them.

Legal basis: performance of our contract with you, and our legitimate interest in preventing licence abuse.

Usage Telemetry

The application sends periodic heartbeats containing a device identifier, a session identifier, session length, app version, OS version, timezone, and IP address. We use this to understand how Devkeepr is used and to prioritise what to build.

If you are signed in, these heartbeats are linked to your account.

Legal basis: our legitimate interest in understanding and improving how the product is used.

Connected Services

If you connect a GitHub or GitLab account to monitor pipelines or deployments, we complete the OAuth exchange on our server and pass the resulting access token to your desktop application. The token is held briefly in our cache during that handover and is not stored permanently on our servers.

We request only the scopes needed for the feature you enabled. You can revoke access at any time from your GitHub or GitLab account settings.

Legal basis: your consent, given when you authorise the connection.

Third-Party Services

We share data with a small number of processors who help us run the service:

Service Purpose What it receives
Paddle Payments, invoicing, tax Your billing details and purchase history
Bento Product and marketing email Your email address and purchase events
Fathom Analytics Website analytics Anonymous, cookie-free page view data
Laravel Nightwatch Application monitoring and error tracking Technical error and performance data
Email delivery provider Sending transactional email Your email address and message contents

Each is bound to handle data securely and only to provide their service to us.

What We Never Collect

Marketing Email

If you subscribe for updates or create an account, we may email you about releases and product news. Every marketing email includes an unsubscribe link, and unsubscribing never affects your access to the service. Transactional email — receipts, password resets, security notices — is sent regardless, because it is necessary to operate your account.

Cookies

This website uses only the cookies required to run it: a session cookie and a CSRF token cookie, plus a "remember me" cookie if you choose that option at login.

Our analytics provider, Fathom, is cookie-free and does not track you across sites. We use no advertising or third-party tracking cookies.

Data Retention

International Transfers

Some of our processors operate outside the European Economic Area. Where data is transferred outside the EEA, it is protected by an adequacy decision or by Standard Contractual Clauses approved by the European Commission.

Your Rights

If you are in the EU or UK, you have the right to:

Email support@devkeepr.app to exercise any of these. We respond within one month.

You also have the right to lodge a complaint with your local data protection authority. In France, this is the CNIL.

Changes to This Policy

If we make changes, we will update the "Last updated" date above. Material changes affecting how we use your data will be communicated by email.

Contact

Questions about this policy? Contact us at support@devkeepr.app.


This policy is effective as of the date listed above.