Back to home

Privacy Policy

Last updated: July 14, 2026

This Privacy Policy explains what data Dev Server Deck, operated by logIC & ViZion("we"), collects, why, and what your rights are. We collect the minimum needed to run the Service.

1. Data We Collect

  • Account data: your email address and a hashed password (we never store plaintext passwords).
  • Billing data: handled by Stripe. We store your Stripe customer and subscription identifiers, plan, and subscription status - never card numbers.
  • Agent data: names you give your machines, hashed Agent Tokens, connection status, and last-seen timestamps. Project names, paths, commands, and logs are relayed between your browser and your machine in real time and are not stored on our servers.
  • Usage data: a daily counter of start/stop actions, used to enforce free-plan limits.
  • Security data: at each sign-in we record the time, IP address, and browser user-agent, and (if you enable two-factor authentication) a 2FA secret and hashed backup codes. This is used to secure your account - detecting new-device logins, alerting you, and showing recent sign-in activity - not for tracking or advertising.

2. Cookies

We use a single, strictly necessary session cookie to keep you signed in - it does not require consent under GDPR/ePrivacy since it is essential to providing the Service, not used for tracking, analytics, or advertising. Your theme preference (light/dark) is stored in your browser's local storage, not a cookie, and is never sent to our servers. We do not use analytics or advertising cookies of any kind. If this changes in the future, we will add a cookie consent option before doing so.

3. What We Do Not Collect

We do not store your source code, environment variables, or terminal output. The relay forwards this data transiently between your browser and your machine and keeps no copy. We do not sell personal data or use it for advertising.

4. Legal Basis & Purpose (GDPR)

We process account and billing data to perform our contract with you (Art. 6(1)(b) GDPR), and minimal usage counters as a legitimate interest in enforcing plan limits (Art. 6(1)(f)).

5. Processors

  • Stripe - payment processing.
  • Turso - database hosting for account, agent, and usage records.
  • Resend - transactional email delivery (verification, password reset, account notices).
  • Vercel - web application hosting.

6. Retention & Deletion

Account data is retained for as long as your account exists - we do not currently delete accounts for inactivity alone. Deleting your account yourself, at any time, from Account & Billing immediately removes your user record, agents, and usage counters from our production database. Billing records are retained by Stripe as required by tax law regardless of account deletion. Database backups, where they exist, may retain deleted data for a limited period before being overwritten by newer backups.

7. Your Rights

You may request access, correction, export, or deletion of your personal data at any time by contacting info@devserverdeck.com, or by using the self-serve account deletion feature in Account & Billing. If you are in the EU/EEA, you also have the right to lodge a complaint with your local supervisory authority.

8. Security

Passwords are hashed with bcrypt; Agent Tokens are stored only as SHA-256 hashes and shown once at creation. All traffic is encrypted in transit in production.

9. Changes

Material changes to this policy will be announced via email or in-app notice before taking effect.

10. Contact

logIC & ViZion - privacy questions: info@devserverdeck.com.