Privacy Policy

Our privacy policy and how we use your data

This Privacy Policy explains how DevTune (the “Company”, “we”, “us”, or “our”) collects, uses, and shares information about you when you use our website and application (the “Service”).

Last updated: 28 August 2026

Who We Are

Controller: PLGeek Ltd, C/O Aardvark Accounting, 1 Cedar Office Park, Cobham Road, Wimborne, BH21 7SB, United Kingdom. You can reach us atprivacy@devtune.ai. If you are an EEA/UK/Swiss resident, we process your personal data as a controller under the GDPR/UK GDPR.

Information We Collect

  • Account & Profile: name, email, password hash, team membership, roles/permissions, and preferences (e.g., language, theme).
  • Billing: plan selection, subscription status, limited billing metadata. Payment card data is handled by Stripe; we do not store full card details.
  • Service Usage: logs of sign-ins, feature usage, and telemetry necessary to secure and operate the Service.
  • Content You Provide: repository URLs, SDK metadata, test configurations, and prompts provided for model testing. Do not include sensitive personal data in prompts or uploads.
  • Device & Technical: IP address, browser type, device identifiers, and performance metrics to protect and improve the Service.
  • Cookies & Similar: see our Cookie Policy for details on preference and essential cookies.

How We Use Your Information

  • Provide, secure, and maintain the Service
  • Authenticate users and enforce authorization and RLS policies
  • Measure usage, troubleshoot issues, and improve performance
  • Process payments, subscriptions, and invoices
  • Communicate about updates, security, and support
  • Comply with legal obligations and enforce our Terms

Google User Data

Google Search Console and Google Analytics 4 connections are optional. DevTune accesses Google user data only after a project manager starts the relevant connection and authorizes the read-only permission shown by Google.

Data We Access

  • Google Search Console: the properties available to the authorizing Google account, property permission information, sitemaps and URL inspection results, and Search Analytics performance such as dates, pages, queries, clicks, impressions, click-through rates, and positions.
  • Google Analytics 4: account and property names, web data stream details, configured key events, and daily aggregate reports covering dates, landing pages, hostnames, streams, traffic sources, mediums, channels, sessions, engaged sessions, engagement duration, and key-event totals.

DevTune requests only the Google Analytics and Search Console read-only scopes. We do not request permission to edit Google data, import raw GA4 events, or access individual Google account profile or email data through these connections.

How We Use Google User Data

We use Google user data only to provide and improve DevTune's customer-facing features: comparing classic search with AI visibility and AI Demand, avoiding recommendations that would put search-performing pages at risk, attributing aggregate AI-referred sessions and selected conversions, measuring Outcomes, and producing the project reports or managed-agent analyses a customer requests.

Storage And Sharing

OAuth refresh tokens are stored as encrypted secrets. Imported Google data is stored in the project that authorized the connection, protected by encrypted transport, role-based access controls, and tenant-isolating row-level security.

We do not sell Google user data or use it for advertising, credit decisions, or training generalized artificial-intelligence or machine-learning models. We share it only with service providers acting on our behalf where necessary to provide or improve a customer-requested feature, for security, or as required by law. When a customer asks a DevTune managed agent to analyse project data, the relevant project-scoped aggregates may be sent to the AI model provider solely to produce that requested result.

Retention And Deletion

Disconnecting Google Search Console or Google Analytics 4 stops future syncs and removes the stored OAuth credential. Historical aggregate performance data already imported may remain available to the project until it is removed under our retention or account-deletion processes. You can request deletion of Google-derived data by emailing privacy@devtune.ai.

If we change how DevTune uses Google user data, we will update this policy and provide any notice or consent required before using that data for a new purpose.

Legal Bases (GDPR)

  • Contract: to provide and support the Service at your request (e.g., account creation, running tests, billing).
  • Legitimate Interests: to secure the Service, prevent fraud, and understand product performance in privacy-preserving ways.
  • Consent: for non‑essential cookies/analytics where required by law.
  • Legal Obligation: to comply with tax, accounting, and regulatory requirements.

Sharing And Disclosure

We share data with vendors acting as processors, including:

  • Cloud infrastructure, authentication, and database providers to operate the Service (e.g., managed Postgres/auth/storage).
  • Payment processors to handle subscriptions and invoices.
  • Optional analytics/service monitoring providers to improve reliability and UX.
  • AI model providers to execute tests you request. We minimize data shared to what’s necessary for the test.

We do not sell personal information. We may disclose information if required by law or to protect our rights, users, or the public. See our Subprocessors page for our current vendor list.

Current Service Providers (Subprocessors)

We use trusted service providers acting as processors to deliver the Service. The specific providers may vary by region and feature set:

  • Stripe (payments and subscription billing)
  • Sentry (error tracking and performance monitoring)
  • Vercel (application hosting and delivery)
  • Inngest (job orchestration and scheduled workflows)
  • Supabase (database, authentication, and storage)
  • Resend (transactional email delivery)
  • PostHog (analytics and product insights - EU region)
  • AI model providers — customer-requested tests, reports, and managed-agent analyses

We will maintain appropriate data protection terms with each processor and update this section as our infrastructure evolves.

International Transfers

We may transfer personal data outside your country (including to the United States). Where required, we use appropriate safeguards such as Standard Contractual Clauses.

Data Retention

We retain personal data for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. We use documented retention rules and remove or anonymize data when no longer needed.

API activity logs used for account governance are retained for up to 30 days. Client metadata (IP address and user agent) is only included in these logs when explicitly enabled by configuration.

Security

We use technical and organizational measures including role-based access control (RBAC), row-level security (RLS), encrypted transport, hardened cookies, audit logging, and least-privilege defaults. No security measure is perfect; we encourage responsible disclosure.

Your Rights

Depending on your location, you may have rights to access, correct, delete, or port your data, and to object to or restrict certain processing. You can exercise rights by contactingprivacy@devtune.ai.

California residents may have additional rights under CCPA/CPRA (e.g., to know, delete, and correct). We do not sell or share your personal information for cross‑context behavioral advertising.

Children

The Service is not directed to children under 16 and we do not knowingly collect their personal data. If you believe a child has provided us personal data, contact us for removal.

Changes To This Policy

We may update this Privacy Policy to reflect changes to our practices or legal requirements. Material updates will be indicated here.

Contact

Controller: PLGeek Ltd, C/O Aardvark Accounting, 1 Cedar Office Park, Cobham Road, Wimborne, BH21 7SB, United Kingdom.

Email: privacy@devtune.ai