Privacy Policy
Last updated September 1, 2026
This policy explains what DevPin collects, why, and what control you have. It covers two groups: customers (people with a DevPin account) and reviewers (people who submit feedback through the widget without an account).
Our role
For customer account data we are the data controller. For feedback submitted through a customer's project, the customer is the controller and we are their processor: we handle that data on their instructions. If you are a reviewer and want your feedback removed, contact the site owner who invited you, or us and we will route it.
What we collect
From customers: email address, display name, project settings, and billing details. Payment card data goes directly to Stripe; we never see or store card numbers.
From reviewers, when they submit feedback:
- The email address they enter.
- The feedback text they write.
- A screenshot of the page at the moment they pinned it, including any drawing they added.
- Page URL and title, and where on the page they clicked.
- Technical context: browser, operating system, device type, viewport and screen size, the CSS selector of the clicked element, recent console errors, and recent failed network requests.
The screenshot is of the page as the reviewer sees it. If your page displays personal or confidential data, that data will appear in the screenshot. Do not install the widget on pages showing information you are not willing to store in DevPin.
Automatically: standard server logs, and product analytics if the customer's deployment has it enabled.
Why we use it
- To operate the Service: store, display, and route feedback to the right project.
- To email reviewers when the issue they reported has been addressed, so they can confirm the fix.
- To send account, billing, and security notices to customers.
- To detect and prevent abuse.
We do not sell personal data, and we do not use your content to train machine-learning models.
Email and opt-out
Reviewers receive a message only when a team marks their report as addressed. Every such email includes a one-click unsubscribe link, and unsubscribing stops all further DevPin email to that address. Customers can likewise unsubscribe from product announcements; we still send essential account, security, and billing notices.
Who we share it with
We use a small number of processors, each under contract and only for the purpose listed:
- Supabase , database, authentication, and file storage.
- Vercel , application hosting and delivery.
- Resend , transactional email delivery.
- Stripe , payment processing (paid plans only).
- Anthropic , only when a customer uses the optional AI fix-prompt feature, and only for the pin being processed.
We also disclose data if legally required, or to protect our rights or the safety of others.
Where data is stored
Data is stored in the United States. If you require data residency in another region, contact us about a self-hosted or region-specific deployment.
How long we keep it
- Feedback and screenshots: until the customer deletes the pin or the project, or closes their account.
- Account data: for the life of the account, then deleted within 30 days of closure.
- Backups: rolling, and overwritten within 30 days.
- Opt-out records: kept indefinitely, because we need them to keep honouring the opt-out.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to processing, and to complain to a supervisory authority. Email privacy@devpin.app and we will respond within 30 days. Customers can delete any pin, project, or their whole account from the dashboard at any time.
Security
- All traffic is encrypted in transit (TLS); data is encrypted at rest.
- Tenant separation is enforced in the database itself with row-level security, not only in application code.
- Screenshots live in a private bucket and are served only through short-lived signed links.
- API tokens are stored hashed and shown once.
- Sign-in is passwordless (magic link), so there are no customer passwords to leak.
No system is perfectly secure. If you believe you have found a vulnerability, email security@devpin.app and we will acknowledge within 3 business days.
Cookies
We use a small number of strictly necessary cookies and local storage entries: to keep you signed in, to remember a reviewer's email on their own device, and to remember dismissed notices. We do not use advertising cookies.
Data processing agreement
If you need a DPA to use DevPin with your clients' data, email privacy@devpin.app and we will send one.
Changes
We will post updates here and, for material changes, notify customers by email before they take effect.