DevAny.aiBack to home

Data Processing Facts

Effective date: August 25, 2026

DevAny LLC — Wyoming, United States · 30 N Gould St, Ste R, Sheridan, WY 82801, USA · Registration no: 2026-002023768 (Wyoming SoS) · hello@devany.ai · +1 (213) 585-1343

The factual answer to a procurement or legal review asking what DevAny does with your data. This page is not a signed data processing agreement (DPA); it is the factual annex a DPA would need. If you require an executed agreement, write to hello@devany.ai — this page is the input to that conversation. Controller/processor: DevAny LLC, Wyoming, United States.

1. What we do NOT claim — stated first

No certifications (no independent security certification is held or in progress). No published uptime commitment (SLA). No regional data-residency option. No SSO/SCIM. No penetration-test report. No named data protection officer — privacy questions go directly to the contact address.

A customer who requires any of the above is not sold on the promise that it is coming.

2. Roles

For ACCOUNT data (who signed up, what was billed, support correspondence) DevAny is the CONTROLLER.

For data INSIDE a customer's generated apps (appointments, records, the app's own end users) DevAny is a PROCESSOR acting on the customer's instructions — that data belongs to the customer.

Generated-app end users are a separate identity domain: they never become DevAny organization members; a Team customer's own customers are not our users.

3. AI processing — the part business customers ask about

Every textual generation goes through ONE gateway; there is no silent rerouting — if the gateway is unavailable the request fails with a stated reason. The model that ran is named by canonical id, and any in-chain fallback is disclosed with its reason.

We do NOT train models on customer data: DevAny operates no training pipeline, does not opt customer content into training and has no mechanism to do so. Upstream providers' own terms apply to what passes through the gateway; a privacy option asking providers not to train on business data is on by default.

Prompts and outputs are stored in your own account so you can see history and restore versions.

4. Security posture — what is actually true

Row Level Security on the database; the application layer deliberately holds no privileged key — privileged operations happen only in audited server functions.

Generated apps run inside a sandboxed iframe and are never injected into the platform interface.

Admin consoles sit behind device-verified Zero Trust access, and each door accepts only its own identity.

Data is encrypted in transit and at rest. Daily encrypted backups are taken and restore drills are verified automatically.

5. Subprocessors and timelines

The maintained subprocessor list is on the Subprocessors page; a new service touching customer data is added there in the same change.

When an account is deleted, account, app and content data are removed; only invoice/transaction records that must legally be kept are retained for their statutory periods. Personal-data rights requests are answered within 30 days at the latest.