DevAny.aiBack to home

Privacy Policy

Effective date: October 4, 2026

DevAny LLC — Wyoming, United States · 30 N Gould St, Ste R, Sheridan, WY 82801, USA · Registration no: 2026-002023768 (Wyoming SoS) · contact@devany.ai

DevAny LLC (based in Wyoming, United States; "DevAny", "we", "us") provides an AI-powered app building service at devany.ai. This policy explains what data we collect when you use the service, why we collect it, and how we protect it.

1. Data we collect

Account data: When you sign in with Google we receive the basic profile your Google account shares, such as your name, email address and profile picture. If you register with email/password we store your email and a secure hash of your password.

Usage data: The apps you create, the instructions (prompts) you provide, generated content, your credit transactions and basic usage logs.

Assistant conversations: Messages you exchange with the in-product DevKitty Assistant are stored so we can support you and improve the product. They are readable only by DevAny administrators, are never used to train models, and are deleted automatically after 90 days.

Technical data: Session cookies, your language and theme preference, and standard logs needed to operate the service.

2. Why we process data

To create your account and sign you in.

To generate, store and host the apps you request.

To manage your credit balance and usage.

To keep the service secure, prevent abuse and meet our legal obligations.

Legal basis for each purpose (GDPR Art. 6 / KVKK Art. 5): account creation, generation, hosting and billing — PERFORMANCE OF A CONTRACT; keeping transaction and invoice records — LEGAL OBLIGATION; security, abuse prevention and service improvement — LEGITIMATE INTEREST (balanced against your rights); usage measurement and marketing communication — CONSENT (collected separately, withdrawable at any time). The service is never conditioned on consent.

We do not carry out solely automated decision-making or profiling.

3. AI providers

Your AI requests (app builds, chat, assistants, image/video/speech generation) pass through a single gateway: Vercel AI Gateway (Vercel Inc., US). The gateway forwards each request to the developer of the model you or the platform selected, or to a host that serves that model. Most requests, defaults and Auto use Anthropic, OpenAI and Google models; the model picker also offers models from Z.ai (Zhipu), DeepSeek, xAI, Mistral AI, Alibaba (Qwen), Moonshot AI, MiniMax and Meta (Llama), and for images and video from Black Forest Labs, ByteDance and Kling AI. Some of these developers are established outside the US and the EU (e.g. in China); when such a model runs — by your choice or in a platform step that uses one (e.g. the multi-model council, translation, a fallback chain) — your request may be processed there. The current list is on the Subprocessors page.

Providers process your instruction to produce the response; the instruction and output are stored by us, associated with your account, so you can see your history. DevAny does not train models on customer content; Vercel's and the model providers' own terms apply to what passes through the gateway.

We recommend not including secrets, personal health/financial data, or sensitive third-party data in your prompts.

4. Payment and billing data

Payments are processed by Stripe. Your card number, expiry date and security code NEVER reach our servers; the payment screen is Stripe's own page, and only Stripe sees and stores those details.

Your billing details (billing address, tax ID if provided, payment method details and invoice history) are held by Stripe. What stays on our side is: your sign-in identity (email, display name), which plan you are on, your credit balance, and the records accounting requires — amount paid, date, and the invoice/customer identifiers Stripe issues.

You reach your invoices and payment method through the Stripe customer portal, opened from the Billing page in your account.

5. Data sharing

We do not sell your data. We share it only with the providers needed to deliver the service: authentication, database and file storage (Supabase), hosting, DNS and encrypted backups (Cloudflare), the AI gateway (Vercel AI Gateway) and the model providers behind it, payments (Stripe), email delivery (Resend), error monitoring (Sentry — error records scrubbed of personal data) and GitHub Actions, which runs our backup jobs. Only when you use the feature: stock photos (Unsplash, Pexels) and Sign in with Google.

We may disclose data to authorities where required by law or a valid legal request.

International transfers: the company and its infrastructure providers are established mainly in the US and the EU; the primary database runs in the EU (Frankfurt) and your data is processed in these countries. When a model from a provider established outside the US and the EU runs, that request may be processed there (see §3). Transfers from the EEA/UK rely on our providers' Standard Contractual Clauses (SCCs) and, where available, their EU-US Data Privacy Framework participation; for transfers from Türkiye see the KVKK Notice. The current subprocessor list is published on the Subprocessors page.

6. Connected AI apps

You can connect a third-party AI assistant (for example ChatGPT, Claude or Cursor) to your DevAny account in two ways: through "Sign in with DevAny", where the assistant asks for access and you approve it on a DevAny consent screen, or with an API key you create in Settings → API & MCP and give to the assistant yourself. Nothing is connected unless you do one of these.

You decide what a connection may do. On the consent screen you choose the permissions (scopes) and exactly ONE workspace; you can narrow what the assistant asked for, never widen it. For an API key you choose the permissions and an optional expiry when you create it; a key can act in the workspaces your account belongs to, and only in those. Platform administration access can never be granted to a connected app, and customer accounts cannot create an administration key. A connection never acts with more authority than your own account has.

A connected assistant acts as you, and only within the permissions you granted. Depending on them, it can read and manage your projects, publish them, start builds and other AI work that spends your AI Credit, and read or write your projects' data — including what visitors submitted to your sites and apps, such as form leads and appointment bookings. Actions that spend AI Credit, delete something, or affect many projects, an organization or a transfer are refused until the assistant repeats them with an explicit confirmation. Assistants are told to give that confirmation only after you agreed to that exact action, but DevAny cannot see your conversation with the assistant and cannot verify that you did. A connected assistant cannot make purchases: payment pages are completed by a person.

When you use a connected assistant, the data it requests from DevAny (project details, page text, records, leads, appointments and the like) is sent to that assistant's provider (for example OpenAI or Anthropic). The provider processes it under its own terms and privacy policy, in its relationship with you; DevAny does not control that processing and is not responsible for it. A connected assistant is a destination you choose, not a DevAny subprocessor — even where the same company appears on our Subprocessors page as a model provider, here it acts under its own terms with you.

For the data inside your sites and apps (your visitors' submissions, bookings and records) you are the controller, and DevAny processes it on your instructions (see Data Processing Facts). Connecting an assistant and letting it read that data is your instruction: you decide whether to share your visitors' data with that provider, and you are responsible for having a legal basis to do so and for informing your visitors.

What we store about a connection: for "Sign in with DevAny" — the name and redirect addresses the app declared when it registered (self-declared, and shown to you as unverified), the network address it registered from, the permissions and workspace you granted, and when the connection was created and last used; for an API key — its name, its first few characters, its permissions, its expiry, and when it was created, last used and revoked. Keys and tokens are stored only as one-way hashes: the full key is shown to you once, and the full token is never stored. An access token is valid for about 1 hour; the app renews it with a refresh token that is replaced on every use (valid for up to 30 days), and if an old refresh token is ever reused, the whole connection is revoked. These records are tied to your account, kept while it exists and deleted with it.

Activity log: for each tool call a connected assistant makes, and for each change and most refused requests it makes over plain HTTP, we record which key or connected app made it, the tool or the route pattern (not the full address), the method, the result and error code, the workspace, the project concerned, and the time. The log never contains what was sent or returned — no request bodies, no results, no prompts and no visitor text. Entries are deleted automatically after 90 days; once the feature is switched on for your account, "Recent activity" in Settings shows the last 30 days.

You can end a connection at any time: disconnect an app in Settings → Connected apps, or revoke a key in Settings → API & MCP. Access ends within a minute; the app can also revoke its own connection. Ending a connection does not delete data the provider has already received — ask that provider about it under its own policy.

We do not sell connection data or the data you share through a connection, and we do not use it to train AI models.

7. Data retention

We retain your data while your account is active. You can delete your account yourself from Settings, or request deletion at the address below; deletion removes your account, apps and content.

Periods by data type: account and app data — until account deletion; invoice and transaction records — the minimum statutory period required by tax and commercial law; server/security logs — limited, reasonable technical periods; measurement data — the provider's configured retention. Records whose statutory period has passed are deleted or anonymized.

8. Security

We protect data with industry-standard measures including encryption in transit and at rest, row-level security (RLS) and access controls. No system is 100% secure, but we exercise reasonable care.

9. Your rights

You have the right to access, correct, delete, restrict processing, OBJECT to processing, and receive your data in a structured, machine-readable format (portability). Where processing relies on consent, you may withdraw it at any time with future effect.

To exercise these rights, write from the address linked to your account to contact@devany.ai; we answer within 30 days at the latest, free of charge. You can also download a copy of your data yourself via "Download my data" in Settings.

If you are not satisfied with our answer you may lodge a complaint with a supervisory authority: the Personal Data Protection Board (KVKK) in Türkiye, your national data protection authority in the EEA, or the ICO in the UK.

10. Cookies

Alongside the strictly-necessary cookies that keep you signed in, we use first-party functional cookies to remember your interface preferences (such as language, theme, tone, accent color, layout, and tour state). We also use Google Analytics (GA4) and Google Ads conversion tracking to measure use of the site and of the signed-in console — but only with your explicit consent; without it no measurement cookie is written. We do not profile you, sell your data, run social-media pixels, or track you across other sites for advertising.

Functional cookies are only written with your consent; see the Cookie Policy (devany.ai/cookies) for the full list and preference management.

11. Changes

We may update this policy from time to time. For material changes we will update the effective date and notify you where appropriate.

12. Contact

Questions? Reach us at contact@devany.ai.