DevFlow Studios
Sign up now and get 20 free credits to get started.

Privacy Policy

1. The controller

Responsible for data processing:

DevFlow Studios

E-mail: [email protected]

The controller ensures that personal data is processed in accordance with the applicable data protection laws, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).

2. What personal data do we process?

Depending on how you use the service, we may process the following data:

If you use your own API key (BYOK – Bring Your Own Key), we may store the API key in encrypted form so that the service can access it during later use.

We do not use the API key for our own purposes, and we do not sell it or pass it to third parties.

In connection with using the service, we may process:

We do not store card details in our own system; card payments are handled by a specialised payment provider, Stripe.

For the secure operation, debugging and accounting of usage, we may process technical and usage data, for example:

We do not use this data to build advertising profiles.

If you enable two-factor authentication (2FA), we process the 2FA secret required for it and the technical data related to authentication.

3. What do we use the data for?

We use personal data only for the purposes necessary to operate the service, including:

We do not use personal data to create advertising profiles of users.

4. AI requests and external AI providers

When you use the platform’s AI features, we may use external AI providers to process the requests.

The content of the AI request may be transmitted to the relevant AI provider to the extent necessary for the model you selected and for the operation of that service.

The service may provide access to AI models via OpenRouter, among others.

A key you provide as your own API key (BYOK) is not logged and is not used for purposes you have not authorised.

5. Processors and external providers used

To operate the service we use external providers in certain cases. These may include:

These providers can access the data they process only to the extent necessary to operate the service, and their own terms and privacy rules also apply.

6. Protection of API keys

Own API keys are particularly sensitive technical credentials. We therefore do not display them publicly, sell them or publish them.

Where the application supports storing API keys, we handle the keys with appropriate technical protection, in encrypted form.

Important: when providing your own API key, we recommend using only a key created for this purpose and for which you have set appropriate usage restrictions with the relevant provider.

7. Cookies and local storage

The website essentially uses only technologies necessary to operate the service. These may include, for example:

We do not use third-party advertising cookies.

As the service currently operates, we do not use any advertising tracking system or behavioural profiling carried out by third parties.

We measure the use of our pages ourselves, on our own servers, without cookies and without third-party services. We do not store IP addresses: from the IP address, the browser identifier and a secret key we derive a code that changes daily, cannot be reversed and takes a different value the next day.

We record the page opened, the domain, the language, the country of the visit, the device type, the browser and operating system, the referring page and the time spent on the page. We also count calls to our public MCP interface and visits by automated crawlers.

We use this data solely for statistics about the use of our service. We do not share it with third parties and do not build user profiles from it. Raw records are deleted after 90 days; only an anonymous daily summary is kept.

8. Data retention

We retain personal data only for as long as it is necessary to provide the service, to fulfil contractual or legal obligations, or to pursue our legitimate interests.

When a user account is deleted, we delete or anonymise the deletable personal data, taking into account the applicable retention obligations.

Certain transactional, accounting or legally retained data may need to be kept for the period prescribed by law.

9. Data security

We apply appropriate technical and organisational measures to protect personal data, among others against:

However, transmitting data over the internet cannot, by its nature, be guaranteed to be completely secure.

10. Data transfers

Data necessary to operate the service may in certain cases also be transferred to providers operating outside the European Economic Area.

In such cases the transfer must take place on an appropriate legal basis and with the safeguards required by the GDPR.

11. Your rights

Under the GDPR you have, among others, the right:

You can send a request to exercise these rights to the following e-mail address: [email protected]

We handle requests without undue delay, within the time limits set out in the GDPR.

12. Lodging a complaint

If you consider that the processing of your personal data infringes the applicable data protection laws, you have the right to lodge a complaint with the competent data protection supervisory authority.

For users in the European Union this is typically the supervisory authority of their place of residence, place of stay or the place of the alleged infringement.

In Germany, the competent authority may, depending on the specific case and the competence of the controller, be the federal or a state data protection authority.

13. Changes to this Privacy Policy

We reserve the right to amend this Privacy Policy where necessary, for example due to changes in the service, the technologies used or the relevant legislation.

The current version is available on the website at all times.

14. Contact

For privacy questions and access, rectification or erasure requests:

DevFlow Studios

E-mail: [email protected]