Skip To Content
DevClashBack To Home

Privacy Policy

Revision 6 October 2026. How DevClash handles local usage, cloud sync and the information you choose to share on desktop, web and mobile.

Last Updated October 6, 2026
FUTUREFORGE LABS SRLStr. Ion Țuculeșcu nr. 8C, Timișoara, Timiș, RomaniaTrade Register: J35/705/2024 · Fiscal Code: 49616330EUID: ROONRC.J35/705/2024hello@devclash.ai

On This Page

Controller And ScopeLocal Desktop UsageAccount And Service InformationVisibility And CommunicationsWhy We Process InformationStorage, Security And ProvidersRetention And Account DeletionYour Choices And RightsPolicy Changes

01Controller And Scope

FUTUREFORGE LABS SRL is the controller for personal data processed through DevClash: Str. Ion Țuculeșcu nr. 8C, Timișoara, Timiș, Romania; registration J35/705/2024; fiscal code 49616330; EUID ROONRC.J35/705/2024. Contact hello@devclash.ai for privacy matters.

This policy covers the website, desktop software, mobile applications and cloud/community services. AI providers and third-party sites have their own policies. Accounts and community services are intended for people aged 16 or older who also meet local eligibility requirements. Contact us if you believe an account is used by a child under 16.

02Local Desktop Usage

The desktop app can track supported usage without signing in. It reads supported local usage sources and, for some integrations, requests usage information directly from your AI provider using credentials available on your device. Local provider requests are governed by that provider's policies.

DevClash cloud usage sync sends usage metadata. It does not upload prompts, replies, source code, raw log contents, file paths or provider credentials. This restriction concerns automated usage collection; information you deliberately submit in a project, message, image or support request is content you choose to send. Do not submit secrets or confidential information. Mobile displays synced usage and does not monitor other mobile applications.

03Account And Service Information

An account stores your email, account identifier, sign-in/session records and connected-device labels. Supported Apple/Google sign-in stores the provider identifier and email needed to identify or link your account. Apple may provide a relay address when you choose Hide My Email. An encrypted Apple refresh token may be retained to revoke the linked grant when you delete the account. Your account email and authentication tokens are not public-profile fields.

When desktop sync is enabled, the service receives usage identifiers, provider/model names, token counts, timestamps and estimated costs. These records support usage history, deduplication, credit calculations and the optional participation choices you enable. Disabling sync stops future uploads from that device; it does not remove records already stored.

Community features store the content and actions needed to provide them: profile fields, selected city, projects and images, updates and roadmaps, stack/workflow details, requests/replies, follows/saves, votes, credits, testing reservations and feedback, circle/session activity, notices, reports, blocks, and moderation/dispute records. Private conversations store their participants, messages and applicable delivery/read state. The server also stores the revision and timestamp of your express community-terms acceptance.

Your selected city is a community choice, not GPS tracking. Virtual Travel temporarily associates your profile with a different city's online community and can generate an arrival notice. It does not determine your actual location. DevClash mobile does not request location, address-book, microphone or camera access for these features. Selecting an image uses the system picker and submits the image you choose.

04Visibility And Communications

Cloud sync, public-profile visibility and ranking participation are separate choices. Supported profile fields and projects become visible according to their publication settings. Rankings use client-reported usage and do not verify professional ability. Public content may be copied outside DevClash. Private messages are intended for their conversation participants; authorized service access may be needed to investigate a report, secure the service or comply with law.

Other users' activity can generate in-app notices. Where enabled, email preferences control supported community emails. Optional mobile notifications require your device permission and in-app registration. The service stores an installation identifier, platform and push token linked to the current session. Expo and the Apple/Google notification networks deliver a generic notification and routing identifiers; the current push payload does not contain private-message text. Disable notifications in the app or device settings. Disabling delivery may leave the registration stored until it is removed or the associated session/account is deleted.

05Why We Process Information

We use information for these defined purposes and GDPR bases:

Requested service, Article 6(1)(b): identify your account, establish sessions, deliver sign-in codes, link a requested identity provider, store/display enabled synced usage, and provide the specific profile, project, conversation, testing or community action you request. Necessary account/service fields must be provided for those features to function; optional publication and sync choices do not become mandatory.

Security and reliable operation, Article 6(1)(f): protect accounts and other users, rate-limit repeated sign-in/actions, detect abuse or manipulated usage, investigate failures and resolve community disputes. Our interests are a secure, usable service and fair community participation. We must assess necessity and balance these interests against users' rights, with particular care for younger users.

Legal obligations, Article 6(1)(c): respond to valid legal requirements and applicable data-rights requests, but only to the extent an obligation applies.

Consent where required, Article 6(1)(a): use a separate, specific permission for an optional processing activity where applicable law requires consent. Device notification permission and optional feature controls are choices; acknowledging this notice is not general consent. Consent can be withdrawn without affecting earlier lawful processing.

DevClash does not make an automated decision with legal or similarly significant effects about you through its usage ranking or credit features. This notice does not authorize advertising profiling or sale of your personal information.

06Storage, Security And Providers

Web sign-in uses an HttpOnly, same-site cookie; native account sessions use platform-protected storage. Sessions expire after 30 days and can be revoked. Email codes are single-use and expire after ten minutes. The web app stores appearance/layout preferences locally. Local browser or device storage is separate from the cloud account.

Railway hosts the application and PostgreSQL database. Resend processes email addresses and message content for supported email delivery. Apple/Google process supported sign-in, and Expo with APNs/FCM processes optional mobile push. GitHub distributes public desktop installers and source. Open-Meteo supplies city-search results: DevClash sends search text/country or a city identifier from its server, without forwarding your account identifier, email or device IP. Bunny supplies domain-name services. Network/infrastructure providers can process technical connection information; external image hosts and linked sites receive requests when their content is loaded or opened. Their independent services are governed by their own policies.

We restrict service access to authorized operation, security and support purposes. Authentication secrets are protected separately from public profile data. Encryption and access controls reduce risk but cannot guarantee absolute security.

Providers can process information outside your country, including the United States. Resend publishes that email content and logs are stored in the United States regardless of sending-region selection. Railway describes US primary processing with local-storage options. Railway's standard terms incorporate its applicable Data Processing Addendum, and Resend states that its addendum is executed automatically at signup; their addenda describe Standard Contractual Clauses and applicable Data Privacy Framework mechanisms. Expo also describes US transfers and Data Privacy Framework participation. You can request information about the relevant safeguards and how to obtain a copy at hello@devclash.ai. These are published standard-provider terms, not a claim of a separately countersigned agreement, a verified bespoke contract or EU-only processing.

07Retention And Account Deletion

Account and community records remain in the active service while needed to provide your account and the actions/history you request. Delete individual supported content or your account through Settings. Account deletion removes the account and associated service records from the active database, revokes its sessions and removes linked account records. Apple-linked deletion first attempts provider-grant revocation; a provider failure leaves the account available for a retry instead of silently claiming deletion. You may request deletion without opening the app at https://devclash.ai/delete-account or by emailing hello@devclash.ai from your account address. Identity verification may be needed. Uninstalling an app or disabling sync does not delete the cloud account.

Expired sessions and OAuth flows are eligible for background cleanup; sign-in challenges become eligible after one day, and sign-in rate-limit buckets after two days. Eligibility and expiry do not promise an exact deletion instant if the cleanup job is interrupted. Other security, moderation and support records are retained only for the relevant investigation, unresolved request, service-recovery need or legal requirement, and we delete or de-identify them when that purpose ends.

Provider retention is separate. Resend publishes 30-day email/log retention for its standard Free, Pro and Scale plans and seven-day backups; enterprise terms can differ. Open-Meteo publishes 90-day individual API logs. Expo says notification content is held only for delivery to Apple/Google, while push tokens may remain stored. Railway logs depend on the account plan, and its documentation says a plan upgrade can make older logs visible again; dashboard availability is not a guarantee of irreversible erasure. These are provider-published practices, not a single deletion deadline for every DevClash record.

Scheduled database backups have provider retention of six days for daily backups, 27 days for weekly backups and 89 days for monthly backups. Manual rollback snapshots do not expire automatically. We remove each manual snapshot no later than 30 days after creation unless a specific incident or legal hold is documented, and remove an exceptional copy when that identified need ends. Account deletion from the active database does not immediately remove data from existing backups. There is no universal 90-day maximum for every copy because documented exceptions can last longer. Backup access is for recovery/security, not ordinary product use. We maintain a minimal account-deletion record while a retained backup can require it and reapply deletions before restored data returns to normal use.

Other people's copies of public content and third-party information outside DevClash are not erased by deleting a DevClash account. Local device data can be removed through the relevant device/app controls. Applicable law can require limited retention; any such exception must be specific to that obligation or dispute, rather than a general right to retain a deleted account indefinitely.

08Your Choices And Rights

Settings provide supported profile/visibility controls, sync choices, notification preferences, blocked-builder management, device revocation, account export and deletion. Declining new community terms does not prevent the available account export/deletion and safety controls.

Depending on the conditions in applicable law, you can request access, correction, erasure, restriction, portability or objection to processing. Where processing depends on consent, you can withdraw it. Contact hello@devclash.ai; we may verify your identity using proportionate information. Do not send passwords or sign-in codes. Requests will be handled within the periods required by applicable law, including any permitted extension with an explanation.

You can complain to the Romanian National Supervisory Authority for Personal Data Processing, ANSPDCP, at https://www.dataprotection.ro, or another competent supervisory authority. Exercising a right does not require accepting optional publicity or notifications.

09Policy Changes

Published revisions will show their revision date. Material changes will be explained before they take effect where required, with a separate request for consent when the law requires it. The service records acknowledgment of the applicable policy together with express acceptance of the community terms; that record does not replace any purpose-specific consent.

Read The Terms Of Use →Return To DevClash →
DevClash

Track your AI usage privately. Share your work when you’re ready.

Download App

Product

  • Usage Tracking
  • Credits
  • Virtual Travel
  • Leaderboard
  • FAQ

Get Started

  • Download App
  • Explore The Demo
  • Community
  • Sign In / Sign Up

Legal

  • Privacy Policy
  • Terms Of Service
  • Support
  • Account Deletion
  • GitHub Releases

© 2026 DevClash. All rights reserved.

Available For macOS, Windows & Linux