DevFlowAI
Back

Privacy Policy

Last updated: April 2026

1

What We Collect

DevFlow AI collects only what is necessary to operate: account information (name, email) via Better Auth, standup entries and sprint data you create, GitHub repository data you explicitly connect for codebase analysis, and usage preferences and settings.

2

What We Do Not Collect

We do not sell your data. We do not run analytics or ad tracking. We do not store your API keys. They live in your environment variables only. We do not have access to the database you host yourself.

3

Third Party Services

DevFlow AI integrates with the following services. Each has its own privacy policy you should review:

4

Data Storage

All application data is stored in the PostgreSQL database you provision and control. If you are self-hosting, you have complete control over your data. If using a managed deployment, refer to your hosting provider's privacy policy.

5

Authentication

Authentication is handled by Better Auth. Credentials are stored in your own database with passwords securely hashed, and Google sign-in is available via OAuth.

6

AI Processing

When you use AI features, your content (standup entries, code chunks) is sent to the Anthropic and OpenAI APIs using your own API keys. Review their privacy policies for how they handle API inputs.

7

Your Rights

You can delete your account and all associated data at any time from Settings → Danger Zone. This permanently removes your data from the database.

8

Contact

For privacy concerns, open an issue on the GitHub repository.

Have questions?

Open an issue on GitHub

View on GitHub