Devoku · Last updated: August 3, 2026
lawyer and matched to your actual, finalized data practices.
Effective date: August 3, 2026
Last updated: August 3, 2026
Version: privacy-policy-2026-08-03
This Privacy Policy explains how Coded, UAB ("Devoku",
"we", "us") collects, uses, shares, and protects personal data when you use
the Devoku hosted service, applications, and website (the "Service").
For the managed Devoku Cloud service, Devoku is the data controller for
account and service data described here. When you use Devoku to process data on
behalf of an organization or team, Devoku may act as a processor on your behalf;
see Section 10 and the Data Processing Addendum.
Self-hosted note. If you run Devoku on your own infrastructure, you (or your
organization) are the controller of the data in that deployment, and this Policy
describes only the practices of the Devoku-operated hosted Service.
Coded, UAB, Republic of Lithuaniaprivacy@devoku.comprivacy@devoku.comWe collect the following categories of personal data, based on how the Service works.
| Data | Examples | Why |
|---|---|---|
| Account & identity | Email address, password (stored hashed by our identity system), display name, optional TOTP two-factor secret | Create and secure your account, sign in, account recovery |
| Profile | Avatar image, profile color, display name | Personalize your account |
| User content | Chat messages, uploaded files (images, audio, video, documents up to 50 MB), voice recordings, agent/"employee" configurations, workspace data, goals/knowledge you add | Provide the core Service and your agents' work |
| Support & communications | Messages you send us, invitation details | Respond to you, operate invite-only access |
| Data | Examples | Why |
|---|---|---|
| Session & device | Authentication tokens (JWT/refresh), user ID, device ID and device name, identity keys | Keep you signed in, manage linked devices |
| Consent records | The consent choices you make, plus IP address, user agent, and the policy version at the time of consent | Prove and honor your consent (GDPR Art. 7) |
| Push notification tokens | Device push token/endpoint, platform, associated control-plane URL, user agent | Deliver push notifications you enable |
| Usage & diagnostics | Operational traces and logs, audit-log events (actions taken on your account) | Security, debugging, abuse prevention, reliability |
| Billing records | Credit balance and ledger of top-ups and usage (cloud accounts) | Operate paid cloud features |
We store certain data locally on your device (for example, in browser local
storage/session storage) such as your session tokens, user ID, email, display name,
avatar URL, profile color, and device identifiers, so the app can function.
Based on the current implementation, the apps do not include third-party
advertising SDKs, and do not integrate third-party analytics SDKs (such as
Firebase Analytics, Mixpanel, or Amplitude). We do not use your data for advertising
and do not sell personal data. An optional analytics/telemetry consent category
exists so that, if we introduce product analytics in the future, it will be opt-in.
We use personal data to:
Where GDPR applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the Service and your account | Performance of a contract (Art. 6(1)(b)) |
| Security, abuse prevention, service improvement | Legitimate interests (Art. 6(1)(f)) |
| Billing and tax records | Contract and legal obligation (Art. 6(1)(b), (c)) |
| Marketing emails, optional analytics/telemetry, routing to third-party AI providers where consent-gated, beta features | Consent (Art. 6(1)(a)), which you can withdraw at any time |
| Responding to legal requests | Legal obligation (Art. 6(1)(c)) |
To operate the Service we share data with service providers ("sub-processors") who
process it on our behalf, and — when you enable an integration — with third-party
tools and AI providers you choose.
When you use AI features, your instructions, prompts, and relevant workspace/content
may be transmitted to the tools and model providers you enable so they can perform the
requested task. Depending on your configuration this can include coding tools (Cursor,
Claude Code, Codex CLI, Qwen Code, Cline) and model providers (such as OpenAI,
Anthropic, Google, xAI, and others). These providers process your data under their own
terms and privacy policies. Where this routing is optional, it is consent-gated.
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Hetzner, UpCloud | Cloud virtual machine hosting | Workloads, content processed on your VMs |
| Cloudflare (R2) | File, backup, and image storage | Uploaded files, backups |
| Soniox | Voice-to-text transcription | Voice recordings you submit |
| Voyage AI | Text embeddings (search/memory) | Text content processed for embeddings |
| Resend | Transactional email (verification, recovery, notifications) | Email address, message content |
| Apple Push Notification service (APNs) | iOS/macOS push notification delivery | Device push tokens, notification content |
| Firebase Cloud Messaging (FCM) | Android push notification delivery | Device push tokens, notification content |
| Browser push services (via Web Push / VAPID) | Web/PWA push notification delivery | Push endpoint/keys, notification content |
Stripe |
Payment processing for credit top-ups | Payment metadata (we do not store full card numbers) |
The full, authoritative sub-processor list is maintained in
subprocessors.md and published at
https://legal.devoku.com/subprocessors/. Firebase is used for Android push messaging
only (FCM), not for authentication or analytics.
Identity/authentication is handled by self-hosted Ory Kratos software running on
Devoku's own infrastructure; your credentials are stored in Devoku's database. Ory (the
company) is not a sub-processor and does not receive your data.
We require sub-processors to protect personal data and to process it only per our
instructions.
The Service and its providers may process data in EU (primary) and
other countries, including outside the EEA/UK. Where we transfer personal data
internationally, we use an appropriate transfer mechanism such as
EU Standard Contractual Clauses (SCCs) where applicable (for example, Standard Contractual Clauses).
We keep personal data for as long as needed to provide the Service and for the
purposes described here. In particular:
up to 7 years for billing and tax records where required; otherwise only as needed for legal, security, and fraud-prevention purposes.Depending on your location, you may have the right to access, correct, delete, restrict,
or object to processing of your personal data, to data portability, and to withdraw
consent. The Service already provides self-service tools in Settings → Privacy & data:
/api/v1/me/export)./api/v1/me/delete), subject to the retention described in Section 7. See theTo exercise rights not covered by these tools, contact privacy@devoku.com.
You also have the right to lodge a complaint with your local data protection authority.
The Service is intended for professional/business users and is not directed to children
under 16. We do not knowingly collect personal data from children.
If you believe a child has provided us personal data, contact
privacy@devoku.com and we will delete it.
When you use Devoku on behalf of an organization or team, that organization is generally
the controller of the personal data it processes through the Service, and Devoku acts as
a processor. In that case, the Data Processing Addendum
supplements this Policy.
We use technical and organizational measures to protect personal data, including
encryption in transit, access controls, secret management, hashed passwords, optional
two-factor authentication, and audit logging. No method of transmission or storage is
completely secure, and you are responsible for keeping your credentials and API keys safe.
The web app uses cookies and browser storage that are necessary for authentication and
core functionality (for example, session cookies used by our identity system and local
storage for your session). We do not use advertising cookies. If we introduce optional
analytics in the future, it will be consent-based. See the
Cookie and Local Storage Notice for details.
We may update this Policy from time to time. If we make material changes, we will provide
notice (for example, in-app or by email) and update the "Last updated" date and version.
Your continued use of the Service after changes take effect constitutes acceptance where
permitted by law.
This is a summary. The fill-ready, authoritative version is
apple-app-privacy.md; use that when completing the App Privacy
questionnaire in App Store Connect, and confirm against your finalized build before submitting.
| Apple data category | Collected? | Linked to identity? | Used for tracking? | Notes |
|---|---|---|---|---|
| Contact info (email) | Yes | Yes | No | Account creation/login |
| User content (messages, files, audio) | Yes | Yes | No | Core functionality; audio sent to transcription provider |
| Identifiers (user ID, device ID) | Yes | Yes | No | Account, session, device management |
| Usage data / diagnostics | Yes | Yes | No | Security, debugging, audit logs |
| Purchases / financial info | Yes (cloud; once payments are live) | Yes | No | Credit balance/ledger; card data handled by processor. Stripe not yet live |
| Audio data | Yes | Yes | No | Voice messages; microphone permission |
| Location | No | — | — | Not collected |
| Contacts | No | — | — | Not collected |
| Browsing history / search history | No | — | — | Not collected |
| Advertising data | No | — | — | No ads |
PrivacyInfo.xcprivacy declaringThis is a summary. The fill-ready, authoritative version is
google-play-data-safety.md; use that when completing the
Data Safety form in Google Play Console.
| Google Play data type | Collected | Shared | Purpose |
|---|---|---|---|
| Personal info (email, name) | Yes | With processors only | Account management, app functionality |
| Messages (in-app) | Yes | With processors only | App functionality |
| Photos/videos/files | Yes | With processors (storage) | App functionality |
| Audio (voice recordings) | Yes | With transcription provider | App functionality |
| App activity / diagnostics | Yes | With processors only | Analytics/diagnostics, security |
| Financial info (purchases) | Yes (cloud; once payments are live) | With payment processor | App functionality |
| Location, Contacts, Health | No | — | — |
privacy@devoku.com.Privacy questions: privacy@devoku.com
Coded, UAB, Republic of Lithuania