Privacy Policy

Devoku · Last updated: August 3, 2026

lawyer and matched to your actual, finalized data practices.

Effective date: August 3, 2026
Last updated: August 3, 2026
Version: privacy-policy-2026-08-03

This Privacy Policy explains how Coded, UAB ("Devoku",
"we", "us") collects, uses, shares, and protects personal data when you use
the Devoku hosted service, applications, and website (the "Service").

For the managed Devoku Cloud service, Devoku is the data controller for
account and service data described here. When you use Devoku to process data on
behalf of an organization or team, Devoku may act as a processor on your behalf;
see Section 10 and the Data Processing Addendum.

Self-hosted note. If you run Devoku on your own infrastructure, you (or your
organization) are the controller of the data in that deployment, and this Policy
describes only the practices of the Devoku-operated hosted Service.


1. Who we are and how to contact us

2. Data we collect

We collect the following categories of personal data, based on how the Service works.

2.1 Data you provide

Data Examples Why
Account & identity Email address, password (stored hashed by our identity system), display name, optional TOTP two-factor secret Create and secure your account, sign in, account recovery
Profile Avatar image, profile color, display name Personalize your account
User content Chat messages, uploaded files (images, audio, video, documents up to 50 MB), voice recordings, agent/"employee" configurations, workspace data, goals/knowledge you add Provide the core Service and your agents' work
Support & communications Messages you send us, invitation details Respond to you, operate invite-only access

2.2 Data collected automatically

Data Examples Why
Session & device Authentication tokens (JWT/refresh), user ID, device ID and device name, identity keys Keep you signed in, manage linked devices
Consent records The consent choices you make, plus IP address, user agent, and the policy version at the time of consent Prove and honor your consent (GDPR Art. 7)
Push notification tokens Device push token/endpoint, platform, associated control-plane URL, user agent Deliver push notifications you enable
Usage & diagnostics Operational traces and logs, audit-log events (actions taken on your account) Security, debugging, abuse prevention, reliability
Billing records Credit balance and ledger of top-ups and usage (cloud accounts) Operate paid cloud features

We store certain data locally on your device (for example, in browser local
storage/session storage) such as your session tokens, user ID, email, display name,
avatar URL, profile color, and device identifiers, so the app can function.

2.3 Data we do not collect via SDKs

Based on the current implementation, the apps do not include third-party
advertising SDKs, and do not integrate third-party analytics SDKs (such as
Firebase Analytics, Mixpanel, or Amplitude). We do not use your data for advertising
and do not sell personal data. An optional analytics/telemetry consent category
exists so that, if we introduce product analytics in the future, it will be opt-in.

3. How we use data

We use personal data to:

4. Legal bases (GDPR / UK GDPR)

Where GDPR applies, we rely on the following legal bases:

Purpose Legal basis
Providing the Service and your account Performance of a contract (Art. 6(1)(b))
Security, abuse prevention, service improvement Legitimate interests (Art. 6(1)(f))
Billing and tax records Contract and legal obligation (Art. 6(1)(b), (c))
Marketing emails, optional analytics/telemetry, routing to third-party AI providers where consent-gated, beta features Consent (Art. 6(1)(a)), which you can withdraw at any time
Responding to legal requests Legal obligation (Art. 6(1)(c))

5. Third-party providers, AI routing, and sub-processors

To operate the Service we share data with service providers ("sub-processors") who
process it on our behalf, and — when you enable an integration — with third-party
tools and AI providers you choose.

5.1 AI and coding providers

When you use AI features, your instructions, prompts, and relevant workspace/content
may be transmitted to the tools and model providers you enable so they can perform the
requested task. Depending on your configuration this can include coding tools (Cursor,
Claude Code, Codex CLI, Qwen Code, Cline) and model providers (such as OpenAI,
Anthropic, Google, xAI, and others). These providers process your data under their own
terms and privacy policies. Where this routing is optional, it is consent-gated.

5.2 Sub-processor list

Sub-processor Purpose Data involved
Hetzner, UpCloud Cloud virtual machine hosting Workloads, content processed on your VMs
Cloudflare (R2) File, backup, and image storage Uploaded files, backups
Soniox Voice-to-text transcription Voice recordings you submit
Voyage AI Text embeddings (search/memory) Text content processed for embeddings
Resend Transactional email (verification, recovery, notifications) Email address, message content
Apple Push Notification service (APNs) iOS/macOS push notification delivery Device push tokens, notification content
Firebase Cloud Messaging (FCM) Android push notification delivery Device push tokens, notification content
Browser push services (via Web Push / VAPID) Web/PWA push notification delivery Push endpoint/keys, notification content
Stripe Payment processing for credit top-ups Payment metadata (we do not store full card numbers)

The full, authoritative sub-processor list is maintained in
subprocessors.md and published at
https://legal.devoku.com/subprocessors/. Firebase is used for Android push messaging
only (FCM), not for authentication or analytics.

Identity/authentication is handled by self-hosted Ory Kratos software running on
Devoku's own infrastructure; your credentials are stored in Devoku's database. Ory (the
company) is not a sub-processor and does not receive your data.

We require sub-processors to protect personal data and to process it only per our
instructions.

6. International data transfers

The Service and its providers may process data in EU (primary) and
other countries, including outside the EEA/UK. Where we transfer personal data
internationally, we use an appropriate transfer mechanism such as
EU Standard Contractual Clauses (SCCs) where applicable (for example, Standard Contractual Clauses).

7. Retention

We keep personal data for as long as needed to provide the Service and for the
purposes described here. In particular:

8. Your rights and choices

Depending on your location, you may have the right to access, correct, delete, restrict,
or object to processing of your personal data, to data portability, and to withdraw
consent. The Service already provides self-service tools in Settings → Privacy & data:

To exercise rights not covered by these tools, contact privacy@devoku.com.
You also have the right to lodge a complaint with your local data protection authority.

9. Children's privacy

The Service is intended for professional/business users and is not directed to children
under 16. We do not knowingly collect personal data from children.
If you believe a child has provided us personal data, contact
privacy@devoku.com and we will delete it.

10. Business/team use (controller vs. processor)

When you use Devoku on behalf of an organization or team, that organization is generally
the controller of the personal data it processes through the Service, and Devoku acts as
a processor. In that case, the Data Processing Addendum
supplements this Policy.

11. Security

We use technical and organizational measures to protect personal data, including
encryption in transit, access controls, secret management, hashed passwords, optional
two-factor authentication, and audit logging. No method of transmission or storage is
completely secure, and you are responsible for keeping your credentials and API keys safe.

12. Cookies and local storage

The web app uses cookies and browser storage that are necessary for authentication and
core functionality (for example, session cookies used by our identity system and local
storage for your session). We do not use advertising cookies. If we introduce optional
analytics in the future, it will be consent-based. See the
Cookie and Local Storage Notice for details.

13. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will provide
notice (for example, in-app or by email) and update the "Last updated" date and version.
Your continued use of the Service after changes take effect constitutes acceptance where
permitted by law.


Appendix A — Apple "App Privacy" (nutrition label) mapping

This is a summary. The fill-ready, authoritative version is
apple-app-privacy.md; use that when completing the App Privacy
questionnaire in App Store Connect, and confirm against your finalized build before submitting.

Apple data category Collected? Linked to identity? Used for tracking? Notes
Contact info (email) Yes Yes No Account creation/login
User content (messages, files, audio) Yes Yes No Core functionality; audio sent to transcription provider
Identifiers (user ID, device ID) Yes Yes No Account, session, device management
Usage data / diagnostics Yes Yes No Security, debugging, audit logs
Purchases / financial info Yes (cloud; once payments are live) Yes No Credit balance/ledger; card data handled by processor. Stripe not yet live
Audio data Yes Yes No Voice messages; microphone permission
Location No Not collected
Contacts No Not collected
Browsing history / search history No Not collected
Advertising data No No ads

Appendix B — Google Play "Data safety" mapping

This is a summary. The fill-ready, authoritative version is
google-play-data-safety.md; use that when completing the
Data Safety form in Google Play Console.

Google Play data type Collected Shared Purpose
Personal info (email, name) Yes With processors only Account management, app functionality
Messages (in-app) Yes With processors only App functionality
Photos/videos/files Yes With processors (storage) App functionality
Audio (voice recordings) Yes With transcription provider App functionality
App activity / diagnostics Yes With processors only Analytics/diagnostics, security
Financial info (purchases) Yes (cloud; once payments are live) With payment processor App functionality
Location, Contacts, Health No

Contact

Privacy questions: privacy@devoku.com
Coded, UAB, Republic of Lithuania