Effective date: March 1, 2026
This Privacy Policy explains how devenv.tools ("we", "us", or "our") collects, uses, and protects your personal information when you use our service. We believe in transparency and in collecting only what we need to provide you with a reliable development tunneling service.
When you create an account, we collect:
While you use the Service, we automatically collect:
If you subscribe to a paid plan, payment processing is handled entirely by Stripe. We do not store your credit card number, CVV, or full card details on our servers. We receive and store only:
To diagnose issues and improve the Service, we may collect:
To be clear about boundaries:
We use the information we collect for the following purposes:
| Provide the Service | Authenticate your identity, create and manage tunnels, route traffic to your domains, and display your account information in the dashboard |
|---|---|
| Transactional emails | Send login verification codes, password-free authentication links, billing receipts, payment failure notifications, and account-related alerts |
| Improve the Service | Analyze aggregate usage patterns (e.g., which features are most used, where errors occur) to prioritize improvements and fix bugs. We do not build individual user profiles for this purpose. |
| Prevent abuse | Monitor for violations of our Terms of Service, detect automated attacks, and protect the integrity of shared infrastructure |
| Billing | Process payments, manage subscriptions, generate invoices, and handle refund requests |
We do not use your information for advertising, profiling, or any purpose unrelated to providing and improving the Service.
We share your information only in the following limited circumstances:
We do not sell, rent, or trade your personal information to third parties. Period. This is not a revenue model we will ever pursue.
We may disclose your information if we are required to do so by law, court order, or government request. If legally permitted, we will notify you before making such a disclosure so you have the opportunity to contest it. We will resist overbroad or vague requests and will only disclose the minimum information necessary to comply.
If devenv.tools is acquired, merged, or substantially all of its assets are transferred, your information may be part of that transaction. In such an event, we will notify you by email and give you the opportunity to delete your account before the transfer takes effect.
All connections to the Service -- including the web dashboard, CLI, and tunnel traffic -- are encrypted using TLS (Transport Layer Security). We enforce HTTPS on all endpoints and do not support unencrypted connections.
Our databases are encrypted at rest using industry-standard encryption (AES-256). Database backups are similarly encrypted.
Access to production systems and user data is restricted to authorized personnel only. We use role-based access controls, audit logging, and multi-factor authentication for all infrastructure access.
Our edge servers and data storage are hosted in professionally managed data centers with physical security controls. We select providers with strong security track records and compliance certifications.
In the event of a data breach that affects your personal information, we will notify you by email within 72 hours of confirming the breach, in accordance with applicable data protection laws. The notification will describe the nature of the breach, the data affected, and the steps we are taking to address it.
We retain your account data for as long as your account is active. If your account has been inactive (no logins or tunnel activity) for 12 months, we may send you a notification and, after an additional 30-day grace period, close the account and delete the associated data.
When you delete your account, all associated personal data -- including your profile, tunnel configurations, domain registrations, and usage history -- will be permanently deleted within 30 days. Some data may persist in encrypted backups for up to 90 days before those backups are rotated.
Server access logs and error logs that may contain IP addresses or request metadata are retained for 90 days, after which they are automatically purged. This retention period allows us to investigate security incidents and debug issues reported by users.
We retain billing records (invoice history, payment amounts, subscription changes) for up to 7 years after your last payment, as required for tax and accounting compliance. These records do not include full payment card details.
Regardless of where you are located, we provide all users with the following rights over their personal data. These rights are aligned with GDPR and similar data protection frameworks:
You can view your account information, tunnel history, and domain configurations at any time through the dashboard. Programmatically, your data is available via GET /account on our API.
You can update your email address, display name, and other account information through the dashboard or via PATCH /account on our API.
You can delete your account and all associated data through the dashboard settings or via DELETE /account on our API. Deletion is permanent and cannot be undone after the 30-day processing period.
You can request a complete export of your personal data by emailing privacy@devenv.tools. We will provide the export in a machine-readable format (JSON) within 30 days of your request.
If you believe we are processing your data in a way that is not covered by this Privacy Policy or not justified by a legitimate interest, you can object by contacting privacy@devenv.tools. We will review your objection and respond within 30 days.
Where we process your data based on consent (rather than contractual necessity or legitimate interest), you can withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing that occurred before the withdrawal.
The Service is not intended for users under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that a user is under 16, we will take steps to delete their account and associated data promptly.
If you are a parent or guardian and believe your child has created an account on devenv.tools, please contact us at privacy@devenv.tools and we will delete the account.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make changes:
We encourage you to review this page periodically. The "Effective date" at the top of the page indicates when the policy was last updated.
If you have questions about this Privacy Policy, want to exercise your data rights, or have a privacy concern, contact us:
We aim to respond to all privacy-related inquiries within 14 days. If you are in the EU and believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local data protection authority.