Devit
Legal

Privacy Policy

Last updated: August 17, 2026

This Privacy Policy explains what information Devit (“Devit,” “we,” “us,” or “our”) collects when you use our website and app at devit-six.vercel.app (the “Service”), how we use it, who we share it with, and the choices you have.

Devit is operated by CyanixLabs. By using the Service, you agree to the practices described here. If you don’t agree, please don’t use Devit.

Contents
  1. Information we collect
  2. How we use information
  3. Legal bases (GDPR)
  4. How we share information
  5. Third-party services
  6. Cookies & local storage
  7. Data retention
  8. Security
  9. Your rights & choices
  10. Children
  11. International transfers
  12. Changes
  13. Contact us

01 Information we collect

We collect the following categories of information:

Account & profile information

Devit lets you sign in using GitHub (OAuth). When you do, we receive from GitHub the information you authorize, which typically includes your GitHub user ID, username, email address, and avatar image. You may also add profile details yourself, such as a display name, bio, links, and profile/banner images.

Content you create

We store the content you submit to the Service, including posts, comments, replies, polls, code snippets, images and files you upload, and reactions such as likes, votes, ratings, and bookmarks.

Direct messages

Devit lets you send one-on-one direct messages to other users. We store the content of these messages so we can deliver them to the intended recipient(s) and so conversation history is available to participants. Messages are visible only to their participants, except as described in Section 4 (for example, if a message is reported for a Terms violation).

Collaboration board

If you post to or apply through the collaboration board, we store your project post (title, description, tech stack) and, if you apply to someone else's project, the application message you send them.

BounceBot link scanning

When you include a web link in a post, comment, or reply, our automated service BounceBot visits that link and analyses the page so we can warn you and other users about broken, unsafe, or inappropriate destinations. This happens automatically, without you asking for it, whenever a link is detected in public content.

For each scanned link we store: the link itself and a normalised version of it; publicly available information about the page (such as its title, description, headings, preview image, HTTP status, response time, and the links it points to); the safety and quality signals BounceBot derives; your user ID as the submitter; and which kind of content the link came from.

We do not scan your private messages. The contents of direct messages are not sent to BounceBot, and links you send or receive in a private conversation are never queued for scanning. If a link in a message happens to match one already scanned from public content, we will still warn you before you open it — but nothing about your message is transmitted, analysed, or stored for that purpose.

Because BounceBot fetches the page, the operator of the destination website will see a request from our servers. That request identifies itself as BounceBot and is not linked to your identity, but it does reveal that the link was shared on Devit and may appear in that site’s own logs. A scan can be triggered either when a link is first shared publicly or when a Devit user later encounters a public link we have not checked yet, so the timing of that request does not necessarily correspond to when the link was posted.

Link warnings when you open a link

When content containing links is displayed to you, we look up the stored scan results for those links so we can warn you before you open something we have flagged. This lookup tells us which links were shown to you and, if you continue past a warning, that you chose to do so. If you dismiss future warnings for a particular website, we store that choice against your account so we can honour it; you can review and clear these under Privacy in your settings.

Safety alerts & moderator review

If BounceBot finds a problem, we create a notification telling you what was found and how to address it, delivered in the app and — depending on your notification settings — by email. See Section 5 for our email provider.

Links flagged as unsafe or inappropriate are also placed in an internal review queue so a human can check the automated finding. Devit moderators can see the flagged link, the signal that triggered it, the page details above, and the username of the person who posted it. When a moderator records a decision, we log that decision, their identity, any note they add, and the time — so that both mistaken flags and repeat problems can be traced.

Notification emails

Where you have email notifications enabled, we send your email address and the contents of the notification to our email provider so the message can be delivered. Urgent safety alerts may be sent immediately; other notifications are grouped into a periodic summary. You can turn notification emails off entirely, or mute individual notification types, in your settings, and every email includes an unsubscribe link.

Usage, interaction & diagnostic data

To operate features like view counts, trending, personalized feed ranking, and notifications, we record activity such as which posts are opened and viewed, likes/votes/ratings, follows, comments, and presence/online status. We derive interest and topic scores from this activity to personalize your feed and recommendations. We also log basic technical information sent by your browser or device, such as IP address, device and browser type, and timestamps, and — when the app encounters an error — diagnostic information such as the error message, stack trace, the page you were on, and your browser's user agent string, to help us find and fix bugs.

Integrations you connect

If you connect optional integrations — for example GitHub webhooks to auto-post releases — we process the data those integrations send us (such as repository and release metadata) to provide the feature.

Connected CyanixLabs apps & account linking

Devit can act as a sign-in and account-linking provider for other products in the CyanixLabs family, such as Cyanix Intelligence. If you choose to link or sign in to another CyanixLabs app with your Devit account, we issue that app a limited authorization (using industry-standard OAuth with PKCE) scoped to what you approve, and we keep a record of the connection (the linking code or token, the scopes granted, and its expiry) so we can let you view and revoke it later. We don't share your Devit password with connected apps, and we don't share content from a connected app back to Devit unless that app's own terms say otherwise.

Push notification tokens

If you enable push notifications, we store the notification token issued by your browser/device so we can deliver alerts. You can disable this at any time in your settings or browser.

Invitations

If you create an invite link to bring others to Devit, we store the link, who created it, and how many times it's been used.

Note: Anything you post publicly on Devit (posts, comments, code, profile details) may be visible to other users and, depending on settings, to the public and search engines. Please don’t post information you want to keep private.

02 How we use information

We do not sell your personal information, and we don’t use your private content to serve third-party advertising.

03 Legal bases (GDPR)

If you are in the European Economic Area or the UK, we process your personal data under these legal bases: performance of a contract (to provide the Service you request), legitimate interests (to secure, operate, and improve Devit), consent (for optional features like push notifications, which you can withdraw), and legal obligation where applicable.

04 How we share information

We share information only as described here:

05 Third-party services

We rely on the following providers to operate the Service. Your data may be processed by them under their own terms and privacy policies:

ProviderPurpose
SupabaseAuthentication, database, file storage, and realtime infrastructure
GitHubSign-in (OAuth), profile data, and optional repository/webhook integrations
VercelWebsite hosting and content delivery
allorigins.winFetching public link previews (Open Graph) for URLs in posts
BrevoDelivering notification and safety-alert emails
Websites you link toNot a provider, but note that BounceBot requests pages you link to, so those sites receive a request from our servers
Cyanix Intelligence (CyanixLabs)Optional account linking / sign-in for a related CyanixLabs product, only if you choose to connect it

We will keep this list current as our stack changes. Where required, we put appropriate data-processing terms in place with these providers.

06 Cookies & local storage

Devit uses cookies and browser storage (such as localStorage) that are necessary to run the Service — for example, to keep you signed in, remember preferences (like sidebar state), and support core functionality. We don’t use advertising cookies. You can clear or block storage in your browser, but some features may stop working.

07 Data retention

We keep your information for as long as your account is active or as needed to provide the Service. When you delete content or your account, we delete or de-identify the associated personal data within a reasonable period, except where we must retain it to comply with legal obligations, resolve disputes, or enforce our agreements. Public content you shared may persist in others’ interactions (for example, quoted or replied-to).

Link scan data. Cached scan verdicts expire on their own — sooner for links that scored as risky, so they get re-checked more often. Records of links that were flagged as unsafe, along with the moderator decision about them, are kept longer: they are how we tell a one-off false positive from a repeated pattern, and deleting them would remove the record that a flag was reviewed and dismissed. These records reference the link and the account that posted it rather than the content of the post it came from.

08 Security

We use industry-standard measures, including encryption in transit and access controls at the database level, to protect your information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If you believe your account has been compromised, contact us right away.

If a personal-data breach occurs, we will notify the relevant supervisory authority and affected users where and as required by applicable law — including, where the GDPR applies, notifying the competent authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach.

09 Your rights & choices

Depending on where you live, you may have the right to access, correct, delete, export, or restrict the use of your personal data, and to object to certain processing. You can exercise many of these directly in the app by editing your profile, deleting content, or deleting your account. To make a formal request, contact us at nixai.cy@gmail.com.

If you are in California, you have rights under the CCPA/CPRA, including the right to know, delete, and correct your personal information, and the right not to be discriminated against for exercising them. We do not sell or “share” personal information as those terms are defined under California law.

California: categories collected (notice at collection)

In the preceding 12 months, we have collected the following categories of personal information (as defined by the CCPA/CPRA) for the business purposes described in this Policy. This table also serves as our notice at collection.

CategoryExamplesCollected
IdentifiersGitHub ID, username, email, avatar, IP addressYes
Internet / network activityPosts viewed, likes, votes, follows, presence, device & log dataYes
User-generated contentPosts, comments, direct messages, code snippets, and files you submitYes
Internet activity (links you share)Links extracted from your public posts, comments and replies, the scan results for those links, and any safety flags recorded against your accountYes
InferencesTopic/interest scores derived from your activity, used to personalize your feedYes
Sensitive personal informatione.g. precise geolocation, government IDs, account passwords, race/health dataNo

We disclose Identifiers and activity data only to the service providers listed in Section 5, for the purposes described above. We have not sold or “shared” personal information for cross-context behavioral advertising, and we do not knowingly collect “sensitive personal information” as defined by the CPRA — so the “Limit the Use of My Sensitive Personal Information” right does not apply to us. If this changes, we will update this Policy and provide the required controls.

You can withdraw consent for push notifications at any time in your settings or browser. EEA/UK users may also lodge a complaint with their local data protection authority.

10 Children

Devit is not directed to children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.

11 International transfers

We and our providers may process and store information in countries other than yours. Where we transfer personal data across borders, we rely on appropriate safeguards (such as standard contractual clauses) where required by law.

12 Changes to this Policy

We may update this Policy from time to time. When we make material changes, we’ll update the “Last updated” date above and, where appropriate, notify you in the app. Your continued use of Devit after changes take effect means you accept the updated Policy.

13 Contact us

Questions about privacy? Reach us at nixai.cy@gmail.com, or by mail at CyanixLabs. This address is our point of contact for all privacy and data-protection requests.