Legal
Privacy Policy
Last updated: August 16, 2026 · Soft-launch draft for DevHoard (operated by 6425 Tech)
This Privacy Policy explains how DevHoard, operated by 6425 Tech (“we”, “us”), handles personal information for the soft-launch / beta Service. It is a practical summary aligned with how the product works today — not a substitute for legal advice.
1. What we collect
- Account: email and profile data from Auth.js sign-in (GitHub, Google, or magic link via Resend), plus session/JWT authentication data
- Vault content: items you create (text, metadata, tags, collections, provenance such as MCP/pack/import source); optional SECRET bodies (encrypted at rest); Pro IMAGE blobs in private object storage
- Public shares (opt-in): if you enable a public link on a SNIPPET or PROMPT, that item’s title and content are visible to anyone with the link until you disable it. SECRET items cannot be shared.
- API keys: hashed tokens and scopes you create for MCP; raw secrets are shown once and not stored in plaintext
- Usage / ops: logs, rate-limit signals (Upstash), error telemetry (Sentry when enabled), and hosting metrics (Vercel)
- Billing (future): when Stripe is enabled, payment and entitlement data from Stripe webhooks — not card numbers stored in our database
2. How we use information
- Provide, secure, and improve the Service (vault, search, MCP, inbox review)
- Authenticate you and prevent abuse (Turnstile on magic link where configured)
- Send transactional email (magic links, security notices)
- Operate soft-launch owner metrics (aggregate only; gated by ADMIN_EMAILS)
- Comply with law and enforce Terms
We do not sell your personal information for advertising. We do not use vault contents to train public foundation models.
3. Processors / subprocessors (high level)
Depending on configuration, we use:
- Vercel — app hosting
- Neon — Postgres (system of record)
- Cloudflare R2 — private object storage for Pro images (presigned access)
- Auth.js providers — GitHub / Google OAuth; Resend for magic-link email
- Upstash — ephemeral rate limiting / short-lived cache (not vault content)
- Sentry — error monitoring when enabled
- Stripe — payments when Checkout is enabled
4. Tenancy and access
Soft-launch tenancy is personal: vault queries are scoped by your user id. MCP agents act with your API keys and scopes. Owner metrics (ADMIN_EMAILS) show platform aggregates — they do not grant Pro storage and are not a dump of other users’ vault bodies.
5. Secrets and images
SECRET items use field-level encryption with a server-held key. We can decrypt for features you use; this is not zero-knowledge E2EE. IMAGE objects are private in R2 and accessed via short-lived presigned URLs — not a public CDN.
6. Retention and deletion
We retain account and vault data while your account is active. Soft-deleted items may be purged on a schedule (see in-app trash / ops docs). You may export vault data and request account deletion via Settings → Security where available. Residual backups or logs may persist for a limited operational period.
7. Your rights (soft-launch summary)
Depending on where you live (including GDPR/UK GDPR and CCPA/CPRA-style regimes), you may have rights to access, correct, delete, export, or restrict certain processing, and to opt out of “sale”/“sharing” of personal information as those terms are defined by law. We do not sell personal information for ads. To exercise rights, contact us using the support / operator email associated with your account notices. We may need to verify your request.
8. International transfers
Infrastructure may process data in the United States and other regions where our providers operate. Soft-launch users should assume US-centric hosting.
9. Children
The Service is not directed to children under 13. We do not knowingly collect their data.
10. Changes
We may update this Policy as the soft-launch evolves. The “Last updated” date on this page will change when we do.
11. Contact
Privacy questions: use the support / operator email used for DevHoard transactional mail (Resend). Terms: Terms of Service. Docs: /docs.
Not legal advice. This soft-launch draft summarizes how DevHoard works today. Have counsel review before paid Checkout, public share monetization, or regulated use.