Privacy Policy
Last updated: December 7, 2025
DevPilot ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
1. Information We Collect
1.1 Information You Provide
- Account Information: When you register, we collect your name, email address, and authentication credentials.
- Workspace Data: Information about your organization, teams, and project configurations.
- Integration Credentials: OAuth tokens and API keys for connected services (GitHub, Bitbucket, Jira, Slack, etc.).
1.2 Information from Third-Party Integrations
When you connect DevPilot to third-party services, we may receive:
- GitHub/Bitbucket: Repository metadata, pull request information, branch names, reviewer assignments, and webhook events.
- Jira: Sprint information, issue metadata, board configurations, and project details.
- Slack/Microsoft Teams: Workspace identifiers, channel information, and user identifiers for notifications.
1.3 Automatically Collected Information
- Usage Data: Pages visited, features used, and interaction patterns.
- Device Information: Browser type, operating system, and IP address.
- Cookies: Session cookies for authentication and preference storage.
2. How We Use Your Information
We use the collected information to:
- Provide and maintain our service
- Send notifications about pull requests, code reviews, and sprint updates
- Auto-assign reviewers and manage PR workflows
- Track sprint progress and send reminders
- Retarget pull requests between release branches
- Improve and optimize our service
- Communicate with you about updates and support
- Comply with legal obligations
3. Data Sharing and Disclosure
We do not sell your personal information. We may share data:
- With Your Consent: When you explicitly authorize sharing.
- Service Providers: With trusted vendors who assist in operating our service (hosting, analytics).
- Legal Requirements: When required by law or to protect our rights.
- Business Transfers: In connection with a merger, acquisition, or sale of assets.
4. Data Security
We implement industry-standard security measures including:
- Encryption in transit (TLS 1.2+) and at rest
- Secure storage of OAuth tokens and credentials
- Regular security audits and vulnerability assessments
- Access controls and authentication requirements
- Webhook signature verification for all integrations
5. Data Retention
We retain your data for as long as your account is active or as needed to provide services. When you delete your account, we will delete or anonymize your data within 30 days, except where retention is required by law.
6. Your Rights
Depending on your location, you may have the right to:
- Access: Request a copy of your personal data
- Correction: Update inaccurate information
- Deletion: Request deletion of your data
- Portability: Export your data in a machine-readable format
- Objection: Object to certain processing activities
- Restriction: Limit how we use your data
7. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place, including Standard Contractual Clauses where required by applicable law.
8. Third-Party Services
Our service integrates with third-party platforms (GitHub, Bitbucket, Jira, Slack, etc.). Your use of these services is governed by their respective privacy policies. We encourage you to review those policies.
9. Children's Privacy
DevPilot is not intended for children under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected such information, please contact us.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
- Email: privacy@devpilot.io
- Support: /support