Privacy Policy

Last updated: April 9, 2026

This Privacy Policy explains how DevOracle.com (“DevOracle”, “we”, “us”) collects, uses, stores, and shares information when you use our websites, web dashboard, desktop applications, and related services (together, the “Services”). By using the Services, you acknowledge that you have read this notice.

1. Data controller

The data controller is DevOracle.com. For privacy-related requests you may contact us at support@devoracle.com. Our Italian VAT number is IT02045420490.

2. Categories of personal data we process

Account & authentication: email address and account identifiers processed through our authentication provider (e.g. Supabase) when you register or sign in, including passwordless sign-in links.

Billing & subscriptions: limited billing metadata (such as plan type, subscription status, and transaction references) processed by our payment processor (Stripe). We do not store full payment card numbers on our servers.

Product usage: information required to operate paid features—such as approximate session counts, token usage against plan limits, and timestamps—so we can enforce fair use and improve reliability.

Technical & security data: IP address, device/browser type, log data, and diagnostics when you use our websites or dashboard, to secure the Services and troubleshoot issues.

Communications: content you send via contact forms or email (name, email address, message text).

Desktop application: the app is designed so that sensitive interview audio and on-screen coaching activity are handled primarily on your device. We do not aim to store full interview recordings on our servers for replay. If limited technical or operational data leaves your device (for example crash reports you choose to send, or data you explicitly sync), we process it only as needed to provide the Services.

3. Purposes and legal bases (EEA/UK users)

We process personal data to perform our contract with you (Art. 6(1)(b) GDPR): account creation, authentication, delivering software downloads, managing subscriptions, and customer support.

We rely on legitimate interests (Art. 6(1)(f) GDPR) where balanced with your rights: securing our systems, preventing abuse, improving reliability, measuring aggregated usage, and—where permitted—communicating service updates.

Where required, we ask for your consent (Art. 6(1)(a) GDPR)—for example for certain cookies or optional marketing communications.

We process data to comply with legal obligations (Art. 6(1)(c) GDPR), such as tax or accounting rules where applicable.

4. How long we keep data

We retain information only for as long as necessary for the purposes above, including legal, tax, or accounting obligations. Account data is typically kept for the life of your account plus a short grace period. Billing records may be retained longer where the law requires. Logs and security data are rotated on a limited schedule.

5. Sharing with processors and third parties

We use trusted service providers (“processors”) who process data on our instructions—for example payment processing (Stripe), authentication/database hosting (Supabase), infrastructure and hosting (such edge/server providers), and transactional email delivery. They may only use your data to perform services for us and must implement appropriate safeguards.

We may disclose information if required by law, court order, or to protect the rights, safety, and security of DevOracle, our users, or the public.

We do not sell your personal information as “sale” is defined under certain U.S. state laws.

6. International transfers

Your information may be processed in countries outside your country of residence, including the United States and the European Economic Area, where our providers operate. Where GDPR applies, we implement appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms approved by the European Commission.

7. Security

We implement administrative, technical, and organizational measures designed to protect personal data against unauthorized access, loss, or alteration. No online service can guarantee absolute security; please use a strong, unique password once you enable password-based access and protect access to your email inbox.

8. Your privacy rights

Depending on your location, you may have rights to access, rectify, delete, restrict, or object to certain processing of your personal data, and to data portability. You may also withdraw consent where processing is consent-based.

EEA/UK users may lodge a complaint with a supervisory authority. In Italy, the Garante per la protezione dei dati personali (www.garanteprivacy.it) is one such authority.

To exercise your rights, contact support@devoracle.com. We may need to verify your identity before responding.

9. California & other U.S. state privacy notices

Residents of certain U.S. states may have additional rights (for example, to know, delete, or opt out of certain sharing). Because we state that we do not sell personal information in the sense used by those laws, “Do Not Sell” requests may not apply in the traditional sense; you may still contact us to understand how we process information.

10. Children

The Services are not directed to individuals under 16. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us so we can delete it.

11. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. For material changes, we may provide additional notice (for example via email or dashboard banner) where appropriate.

12. Contact

Questions about this Privacy Policy: support@devoracle.com.

← Back to home