- Who we are
- Two roles
- Dashboard users
- App users
- This website
- Retention
- Your rights
- Subprocessors
- Transfers
- Security
- Changes
Who we are
DevReply is made by Code Axolot. The legal entity is S.Z. CODE AXOL LTD, 27 Despoinas Nikou Pattichi, Flat/Office 2, 3071 Limassol, Cyprus, registered in Cyprus under number HE 461075 (TIC/VAT CY60088739O) ("DevReply", "we").
Contact for anything on this page: [email protected]. The same address reaches our data protection contact.
Two roles
For people who use the dashboard (developers and their teammates at app.devreply.com), we decide what we collect and why. We are the controller.
For the users of an app that has DevReply inside, the app's developer decides. They put the chat in their app, choose what to pass to it, and read and answer the messages. The developer is the controller; we are their processor and only handle that data to run the chat for them, under our Data Processing Agreement. If you use an app with DevReply and want to see, correct or delete your data, ask the app's developer first; deleting your account in the app may already delete it. You can also write to us and we'll pass it on and help.
Dashboard users (we are the controller)
| What | Why | Legal basis |
|---|---|---|
| Account: email, name, sign-in ID, when you joined and were last seen | Sign you in and show your team who you are | Contract |
| Sign-in details (password or Google account) | Handled by Firebase Authentication; we never see your password | Contract |
| Teams: team name, members and their roles, invites (the invited email and role) | Let owners share an inbox and control who can do what | Contract |
| Personas: the name, title and photo shown to app users next to replies | Show app users who replied | Contract |
| Apps: name, bundle IDs, icon, links, reply time, chat settings, push credentials (encrypted) | Run the chat and push in your app | Contract |
| Keys: public keys; secret keys and agent sign-ins stored only as hashes, with names and when they were used | Let your apps, servers and AI agents connect, and let you revoke them | Contract, security |
| Your replies, notes and files in the inbox, and who wrote each | The inbox itself | Contract |
| Emails you send to hello@ or support@ | Answer you | Legitimate interest (replying to you) |
No advertising, no selling data, no marketing emails without asking, no trackers in the dashboard.
App users (we process for the developer)
When someone uses the DevReply chat in an app, we store, for that app's developer:
- the name they type (or the app passes), and their email if they give one;
- their messages, the photos and files they attach, and when each was sent and read;
- device details: device model, OS version, app version, SDK version, language, platform (on the web: browser, OS and site name);
- an install ID we make up for the chat, and a push token if the app turns on notifications;
- anything the app chooses to pass, such as custom attributes (a plan name, for example);
- whether they unsubscribed from reply emails.
We use it only to deliver the chat: show messages to the developer, send replies back by push and email, and keep the service secure. We don't use it for ads, don't build profiles across apps, don't track users, and don't sell or share it. The SDK has no analytics or crash SDK inside. The full list, per platform, is on Privacy details for your app.
Photos are resized and re-encoded on the device before upload, which removes location and other EXIF data.
This website
Google Analytics, only if you allow it. devreply.com uses Google Analytics 4 to learn which parts of the page help. Until you click “Allow” in the banner, the page sends nothing to Google and sets no cookies. If you allow it, Google Analytics sets two cookies (_ga and _ga_…, kept for 13 months) and records the pages and sections you see and the buttons you click (for example “Start free”, “Sign in” or the chat), with your browser, device type, screen size, language, the site you came from, and an approximate location that Google derives from your IP address (Google Analytics 4 doesn’t store the IP address itself). Google signals and ad personalisation are off, and the reports are kept for up to 14 months. Legal basis: your consent (Art. 6(1)(a) GDPR and § 25(1) TDDDG). You can withdraw it at any time with “Cookie settings” at the bottom of every page; we then stop and delete the cookies. Google Ireland Limited / Google LLC process this data, also in the USA, under the EU–US Data Privacy Framework.
Our fonts are served from our own server. The chat button in the corner is DevReply itself: nothing loads until you click it. Then it works like the chat in any app using DevReply (see above), with us as the developer: what you write, the browser's language and version and the page you opened it from come to our inbox, and it keeps a token in your browser's storage so you see our reply when you come back. Like any web server, ours and Cloudflare's record the IP address, time and page of each request, to deliver the page and keep it safe (legitimate interest). The dashboard keeps your sign-in in your browser's storage; that's needed for signing in, not for tracking.
How long we keep it
- App users' data stays until the developer deletes it: deleting an app in the dashboard removes its users, conversations, messages and files for good. The developer can also delete one user: from their app (when the user deletes their account), from their own server, or in the dashboard. That removes the user's name, email, attributes, conversations, messages and files at once. Signing out of the app makes the device forget the chat; the conversations stay with the developer. When a developer's account ends, we delete their apps' data within 30 days.
- Dashboard accounts stay while you use DevReply. Ask us and we delete your account.
- Push tokens are removed as soon as Apple or Google report them as no longer valid.
- Backups: a nightly database backup kept for 14 days, so anything deleted is gone from backups within 14 days.
- Server logs (IP address, time, request) are kept for 14 days.
- Agent sign-ins: access tokens last one hour; you can revoke an agent at any time in the dashboard.
Your rights
You can ask to see the data we hold about you, correct it, delete it, get a copy in a common format, restrict or object to how we use it, and withdraw consent you gave. Write to [email protected]; we answer within a month. If you're an app user, we'll involve the app's developer, because it's their data to decide on. Every email we send to app users has an unsubscribe link.
You can also complain to a data protection authority, where you live or where we are: in Cyprus, the Commissioner for Personal Data Protection (dataprotection.gov.cy).
Subprocessors
These companies help us run DevReply and may handle personal data for it. We give each only what it needs.
| Company | What for | Data | Where |
|---|---|---|---|
| Hetzner Online GmbH | Servers: API, database, dashboard, website, backups | Everything listed on this page | Germany (Falkenstein) |
| Cloudflare, Inc. | DNS, TLS and the network in front of every devreply.com address; forwarding mail to hello@ and support@; storing encrypted off-site database backups (R2) | All traffic in transit, IP addresses, emails sent to us; backups are encrypted with a key Cloudflare doesn't have | Global network, USA; backups in the EU |
| Stripe Payments Europe, Ltd. | Payments for paid plans: checkout, invoices, taxes, card management | Billing details of paying teams (name, email, address, VAT number, payment method); never app users' data | Ireland, USA |
| Google LLC (Firebase Storage, Google Cloud) | Storing photos and files attached in the chat | Attachments | United States (Google Cloud us-east1) |
| Google LLC (Firebase Authentication) | Dashboard sign-in | Dashboard users' email, name, password hash or Google sign-in | USA |
| Resend, Inc. | Emails to app users ("we got your message", unread replies) and to teams (invites, notices about their plan) | Email address, name, app name, message text | USA |
| Apple Inc. (Apple Push Notification service) | Push notifications to iPhones and iPads, sent with the app developer's own push key | Push token, app or persona name, a preview of the reply | USA |
| Google LLC (Firebase Cloud Messaging) | Push notifications to Android, sent through the app developer's own Firebase project | Push token, app or persona name, a preview of the reply | USA |
| Google LLC (Google Workspace) | The mailbox that hello@ and support@ forward to | Emails sent to us | United States / EU |
Not subprocessors, but good to know. Reply emails and the page that opens a reply from an email load fonts from Google Fonts, so the reader's mail app or browser contacts Google (it sees the IP address). The SDKs' source code is published on GitHub, npm, JitPack and pub.dev; those don't receive anyone's chat data. If a team connects an AI agent to its inbox (MCP), the data that agent reads goes to the provider that team chose; that's the team's decision and their processor, not ours.
We'll update this list before we add a subprocessor, as the DPA describes.
International transfers
Our servers and database are in Germany. Some subprocessors above are in the USA or run global networks. Where data leaves the EEA or the UK, we rely on the EU–US Data Privacy Framework (and its UK extension) for providers certified under it, and on the European Commission's Standard Contractual Clauses otherwise.
Security
- Encrypted connections (HTTPS/TLS) everywhere, end to end through Cloudflare.
- Secret keys, install tokens, invite links and agent tokens are stored only as hashes. Push credentials are encrypted (AES-256-GCM).
- Each app install can only ever read its own conversations; tests check this for every endpoint.
- The install token is kept in the iOS Keychain, or encrypted with an Android Keystore key.
- Attachments sit in a private bucket and are only reachable through short-lived signed links.
- Team roles (owner, agent, viewer) limit who can change what. Server access is limited to our staff over a private network.
If a breach affects your data, we tell you (and, for app users' data, the developer) without undue delay.
Changes
When this policy changes, we update this page and the date at the top. For important changes, we email dashboard users first.