Privacy Policy
Last updated: January 27, 2026
Introduction
DevLoop Runner ("we," "us," or "our") respects user privacy and is committed to protecting personal information. This Privacy Policy explains what information we collect and how we use and protect it.
1. Information We Collect
We collect the following information: (1) Account information: email address, password (stored hashed), language settings. When using Google OAuth login, we receive your Google account email address and profile information. (2) GitHub integration information: GitHub account name, email address, Personal Access Token. (3) AI credentials: OpenAI API key, Anthropic API key, Claude Code OAuth token, Codex auth.json. (4) Payment information: information necessary for payment processing through Stripe (credit card details are managed directly by Stripe and we do not store them). (5) Usage history: job execution history, settings change history, login history, purchase history. (6) Technical information: IP address, browser information, access date/time.
2. Handling of Credentials
Credentials (API keys, OAuth tokens, auth.json files, etc.) registered by users are encrypted at the application layer using AES-256-GCM encryption before storage. Additionally, they are protected through multiple layers including TLS/SSL encrypted communications, access controls (Row Level Security), and infrastructure-level encryption at rest. These Credentials are used solely for accessing third-party AI services on behalf of users during job execution. Our employees do not view or use Credentials. Credentials are linked to your account and are not shared with other users. You can delete Credentials at any time from the Settings page.
3. Handling of Payment Information
The Service uses Stripe for payment processing. Sensitive payment information such as credit card numbers is managed directly by Stripe in compliance with PCI DSS security standards. We do not store card numbers; we only retain customer ID, subscription ID, payment status, and similar information provided by Stripe. For payment details, please refer to Stripe's Privacy Policy.
4. How We Use Information
We use collected information for the following purposes: (1) providing, operating, and maintaining the Service; (2) payment processing and subscription management; (3) providing user support; (4) improving the Service and developing new features; (5) ensuring security and preventing misuse; (6) verifying compliance with terms of service; (7) sending important notices and service change notifications. Marketing emails are sent only with your explicit consent.
5. Information Sharing and Disclosure
We do not share personal information with third parties without your consent, except in the following cases: (1) when necessary for service provision (Credentials are transmitted to AI service providers such as OpenAI and Anthropic during job execution; payment information is transmitted to Stripe; when using Google OAuth login, authentication is processed through Google); (2) when required by law; (3) when necessary to protect the life, body, or property of you or third parties; (4) when necessary to protect our rights and property.
6. Data Retention Period
Account information is retained while your account is active. Job execution history is retained for one year from execution. Payment history is retained for the period required by law. After account deletion, personal information is deleted within 30 days. However, information required to be retained by law is retained for the necessary period.
7. Security Measures
We implement the following measures to protect personal information: (1) encryption of communications (TLS/SSL); (2) application-layer encryption of Credentials (AES-256-GCM); (3) per-user access controls (Row Level Security) for data isolation; (4) infrastructure-level encryption at rest; (5) authentication mechanisms; (6) regular security reviews; (7) PCI DSS compliant payment processing (Stripe). However, please understand that no transmission over the Internet is 100% secure.
8. Your Rights
You have the following rights: (1) Right of access: You may request disclosure of your personal information. (2) Right to rectification: You may request correction of inaccurate information. (3) Right to erasure: You may request deletion of personal information (account deletion available from Settings page). (4) Right to restrict processing: You may request restriction of processing under certain circumstances. (5) Right to data portability: You may request provision of structured data. To exercise these rights, please contact us through the contact form.
9. Cookies and Tracking
The Service uses necessary cookies for session management and authentication. These are essential for providing Service functionality and cannot be opted out. We do not currently use analytics cookies.
10. Children's Privacy
The Service is intended for users 18 years of age or older. We do not intentionally collect personal information from anyone under 18. If we learn that we have collected information from someone under 18, we will promptly delete it.
11. International Data Transfers
The Service is hosted in Japan, but Credentials, job-related data, and payment information may be transferred overseas in connection with accessing AI service providers (OpenAI, Anthropic, etc.) and payment services (Stripe). By using the Service, you consent to such data transfers.
12. Changes to Policy
We may modify this Policy from time to time. For significant changes, we will notify you in advance through notifications on the Service or by email to your registered address. Continued use of the Service after changes constitutes acceptance of the modified Policy.
13. Contact
For questions or requests regarding this Policy, please contact us at devloop-runner@tielec.net.