Legal
Privacy Policy.
Effective September 15, 2026. This describes what DevLinks collects, why, and what control you have over it.
Who this is
DevLinks (devlinks.app) is a developer profile and link-in-bio tool operated by Francis Castillo Cruz, an individual developer — not a registered company. This policy covers the DevLinks dashboard, public profile pages (devlinks.app/@username), and the marketing site.
For anything in this policy, or to exercise any of the rights below, email support@devlinks.app.
Information we collect
Account information. When you sign up, we collect your name, email address, and a password (if you use email/password) — or, if you sign in with GitHub or Google, the name, email, and avatar your OAuth provider shares with us. You choose a username, which becomes your public profile address.
Profile content. Anything you add to build your profile — bio, location, primary language, seniority, availability for hire, website, links, projects, code snippets, articles, talks, support/donation links, and theme settings (including custom CSS, on the Pro plan). Your profile page is public by design: everything here is meant to be visible to anyone who visits your DevLinks URL.
Connected accounts (integrations). DevLinks can display live stats from other services on your profile. Most integrations (GitHub, GitLab, Dev.to, Medium, Stack Overflow, WakaTime, LeetCode, npm, Bluesky, Mastodon, Docker Hub, YouTube, Hugging Face) only need the public username you type in — we fetch publicly available data from that service's own API and cache it. We don't authenticate as you or store a password or token for these.
Three integrations — Product Hunt, Dribbble, and Pinterest — work differently: their APIs only expose your own content when you connect via OAuth, so we store an access token (and refresh token, if the service issues one) after you authorize the connection. That token is used only to fetch your own posts, shots, or pins for display on your profile — never to act on your behalf otherwise, and never shared with anyone else.
Billing. If you upgrade to Pro, payments are handled entirely by Dodo Payments, our payment processor. We store a Dodo customer ID to link your account to your subscription; we never see or store your full card number.
Contact form and support. If you email us or use the contact form, we keep your name, email, and message to respond to you.
Avatar images. Profile pictures you upload are stored on Cloudflare R2, our file storage provider.
Information we collect automatically
Profile visit analytics. When someone views a public DevLinks profile or clicks a link on one, we log: a hashed version of the visitor's IP address (we never store the raw IP — it's run through SHA-256 with a salt that rotates daily, so it can't be reversed or matched across days), a coarse device/browser/OS category parsed from the user agent, country (from a CDN header, not precise location), the referring page, and which link was clicked. This exists so profile owners can see aggregate traffic to their own page — we don't use it to build a profile of individual visitors.
Session cookies. When you sign in, we set a session cookie so you stay logged in. The session record includes your IP address and user agent, used only to detect suspicious activity (like a login from an unexpected location).
Product analytics. We use PostHog to understand how people use DevLinks (which pages get visited, which features get used). PostHog only builds a full identity profile for signed-in users; anonymous visitors are not persistently tracked across sessions.
How we use your information
- To create and run your DevLinks account and public profile.
- To fetch and display data from services you've connected.
- To process Pro subscription payments.
- To respond to support requests.
- To keep the service secure — detecting abuse, fraud, or unauthorized access.
- To understand usage patterns and improve DevLinks (product analytics).
- To comply with legal obligations.
We do not sell your personal information, ever.
Who we share information with
We don't sell or rent your data. We share it only with the service providers that make DevLinks work, each only for the purpose below:
- Neon — hosts our Postgres database (all account and profile data).
- Vercel — hosts the application and runs our scheduled jobs.
- Cloudflare R2 — stores uploaded avatar images.
- Resend — sends transactional email (verification, password reset, contact form replies).
- Dodo Payments — processes Pro plan payments.
- PostHog — product analytics.
- GitHub, Google, Product Hunt, Dribbble, Pinterest — OAuth sign-in or, for the last three, the connected-account flow described above.
- The other services you connect (GitLab, Dev.to, Medium, Stack Overflow, WakaTime, LeetCode, npm, Bluesky, Mastodon, Docker Hub, YouTube, Hugging Face) — we send them only the public username you provide, to fetch your public data from their API.
We may also disclose information if required by law, or to protect the rights, property, or safety of DevLinks, our users, or the public.
Where your data lives
DevLinks and the providers listed above operate infrastructure in the United States. If you're accessing DevLinks from outside the US, your information will be processed there. [We haven't yet confirmed each provider's specific international-transfer safeguards (e.g. Standard Contractual Clauses) — get this reviewed before relying on it for EU/UK users.]
How long we keep your data
- Account and profile data: kept as long as your account exists.
- Deleting your account deletes your profile content and disconnects all integrations. Cached data from connected services is deleted with it.
- Profile visit analytics (hashed IP, device, referrer): kept for 12 months, then deleted.
- Contact form messages: kept for as long as needed to resolve your request, generally no more than 2 years.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your data, or to object to or restrict certain processing. To exercise any of these, email support@devlinks.app. We'll respond within 30 days.
You can also edit or delete most of your profile content directly from the dashboard at any time, and disconnect any integration whenever you want.
If you're in the EU/UK and believe we haven't addressed your concern, you have the right to lodge a complaint with your local data protection authority. [Legal basis for each processing activity under GDPR Art. 6 hasn't been formally mapped out — recommend legal review before this policy is relied on for EU users at scale.]
Cookies
We use a session cookie (to keep you signed in) and a short-lived cookie during the OAuth connection flow for Product Hunt, Dribbble, and Pinterest (to prevent cross-site request forgery — it's deleted immediately after the connection completes). Both are strictly necessary — the site doesn't work without them, so they're not something you can opt out of.
Product analytics (PostHog) is different: it only runs if you accept it in the cookie banner shown on your first visit. Nothing is captured before you choose, and you can change your mind at any time by clearing your browser's site data for devlinks.app. We don't use advertising or cross-site tracking cookies at all.
Security
We use industry-standard measures to protect your data: encrypted connections (HTTPS) everywhere, hashed passwords, OAuth tokens stored server-side and never exposed to the browser, and IP addresses hashed with a rotating salt for analytics rather than stored raw. No system is 100% secure, but if we ever discover a breach affecting your data, we'll notify you.
Children's privacy
DevLinks is not directed at children under 13, and we don't knowingly collect data from them. If you believe a child has created an account, email us and we'll delete it.
Changes to this policy
If we make a material change to this policy, we'll update the effective date above and, for significant changes, notify you by email.
Contact
Questions about this policy or your data: support@devlinks.app.