<DevStamp/>
Start verification How it works FAQ Pricing
Sign inPublic only

Privacy Policy

What data we process, why, who we share it with, and your rights.

DevStamp is currently in beta. The operator's full identifying details are being finalized and will be published here before commercial launch.

Last updated: August 2026

1. Data controller

  • Controller: [FULL NAME OR COMPANY NAME]
  • Tax ID (NIF/CIF): [NIF / CIF]
  • Address: [ADDRESS]
  • Contact: admin@devstamp.dev

2. What data we process

  • GitHub account data: your GitHub numeric id, username, email address, and avatar, obtained through GitHub sign-in.
  • Profile data: a full name, only if you choose to add one.
  • Repository content: the repositories you select for analysis. Your code is cloned temporarily to run the analysis and deleted afterwards; it is not permanently stored. We do store the results of the analysis (skill ratings, written justifications, and which files were analyzed).
  • Payment data: when you pay, the transaction is processed by Stripe. We do not receive or store your card details; we keep a payment/session reference and the amount.
  • Technical data: strictly necessary session cookies and server logs (including IP address) used for authentication and security.

3. Purposes and legal bases

  • Providing the service (authentication, running analyses, generating certificates, processing payments) — performance of a contract (Art. 6.1.b GDPR).
  • Service communications (e.g. emailing you your results) — performance of a contract.
  • Security and fraud prevention — our legitimate interest (Art. 6.1.f GDPR).
  • Legal obligations such as keeping invoicing records — Art. 6.1.c GDPR.

4. Who we share data with (processors and third parties)

To provide the service we rely on the following providers, which process data on our behalf or as independent controllers:

  • Anthropic (Claude API): to perform the AI analysis, the relevant content of the repository you selected, together with commit metadata, is sent to Anthropic's API. This applies to public and private repositories alike. Only the repositories you explicitly choose are analyzed.
  • GitHub: for sign-in and to read the repositories you authorize.
  • Stripe: for payment processing.
  • Email provider: Google (Gmail SMTP) to send you service notifications.
  • Hosting: Hetzner Online GmbH (Germany), where the service runs.

5. International transfers

Some of these providers (for example Anthropic and Stripe) may process data outside the European Economic Area, including in the United States. Where that happens, the transfer is covered by appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision. [Confirm the specific safeguards with each provider.]

6. Data retention

  • Cloned repository code: deleted immediately after each analysis run.
  • Account and analysis results: kept while your account is active, and until you request their deletion.
  • Payment and invoicing records: kept for the period required by tax and commercial law.

7. Your rights

You may exercise the following rights at any time by contacting us at admin@devstamp.dev:

  • Access, rectification, and erasure of your data.
  • Restriction of, and objection to, processing.
  • Data portability.
  • Withdrawal of any consent given, without affecting prior processing.

You also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es).

8. Your repositories

DevStamp only accesses the repositories you choose. Private repositories are included only if you explicitly grant access. Their content is sent to Anthropic to produce the analysis and is not stored beyond the duration of that analysis. If you are not comfortable with a repository's code being processed this way, do not select it for analysis.

9. Changes

We may update this policy; material changes will be reflected by the "last updated" date above.

© 2026 DevStamp FAQ Legal notice Privacy Cookies Terms Report an issue