Privacy Policy

Version v1.0 · Effective September 29, 2026

View previous versions

Hexifyer DevStudio Privacy Policy

Effective date: 1 September 2026 · Last updated: 1 September 2026 · Version: 1.0

Operated by: Hexifyer FZ-LLC

This Privacy Policy describes the personal data that Hexifyer DevStudio handles, the purposes for which it is used, where it is stored, how long it is kept, and the rights you have in relation to it. It covers the DevStudio web application, the AI estimator on our marketing site, and the marketing site itself.

Hexifyer operates the projects delivered through DevStudio and is therefore the controller of most of the personal data described in this policy. This determines where you send a request (see Section 2). DevStudio shares its account system and its database with Polaris, another product operated by Hexifyer (see Section 11). The deletion and retention periods in this policy are the same as those in our Terms of Service and our Data Processing Agreement. If they differ, the period stated in this policy applies.

1. Who we are and how to contact us

Hexifyer DevStudio is operated by Hexifyer FZ-LLC, a free zone company registered in Ras Al Khaimah, United Arab Emirates under licence number 47017173, at FOAM1588, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates.

Hexifyer FZ-LLC is the sole controller of the personal data described in this policy where we act as controller. No other Hexifyer entity is a controller of it.

RoutePurposeAddress
Privacy and data protectionRights requests, deletion and export requests, questions about this policy, Data Processing Agreement requests, sub-processor objectionsprivacy@hexifyer.com
Project and product supportQuestions about your project or about using DevStudio. Support cannot action a rights request and will forward it to the privacy address.support@hexifyer.com

The privacy address is monitored by staff who are able to act on requests sent to it. It is not a support channel and is not handled by your project manager.

2. Our roles

Hexifyer acts in three different capacities in relation to the data in DevStudio, because Hexifyer both operates the platform and delivers the work. The applicable role determines what you can request from us and who is responsible for responding.

  1. Controller: the platform and the delivery operation. Hexifyer determines the purposes of processing of data about the people and the process. This covers partner and agency records, client account records, and delivery records: which partner is assigned to which project and sprint, tasks, logs, comments, meetings and meeting notes, reports, and the audit record of who did what. We are directly responsible to you for this data, and Section 13 sets out how to exercise your rights.
  2. Processor: personal data belonging to your client organisation. Where a client provides us with personal data about its own people, we process it on that client's instructions and for no purpose of our own. This arises in two situations: where our developers are given access to a client's live production system that holds real end-user personal data, and where a client uploads a file containing its own customers' or employees' data into a DevStudio task or asset folder. For that data the client organisation is the controller and Hexifyer is the processor, and the processing is governed by the Data Processing Agreement (Schedule 3 to the Terms at https://devstudio.hexifyer.com/terms). If you are one of those end users, your rights are exercisable against the client, not against us, and we will forward any request you send us to the client.
  3. Neither: commercial deliverables. Wireframes, UI mockups, architecture diagrams, API specifications, PRDs, source code and all other project deliverables are commercial property, and their ownership is governed by the Terms of Service, not by this policy. We do not claim to act as controller of deliverables as such.

A deliverable may contain personal data, for example a PRD that names your stakeholders, a test dataset copied from production, or a screenshot showing a real customer's email address. Where it does, the personal data within it falls under role 2 above and is handled as your client organisation's data on your instructions, even though the document itself is a commercial asset.

2.1 Requests you send us

If you are a client contact, a partner, an agency admin or an estimator user, your personal data falls under role 1 and we action your request ourselves. You do not need to go through anyone else. If your request concerns personal data within a client payload under role 2, we cannot act on it on our own initiative. We will acknowledge the request, inform you of this, and forward it to the client organisation that controls the data, within the six working days set out in Section 13.

3. How DevStudio is organised

DevStudio has no workspaces. It is organised around projects, with four types of participant. This structure determines who can see what (see Section 9).

ParticipantDescription
ClientA person at the organisation purchasing the work. A client belongs to a client company. A company may have more than one contact and more than one project.
Client companyThe organisation itself. It is the counterparty to the Terms of Service and the controller of any client payload under Section 2.
PartnerA vetted freelance developer, designer or project manager. A partner may work as a personal freelancer, as a member of an agency, or both. A partner may belong to more than one agency and switch between those contexts and their personal context from a single account.
AgencyA supplier organisation with its own admin, whose partners can be assigned to projects under the agency's name. An agency joins by applying through the public apply-as-an-agency form, in the same way as an individual partner.

When a partner is assigned to a project while working under an agency, the assignment appears on the partner's dashboard within that agency, and that agency's admin can see it. Work done under agency A is visible to agency A's admin. The same partner's work under agency B, or as a personal freelancer, is not. Section 9 sets out these visibility rules.

4. What we collect and how

Data you provide to us and data the product generates about you are treated differently in the sections that follow.

  • Identity and credentials. Name, email address, password hash, federated sign-in identifier where you sign in with Google, Apple, Microsoft, LinkedIn or GitHub, and two-factor enrolment. Held in Supabase Auth. You provide it at sign-up, or your sign-in provider shares the profile fields you approve. Your account is a Hexifyer account that also signs you in to Polaris, Hexifyer's other product (see Section 11).
  • Profile. Display name, job title, profile photo, language and timezone, and notification preferences. Photos and logos are held in Supabase Storage. You provide it and can change all of it in the product except your email address (see below).
  • Client company record. Company name and logo, the contacts attached to it, their roles, invitations sent and received, and the projects belonging to it. You provide it during onboarding, or we create it when we open your engagement.
  • Partner application and profile. Professional summary, years of experience, hourly rate in USD, weekly availability in hours, portfolio URL, LinkedIn profile, GitHub profile, technical skills, portfolio projects, and your CV or resume as an uploaded document. You provide it through the public apply-as-a-partner form and can update it afterwards from your profile.
  • Agency application. The agency's name, its trade licence or registration details, its country of operation, its website and portfolio, the name and contact details of the applicant, the size of its team, and the disciplines it works in. You provide it through the public apply-as-an-agency form. We assess it in the same way as a partner application, and it is not scored or ranked automatically (see Section 8).
  • Agency record and membership. Agency name and logo, its admin, the partners belonging to it, and the projects assigned to it. The agency admin creates it, and partners join it or are invited to it.
  • Project content. Projects, sprints and milestones, tasks and subtasks, assignments, logs, meetings and meeting notes, comments, topics, custom field values, and the reports generated from them. Held in the primary database. You, your project team and our staff create it in the product. It may contain personal data about you or about other people, entered by whoever wrote it.
  • Files, assets and deliverables. Project files and anything attached to a task, message or meeting, in the format in which it was uploaded. Held in Supabase Storage. You or the project team upload it.
  • Client payload. Personal data belonging to a client's own users, customers or staff, accessed through production access granted to our developers or uploaded into a task or asset folder by the client. The client provides it or grants access to it. We are the processor for it (Section 2, role 2).
  • Calendar and meeting data. The Google or Microsoft calendar you connect: its events, their titles, times and attendee email addresses. Where the AI notetaker is used: meeting audio, its transcript, and the notes generated from it, typically for sprint demos and client calls. You connect a Google or Microsoft calendar and approve read and write access on that provider's consent screen, and the notetaker runs only when it is turned on for a meeting.
  • Estimator submissions. Your email address, the project description you wrote, your expected budget, and the estimate we returned. You submit the form on our marketing site. See Section 6.
  • Derived AI data. Embeddings and vector representations of project content, generated to support search and retrieval; assistant chat history, being your conversations with the DevStudio assistant; and summaries, drafts and automated reports produced by AI from your content. The product generates this from content you have already provided. Embedding takes place at ingestion, so content is sent to our embedding provider when it is created, not only when you search.
  • Usage and device data. Pages viewed, features used, clicks and scrolling, anonymised session recordings of the web app, device and browser, IP address and the approximate location derived from it, push token and device identifiers. We do not send your name or email address to our analytics provider, and text typed into input fields is masked before it leaves your browser. Collected automatically as you use the product. See Section 18 for the choices available to you.
  • Audit and security logs. Sign-ins, permission changes, records of who created, changed or deleted what, and security events. Held in the primary database. Generated automatically by the product.
  • Billing and contracts. Billing contact and address, agreed commercial terms, invoices and payment records, and signed contracts. Agreed with you during contracting. These are currently handled outside DevStudio (see Section 4.1).
  • Support and marketing. Your correspondence with us and, if you subscribe, your marketing contact record. You write to us or subscribe.

Changing your email address. DevStudio does not currently allow you to edit your own email address in the product. To correct it, write to privacy@hexifyer.com and we will change it for you.

4.1 What we do not collect

  • No payout or bank details in the platform. DevStudio currently has no payments module. Invoicing and payment of partners take place outside the product, by arrangement. We do not hold IBANs, card numbers or payment-rail credentials in DevStudio. The introduction of a payments module will be a material change under Section 22, announced 30 days in advance.
  • No time tracking and no monitoring. There is no timer, no screenshots, no activity or keystroke measurement, no idle detection, and nothing that reports on a partner's machine. Every hour figure in DevStudio is either an estimate entered when the task was planned or an hour manually logged by the person who did the work, and the interface labels each as one or the other. The addition of automated time tracking would also be a material change under Section 22.
  • No identity documents and no background checks. Partner vetting uses the information in the partner application described above and an interview. We do not collect passports, national IDs, criminal record checks or credit checks, and we do not use a screening service for partners.
  • No contacts module. DevStudio does not hold a CRM of people you have not engaged with.

4.2 Data from your Google or Microsoft account

If you sign in with Google or Microsoft, or connect a Google or Microsoft calendar, we receive data from that account only with the permission you grant on the provider's consent screen.

What we receivePurposeWhere it is held
Sign-in: your name, email address, profile photo and account identifierTo create your Hexifyer account and sign you inSupabase Auth, in Frankfurt (Section 11)
Calendar, only if you connect one: read and write access to your calendar events, with their titles, times and attendee email addressesTo keep your meetings in sync in both directions: events in your calendar appear in DevStudio, and meetings you create or change in DevStudio are created or updated in your calendar. Where you turn it on, to send the AI notetaker to a meetingThe DevStudio primary database, in Frankfurt (Section 11)
  • We use this data only to provide the DevStudio features you use. We do not sell it, use it for advertising, or use it to train any AI or machine learning model, including generalised models.
  • We share it only with the sub-processors listed in Section 24, only to provide those features, or where required by law. Where a feature uses AI, Section 7 applies.
  • Hexifyer personnel do not read this data unless you ask us to, for example in a support request, or unless it is necessary for security purposes or required by law.
  • You can disconnect a calendar in DevStudio at any time, or remove Hexifyer's access in your Google or Microsoft account settings. We then stop reading and updating it. Events already written to your calendar remain there until you delete them. Calendar data already synced is retained for the periods in Section 12, and you can ask us to delete it sooner at privacy@hexifyer.com.

DevStudio's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Data we receive from Microsoft is handled on the same terms.

Your sign-in is a Hexifyer account shared with Hexifyer's other product. A summary covering both products is available at hexifyer.com/privacy.

5. Purposes and legal bases

The table below sets out each purpose for which we process personal data and the legal basis we rely on. Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before it.

PurposeData usedLegal basis
Delivering your project and providing you with access to itIdentity, profile, client company record, project content, filesPerformance of a contract: the Terms of Service with your organisation, and your own contract with us as a participant.
Assessing a partner or agency applicationPartner application and profile, agency applicationSteps taken at your request before entering into a contract.
Managing partners, agencies and assignmentsPartner profile, agency membership, project content, assignmentsPerformance of a contract, and our legitimate interests in operating a delivery business that can staff projects and evidence who performed the work. We hold a recorded balancing test for this purpose.
The AI estimatorEstimator submissionsSteps taken at your request before entering into a contract. Retention beyond that and use for calibration are described in Section 6.
AI features: the assistant, the writers, search, automated reportsProject content relevant to the request, assistant chat history, embeddingsPerformance of a contract. Section 7 describes what is sent where.
Calendar sync and AI meeting notesCalendar and meeting dataConsent. Nothing is read or written until you connect a calendar, and the notetaker runs only when it is turned on for a meeting.
Client payloadPersonal data belonging to a client's own usersWe act as processor. The legal basis is the client's, and the Data Processing Agreement governs our use of the data.
Billing, invoicing and taxBilling and contract records, identityPerformance of a contract, and compliance with a legal obligation to retain tax records.
Security, abuse prevention and audit loggingAudit and security logs, usage and device dataOur legitimate interests in keeping the service and our customers' data secure, and compliance with a legal obligation to be able to investigate and report a breach. We hold a recorded balancing test for this purpose.
Product analytics and improving DevStudioUsage and device dataConsent. Analytics run only if you allow them, and you can refuse or change your choice at any time in the Cookie Notice (Section 23). No DevStudio functionality depends on them. Session recordings are anonymised. We do not use your project content to improve DevStudio.
SupportSupport correspondence, identityPerformance of a contract, and our legitimate interests in responding to you.
Marketing emailsMarketing contact recordConsent. Separate from the service emails described in Section 19.

6. The AI estimator

The estimator on our marketing site takes a project description in plain language and returns a breakdown: a recommended team composition, estimated hours per phase, cost per role, a total, and a timeline. It can be used by people who are not customers.

  • What we store. Four items: your email address, the project description you wrote, the budget you expect, and the estimate we returned. Nothing else is stored, and no tracking of you across the internet is attached to it.
  • Email address. An email address is required, as the estimate is delivered to it, so the estimator cannot be used anonymously. If you prefer not to provide one, you may contact us instead and we will prepare an estimate with you manually.
  • Processing. The submission is processed by an automation running on n8n Cloud, which calls a model through OpenRouter, the same gateway and providers used for every other AI feature, under the same no-training and 30-day provider retention terms set out in Section 7. The stored record is held in our primary database in Frankfurt.
  • Retention. 24 months from your last contact with us about the submission. At the end of that period we delete your email address and retain the description, the budget and the estimate without any identifier, in order to calibrate the estimator against actual project costs. On request, we will delete the whole record.
  • Marketing. We do not currently use estimator submissions for commercial follow-up, and a submission does not add you to a marketing list. Any change to this would be a material change under Section 22, requiring 30 days' notice, and consent would be requested on the form rather than inferred from an earlier submission.
  • Automated decisions. The estimator estimates a project, not a person, and makes no decision about you. See Section 8.

The description field is free text. You do not need to identify any person to obtain an accurate estimate, and you should not enter named stakeholders, customer lists, internal architecture details or information covered by a third party's confidentiality obligations. We hold the content on the terms above and do not share it.

7. AI features

DevStudio uses AI in four places. The assistant answers questions about your project and carries out actions you request. The writers draft content on request: task descriptions, log entries, idea drafts and classification. The reporting engine generates daily, weekly and monthly reports from project data. A scheduled agent runs on a timer without being initiated by a user (see Section 7.8). The estimator is a fifth use and is covered in Section 6.

7.1 Content sent outside DevStudio infrastructure

Every AI feature sends the project content relevant to the request to a model provider outside our infrastructure. In addition, your content is sent for embedding when it is created, not only when you search, in order to support project search.

7.2 Providers

Every AI request leaves DevStudio through a single gateway, OpenRouter, which routes it to the provider serving that request. The current list of providers, with the function of each and its processing location, is in the sub-processor list in Section 24, which is the authoritative version. As at the effective date of this policy, the providers are OpenRouter (gateway), OpenAI (text generation and embeddings), Google (text generation, request classification, and the safety checks applied to every inbound and outbound message), and Anthropic (answering questions over retrieved content). All of them process in the United States. DevStudio does not route any AI request to a provider processing outside the United States or the European Union. Estimator submissions also pass through n8n Cloud before reaching the gateway.

7.3 Model training

Your project content is never used to train any model, whether ours or a provider's. Every request is pinned to a named provider from the list above, and the gateway is not permitted to fall back to a provider that is not listed.

7.4 Provider retention

The providers we route to retain the inputs and outputs of a request for up to 30 days, solely for trust, safety and abuse monitoring, in order to detect and investigate misuse of their own services, and then delete them permanently. This retention is limited to that purpose. It is not used to train a model or to improve a product, and the data is not read by a person unless an automated system flags an incident. We do not route to an endpoint whose data policy cannot be established.

7.5 Processing location

AI processing does not necessarily take place where your data is stored. Your project content is stored in Frankfurt (Section 11), but AI processing takes place in the provider's own region. The processing location for each provider is stated in the sub-processor list in Section 24.

7.6 The AI features cannot be switched off

There is no setting to disable the AI features, and none will be provided on request. The AI features are integral to how DevStudio operates (search, the assistant, the reports you receive, and the organisation of project content), and the product does not operate without them. If you use DevStudio, your project content is processed by the AI providers named above. Because content is sent for embedding when it is created, it reaches our embedding provider whether or not anyone on your project uses the assistant, and no setting prevents this.

The following commitments apply to all customers: your content is never used to train a model, no provider retains it for more than 30 days, every request is pinned to a provider named on a public page, and the addition of a provider requires 30 days' notice, during which you may object.

Calendar sync and the AI meeting notetaker are optional. Nothing is read from or written to your calendar until you connect it, and the notetaker runs only when it is turned on for a meeting. Both are based on consent (Section 5).

If AI processing of project content is not acceptable to your organisation or to your own client, you should raise this during discovery, before signing, and we will discuss what is possible.

7.7 Personal data belonging to your users

Personal data belonging to your own users is never sent to an AI provider where it reaches us by file upload or through access to your production systems. Such data is not embedded, read by the assistant, or classified. However, anything typed or pasted into a task, comment or note is project content from the moment it is saved, and it is processed by the AI features in the same way as all other project content. No setting prevents this, and we are unable to distinguish a real customer record from any other text. Paragraph 5 of the AI Services Addendum (Schedule 2 to the Terms) and clause 8 of the Data Processing Agreement (Schedule 3 to the Terms), both at https://devstudio.hexifyer.com/terms, set this out in full. Your users' personal data should not be entered into text fields.

7.8 Scheduled processing

Some AI processing runs without being initiated by a user: a scheduled agent reads project content on a timer in order to organise and classify it, and the reporting engine compiles the daily, weekly and monthly reports on the same basis. Both send the same content to the same providers, under the same retention and no-training terms set out above.

The contractual terms governing the AI features are set out in the AI Services Addendum (Schedule 2 to the Terms at https://devstudio.hexifyer.com/terms).

8. Automated decisions

DevStudio makes no automated decision that has a legal effect on you or any other similarly significant effect. In particular:

  • No partner scoring, ranking or shortlisting. There is no matching algorithm, rating model or automated suitability score. A person decides which partner is proposed for a project, and a person decides whether an application is accepted.
  • The estimator estimates a project, not a person. Its output is an assessment of scope and cost. It does not assess the person who submitted it and is not used in any decision about any person.
  • AI output requires confirmation by a person. A draft remains a draft until someone accepts it, a classification remains a suggestion until someone keeps it, and a generated report describes work already done. No DevStudio feature makes any decision about a person's engagement, pay, access or standing.

Any change to this would be a material change to this policy, notified in accordance with Section 22.

9. Who can see what within DevStudio

DevStudio is shared between people who do not work for the same organisation. The following visibility rules apply.

If you areYou can seeYou cannot see
A clientYour company's projects in full (tasks, sprints, logs, meetings and notes, files, assets and reports) and, for each partner on your project, their name and profile photoA partner's hourly rate, CV, portfolio, skills profile, agency affiliations or other projects, or any other client's work
A partnerThe projects you are assigned to, and the team members on those projects: the client contacts and the other partners working on themProjects you are not assigned to, other partners' rates or profiles beyond the team listing, other clients, or the commercial terms between Hexifyer and the client
An agency adminFor partners working under your agency: the client organisations and projects they are assigned to, the tasks assigned to them, and the estimated and manually logged hours recorded against those tasksAnything a partner does as a personal freelancer or under a different agency, and any project your agency is not assigned to
Hexifyer staffWhat the role requires, for the reasons stated in Section 16, with access loggedSee Section 16

Hours visible to an agency admin. These are the estimate entered when a task was planned and the hours the partner chose to log against it. As stated in Section 4.1, DevStudio runs no timer and does not monitor how a partner works. This view shows planned and reported hours only.

Separation of contexts. A partner may belong to several agencies and may also work independently, switching between these contexts from one account. Work remains partitioned by the context in which it was done: agency A's admin sees agency A's assignments only, and work done as a personal freelancer is not visible to any agency. If you take on a project independently, we do not disclose it to any agency you belong to.

Partner information visible to clients. Clients see a partner's name and photo. A partner's rate, CV and history are commercial information between the partner and Hexifyer and are not disclosed to clients as a matter of course. If a specific engagement requires more (for example, a client asking for CVs before approving a team), we ask the partner first.

10. Sharing with third parties

We do not sell personal data, and we do not share it for third-party advertising. We share it with four categories of recipient:

  • Other participants in your project, and your agency, in accordance with Section 9.
  • Sub-processors. Providers we engage to operate the service, each limited by written agreement to the purpose we specify. Categories: cloud infrastructure and databases, authentication and file storage, workflow automation for the estimator, transactional email, push notifications, meeting transcription, product analytics, and the AI providers in Section 7.
  • Independent controllers. If you sign in with Google, Apple, Microsoft, LinkedIn or GitHub, that provider authenticates you under its own terms. It is not our sub-processor, as we do not instruct it to process data on our behalf. If you connect a Google or Microsoft calendar, we read and update it directly through that provider under the permission you grant, and the provider is not our sub-processor for that purpose either. An agency that receives data about its own partners under Section 9 acts as a controller of that data in its own right, and its handling of it is governed by its relationship with the partner, not by this policy.
  • Where required by law. In response to a binding legal request, or for the defence of a legal claim. We inform the affected customer unless we are prohibited from doing so.

Every sub-processor is named in the sub-processor list in Section 24, with its purpose, the data it receives, and the country in which it processes. The list has its own date and is updated separately from the rest of this policy.

Changes to the sub-processor list. A new sub-processor is added to the list and notified by email to everyone subscribed to changes at least 30 calendar days before it begins processing customer data. You may object in writing within 30 calendar days of that notice, on reasonable grounds relating to data protection, to privacy@hexifyer.com. We will work with you to resolve the objection, normally by explaining the safeguards in place or by making a change to the service available where possible. If we cannot resolve the objection within a reasonable period, you may terminate the affected engagement without penalty.

Where you exercise a right that must be passed on (for example, an erasure or rectification affecting data held by a sub-processor), we propagate it to every affected sub-processor within 30 days, using the mechanism each vendor provides.

Each sub-processor is engaged under a standard written vendor agreement, in most cases the vendor's own data processing addendum, requiring confidentiality and protection of the data appropriate to the service provided. Vendor compliance is reviewed periodically.

11. Where your data is stored

All DevStudio project content, files and account records are stored in Frankfurt, Germany, in the AWS eu-central-1 region. This applies to every customer and every partner, regardless of location.

ProviderWhat it holdsLocation
Supabase (Supabase, Inc.)Authentication: user records, credentials, federated sign-in identifiers. Stored files: profile photos, company and agency logos, CVs, project files, task and message attachments.Germany, AWS eu-central-1
Render (Render Services, Inc.)The primary database: projects, tasks, logs, meetings, comments, partner and agency records, estimator submissions, audit logs. The AI database: your chat history with the assistant. The DevStudio backend, frontend and AI services.Germany, AWS eu-central-1
Amazon Web Services (Amazon Web Services, Inc.)The underlying cloud infrastructure for both providers above. AWS does not access the data in the ordinary course.Germany, eu-central-1
n8n Cloud (n8n GmbH)The automation that processes an estimator submission and calls the model gateway. It handles the submission in transit; the stored record is held in the primary database.Germany

Backups. Backups of both stores are held by Supabase and Render in the same region, AWS eu-central-1. If a backup were held outside that region, this policy would state so.

The narrower categories of data that reach our platform and AI sub-processors are processed in those providers' own regions, as stated for each in the sub-processor list in Section 24. Section 7 covers the AI providers.

11.1 Shared infrastructure with Polaris

Hexifyer also operates Polaris, and DevStudio was built alongside it. Your sign-in is a Hexifyer account held in Supabase Auth, and the same account signs you in to both products. The two products also run on the same database and the same schema, not on separate databases or separate schemas. The separation between them is enforced by the application, not by the underlying infrastructure.

Content created in DevStudio does not appear in Polaris, and content created in Polaris does not appear in DevStudio. Signing in to one product gives you no access to anything in the other: access to a project or a workspace is granted only by being added to it. We do not move content between the two products, and we do not use one product's data to operate the other.

Any change to this arrangement (including separation of the stores, or sharing of anything beyond the account system between the two products) will be a material change under Section 22.

12. Retention

CategoryRetention periodAt the end of the period
Active project contentDuration of the engagement, then 24 monthsDeleted
Deleted content, in trash30 days, fixedPurged from the live systems. Restorable at any time within the 30 days.
A verified erasure requestErased from the live systems within 72 hours of verificationDeleted, not hidden or flagged. Backups follow the next row.
BackupsThe last backup copy is removed within 14 days of erasure from the live systemsRemoved on the backup rotation schedule
Partner profileWhile your partner account is openDeleted when you close the account, on the periods above, including your rate, CV, portfolio and skills profile
Agency applications not leading to an engagement12 months from the decisionDeleted, on the same terms as a partner application
Partner applications not leading to an engagement12 months from the decisionDeleted, including the CV
Estimator submissions24 months from your last contact about the submissionEmail address deleted. Description, budget and estimate retained without any identifier, for calibration (see Section 6).
Meeting recordings, transcripts and notesSame as the project they belong to: the engagement plus 24 monthsDeleted with the project record
Embeddings, summaries and other AI-derived dataDeleted in the same transaction as the source contentNot retained as a derived copy (see Section 7)
Assistant chat historyUntil you delete the conversation or the project record is deletedDeleted under the same 30-day trash and 72-hour erasure periods above
Data held by an AI providerUp to 30 daysRetained solely for automated security and abuse monitoring, then permanently deleted. Never used to train a model (see Section 7).
Client payloadAs the client instructs, and by default no longer than the engagement requiresReturned or deleted at the end of the engagement, at the client's election, as the Data Processing Agreement requires
Audit and security logs12 months from the eventDeleted
Inactive accountsNot deleted for inactivityNo action
Marketing contact recordsUntil you unsubscribe, then deleted within 30 daysA minimal suppression record is kept so that we do not email you again
Support correspondence24 months from the last message in the threadDeleted
Contracts, invoices and tax records7 years under UAE corporate tax law, 5 years under Egyptian VAT lawDeleted at the end of the statutory period

Project content. Project content is retained for 24 months after delivery because warranty questions, disputes and follow-on work rely on the project record. A client may ask us to delete its project record earlier, and we will do so unless a statutory record requirement (last row of the table) applies.

Backups. Backups exist to restore the service after a failure and rotate on a schedule rather than being edited. During the backup period your data exists only in backup, is not accessible in the product, and is used only for disaster recovery. If we restore a backup taken before your deletion, we re-apply the deletion to the restored data. Where a stricter rule applies in your jurisdiction, Section 21 states it.

Partner applications. We retain partner applications for 12 months so that we can contact you if a suitable engagement arises. You may ask us to delete an application sooner, and we will.

Estimator submissions. Section 6 describes how to request deletion of the whole record.

Meeting recordings. Any participant may ask us to delete a specific recording earlier, and we do not require a reason.

Embeddings. Deleting a comment deletes the embedding of that comment.

Assistant chat history is held in a separate AI database.

Client payload. Production access granted to our developers is revoked at the end of the engagement or the phase that required it, whichever is sooner.

Audit and security logs. Audit logs are retained for 12 months because a security incident cannot be scoped within 72 hours without records predating it. They are not exempt from the retention period stated above.

Inactive accounts. There is no dormancy deletion, and we do not reserve a right to delete an inactive account's content. Any change to this would be a material change under Section 22.

Contracts, invoices and tax records. These periods are required by law. They continue to apply after account deletion, after the end of your engagement and after an erasure request. They apply only to contract, invoice and tax data, not to your project content. These records are held outside DevStudio, as the platform has no payments module.

Emails already sent. DevStudio notification emails include the content of the item they relate to (for example, a task title, a comment or a project name). Deleting an item in DevStudio does not remove it from emails already delivered to recipients' mailboxes. Those copies are held in recipients' mail systems, outside our control, and cannot be recalled.

13. Your rights

To exercise your rights, write to privacy@hexifyer.com. Exercising any of these rights is free of charge.

RightWhat you can request
AccessA copy of the personal data we hold about you, and confirmation of whether we hold any
RectificationCorrection of inaccurate data and completion of incomplete data. This is the route for changing your email address (see Section 4).
ErasureDeletion of your personal data. Section 14 describes its scope.
RestrictionSuspension of processing while a dispute about the accuracy of the data or our legal basis is resolved
ObjectionCessation of processing based on legitimate interests, including product analytics and the partner management purpose in Section 5
PortabilityYour data in a structured, commonly used, machine-readable format. Section 15 sets out the specification.
Withdrawal of consentWithdrawal of any consent you have given (calendar sync, the notetaker, marketing, analytics) at any time
Automated decisionsHuman involvement in a decision with legal or similarly significant effect. DevStudio makes no such decisions (see Section 8).

13.1 Response time

We respond within 6 working days. We apply this deadline to every customer and every partner in every market. For example, a request logged on a Monday has a decision recorded by the following Tuesday.

13.2 Verification

We verify a request against the account to which it relates, usually by requiring it to be sent from, or confirmed at, the account's registered email address, and for an organisation-level request by confirming the requester's role. If we cannot verify your identity, we tell you what we need rather than refusing the request without explanation. We do not ask for identity documents.

13.3 Requests about a client payload

We forward the request to the client organisation that controls the data, as described in Section 2, and inform you that we have done so within the same six working days. This is the only category of request that we cannot answer ourselves.

13.4 Complaints

You may contact us first with any concern. You also have the right to lodge a complaint with a supervisory authority. Section 21 identifies the authority and the route for each region.

14. Deleting your account

You may ask us to delete your account at any time. A 14-day grace period applies, during which you may cancel the request without losing any data. After the grace period, erasure from the live systems is completed within 72 hours, and the backup period in Section 12 applies.

Your account is a Hexifyer account. The same account signs you in to Polaris, so deleting it from DevStudio deletes it for both products and removes your access to Polaris. What happens to your Polaris data is set out in the Polaris Privacy Policy. If anything in either product prevents the deletion, the product informs you before you confirm.

The scope of deletion depends on the type of account.

14.1 Partner accounts

Your account record, profile, rate, availability, links, skills and uploaded CV are deleted. The work you performed remains in the project record, which belongs to the engagement and to which the client is entitled, but your authorship of it is anonymised. The project team can see that the work exists and was performed by a former partner, but cannot see your name, email address or profile. Your name remains in audit records for their 12-month retention period, and in any signed contract or invoice for the statutory periods in Section 12.

14.2 Client contact accounts

Your account record and personal data are deleted. Your company's project record is not deleted, as it belongs to the company and other contacts at your company may still be using it. Your authorship within it is anonymised on the same terms as a partner's. Deletion of the company's project record must be requested by the company, as described in the first row of the table in Section 12.

14.3 Agency admin accounts

The same terms apply as for a client contact, with one exception: if you are the only admin of an agency that still has partners, the deletion is suspended until another admin is appointed or the agency is closed, so that the agency's partners are not left with assignments that no one can administer.

14.4 Scope of deletion

Deletion of your account removes your account record and anonymises your profile. It does not remove project content. Project content and historical logs remain as they are, including personal data about you entered by others: for example, your name in a meeting note, your email address in a task description, or a mention of you in a comment. A project record is the record of what was built, by whom and when. The client is entitled to it, and warranty and dispute questions rely on it. We do not undertake to search project content for references to a departing person or to redact them.

Where the law requires specific data to be removed in a particular case, we will assess and act on that case. The right to erasure in Section 13 is not displaced by this Section, and it is not absolute.

Section 15 describes how to obtain a copy of your data before deletion.

15. Exporting your data

Request an export at privacy@hexifyer.com. We deliver your export within 5 working days, which is within the six-working-day deadline in Section 13.

ItemDetail
One ZIP archivedevstudio-export-{project or account}-{YYYY-MM-DD}.zip
A READMEThe export date, its scope, the requester, every entity type included, and any excluded data, named explicitly
Your data as UTF-8 CSVOne file per entity type. For a project: tasks, subtasks, comments, logs, meetings and notes, sprints, topics, custom field values, team members with their roles, assistant chats, and an audit extract. For a partner: your profile, your application, your assignments and your contributions. Archived content is included.
Keys in every rowEach row includes its own identifier and its parent's identifier, so that the data structure is preserved
Your filesAttachments and deliverables in their original formats, with a manifest mapping the stored filename to the original filename, parent item, uploader and upload date

A self-service export in the product is planned. Until it is available, the email route above applies, as also provided in our Terms of Service.

16. Security

Encryption. Data is encrypted in transit using TLS, and at rest in every store described in Section 11.

Authentication. Password hashing, optional two-factor authentication, and federated sign-in with Google, Apple, Microsoft, LinkedIn and GitHub.

Access control within the product. The role model in Section 9 determines what each participant can see and do. It is enforced per project and per agency context rather than per organisation.

Audit logging. Sign-ins, permission changes and content changes are recorded and retained for the 12 months stated in Section 12.

Staff access. Hexifyer staff deliver your project, so staff access to project content is part of the service. Access by anyone other than the people delivering your project requires a business reason and is logged. Staff access to data stored in Frankfurt is remote access and does not move your data.

Access to client systems. Where a client grants our developers access to a live production system, that access is limited to the people who need it, revoked at the end of the engagement or the phase that required it, and governed by the Data Processing Agreement. Partners are bound by confidentiality obligations before they are assigned to a project.

Sub-processor due diligence. Standard written vendor agreements, in most cases the vendor's own data processing addendum, with vendor compliance reviewed periodically.

Certifications. Hexifyer DevStudio does not currently hold SOC 2 or ISO 27001 certification. Our security measures are those described above, together with the sub-processor list in Section 24 and the Data Processing Agreement. If certification is relevant to your procurement process, contact us for information on our current position.

17. Personal data breaches

If a breach of personal data we hold occurs, we notify the relevant supervisory authority within 72 hours of becoming aware of it, or sooner where a regime requires it. Under UAE law, notification is required immediately upon discovery, and we comply with that requirement. The 72-hour period applies under Saudi, Egyptian and EU law.

Where a breach affects a client payload and we act as processor, we notify the client organisation without undue delay so that it can meet its own obligations as controller, and we provide it with the information it needs to do so.

Where a breach is likely to result in a high risk to you, we also notify you, whether you are a partner or a client contact.

We document every breach, including those that do not meet the notification threshold, together with the reasons for that conclusion.

18. Cookies and analytics

We use cookies and similar technologies to keep you signed in, remember your preferences, and understand how the product is used. The last of these includes session recording of the web app. Session recordings run only if you allow analytics, and they are anonymised: we do not send your name or email address to our analytics provider, and text typed into input fields is masked before it leaves your browser.

Essential cookies are required for DevStudio to function. You can refuse all other technologies (analytics, session recording, and the attribution and advertising technologies on our marketing site) without losing any product functionality, including the estimator.

The Cookie Notice in Section 23 sets out what is set, by whom, for what purpose and for how long, and explains how to change your choices.

19. Marketing communications

DevStudio sends two types of email.

Service email. Project invitations, email verification, password resets, assignment notifications, sprint and meeting notifications, billing notices, security alerts, and the notifications you have configured. These are part of the service. You cannot opt out of them while your account is active, but you can choose which notifications you receive in your profile.

Marketing email. Product news, announcements and other promotional communications. These are sent only with your consent. Every marketing email includes an unsubscribe link. Unsubscribing takes effect immediately and does not affect service email. Submitting an estimator request does not constitute consent, and neither does applying to be a partner (see Section 6).

Content in notification emails. A notification about a task includes the task's title and the relevant text. These emails are delivered to recipients' mail systems, which we do not control, and deleting the item in DevStudio does not remove it from emails already delivered (see also Section 12). If content is sensitive, configure notification preferences accordingly before the content is created.

20. Age

You must be at least 18 years old to hold a DevStudio account. Every account holder acts on behalf of a company purchasing services or contracts to be paid for work.

We do not knowingly collect personal data from anyone under 18, and DevStudio is not directed at children. If we become aware that we hold personal data belonging to someone under 18, we promptly delete the account and its personal data. If you believe a minor holds an account, write to privacy@hexifyer.com and we will act on it.

21. Regional terms

The preceding sections apply to everyone. Hexifyer FZ-LLC is established in the United Arab Emirates, and the law set out in Section 21.1 applies to us as a company. The following provisions apply in addition for users in other regions. Where they conflict with the preceding sections, the regional provisions prevail for people in that region.

21.1 United Arab Emirates

ItemDetail
Applicable lawFederal Decree-Law No. 45 of 2021 on the Protection of Personal Data. Hexifyer FZ-LLC is registered in a Ras Al Khaimah free zone, which has no data protection legislation of its own, so the federal law applies and the DIFC and ADGM regimes do not.
AuthorityThe UAE Data Office. Its Executive Regulations have not yet been issued.
Response deadlineThe federal law requires a response without undue delay and sets no fixed period. We apply 6 working days.
BreachNotified immediately upon discovery, which is stricter than the 72-hour period, and we comply with it
LanguageThis policy is published in Arabic and English with the same effective date. Where the two versions conflict, the English version governs, except where UAE consumer protection rules require otherwise.

21.2 Saudi Arabia

ItemDetail
Applicable lawThe Personal Data Protection Law and its Implementing Regulations
AuthoritySDAIA, the Saudi Data and AI Authority
Response deadline6 working days, which is shorter than the Law requires
BackupsWhere Saudi law requires all backup copies of erased data to be destroyed rather than allowed to rotate out, we destroy them, and the 14-day period in Section 12 is a maximum rather than a schedule
RecordsWe keep our record of processing activities for the processing period plus five years, as required
TransfersYour data is stored in the EU. The transfers described in Section 7 to providers processing in the United States are covered by the safeguards in our Data Processing Agreement. Where the Law requires a particular instrument for a transfer of a client payload out of the Kingdom, putting it in place is the responsibility of the client organisation, as the exporter of that data.

21.3 Egypt

ItemDetail
Applicable lawPersonal Data Protection Law No. 151 of 2020 and its 2025 Executive Regulations
AuthorityThe Egyptian Personal Data Protection Centre. You may complain to the Centre directly without contacting us first.
Response deadline6 working days, per Article 32.
Legal basisConsent is the primary basis. Where Section 5 refers to legitimate interests, we collect and record your consent instead, and maintain a register of consent records with the withdrawal route attached.
LicensingThe Law provides for licences issued by the Centre to controllers and processors. Hexifyer FZ-LLC does not currently hold one.
BreachNotified to the Centre within 72 hours of awareness. The Centre notifies affected individuals within three days of our notification.

Licensing. The protections described in this policy (where your data is held, who can access it, how long we keep it, and the rights you have) do not depend on a licence and apply to you in full.

Transfers out of Egypt. Your personal data is written to Frankfurt, Germany when you create it, so it is transferred out of Egypt at the point of collection and continuously thereafter. Articles 14 to 16 govern the transfer, and the arrangement differs by role:

  • Where we are the controller (your account, your partner profile, project content, estimator submissions), we rely on the level of protection available at the destination. Germany is an EU member state, and the data is protected there by the GDPR and by German federal data protection law.
  • Where we are the processor (client payload), the transfer is governed by the Data Processing Agreement between Hexifyer FZ-LLC and the client organisation, incorporated into the Terms of Service, under which that organisation is the exporter and Hexifyer the importer. Hexifyer does not obtain Egyptian licences or permits on a client's behalf.

We do not ask individual users to consent to the transfer, and no individual consent is required under either arrangement.

21.4 European Economic Area and United Kingdom

ItemDetail
Applicable lawThe EU General Data Protection Regulation, and the UK GDPR with the Data Protection Act 2018
AuthorityYour national data protection authority, or in the UK the Information Commissioner's Office
StorageYour data is stored in Frankfurt, Germany. Hosting does not involve any transfer out of the EEA.
TransfersThe AI sub-processors in Section 7 and in the sub-processor list in Section 24 process in the United States. Those transfers rely on Standard Contractual Clauses with the supplementary measures set out in our Data Processing Agreement.
BackupsThe 14-day period in Section 12 is our advance disclosure of the backup deletion delay, as guidance requires. Regulatory guidance on backup erasure is expected to develop, and we will update this period and notify you if it changes.
Data Processing AgreementIncorporated into our Terms of Service by reference, so it is in force for every client without separate signature. It includes Standard Contractual Clauses and the security annex containing every period in Section 12. A copy is available at privacy@hexifyer.com, and we will sign a countersigned version on request.

21.5 California

We do not sell personal information and we do not share it for cross-context behavioural advertising. Section 12 sets out our retention period for each category, as required. California's rules permit the erasure of data held in backup to be delayed until the backup is restored or next used. Our practice is the 14-day period in Section 12, which is shorter, and we apply the shorter period.

22. Changes to this policy

The effective date of this version is shown at the top of the page.

Material changes (a new purpose, a new category of recipient, a longer retention period, a weaker commitment, a change to how deletion works, or any change to the separation described in Section 11) are announced at least 30 days before they take effect, by email to client contacts, agency admins and partners, and by a notice in the product. The introduction of a payments module, automated time tracking or automated partner scoring, or the use of estimator submissions for sales follow-up, would each be a material change under this Section. This policy states that we do not currently do any of these.

Other changes (clarifications, corrections, or rewording that does not change our practices) take effect on publication, and the last-updated date at the top of the page is changed.

Previous versions are kept in a public archive, showing what this policy stated on any date and what changed.

The sub-processor list in Section 24 is not part of this policy. It is updated separately, with its own 30-day notice and objection period, as described in Section 10.

23. Cookie Notice

This Cookie Notice describes the information DevStudio stores on your device, the purposes for which it is stored and the controls available to you. It applies to the DevStudio web application, the DevStudio mobile applications and our marketing site.

In this notice, "cookies" refers to cookies, browser storage that functions in a similar way, and the limited data our mobile applications store locally. Where any of this information is personal data, your rights in respect of it are set out in this Privacy Policy.

23.1 Summary of categories

CategoryPurposeOptional
Strictly necessaryKeeping you signed in and keeping your account secure. DevStudio cannot operate without them.No. They are used for no other purpose.
Functional and preferencesRemembering your theme, language, sidebar state, last view and unsubmitted drafts.Yes, by clearing site data. This removes your preferences, not your work.
AnalyticsUnderstanding how DevStudio is used in order to improve it. Set by Microsoft Clarity, a third party, and anonymised.Yes. Not loaded without your consent. See Section 23.7.

We do not use cookies for advertising, and we do not sell the information we collect.

23.2 Strictly necessary cookies

These are the only cookies DevStudio itself sets. They enable you to sign in and remain signed in securely.

CookiePurposeDuration
sb-{project-ref}-auth-tokenHolds your authentication session so that you remain signed in as you use DevStudio. Set by Supabase, our authentication provider. First-party.For the duration of your sign-in session
password_reset_pendingA short-lived marker used during password reset and multi-factor verification so that the process can complete securely. First-party, and removed when the process ends.Minutes (the duration of the process)

These cookies cannot be disabled. If you block them, you will not be able to sign in.

23.3 Browser storage

Most of the information DevStudio stores is held in browser storage rather than in cookies. Browser storage remains on your device and is not sent to us with each request. It falls into three groups.

Sign-in and navigation

ItemPurpose
authTokenKeeps your session valid in the application.
app_sourceRecords whether you arrived at Polaris or at Hexifyer DevStudio, so that you are directed to the correct product.
hexifyer_pending_invite_urlRecords the project invitation you were opening, so that you are taken to it after signing in.
Sign-up cooldown timersPrevents repeated sign-up and verification attempts in quick succession, as an abuse control.

Preferences

ItemPurpose
Language (i18nextLng) and themeRetains your language and appearance settings between visits.
Sidebar and widget layoutRecords whether your sidebar is collapsed and how your dashboard widgets are arranged.
View modesRecords whether you last used Kanban or list view on a project.
Dismissed hints and toursPrevents a tip from being shown again after you have dismissed it.

Caches and unsubmitted work

ItemPurpose
Attachment display URLsA short-lived cache so that files you are viewing are not repeatedly re-fetched.
Meeting recording timersKeeps a recording's elapsed time accurate if the page reloads during a meeting.
Unsubmitted draftsHolds work in progress (for example, an unfinished estimator wizard) so that it is not lost on refresh.
Session-only itemsProject and task filters, and temporary redirects during sign-up. These are held in session storage and deleted when you close the tab.

This information remains on your device. Clearing your browser's site data removes it and does not affect anything you have saved in DevStudio, which is held on our servers.

23.4 Mobile applications

The DevStudio mobile applications do not use cookies. They store the following in the application's own storage on your device:

  • Push notification subscription ID (onesignal_subscription_id), so that notifications are delivered to your device.
  • The currently open chat thread, so that the application returns you to it.
  • Grouped notification contents (onesignal_group_thread:{id}), so that multiple notifications about the same item are displayed as a single entry.

Uninstalling the application removes all of this data. You can disable notifications in your device settings at any time.

23.5 Analytics

If you consent to analytics, we use Microsoft Clarity to understand how DevStudio is used, which features are used, where users encounter difficulties and where errors occur. Clarity records interactions such as mouse movement, clicks, scrolling and page rendering, and replays them as a session.

Clarity is a Microsoft product and sets its own cookies, only after you have consented to analytics. Two are first-party; the others are Microsoft's own and are set across Microsoft services.

CookieSet byPurpose (as used by Microsoft)
_clckFirst-partyHolds a Clarity identifier for your browser, so that repeat visits are recognised as the same user.
_clskFirst-partyCombines the pages you view into a single recorded session.
CLIDMicrosoftIdentifies the Clarity project to which the recording belongs.
ANONCHKMicrosoftIndicates whether a user identifier is used for analytics only, and supports fraud checks.
MRMicrosoftControls whether the MUID identifier is refreshed.
MUIDMicrosoftIdentifies a browser across Microsoft sites. Microsoft's documentation describes it as used for advertising, site analytics and other operational purposes.
SMMicrosoftSynchronises the MUID identifier across Microsoft domains.

We do not use Clarity for advertising and do not run advertising campaigns using this data. The Microsoft cookies listed above are controlled by Microsoft and operate as Microsoft describes.

Consent. Clarity is not loaded until you accept analytics in the cookie settings, and no DevStudio functionality depends on it. If you decline, or do not respond, Clarity is not loaded and none of the cookies above are set.

Data not sent to Clarity. We do not send Clarity your name or email address. Recordings are not linked to a named account, and we cannot use them to look up the activity of a specific individual. Text entered into input fields is masked before it leaves your browser.

Page addresses. Masking applies to text entered into input fields and does not apply to page addresses. A page URL can reach Clarity as part of a recording, and a DevStudio URL can contain a project name. For this reason, analytics are loaded only with your consent.

Microsoft retains Clarity recordings for up to 30 days, and for up to nine months where a recording has been marked as a sample or favourite. Microsoft's privacy statement governs its use of the data it holds.

You may withdraw your consent at any time, as described in Section 23.7.

23.6 Technologies we do not use

  • No Google Analytics, and no advertising or attribution pixels in the DevStudio application.
  • No advertising profiles. We do not build, buy or sell advertising profiles, and we do not sell the data we hold.
  • No IndexedDB and no persistent offline database. Our API caches are held in memory only and are cleared when you refresh the page.
  • No cross-site tracking. The only third party that sets anything through DevStudio is Microsoft Clarity, described in Section 23.5.

23.7 Managing your preferences

Analytics. We request your consent before loading analytics. You can change your choice at any time using the cookie settings link in the footer of any DevStudio page. Declining prevents Clarity from loading and does not affect any other functionality.

Other storage. All other storage is controlled through your browser. Major browsers allow you to view and delete cookies and site data for an individual site, block third-party cookies, or clear all data on exit. Clearing DevStudio site data signs you out and resets your preferences; it does not affect your work.

Mobile. Notification permissions are managed in your device settings. Uninstalling the application removes the data it stored.

Do Not Track and global privacy signals. DevStudio does not respond to these signals. Use the cookie settings link described above to manage analytics.

To request access to or deletion of the personal data we hold about you, see this Privacy Policy, which sets out how to make a request and our response times.

23.8 Changes to this notice

We update this notice if we add a cookie, add a provider, or begin using an existing one for a new purpose. A material change (a new third party, or an existing one used for a new purpose) is announced at least 30 days before it takes effect, the same notice period as applies under this Privacy Policy and our Terms of Service. Corrections and clarifications take effect on publication, and the last-updated date is changed. Previous versions are kept in a public archive.

24. Sub-processors

Hexifyer DevStudio is operated by Hexifyer FZ-LLC, a free zone company registered in Ras Al Khaimah, United Arab Emirates under licence number 47017173, at FOAM1588, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates. We use a limited number of third-party providers that store or process personal data in order to operate the service. Each of these is a sub-processor.

This Section lists each sub-processor, its function, the data it receives and the location of processing. We keep this list current. Section 24.6 explains how to receive notice before the list changes.

24.1 Role of sub-processors

A sub-processor is a company we engage to help deliver the service and which may access personal data in doing so. Each is engaged under a written vendor agreement (in most cases that vendor's own data processing addendum) requiring confidentiality and protection of the data appropriate to the service it provides, and we review vendor compliance periodically. We remain responsible to you for their acts.

In DevStudio, Hexifyer is the controller of most of the data described here (project content, partner and agency records, and account records), because we deliver the work rather than providing a software tool. We act as processor only for personal data belonging to your own users, which this Privacy Policy refers to as client payload. Section 2 of this Privacy Policy sets out all three roles, and the Data Processing Agreement (Schedule 3 to the Terms, https://devstudio.hexifyer.com/terms) governs the processing of client payload.

Whether client payload reaches a sub-processor depends on how it is provided. Personal data belonging to your own users does not reach an AI sub-processor where it is provided by file upload or through access to a production system. An uploaded file is held only by the infrastructure providers listed in Section 24.2. A production system to which we are given access remains on your infrastructure and involves none of our sub-processors.

Text typed or pasted into a task, comment or note is project content regardless of what it contains. It is embedded when it is saved and reaches the AI providers listed in Section 24.4. Clause 8 of the Data Processing Agreement (Schedule 3 to the Terms) sets out where this line falls and who is responsible for observing it.

24.2 Infrastructure sub-processors

These providers host the DevStudio service and the data in it.

Sub-processorPurpose of processingData processedProcessing locationMore information
Supabase (Supabase, Inc., United States)Authentication and file storageAccount records and credentials, including email addresses, password hashes and federated sign-in identifiers. Stored files: profile photos, company and agency logos, partner CVs, agency application documents, project files, and task and message attachments.Germany (AWS eu-central-1)supabase.com/privacy
Render (Render Services, Inc., United States)Application hosting and databasesThe primary database: projects, sprints, tasks, logs, meetings, comments, partner and agency records, applications, estimator submissions and audit logs. The AI database: chat history between a user and the DevStudio assistant. Render also hosts the DevStudio backend, frontend and AI services.Germany (AWS eu-central-1)render.com/privacy
Amazon Web Services (Amazon Web Services, Inc.)Underlying cloud infrastructureAll data held by Supabase and Render is hosted on AWS. AWS does not access it in the ordinary course.Germany (eu-central-1)aws.amazon.com

All DevStudio project content, files and account records are stored in Frankfurt, Germany, in the AWS eu-central-1 region, for every client and partner regardless of location. Backups of both stores are held in the same region. The platform and AI sub-processors listed below receive narrower categories of data and process them in the regions stated for each.

24.3 Platform sub-processors

These providers deliver specific features. Each receives only the data required for that feature.

Sub-processorPurpose of processingData processedProcessing locationMore information
n8n Cloud (n8n GmbH, Germany)Workflow automation for the AI estimatorAn estimator submission in transit: the email address provided, the project description, the expected budget and the estimate returned. The stored record is held in the primary database.Germanyn8n.io/legal/privacy
Twilio SendGrid (Twilio Inc., United States)Transactional email deliveryRecipient name and email address, and message content, including project invitations, email verification, password resets, assignment and sprint notifications, and estimator results. Notification emails include task and project names.United Statestwilio.com/legal/privacy
OneSignal (OneSignal, Inc., United States)Mobile push notificationsDevice push token, device and app identifiers, and notification content, which can include task and project names. Delivery is completed by Apple Push Notification service on iOS and Firebase Cloud Messaging on Android.United Statesonesignal.com data handling
Nylas (Nylas, Inc., United States)AI meeting notesWhere the AI notetaker is used: the details of the meeting it joins, the meeting audio, the transcript and the notes generated from it, typically for sprint demos and client calls.United Statesnylas.com/platform/security
Microsoft Clarity (Microsoft Corporation, United States)Product analytics and session recording. Loaded only where a user has accepted analytics.Anonymised session recordings of use of the DevStudio web app: pages viewed, clicks, scrolling, form interaction, device and browser, and approximate location derived from IP address. We do not send Microsoft a user's name or email address, and text entered into input fields is masked before it leaves the browser. Page addresses are not masked and can form part of a recording.United Statesprivacy.microsoft.com

Section 6 of this Privacy Policy describes the handling of estimator submissions in full.

Payments. DevStudio has no payments module and no payments sub-processor. It holds no card numbers, bank details or payout credentials. Invoicing and payment of partners take place outside the product. If a payments module is introduced, the payment processor it uses will be added as a new sub-processor under the notice terms in Section 24.5.

Sign-in providers. Google, Apple, Microsoft, LinkedIn and GitHub are not sub-processors when used to sign in to DevStudio. The provider authenticates you under its own terms and provides the profile fields you approve. We do not instruct it to process data on our behalf, and it acts as an independent controller. Your account record, including the identifier linking it to that provider, is held by Supabase. If you connect a Google or Microsoft calendar, DevStudio reads and updates it directly through that provider under the permission you grant, on the same basis. Google is listed in Section 24.4 in its capacity as a provider of the AI models DevStudio uses, not as a sign-in provider.

24.4 AI sub-processors

DevStudio uses AI in five areas. The assistant answers questions about a project and carries out actions. The writers draft task descriptions, log entries and summaries. The reporting engine compiles daily, weekly and monthly reports. A scheduled agent organises and classifies project content on a schedule, without user initiation. The AI estimator produces an estimate from a project description.

Each of these sends the relevant content to a model provider outside DevStudio infrastructure. All AI requests pass through a single gateway, OpenRouter, which forwards each request to the provider serving it.

Sub-processorPurpose of processingData processedProcessing locationMore information
OpenRouter (OpenRouter, Inc., United States)AI gateway. Routes every AI request to the model provider that serves it.The full request sent to the model: the message, recent conversation history, and the project content the request requires (retrieved tasks, logs, meeting notes, comments and activity records). Estimator submissions reach the gateway through n8n Cloud.United Statesopenrouter.ai/privacy
OpenAI (OpenAI, L.L.C., United States)Text generation and embeddings: drafting tasks and logs, writing the final reply, summarising retrieved documents, and generating the embeddings used for project search.The request content above, and the text of project content embedded for search. Content is embedded when it is created, so it reaches this provider whether or not the assistant is used.United Statesopenai.com/policies
Google (Google LLC, United States)Text generation and pre-model processing: drafting task descriptions, classifying and routing requests, tool selection, rewriting search queries, compiling reports, and safety checks on incoming and outgoing messages.The request content above. The classification step and the safety checks process every message sent to and from the assistant.United Statespolicies.google.com/privacy
Anthropic (Anthropic, PBC, United States)Text generation over retrieved content: answering questions about project activity and documents from the records retrieved for that question.The retrieved records and documents, the question asked and recent conversation history.United Statesanthropic.com/legal/privacy

Retention and training. The providers listed above retain the inputs and outputs of a request for a maximum of 30 days, solely to detect and investigate misuse of their own services, and then delete them permanently. This retention is limited to trust, safety and abuse monitoring. It is not used to train any model or to improve any product. DevStudio does not route requests to an endpoint whose data policy cannot be established. Each request is pinned to a named provider from the table above, and the gateway is not permitted to fall back to an unlisted provider. Sections 7 and 12 of this Privacy Policy state the same 30-day figure.

Location. All AI providers process data in the United States. DevStudio does not route any AI request to a provider processing outside the United States or the European Union. The Data Processing Agreement (Schedule 3 to the Terms) sets out the safeguards applicable to these transfers.

No opt-out from AI features. The AI features cannot be disabled for a project or an account, and no such option is planned. The features form part of the operation of DevStudio (search, retrieval, the assistant and the reports), and use of DevStudio therefore involves processing of project content by the providers listed above, including at the time the content is created. The following commitments apply in place of an opt-out: no training, a maximum provider retention period of 30 days, pinning to named providers, 30 days' notice before a provider is added, and the client payload limitation in Section 24.1. Paragraph 9 of the AI Services Addendum (Schedule 2 to the Terms) and Section 7 of this Privacy Policy state the same.

Calendar sync and the AI meeting notetaker are optional, because consent is the lawful basis for them. No calendar data is read or written until a calendar is connected, and the notetaker runs only when it is enabled for a meeting.

24.5 Change notifications

We update this list when we add, replace or remove a sub-processor.

  • New sub-processors are posted here, and all subscribers are notified by email, at least 30 calendar days before they begin processing customer data.
  • You may object in writing within 30 calendar days of that notice, on reasonable grounds relating to data protection, by writing to privacy@hexifyer.com. This right applies to every client, partner and agency.
  • We will work with you to resolve the objection. If we cannot resolve it within a reasonable period, you may terminate the affected engagement without penalty.
  • Removal of a sub-processor requires no notice and carries no objection period. This list and our configuration are updated in the same release.

A new sub-processor does not begin processing until the notice period has expired.

Models may be changed within a named provider. A new provider cannot be added before the 30-day notice period has expired.

24.6 Subscribing to change notices

To be added to the sub-processor notice list, write to privacy@hexifyer.com. We use that address only to send sub-processor and data processing notices.

24.7 Contact

Questions about this list may be sent to privacy@hexifyer.com. Our Data Processing Agreement is Schedule 3 to our Terms of Service (https://devstudio.hexifyer.com/terms) and is in force. If your procurement process requires a countersigned copy, request one at the same address.

25. Deleting your account

This Section describes how to delete your DevStudio account and what is deleted and retained. Section 14 of this Privacy Policy sets out the full detail.

Hexifyer account. Your account is a Hexifyer account and also signs you in to Polaris. Deleting it removes your access to both products. The treatment of your Polaris data is set out in Section 11 of the Polaris Privacy Policy (https://polaris.hexifyer.com/privacy).

In the app. On the web, or in the DevStudio app for iOS or Android, open your account settings and select Delete account. Before you confirm, the app indicates which of the cases below applies to you and whether anything prevents the deletion.

By email. Write to privacy@hexifyer.com from the email address associated with your account and request deletion. We verify the request against the account and respond within 6 working days.

What is deleted. Your account record, credentials and profile.

  • Partner accounts: your profile, rate, availability, links, skills and uploaded CV are deleted. Work you performed remains in the project record, and your authorship of it is anonymised.
  • Client contact accounts: your company's project record is retained, as it belongs to the company, and your authorship within it is anonymised.
  • Sole admin of an agency with partners: deletion is blocked until another admin is appointed or the agency is closed.

What is retained. Invoice and tax records, for the statutory periods set out in Section 12. Audit records, for 12 months. Your name in any signed contract or invoice, for the statutory periods set out in Section 12. Project content remains with the project record, as described in Section 14.

Timing. A 14-day grace period applies, during which you can cancel the deletion without loss of data. After the grace period, your data is erased from live systems within 72 hours, and the last backup copy is deleted within 14 days after that.