1. Data controller
The controller for personal data used to operate DevPost is Emanuele Pavanello, Via Giuseppe Garibaldi 8, 10040 San Gillio (TO), Italy. Privacy requests can be sent to legal@emadev.co.
2. Data we process
- Account data: name, email address, password hash, email-verification records, waitlist access status and account timestamps.
- Session and security data: session identifiers, IP address, user agent, authentication events and OAuth state.
- Connected-account data: platform, account identifier, handle, display name, permissions, access and refresh tokens, token expiry and connection health.
- Publishing data: drafts, posts, titles, destinations, schedules, media, alt text, status, failures, source, prompts and model metadata when generative tools are used.
- Synced platform data: your published posts, public metrics, comments, replies, mentions, direct messages made available by the platform, author handles, links and sync cursors.
- MCP data: authorised client details, scopes, consents and access or refresh tokens.
- Support data: messages and information you send when asking for help or exercising a legal right.
3. Why we use it
| Purpose | Legal basis |
|---|---|
| Create accounts, authenticate users and provide publishing, scheduling, sync and MCP features | Performance of the service contract |
| Connect platforms and carry out the actions you request | Performance of the service contract |
| Protect accounts, investigate failures, prevent abuse and maintain reliability | Legitimate interests in security and service operation |
| Send verification, security and essential service emails | Performance of the contract and security interests |
| Meet binding legal requests and record obligations | Legal obligation |
DevPost does not use your content to make decisions producing legal or similarly significant effects about you. Generative features produce editable suggestions; publishing remains under your or your authorised agent's control.
4. Media and published content
Media uploaded through DevPost is stored for delivery to social platforms and served from a public, non-indexed URL. Anyone who obtains that URL may be able to access the file. Do not upload confidential material. Posts and media sent to a social platform become subject to that platform's visibility, retention and deletion rules. Removing material from DevPost does not automatically remove copies already published or retained by a third party.
5. Who receives data
We disclose data only as needed to operate the service or when legally required, including to:
- social platforms you deliberately connect or choose as publishing destinations;
- hosting, database, storage and infrastructure providers used for DevPost;
- Resend, which delivers account-verification and essential service email;
- MCP clients and agents you explicitly authorise;
- professional advisers, authorities or counterparties where necessary to comply with law or protect legal rights.
We do not sell personal data or share it for cross-context behavioural advertising.
6. International transfers
Connected social platforms and service providers may process data outside the European Economic Area. Where European data-protection law requires it, transfers must rely on an adequacy decision, standard contractual clauses or another permitted safeguard. You can request further information about relevant providers and safeguards at legal@emadev.co.
7. Retention
- Account, content and publishing history are generally kept while your account is active.
- Platform and MCP tokens are kept until you disconnect the integration, revoke access or delete the account.
- Sessions and verification records expire according to their security lifetime.
- Uploaded files may remain until they are deleted or no longer needed for publishing and operational recovery.
- Limited backups, security records or records required by law may be retained for longer.
You may request deletion at any time. We will remove or anonymise data unless retention is required by law or needed to establish, exercise or defend legal claims.
8. Cookies
DevPost currently uses only technical cookies and similar storage necessary for sign-in, session security and social-platform OAuth flows, including short-lived state and PKCE values. They are not used for advertising or behavioural profiling. Because these tools are necessary to provide the service, they do not require consent, but they are disclosed here.
9. Security
DevPost uses access controls, hashed passwords, scoped sessions, OAuth state checks and other reasonable technical and organisational measures. No online service can guarantee absolute security. If you believe your account or data has been compromised, contact us immediately.
10. Your rights
Subject to the GDPR and applicable law, you may request access, correction, deletion, restriction, portability or objection. Where processing relies on consent, you may withdraw it without affecting prior lawful processing. Requests can be sent to legal@emadev.co. We may need to verify your identity and will respond within the period required by law.
You may also lodge a complaint with the Italian Data Protection Authority or the supervisory authority in your country of residence or work.
11. Children
DevPost is intended for adults and is not offered to anyone under 18. We do not knowingly collect children's data.
12. Changes
This policy may be updated when the product, providers or legal requirements change. Material changes will be communicated in the service or by email where required. The effective date at the top shows the current version.
13. Contact
Emanuele Pavanello
Via Giuseppe Garibaldi 8, 10040 San Gillio (TO), Italy
legal@emadev.co