Privacy Policy

Last updated July 10, 2026

1. Overview

Vireo DevPulse (“DevPulse”, “we”, “us”) analyzes GitHub activity, quiz results, and profile settings to help developers understand and share their skill profile. This policy explains what data we collect, how we store it, and your rights under the GDPR and similar laws.

2. Data We Collect

  • Account data: Email address, display name, avatar (from GitHub OAuth).
  • GitHub data: Public repository metadata, languages, contribution patterns, pull requests, and issues — fetched via the GitHub API using your OAuth token.
  • Quiz data: Your quiz answers, scores, proficiency levels, and session history.
  • Usage analytics: Anonymous usage events via PostHog (page views, feature interactions, conversion events). No tracking cookies.
  • Crash reports: Error reports via Sentry, including stack traces and device information.
  • Billing data: Subscription status and provider identifiers (Stripe or Google Play). We do not store full card numbers.
  • Portfolio data: Bio, theme selections, visibility settings, and public portfolio content.

3. Data Storage

Your data is stored in the following locations:

  • Appwrite (self-hosted): Primary database and authentication for all user data.
  • Cloudflare: Pages (web hosting), Workers (API), KV (caching), R2 (file storage).
  • PostHog: Anonymous analytics events (EU region).
  • Sentry: Error reports and crash data (EU region).
  • Stripe: Billing records and payment identifiers.
  • Google Play: Android billing records and purchase tokens.

4. GitHub Token Handling

GitHub OAuth tokens are stored encrypted in Appwrite Auth identities and are never exposed to the browser or mobile client. Tokens are only used server-side by the Cloudflare Worker to fetch your repository data via the GitHub API. You can revoke GitHub access at any time from your GitHub settings or by deleting your DevPulse account.

5. Recruiter Visibility

Recruiter visibility is opt-in and only available for eligible premium profiles. You can enable or disable recruiter visibility from your settings at any time. When enabled, your public profile (skills, proficiency levels, portfolio) becomes searchable by recruiters with an active recruiter subscription. Your email address is never shown to recruiters.

6. Cookie Usage

DevPulse uses minimal cookies: an Appwrite session cookie for authentication and a PostHog cookie for anonymous analytics. We do not use third-party tracking cookies, advertising cookies, or social media tracking pixels. No cookies are set for users who are not logged in (except for the optional analytics cookie, which can be disabled).

7. Your Rights (GDPR Articles 15, 17, 20)

  • Access (Art. 15): You can request a copy of all your data at any time from your account settings.
  • Erasure (Art. 17): Delete your account from settings. This triggers a cascade delete of all your data, including GitHub data, quiz results, portfolios, and billing records.
  • Export (Art. 20): Export your portfolio data as JSON from the portfolio editor.
  • Rectification (Art. 16): Update your profile, bio, and job preferences from settings.
  • Objection (Art. 21): Disable recruiter visibility or analytics from settings.

To exercise any of these rights, contact support@devpulse.app or use the in-app account deletion feature.

8. Data Retention

GitHub data is cached for 7 days and refreshed on each sync. Quiz results and skill profiles are retained for the lifetime of your account. Account deletion removes all data within 30 days. Analytics data is retained according to PostHog’s data retention policy (default 1 year). Crash reports in Sentry are retained for 90 days.

9. Data Sharing

We do not sell your data. We share data only with our service providers (Appwrite, Cloudflare, PostHog, Sentry, Stripe, Google Play) for the purpose of providing the service. These providers process data under their own GDPR-compliant agreements. Recruiter searches are opt-in and only display your public portfolio content.

10. Billing

Billing data is processed by Stripe on web and Google Play on Android. DevPulse stores subscription status, provider identifiers, and billing event history for access control and auditability. We do not store full card numbers — Stripe and Google Play handle all payment processing securely.

11. Contact

For access, correction, export, deletion, or any privacy-related requests, contact support@devpulse.app.