Privacy
Last updated: 3 September 2026
Dev Mutual is run by CodeEnsis Ltd, a company registered in Cyprus. This page says what we store about you, why we store it, who else sees it, and how to make us delete it. Questions and requests go to [email protected].
The short version: we store what the exchange needs to work and nothing else. We do not sell data, we do not run advertising, and there are no analytics or tracking cookies on this site.
What we store
- Your account. Name, email address, and a hash of your password — never the password itself. If you sign in with Google we store your Google account identifier and the name and email address Google gives us. We do not receive your Google password and we ask Google for nothing beyond your name and email.
- What you publish here. Apps you submit — store link, title, what you want tested — and the reports you write about other people’s apps.
- Screenshots you upload as proof that you installed an app and did the requested action, together with a checksum of each file.
- Your credit ledger. Every credit movement is a line in a journal: what happened, when, and how much.
- Server logs containing IP addresses and request times, kept because without them abuse cannot be traced.
Why we are allowed to
For everything that makes the exchange work — your account, your apps, your reports, your credits — the legal basis is the contract between us: you asked for the service and it cannot run otherwise. For server logs and abuse handling the basis is our legitimate interest in keeping the service usable for everyone.
Who else sees it
- Other members, in a limited way. A developer whose app you test sees your report and your screenshots. Your email address is never shown to them.
- Hetzner (Germany) hosts the servers and the database.
- Cloudflare (EU region) terminates TLS in front of the site and stores our encrypted backups.
- Resend (Ireland) delivers our email — confirmations, password resets, reminders.
That is the whole list. We do not pass your data to anyone else, and we do not move it outside the EU except as those providers do in the ordinary course of running their own infrastructure.
How long we keep it
- Screenshots: 90 days after the task they belong to is settled, then deleted automatically. The checksum stays, so duplicate submissions can still be spotted after the image itself is gone.
- Account, apps, reports and credit ledger: until you ask us to delete them.
- Backups: 90 days. A deletion reaches the live system immediately and works its way out of backups within that window.
Your rights
Under the GDPR you can ask for a copy of your data, ask us to correct it, ask us to delete it, or object to how we use it. Write to [email protected] and we will act within 30 days.
Deletion is handled by a person, not a button — the button is on our list, and until it exists an email does the same job. One part cannot be undone: reports you have already sent to a developer stay with them, because they paid credits for that feedback and it is theirs. We remove your name from them.
If you think we are handling your data wrongly, you can complain to a data protection authority — in Cyprus that is the Office of the Commissioner for Personal Data Protection, and you may also go to the authority where you live.
Cookies
One cookie, and it holds your session so that you stay signed in. It is not shared, not used for advertising, and disappears when you sign out. There is nothing here to consent to, which is why we do not ask.
Changes
If this page changes in a way that matters, we will say so by email before the change takes effect. The date at the top always reflects the current version.
See also our terms of service.