Privacy
What we hold, and what we refuse to do with it.
This policy describes the DeveloperAI workspace at this site. It is written in plain language so you can decide whether to connect production tokens.
Last updated October 6, 2026. Questions go to xandermarllc@gmail.com.
Who operates the service
DeveloperAI is the product name of this site. The operator is the party that runs this installation and can be reached at the address above.
Information we collect
- Account. Name, email, optional company, and a password hash. We do not store the password itself.
- Billing. The plan and cycle you select, the amount, whether you accepted the terms, and the Stripe customer, checkout, and subscription ids. Card numbers are entered on Stripe’s site. We store the payment status Stripe reports back, not the card.
- Integration credentials. GitHub personal access token, Jira site URL, Jira account email, Jira API token, Cursor API key, and the repository, source branch, and pull-request branch you select. Tokens and API keys are encrypted with AES-256-GCM before they are written to the database.
- Webhook secrets. A per-workspace token embedded in your Jira URL, plus separate secrets used to authenticate Jira and Cursor callbacks.
- Workflow metadata. Issue keys, run status, branch names, pull request URLs, agent ids, short summaries, and error text returned by the workflow.
- Security logs. Email and IP address for failed logins, kept long enough to rate-limit guessing.
Information we do not try to collect
We do not ask for payment card numbers on this site. We do not sell personal information. We do not use your repository contents or API keys to train models. Cursor usage is between you and Cursor; GitHub usage is between you and GitHub; Jira usage is between you and Atlassian.
How we use it
Credentials are decrypted only to call GitHub, Jira, or Cursor on behalf of that workspace: listing repositories and branches, reading an issue, creating a branch, launching an agent, commenting, and transitioning status. Account data is used to sign you in, enforce plan limits, and send operational replies if you contact us. Workflow metadata is shown on your dashboard and used to finish an in-flight ticket.
A temporary clone
Starting a ticket clones the selected repository to a temporary directory so the ticket branch can be created and pushed. That directory is deleted when the run finishes or fails. It is working space, not a code archive.
Cookies
The site sets one essential session cookie so you can stay logged in and so forms can be checked for forgery. It is HttpOnly and SameSite. We do not run advertising or analytics cookies.
Sharing
We transmit data to the GitHub, Atlassian, and Cursor accounts you connect, because that is the product. We send your email, the plan name, and the amount to Stripe so it can charge the card and renew the subscription. We do not give API credentials to other customers or to Stripe. Hosting and database infrastructure that runs this installation can technically access stored ciphertext and account fields; access is limited to operating the service.
Retention and deletion
Account data, credentials, and run history stay until you delete the workspace from the account page, or until the operator removes the account. Deleting the workspace removes the user, encrypted keys, repository selections, invoices, and run history. Login-attempt rows are operational and may persist after a failed login even if no account exists for that email.
Security
Passwords are hashed. API secrets are encrypted at rest. Webhook URLs are unguessable random tokens, and Jira calls also require a secret. You should still treat a personal access token like a password: create it with the narrowest access that can read and write the chosen repository, and revoke it if you stop using the workspace.
Your choices
You can replace any key, remove a saved repository, or delete the workspace. You can stop using the webhook by disabling it in Jira. To ask for a copy of account information, or to report a security problem, email the contact above.