Privacy Policy

Information on data protection pursuant to GDPR

Who we are

The address of our website is: https://devshot.com

Responsible for this website is Anticipater GmbH, Alter Schlachthof 39, 76131 Karlsruhe, represented by Thorsten Reiser.

Cookies, analytics, and browser storage

We do not use advertising cookies, tracking pixels, or behavioural advertising. Necessary cookies may be used for authentication, security, and session continuity. Studio also uses local or session browser storage to retain your project capability, chat state, preferences, and recovery information in your browser. Clearing browser data removes that local state but does not automatically delete server-side account or project records.

Further information can be found in our Cookie Policy.

Website Hosting (Ionos)

The main DevShot website (devshot.com) is hosted on Ionos SE, Elstner Straße 57, 76199 Karlsruhe, Germany. Ionos may process server logs including IP addresses when serving pages.

More information: https://www.ionos.com/en/terms-privacy

Account Registration & Console Usage

When you register, use Studio or the Console, or contact us, we process data you provide, such as name, email address, billing details, prompts, project files, tool results, screenshots, command history, generated outputs, and support messages. We also process technical data such as IP address, browser information, request timestamps, project and session identifiers, security events, and usage metadata.

We process data to perform the contract and provide requested functions (Article 6(1)(b) GDPR), to protect the service, prevent abuse, keep audit records, and improve reliability based on our legitimate interests (Article 6(1)(f) GDPR), to comply with legal obligations (Article 6(1)(c) GDPR), and on consent where a function is optional and consent is the appropriate legal basis (Article 6(1)(a) GDPR).

AI-assisted Studio functions

Studio sends the information needed for a requested AI function to external AI model or speech processors. Depending on the task, this can include your prompt, selected project context or source files, tool results and screenshots, generated output, and — only after you confirm the separate AI voice disclosure — generated reply text for speech synthesis. DevShot does not intentionally send passwords, payment-card details, or other secrets; you must not include them in prompts or project context.

Before Studio sends a prompt or project context to an external AI processor, it asks for your explicit consent under Article 6(1)(a) GDPR. The consent banner identifies the data categories, purpose, recipient category, processing region, transfer risk, and withdrawal method. Your decision, the applicable consent version, and the decision time are kept in local browser storage; the current consent version is also submitted with each AI request and recorded in operational audit metadata. If you decline, Studio does not enable its AI functions. You can change your decision at any time using the "AI privacy" control in Studio. Withdrawal stops new AI requests and does not affect processing completed before withdrawal.

AI outputs may be inaccurate and must be reviewed. Studio displays that you are interacting with AI and marks generated content in the interface. We keep operational audit metadata such as timestamps, model identifiers, project or session identifiers, input size, consent version, and success or failure. The voice audit event records character count rather than the voice text itself.

Do not submit special-category data or third-party personal data unless you have a valid legal basis, have provided all required notices, and your agreement with DevShot covers that processing. Contact privacy@devshot.com before enabling a production workflow that requires a data-processing agreement.

International AI service providers

Some external AI model and speech services process data in the United States, outside the EEA. Depending on the service and transfer mechanism, this may expose data to different laws and possible access by public authorities. EEA transfers require a valid Chapter V GDPR mechanism: an adequacy decision where applicable or appropriate safeguards such as the European Commission's Standard Contractual Clauses together with a transfer-impact assessment and any required supplementary measures. Consent to the optional AI function is a separate legal basis for processing and does not replace those transfer safeguards.

The current service category, data scope, and region are listed on our Sub-processors page. The provider's identity and applicable compliance documents are available to business customers on request where contractual confidentiality permits. Unrestricted personal-data production use remains blocked until the required data-processing agreement, transfer safeguards, and legal/security review have been completed. Do not submit personal or sensitive data unless DevShot has confirmed that your use case is approved and contractually covered.

AI voice is optional and off by default. Before it is enabled, Studio explains the data sent, processing location, purpose, and how to withdraw. Turning AI voice off stops new speech requests; it does not undo processing already completed.

Hosting & Infrastructure (Hetzner)

Our servers and VM infrastructure run on Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Hetzner processes data on our behalf as a data processor. All data remains within the EU.

More information: https://www.hetzner.com/legal/privacy-policy

Console Hosting & Backend (Railway & Supabase)

The DevShot Console (web application) is hosted on Railway.app. Railway may process server logs including IP addresses when serving pages.

The Console backend, including authentication and data management, runs on Supabase, an open-source PostgreSQL database platform. Supabase processes account data and console metadata.

More information:

WebRTC & Real-time Connections (Cloudflare)

Desktop sessions use WebRTC technology to establish peer-to-peer connections between your browser and the VM agent. Cloudflare provides TURN relay services for NAT traversal. When a direct peer-to-peer connection is not possible, your session data is relayed through Cloudflare's infrastructure.

Session data (VNC and terminal) flows through encrypted WebRTC DataChannels and is not stored by Cloudflare. Cloudflare's involvement is limited to facilitating the connection; we do not transmit personal data to Cloudflare beyond the minimum required for relay.

More information: https://www.cloudflare.com/en-gb/privacypolicy/

Email Communication (Brevo)

We use Brevo (formerly Sendinblue) to send transactional and marketing emails. Brevo processes your email address and communication data. Email content and engagement data may be processed by Brevo's infrastructure.

More information: https://www.brevo.com/legal/privacypolicy/

Payment Processing (Stripe)

For payment processing we use Stripe Payments Europe, Ltd. Payment data is transmitted directly to Stripe and processed by them. We do not store your payment card details.

More information: https://stripe.com/privacy

Who we share your data with

We do not sell personal data. We disclose data only where necessary to provide, secure, and administer the service, including to:

  • Ionos — website hosting
  • Hetzner — VM infrastructure hosting
  • Railway — Console hosting and deployment
  • Supabase — Console backend and authentication
  • Cloudflare — WebRTC TURN relay for peer-to-peer connections
  • Brevo — email communication and transactional emails
  • Stripe — payment processing
  • External AI model and speech services — requested generation, review, computer-use, and optional voice functions
  • Professional advisers and authorities where legally required
  • Other recipients where you have given valid consent
  • Where we are legally required to do so

How long we retain your data

Account and billing data is stored for the contractual relationship and applicable statutory retention periods. Project, prompt, output, VM, and command-history content is retained while needed to provide the project or account and then deleted or anonymised according to the applicable plan and deletion workflow. Security and AI operational audit metadata is normally retained for 365 days unless a shorter period applies or a longer period is necessary to investigate abuse, establish legal claims, or comply with law. External processors may retain data for the periods stated in their applicable data terms.

You may request deletion at any time, subject to legal retention duties and data required to establish, exercise, or defend legal claims.

Your rights

Under GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, and the right to object. To exercise your rights, contact us at privacy@devshot.com.

Where processing is based on consent, you may withdraw consent at any time without affecting processing that occurred before withdrawal. You may object to processing based on legitimate interests. We do not make decisions producing legal or similarly significant effects solely through Studio AI output.

You also have the right to lodge a complaint with the supervisory authority: Landesbeauftragter fur den Datenschutz und die Informationsfreiheit Baden-Wurttemberg.

Contact

Anticipater GmbH

Alter Schlachthof 39, 76131 Karlsruhe

Email: privacy@devshot.com

Last updated: August 10, 2026