Data Usage Policy

This policy explains how DeviceLink handles and processes your data.

What Data We Process

  • Authentication data: OAuth tokens and session cookies for user identity
  • Device identifiers: Cryptographic device keys for device authorization and proof-of-possession
  • Workspace metadata: Shared directory names and paths you explicitly publish
  • Usage records: Tool call metadata (tool name, timestamp, credit cost, success/failure status)
  • Billing data: Credit balance, purchase history, and payment references
  • Audit records: What was done to an organization, by which account, from which IP address and browser, and when
  • Product usage data: Pages visited, actions taken, errors encountered, and CLI lifecycle events, linked to your account. See the privacy policy for the detail

What We Do NOT Store

File contents are never stored on DeviceLink servers. When an MCP client requests a file, the content is streamed in real-time from your device through our bridge and is not persisted, cached, or logged. Tool arguments and file paths are not written to our analytics or audit records either - those record the tool name and result only.

DeviceLink is not end-to-end encrypted. Traffic is encrypted in transit with TLS, and our bridge terminates that connection in order to route the request, so file contents pass through our servers in memory. They are never written to disk, cached, or logged.

Data Processing Location

DeviceLink follows a local-first architecture. File operations happen on your device. Our cloud infrastructure handles authentication, device routing, billing, and MCP protocol bridging. Infrastructure is hosted on Fly.io with database on Neon (PostgreSQL) and caching on Upstash (Redis). Our application servers run in Fly.io's Stockholm region, and product analytics is processed in the European Union.

Data Retention

  • Account data: Retained while your account is active
  • Device registrations: Retained until you revoke or delete the device
  • Usage charge records: Retained while your account is active for billing purposes
  • Authentication tokens: Short-lived with configurable expiration; automatically cleaned up
  • Audit records: Retained while the account is active, and kept after deletion where needed as a record of security-relevant activity

You can delete your account at any time from the Danger Zone on your profile page, or ask us on the support page. Deletion removes your sign-in identities, closes your personal organization and its workspaces, ends your other memberships, and revokes your devices and connected AI clients. Billing records and audit entries are retained - the full detail is in the privacy policy.

Third-Party Services

  • Google, GitHub and Microsoft: User authentication (we receive the email address on the account and basic profile information)
  • PostHog (European Union): Product analytics and error reporting
  • Paddle: Payment processing (we do not store payment card details)
  • Stripe: Payment processing (we do not store payment card details)
  • Fly.io: Application hosting
  • Neon: PostgreSQL database
  • Upstash: Redis caching

Your Control

  • Disconnect your device or stop the agent at any time to revoke file access
  • Choose exactly which directories to share
  • View your usage history and billing at /profile
  • Request a copy of your data or request deletion via the support page

Last updated: September 2026