Privacy Policy

Your privacy is important to us. This policy explains how DeviceLink collects, uses, and protects your information.

Information We Collect

DeviceLink collects only the minimum information necessary to provide our services:

  • Account information (the email address held by the sign-in method you use: Google, GitHub, Microsoft, or an email and password you set yourself)
  • Device identifiers for authorization and tool routing
  • Tool call usage records (tool name, timestamp, credits consumed)
  • Shared directory metadata (folder names and paths you explicitly publish)
  • Security and audit records (see Security and Audit Logs below)
  • Product usage data (see Analytics and Usage Data below)

DeviceLink does not store the contents of your files. File data is streamed in real-time between your device and the requesting client, and is never persisted on our servers.

How We Use Your Information

  • Authenticate and authorize your devices via OAuth and device proof-of-possession
  • Route tool calls between MCP clients and your local device agent
  • Track credit usage for billing purposes
  • Maintain service reliability and security

Analytics and Usage Data

We collect product usage data to understand how DeviceLink is used, where setup fails, and what to improve. This data is processed on our behalf by PostHog, hosted in the European Union.

When you are signed in, this activity is linked to your account: your user ID, together with the organization and workspace you are working in. We do not send the email address on your account to our analytics processor. We use that link to support you, to see how teams actually use the product, and to tell a real problem from a one-off. Your IP address is never sent to our analytics processor, and IP-based geolocation is disabled there, in both the web app and the CLI agent. Your IP address is recorded in our own security audit log, described below.

In the web app we record the pages you visit, the actions you take in the interface, your browser and operating system, and errors the application runs into. We never record file names, file contents, directory paths, or tool arguments.

The DeviceLink CLI agent reports usage data from your machine: a random install identifier generated on first run, the agent version, your operating system platform and major version, CPU architecture, and lifecycle events such as sign-in, connection, and the names of tools invoked. It never reports file names, file contents, directory paths, tool arguments, your username, or your machine identifier, and it does not record your IP address. Your device name is sent to DeviceLink, not to our analytics processor, so that you can tell your devices apart in the dashboard; it defaults to your computer's hostname unless you set one.

That install identifier is anonymous until you pair the device. When you sign in from the CLI, we link it to your account so that a device connecting and a tool running can be seen as the same person's session rather than as two unrelated ones. Opting out of telemetry means no identifier is sent and no link is made.

CLI telemetry is enabled by default and can be disabled at any time by setting DLINK_TELEMETRY=0 or DO_NOT_TRACK=1 in your environment.

Security and Audit Logs

Actions taken against an organization - signing in, approving a device, changing a member's access, calling a tool - are written to an audit log. Each entry records what was done and to which resource, the result, the email address of the account that did it, the IP address and browser user agent the request came from, the AI client used where one applies, and the time. This log exists so that an organization can see who did what, and so that we can investigate abuse and security incidents.

Audit entries for an organization are visible to that organization's administrators. They are retained while the account is active, and are kept after an account is deleted where we need them as a record of security-relevant activity.

Processors We Use

We use the following providers to run the service. They process data on our behalf and only for the purposes described here.

  • Google, GitHub, Microsoft - sign-in. We receive the email address on the account you sign in with, and basic profile information returned by that provider.
  • PostHog (European Union) - product analytics and error reporting, as described above.
  • Paddle - payment processing. Card details are handled by Paddle and never reach our servers.
  • Stripe - payment processing. Card details are handled by Stripe and never reach our servers.
  • Fly.io - application hosting.
  • Neon - PostgreSQL database.
  • Upstash - Redis cache.

Third-Party Integrations

DeviceLink integrates with AI platforms including Claude (Anthropic), ChatGPT (OpenAI), and other MCP-compatible clients. When you connect DeviceLink to a third-party AI platform, that platform may access your shared directories through our MCP server, subject to your explicit consent and the directories you choose to share. Beyond the anonymous analytics described above, we do not share your data with third parties beyond what is necessary to fulfill tool call requests you initiate.

You may revoke access granted to any AI platform at any time by disconnecting the connector from that platform's settings, or by revoking your OAuth token via the DeviceLink profile page. Revoking access immediately invalidates all active sessions for that platform.

Data Security

All communications are encrypted in transit (TLS). Authentication uses ES256 JWT tokens with short expiration times. Device authorization requires cryptographic proof-of-possession (Ed25519 signatures). OAuth flows use PKCE (S256) to prevent authorization code interception.

Data Retention

  • Account data - retained while your account is active
  • Device authorization records - authorization requests expire after 5 minutes; approved device keys are retained while the device is registered
  • Access tokens - short-lived, configurable expiration (typically minutes); automatically refreshed
  • Refresh tokens - time-limited with configurable TTL; extended on active use, expire after period of inactivity
  • Usage charge records - retained while your account is active, and after account deletion where we are required to keep billing records
  • Audit log entries - retained while the account is active, and kept after deletion where needed as a record of security-relevant activity
  • Product analytics events - retained by our analytics processor under its standard retention; deleted on request
  • File contents - never stored; streamed in real-time only

Your Rights

You have the right to:

  • Access your data - view your profile and usage history at /profile
  • Correct your data - update account information through your identity provider
  • Delete your account - from the Danger Zone on your profile page, or by asking us
  • Revoke access - disconnect devices or revoke MCP client access at any time

Deleting your account removes your sign-in identities and the email address attached to them, closes your personal organization and its workspaces, ends your memberships of any other organization, revokes every paired device so that a running agent can no longer connect, and revokes the access you granted to AI clients.

Two things are deliberately kept: billing and usage charge records, which we retain as financial records, and audit log entries, which are a record of security-relevant activity and may name the account that performed an action. If you want your product analytics events erased as well, or a copy of the data we hold, ask us on the support page and we will action it within 30 days.

Last updated: September 2026