devXOS

Privacy Policy

How devXOS handles your data

Last updated: August 9, 2026

Who we are

devXOS is an engineering intelligence product built by Sunny Systems. It studies how software gets delivered, and how AI is changing that, from the history your repositories already contain. What follows describes what the product stores today — not what it might store one day.

Your account

Signing in creates a user record holding your email address, display name and avatar URL, along with your language and theme preferences and the time of your last sign-in. Where email and password sign-in is enabled, we store a bcrypt hash of your password and never the password itself; turning on two-factor authentication adds the secret and backup codes that make it work. Administrative actions inside an organization — inviting a member, changing a role, revoking a token — are written to an audit log together with who acted, the IP address and the browser user agent of that request.

Repository data

devXOS reads commit and pull request metadata: sha, message, the author name and email as recorded by Git, dates, branch names, file paths and line counts. We do not download, store or transmit your source code, even where the permissions we hold would allow it. The analysis runs locally in the CLI, so what reaches our servers is the computed metrics rather than the repository.

AI usage data

If you enable AI usage reporting, the CLI reads your local agent logs and uploads aggregates only: session counts, token totals, duration and tool calls, grouped by repository, day, agent and model. Identity is discarded on your machine before anything is sent, and the receiving endpoint rejects outright any payload carrying a user, author or email field rather than quietly dropping it. The figures are shown at repository and team level behind a minimum-contributor threshold, so a row cannot be narrowed down to one person.

What we do not collect

No source code. No third-party analytics, advertising or session-replay scripts — the application loads none, so there is nothing to opt out of. No behavioural profiling. And no per-developer ranking or productivity score: devXOS analyses systems, and refusing to score individuals is a constraint built into the product, not a setting you have to find.

Cookies

Three, all functional. One keeps you signed in, one remembers the language you picked, and a short-lived one holds the GitHub organization you selected part-way through signup. None of them follow you across sites and none serve advertising.

Who else touches your data

Magalu Cloud hosts the application itself. Supabase hosts our database and file storage. GitHub provides sign-in and, once you install the devXOS GitHub App, the repository metadata we read. Transactional email — verification, password resets, two-factor codes, invitations — goes out through Maritaca, our notification service, which uses Resend for the final hop. Two more apply only if you switch them on: Stripe for billing, and Datadog when an organization connects it for deployment and incident correlation.

How long we keep it

Ingested metrics and analysis runs are kept for as long as your organization uses devXOS. We are honest about the current state here: there is no automatic expiry yet, so nothing is deleted on a timer. Deletion happens when you ask for it.

We do not sell your data

devXOS does not sell, rent or share your data with advertisers or data brokers. The subprocessors listed above are the only third parties that handle it, and each is there to operate the service.

Your rights

You can request an export, a correction or the deletion of your organization's data at any time. Removing the devXOS GitHub App installation revokes our access immediately; on request we delete the ingested metadata as well, and confirm when it is done.

Questions?

Reach us through our contact page for any privacy-related question.