Privacy Policy
Last updated: July 31, 2026
DevThrottle is made and operated by Center Consulting. This page says what data the product and the website handle, where each part goes, how long it is kept, and what controls you have. It is written as capability — what each feature does — because that is the claim we can keep.
The shape of the product
Your coding agents run on your machines. What leaves your machine is what makes the remote features work: your Director pushes session state, conversation history, and similar data to a gateway — either the hosted Gateway we run for you, or one you run yourself. When you self-host, that data goes to your own machine and this page describes the software's defaults; when you use the hosted Gateway, we store it for you as described below.
The data map
One row per kind of content the product handles. This table is maintained against the product itself — when a store or a retention window changes, this page changes with it.
| What | Captured when | Stored where | Kept for | Your controls |
|---|---|---|---|---|
| Prompts and agent replies | On your machine, by the Director, from the agent’s transcript at the end of each turn | The Gateway, in your account’s own partition. The Director keeps no copy — this is the single copy | 30 days today (we may extend the default to 90; changes are posted here). Self-hosting? You choose your own window; the hosted Gateway always uses the published default | Export your entire history as one file, or delete all of it, from your account — deletion is immediate and removes the only copy; there are no backup copies of prompt history |
| Terminal screen recordings | On your machine, by the Director — and only when you turn recording on; it is off by default | Your machine only. Recordings are never pushed to any Gateway | Until you remove the session (removing a session purges its recording; each is capped at 8 MB). Short-lived turn-review screens expire after 7 days | The files are on your own disk — whoever can read that disk can read them, and deleting them is deleting files |
| Dictation text and audio | Your phone or desktop microphone, only while you are dictating | The Gateway, in your account’s partition | Transcripts 30 days. Audio: the turn’s clip is deleted when the turn completes; short-lived diagnostic audio expires within 24 hours; voice test clips and microphone-quality metrics after 30 days | Readable by members of your account only. No self-serve export or delete today — everything in this class ages out on the windows listed |
| Activity and status events | Pushed by your Directors as your sessions run (started, needs you, finished) | The Gateway database, in your account’s partition | 30 days | Readable by members of your account only; ages out on schedule |
| Session history and summaries | Derived on the Gateway from what your Directors push (repo, timing, outcome, AI-written summaries) | The Gateway database, in your account’s partition | 90 days. Deleting your prompt history does not retroactively remove already-derived summaries — they age out on this 90-day window | Readable by members of your account only; ages out on schedule |
| Operational telemetry and statistics | Counted by the Gateway as your Directors push — aggregate counts only (prompts per day, characters, concurrency), never prompt text | The Gateway database, in your account’s partition; service logs are identity-free by policy | Aggregate daily totals are kept indefinitely (they contain no content); concurrency detail 90 days; per-repository rollups 189 days | Your statistics pages show them; aggregates are not content |
| Account and device records | Sign-up and device enrollment — your email, subscription state, and the keys that enroll your machines | The Gateway database and the account system. API keys and device keys are stored as a SHA-256 hash only — the raw value is shown once at creation and cannot be shown again | Kept while your account exists | Revoking a key or device takes effect immediately; contact us to export records or close the account |
Who can see your data
Every Gateway store above is partitioned by account: the hosted Gateway physically separates each account's data, and one account's data is never readable by another. There is no in-product support access to your content — no impersonation feature, no admin read route over customer content, and no operator screen that shows it. Infrastructure access exists, as it does for every hosted service: the hosting operator administers the platform and could, at the infrastructure level, reach stored files and databases. The rule for that access: customer content is opened only for a named incident, with your explicit written consent, or where the law requires it — never for curiosity, debugging convenience, or product analytics. Every such access is written up as an incident record stating who accessed what, when, and why, and you are told, unless the law forbids telling you.
Processors we use
- Supabase hosts the service database and authentication.
- Stripe processes payments; card details go to Stripe, not to us.
- PostHog provides product analytics.
- Hosted AI features (transcription, speech, inference) run on AI providers we operate against; requests are sent to serve your call and usage is metered per account.
Export and deletion
You can export your entire prompt history as one file and delete all of it from your account. A prompt-history delete is immediate and final: the Gateway holds the single copy and keeps no backups of it. Already-derived session summaries age out on their own 90-day window. API keys and devices can be revoked at any time, immediately. For account deletion or any data request this page does not cover, use the contact below and we will handle it directly.
The website and billing
Separate from the product: your account and subscription live in our service database (Supabase); payments are processed by Stripe and card details stay with Stripe — we never hold card numbers; the usage ledger behind your credit balance is kept as the billing record; sign-ins are recorded (that is how accounts work); and devthrottle.com uses PostHog product analytics to understand product usage, not to build advertising profiles.
Changes
When this policy changes in a way that matters, the change appears here with a new date; significant changes are announced to account holders by email.
Contact
Privacy questions and data requests: open an issue on the DevThrottle repository or reach Center Consulting through centerconsulting.com.