Privacy Policy
DevControl processes only the information needed to connect an authenticated user to development machines they are authorized to control.
Data we process
- Account and authentication identifiers, OAuth grants, and capability selections.
- Device identifiers, device ownership, connection health, and enrollment state.
- Tool requests and results needed to perform the operation requested by the user.
- Artifacts explicitly transferred through DevControl.
- Billing and subscription identifiers when a paid plan is used.
Why we process it
We use this information to authenticate users, enforce device ownership and capabilities, route requested development operations, provide reliability and security controls, support customers, and administer paid subscriptions.
Recipients
Data may be processed by infrastructure providers required to operate the service and, for paid plans, by the configured payment provider. Tool results are returned to the authorized MCP client as required to complete the user's request. DevControl does not sell personal data or use tool content for advertising.
Retention
- OAuth access tokens expire after one hour. Refresh credentials remain until they are rotated, revoked, or the account authorization state is removed.
- Browser-control sessions default to two hours and are capped at eight hours. Web account sessions expire after twelve hours.
- Transferred artifacts expire after 24 hours by default; transfer grants expire after 15 minutes unless the deployment is configured more restrictively.
- Completed durable task records are retained for up to 30 days by default and are also capped by count. Nonterminal tasks are preserved for reliability until they reach a terminal state.
- Device ownership and enrollment state remain until the device is unlinked or the corresponding account state is removed.
- Payment records are retained by the payment provider and DevControl only as needed for subscription administration, accounting, fraud prevention, and applicable legal obligations.
Your controls
You can revoke browser sessions, unlink devices, sign out, rotate authorization, cancel a paid subscription through the configured billing flow, and request account or stored-state assistance through Support.
Security
Do not place authentication credentials in URLs or support reports. DevControl is designed to enforce account ownership, explicit capabilities, bounded execution, and minimum necessary tool responses.
Last updated: 2026-09-23.