Privacy Policy
01What we collect
From sign-in: your email address (or the email on your Google/GitHub account). From a paired GitHub account: your GitHub ID and username, used to verify that submitted repositories are yours. From an optional linked Discord account: your Discord ID, handle, avatar, and account creation date. From you: handle, and any display name, bio, tags, links, or location you choose to add. From submissions: your deployed URL, repository URL, demo video, screenshots, and description. From usage: basic analytics (pages viewed, language, rough region) and error reports when something breaks.
02What we don't collect
No passwords — our sign-in provider handles those and we never see them. No payment card numbers; Stripe holds those. No precise location, no contacts, no advertising profiles, no tracking across other sites.
03Age
devSprint is for people 13 and older. We don't knowingly collect data from anyone younger. If you believe a child under 13 has an account, email hello@devsprint.app and we will delete it.
04How submission data is used, including automated judging
Submission materials are used to verify eligibility and score your entry. To do that, your demo video, screenshots, and submission text are sent to third-party model providers for automated analysis and scoring, and your public repository is read through the GitHub API to confirm the work happened inside the sprint window. Providers process this content to return a result; they are not permitted to use it to train models on our account settings.
Scores, judging notes, and submission materials are published on the sprint page. Full transparency is a core feature: entering a sprint means your results are public, including non-winning ones.
05What's public and what isn't
Public: your handle, profile details you add, your submissions, scores, placements, and certificates. Your real name is public only if you choose to set a display name. Not public: your email address, your linked account IDs, and internal integrity checks.
06Where data lives and how long we keep it
Files (videos, screenshots, certificates) are stored on Cloudflare R2. Account and sprint records live in our database, hosted in the US. Demo videos and submission materials are retained for as long as the sprint results stand, so that any result can be re-reviewed in a dispute. Error reports are kept for a limited window for debugging. Certificates are designed to be permanent — that is the point of a verifiable credential — unless revoked for an integrity violation.
07Third parties we use
Clerk (sign-in and account linking), Convex (database), Vercel (hosting), Trigger.dev (running the sprint pipeline), Cloudflare (R2 storage and Turnstile human verification), Anthropic and Google (automated theme generation and judging), fal.ai (sprint artwork), GitHub (repository verification), Resend (transactional email), Discord (community and notifications, optional), Stripe (host payments), PostHog (analytics) and Sentry (error reporting). We don't sell data. Ever.
08Your rights
Export. Sign in and open your dashboard: “Download my data” gives you a JSON file containing everything we hold on your account — profile, linked accounts, notification settings, stats, sprint registrations, every submission with its scores and judging notes, your placements, and your certificates. It covers your account only; other builders' data and our internal integrity records are not included, and the file lists what it leaves out.
Deletion. The same page has a danger zone: type your handle to confirm and the account is closed immediately. We anonymize rather than erase. Your display name, avatar, bio, location, links, and your linked GitHub and Discord accounts are deleted; upcoming sprint registrations are dropped; every notification and email setting is switched off; and your handle is replaced with an anonymous one such as “deleted-builder-1a2b3c4d”. Past submissions and podium places are repointed to that anonymous handle so historical leaderboards stay accurate.
Deletion is permanent and cannot be undone — signing in again with the same email will not restore the account. Certificates you have already earned remain valid and verifiable unless they are separately revoked for an integrity violation. Our newsletter is a separate subscription that is not tied to your account: to stop those emails, use the unsubscribe link in any issue or email hello@devsprint.app.
You can also correct your data at any time by editing your profile. If you would rather not use the self-serve tools, or you want a copy or correction we don't cover above, email hello@devsprint.app from the address on your account and we'll action it within 30 days.
EU/UK users: our legal basis is contract for sprint features, legitimate interest for integrity and anti-abuse checks, and consent for analytics cookies.
09Cookies
A session cookie keeps you signed in and a preference cookie remembers your language. Analytics cookies load only if you accept them in the cookie notice. No advertising cookies.
10Changes and contact
We'll announce material changes before they take effect. Privacy questions, data requests, deletions: hello@devsprint.app. We answer within 7 days.