Privacy Policy
Last updated: September 2026
DevOpser LLC ("DevOpser", "we", "us") runs DevOpser Agents at agents.devopser.io (the "Service"). This policy explains what we collect when you use the Service, why we collect it, who processes it for us, and the choices you have.
The short version
- We collect what your team needs to work: your email address, your brief, your brand content and the work your experts produce.
- AI models on Amazon Bedrock process that content to do the work you ask for. We do not use your content to train AI models.
- We set two cookies, and both are needed for the Service to work. There are no analytics, advertising or tracking cookies.
- We do not sell your personal information or share it for advertising.
- You can ask for a copy of your data, a correction or deletion at info@devopser.io.
This summary is here to help. The numbered sections below are the policy.
1. Who we are
DevOpser LLC is responsible for the personal information described in this policy. If you have a question about it, email info@devopser.io. This policy covers DevOpser Agents only.
2. What we collect
Your account
- Email address and name. You sign in with a six-digit code we email to you, or with Google. If you use Google, we receive your name, email address and Google account ID.
- Two-factor authentication settings, if you turn it on.
- Guest teams. You can launch a team before you sign up. We create a guest account with a random placeholder email address and give it 100 free credits. When you save the team, we attach the email address you verify. To stop free credits being claimed again and again, we count launches per IP address for 24 hours.
Your onboarding brief
The brief asks for your site's address, your business name, what you sell, who buys it, competitor pages, what makes you different, claims you can prove, what your team must never promise, and the tone you want. With your answers we record which questions you reached, any campaign tags in the link that brought you (such as utm_source), and a keyed hash of your IP address instead of the address itself.
Your brand and your team's work
- Brand brain and library: what you and your experts record about your business, such as positioning, offer, voice, proof and guardrails, and the documents in your library. If you ask your team to read your website, it drafts entries from the pages it reads.
- Images: brand images you upload and images your experts generate. They are stored in DevOpser's Amazon S3 bucket and delivered through Amazon CloudFront so they can appear in your articles. Anyone who has an image's web address can open it.
- Knowledge documents you add to an expert.
- Your team's work: conversations with your experts, their runs and the steps they took, audits, targets, drafts, approvals and the articles you publish.
- Research about other sites and people: your experts read public web pages, such as competitor pages. When an expert researches outreach or press contacts, it records their public contact details, where it found them and why they are relevant. Experts draft outreach for you to review; the Service cannot send email to those contacts.
Google Search Console, if you connect it
We ask Google for read-only access. We store an encrypted refresh token and snapshots of your search performance: totals, daily figures, top queries and pages, and keywords where a small improvement could lift your ranking. We never change anything in your Search Console account. You can disconnect it in the Service at any time, and you can also remove our access from your Google account.
Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
Payments
Stripe handles checkout and payments. We never see or store your card number. Stripe tells us your customer ID, your plan, and the status of your subscription, invoices and payments.
Connected AI apps (MCP)
You can connect an app that supports the Model Context Protocol (MCP), such as Claude or ChatGPT. When you approve a connection, we store which app it is, the access you granted and when you granted it. The app's access tokens are short-lived. Work you send from a connected app runs on your account like work started in the command center. What happens inside that app is also covered by its provider's privacy policy.
Web search and your own search key
Your experts can search the web only through a SerpApi or Google Programmable Search key that you connect. There is no DevOpser search key. We store your key encrypted and use it only for your team's searches, and your search queries go to that provider under your own account.
Technical information
- Session: a session identifier in a cookie, with session data held in Redis. See Cookies.
- Request logs: our servers log the page or API route requested, the time, whether you were signed in and your session identifier. Some log lines include your account email address. We use logs to keep the Service secure and to fix problems.
- Abuse limits: sign-in attempts and free trial launches are rate limited, which means counting recent requests, for example by IP address.
3. How we use it
- To run the Service: your experts' research and drafts, your command center, and publishing what you approve.
- To email you sign-in codes, requests for your approval and notices about your account.
- To take payments and keep track of your credits.
- To keep the Service secure and prevent abuse, such as repeated free trials.
- To find and fix problems and make the Service more reliable.
- To meet legal obligations, such as keeping tax records.
We do not use your content to train AI models, we do not sell your personal information, and we do not use it for advertising.
4. AI processing
To do the work you ask for, the Service sends your instructions, your brief, your brand brain and library, and the pages your experts read to AI models. We use Anthropic's Claude models and Amazon's Nova models, run on Amazon Bedrock in AWS regions in the United States.
To generate an image, a Claude model on Amazon Bedrock first rewrites the request into an image prompt. The Service then queues a job for an AWS Lambda function that DevOpser operates, which sends the prompt to Stability AI's Stable Image Core model on Amazon Bedrock in the AWS us-west-2 region, through an AWS account DevOpser controls. The finished image is stored in DevOpser's Amazon S3 bucket and served through Amazon CloudFront.
AWS states that Amazon Bedrock does not use prompts and responses to train models and does not share them with model providers. AI output can be wrong; our Terms of Service explain what you need to review.
5. Who processes it for us
These companies process personal information on our behalf, only to run the Service:
- Amazon Web Services, Inc.
- Hosting in the United States, database, Redis, file storage (Amazon S3), content delivery (Amazon CloudFront), AI models (Amazon Bedrock), image generation jobs (Amazon SQS and AWS Lambda) and email delivery (Amazon SES). Receives the information needed to run the Service.
- Stripe, Inc.
- Checkout and payments. Receives your email address and plan choice, and the payment details you enter on Stripe's checkout page.
- Google LLC
- Google sign-in and Search Console, if you use them. Receives the requests those features need.
- DataForSEO
- Rankings, keyword data and backlink summaries, looked up on DevOpser's DataForSEO account. Receives the keywords and web addresses your experts look up.
- Zernio
- Social media scheduling and posting, on DevOpser's Zernio account. Receives the text, images and schedule of the posts you approve, and the access you grant to the social accounts you connect, so it can publish for you.
- Microsoft Corporation
- A backup route for some of our email, through Microsoft 365. Receives the recipient's address and the message.
Web search is not run by DevOpser. If you connect your own SerpApi or Google Programmable Search key, your experts' search queries are sent to that provider under your own account, and that provider's terms and privacy policy apply.
When an expert reads a public web page, the request comes from our servers, so that site sees our server's address, not yours.
6. Cookies
We set two cookies. Both are strictly necessary for the Service to work, so we do not ask for consent to use them.
__Host-session- Keeps you signed in and remembers your place. It is only sent over HTTPS, cannot be read by scripts on the page, and expires one day after your last visit.
dv_ob- Links an unfinished onboarding brief to your browser so you can come back to it. It cannot be read by scripts on the page and lasts up to 30 days.
We do not use analytics, advertising or social media cookies, tracking pixels or similar tools, which is why there is no cookie banner. If that changes, we will update this policy first and ask for your consent where the law requires it.
Google's sign-in page and Stripe's checkout page are run by those companies and may set their own cookies under their own policies.
7. When we share it
- With the providers in section 5, to run the Service.
- When you publish. Articles you approve, or let auto-publish, appear on your hosted blog, where anyone can read them.
- With apps you connect, within the access you approve.
- For legal reasons, when the law requires it, or to protect the rights, safety and security of our users, the public or DevOpser.
- In a business transfer, such as a merger or a sale of assets. This policy keeps applying to your information.
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as California law defines those terms.
8. International transfers
We host the Service in the United States. If you use it from another country, your information is transferred to and processed in the United States, where data protection laws may differ from yours. Where the law requires a safeguard for that transfer, such as for information from the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses, with the UK Addendum where needed, including in our agreements with the providers in section 5.
9. How long we keep it
- Account and workspace content: while your account is open. See Deleting your account.
- Session data: one day after your last visit.
- Unfinished onboarding briefs: the cookie that links a brief to your browser lasts 30 days.
- IP address counts for free trial limits: 24 hours.
- Guest teams that are never saved: we may delete them after a period without use.
- Billing records: as long as tax and accounting laws require.
- Request logs: for a limited period, for security and troubleshooting.
10. Deleting your account
You can delete your account yourself from Settings, under Account. Deletion is permanent. When you delete your account, we:
- cancel your subscription right away, so you are not charged again, and any unused credits are lost
- erase your workspace data for every property you own: your brand brain, library, images, knowledge documents, experts, their work and your Search Console data
- disconnect Search Console and every connected AI app, and delete your search keys and API keys
- take down your hosted blog
- delete your user record and sign you out everywhere
Stripe, which processes our payments, keeps its own records of your payments and invoices. Copies of erased data can remain in our backups until they age out on their normal retention cycle.
We may keep some records after deletion where the law requires it or to prevent fraud and abuse, such as billing records.
11. Security
- Connections to the Service use HTTPS.
- Stored credentials, such as Search Console tokens and your own search keys, are encrypted with AES-256-GCM.
- Sign-in uses one-time email codes or Google, with optional two-factor authentication, and sign-in attempts are rate limited.
- Session cookies are HTTPS-only and hidden from page scripts, pages run under a strict Content Security Policy, and changes to your account must come from our own site.
No system is completely secure. If a breach affects your personal information, we will notify you and the authorities as the law requires.
12. Your rights
Wherever you live, you can ask us to tell you what personal information we hold about you and give you a copy, to correct it, or to delete it.
European Economic Area and United Kingdom
Under the GDPR and the UK GDPR, we rely on these legal bases:
- Contract: to provide the Service you signed up for, including billing.
- Legitimate interests: to keep the Service secure, prevent abuse and make it more reliable, where your rights do not override those interests.
- Consent: where we ask for it. You can withdraw consent at any time.
- Legal obligation: for records the law requires us to keep, such as tax records.
You also have the right to restrict or object to our processing, to receive your information in a portable format, and to complain to your local data protection authority (in the UK, the Information Commissioner's Office). We do not make decisions about you based only on automated processing that have legal or similarly significant effects.
California and other US states
Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and similar state laws, you have the right to know what personal information we collect, use and disclose, to access it, to correct it, to delete it, and not to be treated differently for using these rights.
We collect these categories of personal information: identifiers (such as name, email address and IP address), commercial information (such as your plan and purchases), internet activity (such as request logs) and professional information (such as details about your business). We collect them for the purposes in section 3 and disclose them to the providers in section 5. We do not sell or share personal information, and we do not use sensitive personal information for any purpose that would give you a right to limit it.
You can use an authorized agent to make a request for you.
How to make a request
Email info@devopser.io. We may ask you to confirm the request from your account email. We reply within 30 days. If the law allows more time and we need it, we will tell you why.
13. Children
The Service is for adults running a business. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you think a child has given us personal information, email us and we will delete it.
14. Changes to this policy
When we change this policy, we update the date at the top of this page. If a change is significant, we will also email account holders before it takes effect.
15. Contact us
DevOpser LLC
Email: info@devopser.io