Who we are
DevFox Labs is a personal project run by one person based in Romania, and that person is the data controller for everything described below. For anything to do with your data — a copy of it, a correction, deletion, or a question about any of this — write to privacy@devfoxlabs.com. That address reaches the controller directly.
No Data Protection Officer has been appointed. The Platform does not monitor people on a large scale and does not process special categories of data as a core activity, so none of the conditions in Art. 37 apply.
Controller of record: Antonii Illarionov, a private individual resident in Romania.
1. Introduction
DevFox Labs (“we”, “us”, “our”) is committed to protecting your personal data. This Privacy Policy explains what information we collect, how we use it, and your rights under applicable data protection law, including the General Data Protection Regulation (GDPR).
2. Data We Collect
When you register or use the Platform, we may collect:
- Account data — email address, username, and hashed password
- Profile data — name, phone, country, city, profession, experience, and social links you optionally provide
- Usage data — lessons started, completed, time spent, and sections viewed
- Technical data — IP address, browser type, and device information collected via server logs
- OAuth data — if you sign in with GitHub or Google, we receive your public profile information from that provider
3. How We Use Your Data
We use your data to:
- Provide, maintain, and improve the Platform
- Authenticate you and manage your account
- Track and display your learning progress
- Send transactional emails (email verification, password reset)
- Detect and prevent fraud, abuse, and security incidents
We do not sell your personal data to third parties. We do not serve advertising.
4. Cookies and Consent
Storage that is strictly necessary to run the Platform is set without asking, because without it the Platform cannot do what you came for: an HTTP-only cookie holding your refresh token, a cookie recording your cookie choices, Cloudflare’s bot-protection cookies on forms you submit, and — only once you change them yourself — your theme and editor preferences.
Everything else is off until you turn it on, and we ask before setting any of it. We use no advertising cookies and no cross-site tracking. Refusing has no effect on what you can read or do here.
You can change your choices at any time from Cookie settings in the footer of every page. We honour the Global Privacy Control browser signal as a refusal. The full inventory — every cookie and storage key, its purpose and its lifetime — is on the Cookie Policy page.
Because the law requires us to be able to demonstrate that consent was given, we keep a record of each decision: the categories chosen, the version of the notice shown, the time, a random identifier that links a device’s decisions together, and a one-way hash of the IP address — never the address itself. These records are deleted after three years. Deleting your account removes your name from them but keeps the pseudonymised record, which we rely on Art. 17(3)(e) to retain as evidence.
5. Counting Visits Without Cookies
Separately from anything above, we count visits to the Platform in a way that sets nothing on your device and reads nothing from it. It works entirely from what your browser sends with every request anyway, which is why it does not appear in the cookie banner: there is no storage involved, so there is nothing to ask permission for under the ePrivacy rules that govern cookies.
What we record is: the page requested, your country as our content delivery network reports it, the website you followed a link from — the site’s name only, never the full address — and whether you are using a desktop, a phone or a tablet. We do not store your IP address and we do not store the identifier your browser sends describing itself.
To count one reader once a day rather than once a page, we turn your IP address and browser description into a one-way hash using a secret that changes every calendar day. That hash cannot be reversed into an address, it cannot be matched against the following day’s hashes, and we delete it within 48 hours. What remains after that is a set of counters — a date, a country, a number — that describes nobody. We keep those for three years so one year can be compared with another.
The lawful basis is our legitimate interest under Art. 6(1)(f) GDPR in knowing whether the material we publish is being read at all. We have carried out and written down the balancing test that basis requires. You can object under Art. 21 GDPR: send a Global Privacy Control signal from your browser and we stop counting you before anything leaves our servers, or write to us using the contact details below.
6. Third-Party Services
We rely on the following sub-processors to operate the Platform. Each processes personal data only on our instructions, under a data processing agreement.
- Supabase — database and file storage (EU or US region depending on configuration)
- Upstash — Redis caching and session storage
- Resend — transactional email delivery (verification and password reset)
- Vercel — frontend hosting and edge CDN
- Render — backend API hosting
- Sentry — error and performance monitoring. Runs on every page as a security and stability measure. It is configured not to send personal data, and session replay is not enabled
- Cloudflare — DNS, CDN, WAF, and Turnstile bot protection
- YouTube (Google) and Vimeo — video embedded in lessons. Contacted only after you allow embedded content; until then no request reaches them
- Google Analytics (Google Ireland Ltd / Google LLC) — counts visits and shows which lessons are read and where readers stop. Loaded only after you allow analytics; refuse, and the script is never fetched at all
About Google Analytics specifically. We send it no name, email, username or search text, and no account identifier of any kind — nothing in an analytics event can be traced back to your profile. Google processes the data on our instructions under the Google Ads Data Processing Terms and retains it for 14 months. Google signals and ads personalisation are switched off, so it is not used for advertising or cross-device tracking.
Withdraw at any time through Cookie settings in the footer — the cookies it set are deleted in the same click. Google also publishes a browser opt-out add-on that works across every site using Analytics.
Some of these process data in the United States. Where they do, the transfer relies on the EU–US Data Privacy Framework or on Standard Contractual Clauses, depending on the provider.
7. Your Rights (GDPR)
If you are located in the European Economic Area, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request erasure of your data (“right to be forgotten”)
- Object to or restrict processing of your data
- Receive your data in a portable, machine-readable format
- Withdraw consent at any time where processing is based on consent
To exercise any of these rights, use the data export or account deletion features in your Profile settings, or contact us directly.
You also have the right to lodge a complaint with a data protection supervisory authority. You may complain to the authority in the country where you live or work, or to the one that supervises us: the National Supervisory Authority for Personal Data Processing (ANSPDCP) in Romania — www.dataprotection.ro.
8. Data Deletion
You may delete your account from your Profile settings at any time. Account deletion is soft-deleted immediately and permanently deleted after a 30-day grace period, during which you may cancel. On permanent deletion, your personal data is anonymised — progress records are retained in anonymised form for aggregate analytics only.
You can request a full export of your data (profile, progress, and activity) as a JSON file from your Profile settings before deleting your account.
9. Data Retention
We retain your account data for as long as your account is active. Server logs are retained for up to 90 days. After your account is permanently deleted, all personal data is anonymised within 30 days.
10. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes by email or by posting a prominent notice on the Platform. The “last updated” date at the top of this page reflects the most recent revision.
11. Contact
For privacy-related requests or questions, please use our contact page or email privacy@devfoxlabs.com.