Home

Legal · Privacy · updated August 2026

Privacy Policy

One policy for everything DevLune makes: the site, the client rooms, every app and tool. Written in plain English, without the legalese.

01

Who this covers

DevLune (“we”, “us”) is a software studio run by Sidharth from Hyderabad, India. This one policy applies to the DevLune website, the client portal and client rooms, and every application we publish or operate: Android apps on Google Play, desktop apps for Windows, macOS and Linux, web apps and SaaS products, browser extensions, APIs, and products we build and host for clients. If you reached this page from an app store listing, a sign-in screen, or an OAuth consent screen, this is the policy for that product.

Products covered today:

  • devlune.in (Website and client portal): Marketing site, estimate and contact forms, private client rooms at /client, admin portal at /portal.
  • DevLune app (Android app): The client's side of a DevLune project. Sign in with Google or email; we keep your name, email, a push-notification token per device, what you upload or write in a project, and payments you report. Shown to no third party. Delete the account from Settings; project records stay as contracts and invoices.
  • LearnFlow (Desktop and web app): Course player. Optional Google sign-in to stream videos from your own Google Drive. Progress stays on your device unless you opt in to sync.
  • SysWatch (Desktop agent and Android app): Real-time system telemetry paired with a short code. Metrics relay through our realtime backend and are not stored long term.
  • Aurora (Desktop app): Music player. Connects to streaming providers you choose to sign in to; credentials stay on your device.
  • Membrain (Self-hosted tool and hosted service): Memory ledger for AI assistants. Self-hosted data never reaches us; the hosted version stores what you save under your account.
  • Humanize (Web app): Text rewriting. Submitted text is processed by an AI provider to produce the result and is not used to train models.
  • DevLune Webmaster (Web dashboard): Site analytics for sites you own. Collects page views and performance events from those sites under your account.
  • HanuMart (Android app): Grocery shopping app with its own account system; see also the in-app policy pages hosted at devlune.in/hanumart.
  • Raseed (Desktop app): Billing software activated with a licence key bound to your machine; invoices and customers stay in your local database.
  • DevLune Inspector (and PE Inspector, APK Inspector) (Desktop app): Read-only static analysis of Windows PE binaries and Android packages. Files you open are read on your machine as data and are never uploaded, executed, or modified. No account, no licence key, and no analytics. The only network activity is a signed auto-update check and, if you open the Learn course, downloading its lessons from devlune.in.
  • Bespoke (Web app): Free, open-source AI resume builder at resume.devlune.in. No account; your resume is stored only in your browser. Only the text you send to your chosen AI provider leaves the device, and a local model or manual copy-paste mode sends nothing. Nothing per-user is stored on our servers, so there is no account to delete.
  • repo-sweep (Web page): Free, open-source page that bulk-manages the GitHub repositories you own, at siddhu123m.github.io/repo-sweep or from the file itself. No account and no server of ours: the GitHub token you paste stays in your browser and is sent to api.github.com only; the page loads nothing from any third party. Nothing per-user is stored on our servers, so there is nothing to delete.
  • Client builds (Apps and sites we build for clients): Where DevLune hosts or operates a product on a client's behalf, this policy applies to the parts we operate. The client's own policy governs their business data.

New products we release are covered from the day they ship, and the list above is updated when they do.

02

What we collect

We collect as little as each product needs to work. Depending on the product, that can be:

  • Account details you give us when you sign up or sign in: name, email address, and for social or Google sign-in the identifier and profile basics the provider shares.
  • What you submit: messages through our forms, estimate answers, files you upload to a client room, text you paste into a tool, comments and ratings.
  • Product data you create inside an app: course progress, playlists, saved memories, invoices, analytics events for sites you own, system metrics you chose to share.
  • Device and technical data: device model, operating system version, app version, language, crash reports, and a machine fingerprint for licence-locked desktop software.
  • Usage and analytics: pages visited, features used, approximate location from IP address, referrer and UTM parameters. We use privacy-respecting analytics and Meta's Conversions API for our own marketing site only.
  • Payment records: invoice and payment status. Card and bank details are entered with the payment provider (Razorpay or your bank), never stored by us.

We never ask for, and never store, passwords in plain text, government identity numbers, or payment card numbers.

03

How we use it

  • To run the product you are using and keep your data available across your devices where you opted in to sync.
  • To reply to you, send proposals, invoices, project updates and meeting invites when you are a client or a lead.
  • To activate and validate software licences and prevent a key from being used beyond its allowed devices.
  • To diagnose crashes and fix bugs.
  • To understand which pages and features are used so we can improve them.
  • To meet legal and accounting obligations, such as keeping invoices.
05

Where data lives and how it is protected

Hosted data is stored with Supabase (PostgreSQL, Mumbai region) and, for some products, Firebase, Cloudflare (KV, D1, R2) and Upstash. Files are stored in private buckets with signed access. Connections use TLS, secrets live in environment configuration rather than code, and administrative access is limited to Sidharth with multi-factor authentication.

Desktop apps keep your data on your machine in their own application folder. Licence files are signed so they can be checked offline without contacting us. Uninstalling the app removes the local database unless the app offers a separate export.

No system is perfectly secure. If we learn of a breach that affects you, we will tell you without undue delay.

06

How long we keep it

  • Leads and contact messages: until the conversation is over plus 24 months, unless you become a client.
  • Client rooms, proposals, signed agreements and invoices: for the life of the engagement and 7 years after, as accounting law requires.
  • Product accounts: until you delete the account or ask us to.
  • Realtime telemetry (SysWatch) and analytics events: raw events are discarded within 30 days; aggregates may be kept longer.
  • Crash reports and server logs: 90 days.
  • Licence activations: for the life of the licence, then deleted.
07

Google API Services user data

Products that connect to your Google account (for example LearnFlow, which reads the Google Drive folders you pick to stream course videos, or Google sign-in in any of our apps) comply with the Google API Services User Data Policy, including the Limited Use requirements. Use of information received from Google APIs is limited to providing or improving the user-facing features of that product.

Scope: we request the narrowest scopes that work. For Drive that is read access to files you explicitly select or share with the app, never your whole Drive.

Storage: Drive file contents are streamed and never stored on our servers. OAuth tokens and the folder structure are cached on your device (the app or your browser) only.

No transfer: Google user data is not transferred to third parties except as needed to provide the feature, for security, or as required by law. It is never used for advertising and never used to train AI or machine learning models.

Deletion: signing out revokes and deletes the tokens on your device. You can also revoke access at any time from your Google Account permissions page.

08

AI processing

Some products send text you provide to an AI model provider to produce a result (Humanize rewrites text; the client portal drafts emails and proposals; Membrain answers questions over your own saved notes). Only the text needed for that request is sent, it is processed transiently, and we use providers whose terms prohibit training on API inputs. We do not use your data to train models ourselves.

09

Third-party services

We rely on these providers, each under their own privacy policy and a data-processing agreement where applicable:

  • Hosting and infrastructure: Vercel, Cloudflare, Supabase, Firebase (Google), Upstash.
  • Email: Resend, for transactional and requested emails. Open and click tracking is enabled on studio emails so we know a proposal reached you.
  • Payments: Razorpay for Indian payments; international clients pay by bank transfer or a link we share after signing.
  • Scheduling: Calendly, when you book a call.
  • Sign-in providers: Google, Facebook and Instagram (Meta), where a product offers them.
  • Analytics and ads: privacy-respecting page analytics and Meta's Conversions API on devlune.in only. No ad tracking inside our apps.
  • App distribution: Google Play, which collects its own install and crash statistics.
  • AI providers: as described above, under API terms that exclude training.

Self-hosted versions of our open-source tools (such as Membrain) run entirely on your infrastructure; nothing from them reaches us.

10

Cookies and local storage

devlune.in uses a session cookie for portal and client-room sign-in and local storage for small preferences (for example a remembered choice). Marketing pages use no advertising cookies. Our apps use local storage and the operating system's secure credential store for tokens. Blocking cookies may sign you out of the portal but does not affect the public site.

11

Deleting your data

Any account or product: email sidharth@devlune.in with the subject “Delete my data” from the address on the account. We confirm within 7 days and remove everything we are not legally required to keep (signed agreements and invoices are retained for accounting). Apps with an in-app delete option (HanuMart, Membrain hosted, Webmaster) remove the account immediately.

Facebook and Instagram sign-in: see devlune.in/data-deletion, which also serves as the Meta data-deletion callback. Google: revoke access from your Google Account and sign out of the app.

12

Children

Our products are not directed at children under 13 (or the higher age your country sets) and we do not knowingly collect their data. If you believe a child has given us personal data, email us and we will delete it.

13

International transfers

We are based in India and our primary servers are in Mumbai. Some providers above process data in the EU or the United States under standard contractual clauses or equivalent safeguards. By using our products you understand your data may be processed in those regions.

14

Changes to this policy

When this policy changes we update the date at the top. For material changes affecting a product you have an account with, we notify you by email or inside the product before they take effect.

15

Contact

Data controller: DevLune, Hyderabad, Telangana, India. Questions, requests and complaints: sidharth@devlune.in. If you are in the EU or UK and are unhappy with our answer, you can complain to your local data-protection authority.