Privacy policy
Last updated 3 October 2026
This page explains what personal data devquake.com and its apps on *.devquake.com collect, why, how long we keep it, and what you can ask us to do with it. In short: we collect what we need to run your account and keep it safe, we never sell data, and analytics only run if you say yes.
This policy is available in English, German, Romanian and Hungarian; every language version is equally valid.
1. Who is responsible
The controller of your personal data is Kurazs Lorant Alexandru, Telegrafului 34, Timisoara, Timis, Romania 300135. For anything related to your data, write to contact@devquake.com.
2. What we collect and why
| Data | When | Why | Legal basis (GDPR) |
|---|---|---|---|
| Name, email address, password (stored only as a one-way scrypt hash) | When you create an account | To give you an account and sign you in | Contract (Art. 6(1)(b)) |
| Your language (English, German, Romanian or Hungarian), and the preferred language you chose in your profile | When you use the site in a language or pick one | To show the site and send you emails in your language | Contract (Art. 6(1)(b)) |
| Roles, projects you subscribed to, projects the owner assigned to you, and an internal rating set by the site owner | When the owner configures your account | To give you access to the right apps and manage the community | Contract; legitimate interest (Art. 6(1)(f)) |
| Ideas you share (title, description, the project, an optional picture), your votes and your comments on ideas | When you share an idea, vote or comment | To collect and discuss ideas for new apps. Public ideas and comments show your name to signed-in members; private ideas only to you | Contract (Art. 6(1)(b)); legitimate interest for moderation (Art. 6(1)(f)) |
| Projects you liked and your ratings of them (quality and usefulness, 1 to 5 stars) | When you like or rate a project | To show which projects people find useful and decide what to build next; only totals and averages are shown publicly | Legitimate interest (Art. 6(1)(f)) |
| One-time sign-in codes (stored only as a hash, valid 10 minutes) and account activation links (stored only as a hash, valid 48 hours) | Every sign-in, and once when you create an account | To confirm it is really you | Contract; legitimate interest in security |
| Password-reset links (stored only as a hash, valid 60 minutes), the time and IP address of each request | When you use “Forgot your password?” | To let you choose a new password and to stop abuse of the reset form | Contract; legitimate interest in security |
| Sign-in details: date and time, IP address, approximate location of the IP (country, region, city), internet provider, whether the IP belongs to a VPN or proxy (and its provider), browser, operating system, device type, and your browser’s time zone, language and screen size | Every sign-up, sign-in and code entry, successful or not | To detect and stop account takeovers, lock an account for 3 hours after 3 wrong passwords in a row, show you your recent sign-ins, and produce security statistics | Legitimate interest in keeping accounts and the site secure |
| Name, email address, subject, message, IP address and browser, and our replies to it. Signed in, your account’s name and email are used, and you see your messages and our replies on your account, where you can delete them | When you use the contact form or write from your account | To answer you (on your account and by email) and to block spam | Legitimate interest in answering enquiries; pre-contract steps where relevant |
| Log of emails we sent you (type, time, delivery status; not the content) | When we email you | To troubleshoot delivery and prove security notices were sent | Legitimate interest |
| Activity log of actions on the site (for example sign-ins, account changes, errors), with IP address and browser | While you use the site | Security, troubleshooting and abuse prevention | Legitimate interest |
| Profile picture (optional, 256x256), your personal invitation code and NPS score, who invited you, and the email addresses you invite | When you upload a picture, share your link or send an invitation | Your profile, and the invitation feature you use (the invited person gets one email naming you) | Contract; legitimate interest in letting members invite people |
| Which apps you tried for free and when the 24-hour trial started and ended | When you start a free trial of an app | To open the app for you for 24 hours, only once, and to delete what you created in it if you do not subscribe | Contract (Art. 6(1)(b)) |
| Your custom themes (name, colours, fonts), the members you shared them with, and the theme you last chose | When you create or share a theme | To show the site in your theme on every device you sign in on, and let the people you chose use it; they see the theme and your name | Contract (Art. 6(1)(b)) |
| Your birthday (day and month, the year only if you give it; or only the year, if an app you allowed saved just that), and for each year when we sent the birthday email and when and how you received the gift point | When you enter your birthday on your account page | To wish you a happy birthday by email and on the site and to give you one NPS point as a gift, once a year; the year is never shown The apps you allow (Account → Connected apps) may read it and, if you allow it, change it; a family app shows it to your family. | Consent (Art. 6(1)(a)): remove your birthday at any time on your account page |
| Which apps you subscribed to, also after you leave one | When you subscribe to an app | So that connecting an app you had before subscribes you to it again without NPS points | Contract (Art. 6(1)(b)): part of how subscriptions and NPS points work |
| In-app notifications: reminders of upcoming events from the apps you subscribed to (title, short text, link, when you read it) | When an app reminds you of an event it also emails you about | To show the reminder in that app and on devquake.com | Contract (Art. 6(1)(b)): part of the apps you subscribed to |
| Anonymous visit counts: a daily visitor number derived from your IP address and browser with a random salt that is deleted the next day; only daily totals are kept | Each page view on devquake.com | To show how many people visit (also on the landing page) | Legitimate interest; no cookies, and nobody can be identified from what is stored |
| Usage statistics via Google Analytics (pages viewed, which app you use, which app features are used such as “list created” or “product added” without any names or contents, approximate location, device, a random identifier in a cookie) | Only if you click “Accept analytics” | To understand which pages are useful and improve the site | Consent (Art. 6(1)(a)), which you can withdraw any time |
We cannot see your device’s MAC address or, if you use a VPN, your real location: we only see the VPN server. We do not use your data for advertising, we do not sell it, and we make no automated decisions about you other than the temporary security lock described above.
4. Who else processes data
We only share data with service providers that help us run the site:
- Hostinger hosts the website, the database and our email, so all data above is stored on its servers.
- proxycheck.io receives the IP address of each sign-up and sign-in and returns its approximate location, provider and whether it is a VPN or proxy.
- Google (Google Analytics) receives usage data only if you accept analytics. Google may process it outside the EU, including in the United States under the EU–US Data Privacy Framework.
We may also disclose data where the law requires it, or to protect the site and its users against fraud or abuse.
5. How long we keep it
Old data is deleted automatically once a day after these periods:
| Data | Kept for |
|---|---|
| Your account, picture, language, roles, subscriptions, likes, ratings, invitations, and your ideas, votes and comments | Until you delete your account (Your account → Delete account) or ask us to. The site owner may remove accounts that have not been used for a long time; you get an email when that happens. |
| What you created in an app (for example your shopping lists) | Until you unsubscribe from that app or delete your account; shared content stays with the other people, without your name |
| What you created in an app during a free trial, if you did not subscribe | 30 days after the trial ended |
| Your custom themes and who you shared them with | Until you delete the theme or your account |
| Your birthday and the record of each year’s gift | Your birthday until you remove it; the gift record until you delete your account |
| Which apps you subscribed to | Until you delete your account |
| In-app notifications | 2 months |
| Addresses you invited who never joined | 3 months |
| Accounts whose email was never confirmed | 30 days |
| Sign-in activity (sign-in details and snapshots) | 3 months |
| Your account activity (sign-ins, subscriptions, changes to your account) | 3 months |
| Password attempts used for lockouts | 3 months |
| Other activity log entries | 6 months (security events 1 year) |
| Expired sessions, one-time codes, activation and password-reset links | 7 days |
| Record of emails sent | 1 year |
| Contact-form messages and our replies | 2 years |
| Anonymous visitor hashes and their daily salt | 1 day (only daily totals remain) |
| Google Analytics data | Per the retention set in Google Analytics (at most 14 months) |
6. Your rights
Under the GDPR you can ask us to:
- give you a copy of your personal data (access and portability);
- correct it if it is wrong;
- delete it, including your whole account (you can do this yourself: Your account → Delete account);
- restrict or object to how we use it, including processing based on legitimate interest;
- withdraw your analytics consent at any time (with “Cookie settings”).
Email contact@devquake.com from the address on your account. We answer within one month. If you are not satisfied, you can complain to the data protection authority of the EU country where you live or work.
7. Security
Passwords are hashed with scrypt, sign-in codes and session tokens are stored only as hashes, every sign-in needs a code sent to your email, connections use HTTPS, and repeated failed sign-ins lock the account temporarily and notify you. Access to user data is limited to the site owner.
8. Changes
We update this page when what we collect or why changes, and show the date at the top. For significant changes we will also email account holders.