Devoku Legal Official document

Devoku Privacy Policy

Effective: 18 September 2026 Last updated: 16 September 2026

This Policy explains how Coded UAB processes personal data when it provides Devoku. It must be read with the Terms of Service.

1. Controller and contact

Coded UAB is the controller for Devoku consumer accounts and for operating its websites and Coded-managed Services:

Coded UAB

Karaliaus Mindaugo pr. 38, LT-44307 Kaunas, Lithuania

Company code 306350327, Register of Legal Entities of the Republic of Lithuania

VAT number LT100016150719

Privacy: privacy@devoku.com

Coded has not appointed a data protection officer. Privacy questions and requests should be sent to the privacy contact above.

For an organization-managed account, the organization may be the controller and Coded its processor. For a customer-cloud deployment, its operator may control most processing and Coded may receive only limited account, billing, support, or security data. Contact that organization for its privacy practices.

2. Scope and age

This Policy covers Devoku websites, apps, human and agent chats, managed messaging, workspaces, billing, support, and related Services operated by Coded. Third-party sites and services have separate policies.

Devoku is for people who are at least 18 and at least the age of majority where they live. We do not knowingly offer it to children. If you believe a minor uses Devoku, contact privacy@devoku.com.

Existing internal accounts known to pre-date the public age gate may be marked eligible through a documented administrator attestation. That process records the verification time and source, but does not invent or infer a date of birth.

3. Data we process

Depending on your deployment and features, we process:

  • Account and identity data: name, display name, email, avatar, account identifiers, password-authentication records held by our identity system, passkeys, social-login identifiers, multi-factor settings, date of birth, age-of-majority attestation, age-eligibility result, verification time and verification source, team memberships, invitations, roles, and organization details.
  • Content: messages, prompts, model responses, tool calls and results, uploads, code, workspace files, images, voice transcripts, feedback, agent memory, configurations, and metadata about them.
  • Workspace and agent activity: commands, files accessed or changed, browser and network actions, integrations, approvals, run state, resource use, audit events, and error diagnostics. Host-security telemetry is intended to describe privileged operations and health, not copy prompt or file content, but support diagnostics you choose to provide may contain it.
  • Messaging data: senders, recipients, group membership, invitations, timestamps, edits, reactions, search tokens, attachment metadata, delivery and presence information, and notification previews.
  • Voice data: microphone audio streamed for speech recognition or related voice features, temporary workspace or provider copies, transcripts, duration, and usage records. Standard speech recognition is designed not to retain raw audio in Coded’s control-plane database, but asynchronous and agent features may temporarily store or upload audio until processing and cleanup complete. Failures can delay cleanup.
  • Billing and transaction data: plan, purchase channel, customer and subscription identifiers, invoices, tax location, credit balance, metered use, refunds, disputes, and limited payment metadata. Payment providers process full payment-card details.
  • Device and network data: IP address, approximate country/region/city, device and browser type, operating system, app version, language, time zone, session identifiers, push token, cookies, logs, security events, and diagnostic data. Approximate location may be derived from the network even though Devoku does not request mobile GPS/location permission.
  • Data stored on your device: access and refresh tokens, user and device identifiers, display name, email, avatar and color preferences, account mode, routing and runtime URLs, home tokens, active team, identity/path keys and cryptographic secret-key material can be stored in browser local or session storage so the app can authenticate, route, encrypt, and maintain state. Anyone with access to an unlocked device or browser profile may be able to access this data.
  • Support and safety data: communications, reports, evidence, moderation decisions, appeals, vulnerability reports, and information needed to investigate abuse or incidents.
  • Settings and consent: privacy choices, product-email preferences, analytics consent, beta enrollment, third-party AI choices, accepted document version, timestamps, source, IP address, and user agent.
  • Information from others: organization administrators, chat participants, integration providers, identity providers, payment providers, app stores, security partners, and lawful public sources.

Do not intentionally provide special-category or other highly sensitive data unless a feature and written agreement expressly support it. Human messages, files, and prompts may nevertheless contain such data incidentally. Where we cannot avoid processing it while carrying out your communication or request, we limit use to delivering, securing, and supporting that request and rely on the applicable Article 9 condition or other legal permission. We may reject or remove unsupported sensitive data. Organizations must identify and document their own lawful basis and instructions before using Devoku for such data.

4. Why and on what legal basis

Where the GDPR or similar law applies, we use:

Purpose Typical legal basis
Create accounts; authenticate; deliver chats, workspaces, agents, storage, support, exports, and deletion controls Contract; steps requested before contract
Confirm that users meet the minimum age and local age-of-majority requirements Contract; steps requested before contract; legitimate interests in protecting minors and enforcing eligibility
Process payments, subscriptions, taxes, credits, and accounting Contract; legal obligation
Route requested prompts, content, voice, and tool actions to selected providers Contract; explicit consent where law requires it
Secure accounts and infrastructure; prevent fraud, spam, abuse, and harmful activity Legitimate interests; legal obligation; vital interests in emergencies
Moderate content, respond to notices, enforce terms, and protect users Legitimate interests; legal obligation
Maintain operational logs, diagnose failures, measure service health, and improve reliability Legitimate interests, balanced against user rights
Optional product analytics, non-essential cookies, and marketing Consent, legitimate interests, or existing-customer rules, as applicable
Establish, exercise, or defend legal claims and answer authorities Legal obligation; legitimate interests
Corporate transactions and service administration Legitimate interests, subject to safeguards

When we rely on legitimate interests, they include operating a safe, reliable service, preventing misuse, understanding aggregate performance, and protecting legal rights. You may object as described below. We do not use consent where processing is necessary to perform your requested service.

5. AI, agents, and integrations

When you choose a cloud model, coding provider, speech service, plug-in, MCP server, identity provider, or other integration, we send it the data needed to complete the request. That can include prompts, relevant message history, workspace context, files, tool results, identifiers, network data, and configuration. Your administrator may select providers for a managed account.

Providers may act as our processors, independent controllers, or providers contracted directly by you (for example, when you use your own API key). Their retention and model-training practices depend on their agreement and settings. Review them before sending confidential data.

Agents can transmit information through commands, browsers, networks, or connected systems. You control the permissions you grant, but Coded processes the resulting activity as needed to deliver and secure the feature.

We do not use Your Content to train a Coded general-purpose AI model without separate notice and any legally required consent.

6. Messaging privacy and encryption

Coded-managed messaging uses transport encryption and encryption at rest with keys operated by Coded. It is not necessarily user-held end-to-end encryption. Authorized Coded systems and personnel can technically access content when needed for delivery, search, support, safety, incident response, or legal compliance under access controls.

Conversation members can access shared content. Organization administrators can access organization-managed messages, agent chats, files, and retained work. Recipients can copy or retain messages outside Devoku. Push notifications may display a message preview on a locked device depending on your device settings.

Some deployment or conversation modes may provide different encryption. Feature-specific notices identify those modes; do not assume they apply to all messages.

7. How we disclose data

We disclose data:

  • to chat participants and people or organizations you direct;
  • to organization owners, administrators, and authorized members;
  • to infrastructure, hosting, database, storage, content-delivery, and security providers;
  • to authentication, email, notification, support, and voice-transcription providers;
  • to AI, model, and developer-tool providers selected for a feature;
  • to payment processors and app-store platforms;
  • to integrations and APIs you or your administrator enable;
  • to professional advisers, auditors, insurers, and transaction counterparties under confidentiality protections;
  • to authorities or other parties when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or defend claims; and
  • in a merger, financing, acquisition, reorganization, or sale, subject to applicable notice and protection requirements.

We do not sell personal data for money. We do not share it for cross-context behavioral advertising. If our practices change, we will update this Policy and provide opt-out rights required by law.

Providers acting on Coded’s behalf may process data only for agreed purposes and must protect it as required by applicable law and contract. Other recipients, including payment providers, app-store platforms, and integrations you select, may act as independent controllers under their own privacy notices. Contact privacy@devoku.com for additional information about recipients applicable to your use of Devoku.

Coded maintains a non-public provider register. Before Coded processes personal data on behalf of a business customer under Article 28 GDPR, the parties must enter into an applicable data-processing agreement identifying the authorized subprocessors. The draft enterprise DPA and provider inventory are not part of this consumer launch publication.

8. International transfers

Coded is established in Lithuania and processes data in the EEA and other countries where providers operate. Those countries may have different laws. For restricted EEA/UK transfers, we use an adequacy decision, Standard Contractual Clauses, the UK Addendum or International Data Transfer Agreement, or another lawful mechanism, and supplementary safeguards where required. Contact privacy@devoku.com for relevant transfer information.

9. Retention

We keep data only for the purposes above and consider account status, deployment mode, plan, user settings, legal duties, security needs, dispute periods, and technical constraints.

  • Account identifiers, date of birth and associated age attestation, or an administrator-verified eligibility timestamp and source, are kept while the account is active. Self-service deletion clears those age-eligibility fields, anonymizes core profile identifiers, and revokes sessions, subject to the qualifications below.
  • Managed-chat retention depends on the production plan, deployment configuration, and conversation settings shown in the Service. A visibility period is not necessarily a hard-deletion period. Until Coded confirms that a deletion job completed, users should not assume hidden or disappearing content has been erased from active systems.
  • Attachment and content deletion may require processing queues and backup aging after the item is no longer visible.
  • Transaction, tax, and accounting records are retained for statutory periods.
  • Security evidence may be retained for approximately 90 days in active systems and up to 560 days in protected archives where the documented security schedule applies.
  • Governance, release, incident, audit, and legal records may be retained for at least three years or longer where law or a claim requires it.
  • Backups are protected and age out on their normal cycle; restored systems are designed to reapply completed deletion requests.
  • Third-party providers apply their own retention schedules.

Production retention differs for customer-cloud and organization-managed deployments. Their operators set and disclose the applicable periods. Current Coded-managed plan-specific periods are shown in the Service or order.

10. Deletion and portability

You can request an account export and deletion in settings or contact privacy@devoku.com. Current self-service export includes profile, billing, team, consent, session, audit, VM, and backup metadata, but does not include all raw chats or workspace files. Use available chat and workspace export or copy tools before deletion and contact us for a legally required broader request.

Before self-service deletion, you may need to transfer team ownership and remove active VMs and backups. An organization-managed account must be deactivated through its administrator.

Self-service deletion disables login immediately, revokes tracked sessions, removes core profile identifiers, and attempts to remove the identity-provider record. We permanently delete or de-identify remaining eligible account data within 30 days. Historical shared content, organization work product, transactions, security or moderation evidence, legal records, and protected backup copies may remain where necessary for another person’s rights, the organization, legal obligations, security, claims, or technical backup cycles. Contact privacy@devoku.com for a verified deletion request.

The standalone Account and Data Deletion page gives step-by-step instructions and explains how deletion differs from subscription cancellation.

11. Your rights

Depending on where you live, you may request access, correction, deletion, restriction, portability, or a copy of personal data; object to legitimate- interest processing; withdraw consent; opt out of certain sharing or profiling; and appeal a refusal. Withdrawing consent does not affect earlier lawful processing.

Send requests to privacy@devoku.com. We may verify identity and authority. Authorized agents may submit requests where local law permits. You may complain to the Lithuanian State Data Protection Inspectorate or your local supervisory authority. You may also seek a judicial remedy.

We do not make decisions producing legal or similarly significant effects about you solely through automated processing unless we provide a feature-specific notice and safeguards.

12. Cookies, analytics, and communications

We use necessary local storage, cookies, and similar technologies for login, security, preferences, and requested features. We use non-essential analytics or advertising technologies only with consent where required. A cookie panel or feature notice will identify active non-essential vendors and retention. See the Cookie and Local Storage Notice for the current device-storage inventory.

We send transactional account, billing, safety, legal, operational, and service-change messages as needed to provide the Services. When permitted by law, product email is enabled for a new account unless the user uses the clear opt-out presented when the email address is collected. Product emails may cover new models, features, credits, and Devoku offers. They concern our own similar Services, identify us, and provide an easy unsubscribe method. The preference can also be changed in settings. Opting out does not stop essential service communications.

13. Security

We use organizational and technical measures designed to protect data, including access controls, logging, and encryption appropriate to the service. No system is completely secure. Contact security@devoku.com about a vulnerability and support@devoku.com about account compromise.

Our program may be informed by SOC 2 and ISO/IEC 27001 control frameworks. That statement is not a claim of certification, attestation, completed audit, or compliance. We will identify the exact scope and validity if independent assurance is obtained.

14. Changes

We may update this Policy as the Services or law changes. We will publish the new date and provide prominent advance notice where a change materially affects your rights. We will obtain consent where a new purpose requires it.