Privacy Policy
Devscroll (the "Service") is a personal, non-commercial hobby project operated by an individual ("we", "us", or "our"). This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and the rights you have over it. It is intended to meet our obligations under the EU/UK General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act as amended ("CCPA/CPRA").
1. Who is the data controller
The individual operator of Devscroll is the controller of your personal data. As this is a personal hobby project, there is no company or business address; the point of contact for any privacy question or to exercise your rights is support@devscroll.in.
2. What data we collect
| Category | Specific data | Source |
|---|---|---|
| Account identity | Email address; display name; profile picture URL; authentication method (native, Google, or Facebook) | You, or your chosen sign-in provider |
| Authentication credentials | For native accounts, a one-way hashed password (bcrypt). For federated accounts, a provider identifier (Google subject ID or Facebook ID). Refresh tokens are stored only as SHA-256 hashes and expire automatically. | You, or your sign-in provider |
| Usage & preferences | Articles you save; blogs you unsubscribe from; reading-streak counts and last activity date; account creation date | Generated as you use the Service |
| Technical data | IP address and request metadata used transiently for rate limiting and abuse prevention | Collected automatically |
| Diagnostic data | If the mobile app crashes: a stack trace, device model, operating-system version, app version, and a randomly generated installation identifier. This identifier is not an advertising identifier and is not used to profile or track you. | Collected automatically by the app when it crashes |
We do not knowingly collect special-category data, and we do not require you to provide any personal data beyond what is needed to operate your account.
3. How and why we use your data (GDPR legal bases)
| Purpose | Legal basis |
|---|---|
| Creating and authenticating your account | Performance of a contract (our Terms of Service) |
| Providing your personalized feed, saved articles, subscriptions, and streaks | Performance of a contract |
| Rate limiting, security, and preventing abuse of the Service | Legitimate interests |
| Diagnosing crashes and improving the stability of the mobile app | Legitimate interests |
| Responding to your requests and support enquiries | Legitimate interests / legal obligation |
| Complying with legal obligations | Legal obligation |
4. Third parties we share data with
We do not sell your personal data. We share data only with service providers ("processors") that help us run the Service, and only as needed:
- Google and Facebook — if you choose to sign in with them, they provide us your basic profile (email, name, picture) and we exchange an identifier to authenticate you. Their use of your data is governed by their own privacy policies.
- Oracle Cloud Infrastructure (OCI) — our hosting and object-storage provider, which stores application data and image assets on our behalf.
- Google Firebase Crashlytics — receives the diagnostic data described in Section 2 when the mobile app crashes, so that we can identify and fix defects. It is used solely for crash diagnostics; we do not use it for advertising, analytics, or profiling.
Aggregated developer articles shown in the Service originate from public third-party blogs and RSS feeds (including dev.to); that content belongs to its publishers and is not personal data about you.
In-app article viewer
When you open an article, the mobile app displays the publisher's own web page inside an embedded browser view with JavaScript enabled. That page is loaded directly from the publisher and may set its own cookies and run its own analytics or advertising trackers, exactly as it would in your normal browser. We do not control, receive, or have access to the data those third parties collect; their processing is governed by their own privacy policies. We do not inject any tracking of our own into these pages, and we do not record which articles you open.
5. International transfers
Your data may be processed in countries outside your own. Where we transfer personal data outside the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses. Contact us for details.
6. How long we keep data
- Account data is retained for as long as your account is active.
- Aggregated articles are automatically purged approximately 30 days after publication to minimize stored data.
- Refresh tokens are held only as hashes in a cache and expire automatically.
- Crash reports are retained by our crash-reporting provider for a limited period (currently 90 days) and are then deleted automatically.
- When you delete your account, we permanently delete your saved articles, subscription preferences, profile, and streak data, and revoke all active sessions. Some records may persist briefly in backups before being overwritten on their normal cycle.
7. Your rights
Under the GDPR (EU/UK)
- Access — obtain a copy of the personal data we hold about you.
- Portability — the Service provides a self-service export of your subscriptions and saved articles in machine-readable JSON.
- Rectification — correct inaccurate data via your profile.
- Erasure — delete your account and associated data at any time from the account section of the app. If you have already uninstalled the app, email support@devscroll.in from your registered address and we will delete the account for you.
- Restriction and objection — limit or object to certain processing.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with your local data protection authority.
Under the CCPA/CPRA (California)
- Right to know the categories and specific pieces of personal information we collect, as described in Section 2.
- Right to delete your personal information.
- Right to correct inaccurate personal information.
- Right to opt out of the sale or sharing of personal information — note that we do not sell or share your personal information as those terms are defined by the CCPA.
- Right to non-discrimination for exercising your rights.
To exercise any right, use the in-app controls where available, or contact support@devscroll.in. We will verify your identity before acting and respond within the timeframes required by law.
8. Security
We protect your data with measures including password hashing (bcrypt), hashed and expiring session tokens, encrypted secrets management, transport encryption (HTTPS), and rate limiting. No method of transmission or storage is completely secure, but we work to protect your data and to notify you and regulators of breaches where legally required.
9. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact support@devscroll.in and we will delete it.
10. Cookies, tokens, and identifiers
The Service authenticates you using access and refresh tokens rather than tracking cookies. We do not use cookies for advertising, analytics, or cross-site tracking, and we do not collect your device's advertising identifier. The only automatically generated identifier we hold is the random installation ID attached to crash reports (Section 2), which exists to group crashes from the same installation and is not used for advertising or profiling. Note that pages you open in the in-app article viewer may set their own cookies, as described in Section 4.
11. Changes to this policy
We may update this policy from time to time. Material changes will be notified through the Service or by email, and the "Last updated" date above will change.
12. Contact
For privacy questions or to exercise your rights, contact us at support@devscroll.in.