Plain language, because that’s the whole point of this product. Last updated August 2026. DevMargin (devmargin.app) is operated by Peter Buchlak, a sole operator in the Czech Republic, who is the data controller. Questions or data requests: hello@devmargin.app.
Each item above exists for one reason: to sign you in, to fetch your figures on your behalf, to compute and display revenue and net margin, to answer your own agent’s read-only queries, to bill you if you upgrade, and to keep the service working and secure. The legal basis is performing the contract you enter by using DevMargin, plus our legitimate interest in keeping it secure. We do not sell or rent your data, do not use it for advertising, do not share it with other users, and do not use it to train machine-learning models.
Four companies, each for one job. Disclosure happens only over encrypted HTTPS/TLS connections to their APIs, from our servers, and limited to the data that job requires. No data is disclosed to anyone else, and none is transferred by any other method.
The billing providers you connect (Stripe, Lemon Squeezy, Polar, Paddle, Gumroad, Freemius, Dodo Payments, Creem, Shopify, Shopify Partners, Adapty, RevenueCat, App Store Connect, Google Play) are not recipients — we read from them, we never send them your data. We may also disclose data if the law requires it; if that ever happens and we are permitted to tell you, we will.
No system is perfect, and DevMargin is run by one person — so the design assumes breach and limits the damage: read-only keys, encrypted secrets, and database-enforced isolation. If a breach ever affected your data, we would tell you and the supervisory authority as the law requires.
Your data is kept while your account exists. That is true on the free plan too: the free plan limits how far back you can read your history, not how much of it is kept — every snapshot is still recorded daily, nothing is thinned or discarded, and upgrading makes the earlier ones readable again straight away. Deletion is self-serve: Account → Delete account. It is immediate and irreversible — profile, connections including their encrypted credentials, projects, costs, snapshots and tokens are all erased, with no retention period and no soft delete. Stripe keeps payment and invoice records for as long as tax law requires; that is out of our hands.
One thing is kept for less time on purpose. An invoice you forward to your cost address is someone else’s document — it usually carries a supplier’s address and bank details, which are their personal data rather than yours. The file is deleted 90 days after it arrives, automatically and whether or not you did anything with it. The cost you made from it stays, because a monthly figure carries none of that.
Under the GDPR you can ask for a copy of your data, correct it, delete it, restrict or object to processing, and receive it in a portable form. Delete-account does the erasure instantly, and a copy of your data is free on any plan — the CSV/JSON export under Settings is a paid convenience, never the route to exercising this right. For anything else write to hello@devmargin.app and you will get an answer within 30 days. You may also complain to your local data protection authority — in the Czech Republic, the Úřad pro ochranu osobních údajů.
One kind only: the session cookie that keeps you signed in. It is essential to the service, so there is nothing to consent to and no banner to dismiss. No advertising or analytics cookies are set, by us or by anyone else.
If this policy changes materially, the date above changes and you will be told before it affects you. See also the terms of service.