Effective date: 30 July 2026
Last updated: 13 August 2026
1. Who we are
Devopsly ("Devopsly", "we", "us") is a cloud infrastructure monitoring and cost-analysis service operated by Muhammad Hamza, operating as Devopsly, based in Lahore, Pakistan. We are the data controller for the personal data described in this policy.
Privacy contact: privacy@devopsly.app
General contact: support@devopsly.app
This policy explains what data we collect, why, who we share it with, and what rights you have. It applies to devopsly.app and its subdomains.
2. What we collect
2.1 Data you give us
| Data | When | Why |
|---|---|---|
| Name, email address | Account registration | Create and identify your account, service communication |
| Password | Registration | Authentication. Stored only as a bcrypt hash — we never store or see your password |
| Marketing preference | Registration | To know whether you consented to non-essential email |
| Workspace, project, and environment names | While using the service | Organising your account |
| Feedback you submit through the in-app form, and the page you were on when you sent it | When you send it | Improving the service and replying to you. Forwarded to our own Slack/email so we see it (see §4). Kept even if you later delete your account |
2.2 Data we record automatically
| Data | Why |
|---|---|
| IP address and browser user agent, recorded with each consent action (privacy policy, terms, marketing) | Legal evidence that consent was given, as required by GDPR |
| Consent type, version, and timestamp | Same as above |
| Email verification status | Account security |
| Session tokens | Keeping you signed in across devices |
2.3 Cloud infrastructure data
When you connect a cloud account, we retrieve and store configuration and billing metadata:
- Cloud provider credentials — access key ID and secret access key. Encrypted at rest using AES-256-CBC. Never returned in API responses, never displayed in the interface, and never sent to any third party.
- Cloud account ID and regions
- Compute instances: identifiers, names, tags, private and public IP addresses, network identifiers, image and platform identifiers, availability zone, launch time
- Databases: identifiers, endpoint addresses, engine versions, backup retention settings, storage type and size, multi-AZ status
- Storage: bucket and volume identifiers, tags, size and object counts, and security-posture flags — encryption state and key identifiers, versioning, public-access settings, lifecycle configuration
- Spending figures by service, and detected cost anomalies
- Generated recommendations, backup assessments, health scores, and AI-written summaries
- The complete raw response from each AWS describe/list call, stored alongside the fields above so we can add checks later without re-reading your account. For compute instances this can include security-group names and identifiers, the attached IAM instance-profile identifier, the SSH key-pair name, and network-interface details. It is metadata about your configuration — never the contents of your systems.
We retrieve metadata only. We do not read the contents of your databases, storage buckets, or application data. Every AWS call we make is read-only (Describe*, Get*, List*); we never create, modify, start, stop, or delete anything in your account.
Tags are worth calling out: we store the tags you have applied to your AWS resources, and tags commonly contain names, email addresses, team names, or ticket references. If your tags contain personal data, that data is stored with the resource record and deleted when you disconnect the cloud account.
2.4 Waitlist
If you join our launch waitlist without creating an account, we store your email address, together with the IP address and browser user agent of the submission. We use it for one purpose only: to notify you once Devopsly opens to new users. We send a single notification email and we do not add you to any marketing list.
Legal basis: consent. Ask us to remove you at any time by emailing privacy@devopsly.app.
2.5 Team invitations
If you invite someone to your workspace, we store the email address you provide and the role
you assigned, so we can send the invitation and let them accept it. We send one invitation
email per invitation. The invited person is not added to any marketing list, and we do not use
their address for anything other than that invitation.
If you were invited and did not want to be, no account is created for you and nothing further
happens — invitations expire automatically. If you do have a Devopsly account, you can decline the
invitation yourself from your dashboard, which closes it immediately. Otherwise, to have your
address removed before it expires, email privacy@devopsly.app and we will delete it.
Legal basis: legitimate interests — enabling our customers to collaborate with colleagues they
have chosen to invite. Please only invite people who expect to hear from you.
2.6 What we don't collect
We do not use advertising or analytics trackers, we do not build user profiles for marketing, and we do not sell personal data to anyone.
3. Why we process it, and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the service — accounts, syncing your infrastructure, cost and risk analysis | Performance of a contract |
| Sending service emails — verification, password reset, alerts, weekly reports | Performance of a contract |
| Security, abuse prevention, debugging | Legitimate interests |
| Improving the service | Legitimate interests |
| Marketing email | Consent — withdrawable at any time |
| Waitlist launch notification | Consent — withdrawable at any time |
| Keeping consent and audit records | Legal obligation |
4. Who we share it with
We use the following sub-processors. We do not sell or rent your data, and we share it only as described here.
| Sub-processor | What it receives | Location |
|---|---|---|
| Amazon Web Services | Hosting for our application and database — all stored data | United States |
| Anthropic PBC (Claude API) | Infrastructure metadata used to generate weekly summaries: account name, region, cost figures, resource names, recommendations. Your cloud credentials are never transmitted. | United States |
| Resend | Your email address and the content of emails we send you | United States |
| GitHub / Google | Only if you sign in with them: they authenticate you and return your name, email address, a provider account identifier and a profile-image URL, which we store | United States |
| Vercel | Hosts our web interface, so it processes your requests to the site | United States |
| Cloudflare | DNS resolution, network traffic, and inbound email routing | Global |
| Slack | (a) Alert content — only if you choose to configure a Slack webhook. (b) If you submit in-app feedback, your message together with your name, email address and the page you were on is forwarded to a Devopsly-operated Slack workspace so we can respond — this happens for all feedback, not by your choice | United States |
| Paddle | Billing and payment data — only once paid plans are introduced. Paddle acts as Merchant of Record and is a separate controller for payment data | United Kingdom / EU |
We may also disclose data where legally required, or to protect our rights, safety, or property.
5. Where your data is processed
All data is processed and stored in the United States on Amazon Web Services infrastructure.
If you are in the European Economic Area or the United Kingdom, this means your data is transferred outside your region. That transfer relies on AWS's GDPR Data Processing Addendum incorporating Standard Contractual Clauses. As the controller is located in Pakistan, which has no EU adequacy decision, we also apply equivalent contractual and technical safeguards — including encryption of credentials at rest and access limited to authorised personnel.
Devopsly does not currently offer regional data residency. Any region preference stored on your account has no effect on where data is processed.
6. How long we keep it
| Data | Retention |
|---|---|
| Account data | For the life of your account |
| Cloud provider credentials | Deleted immediately when you disconnect a cloud account |
| Synced infrastructure, cost, and recommendation data | For the life of your account; deleted within 30 days of account deletion |
| All other customer data | Deleted within 30 days of account deletion |
| Waitlist entries | Retained until we send the launch notification, then deleted on request. Deletion is manual today — email privacy@devopsly.app and we will remove you |
| Team invitations | Pending invitations expire after 7 days. Accepted and revoked records are retained as an access-audit trail for the life of the workspace, then deleted with it |
| Consent records | Held for the life of the account. Note: they are linked to your account record, so deleting the account currently removes them too — we do not keep a separate copy after deletion |
7. Your rights
If you are in the EEA or UK, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict or object to processing
- Data portability — receive your data in a machine-readable format
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with your local data protection supervisory authority
To exercise any of these, email privacy@devopsly.app. We respond within 30 days.
If you are a California resident, you additionally have the right to know what personal information we collect and disclose, to request deletion, and to non-discrimination for exercising those rights. We do not sell personal information. Similar rights apply under other US state privacy laws.
8. Automated processing and AI
We use AI (via Anthropic's Claude API) to generate written summaries of your infrastructure data. This is descriptive only — it summarises figures we have already calculated. It does not make automated decisions that produce legal effects for you, and it does not perform profiling. AI-generated summaries may contain errors and should be verified against the underlying data in the service.
9. Security
- Cloud provider credentials are encrypted at rest with AES-256-CBC, and are never exposed via our API or interface
- Passwords are stored as bcrypt hashes
- All traffic is served over HTTPS/TLS
- Access to production systems is restricted to authorised personnel
- We request read-only access to your cloud infrastructure
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority as required by law.
10. Cookies and similar technologies
We use only what's necessary to run the service: authentication tokens to keep you signed in, and technical cookies set by Cloudflare for network security and bot protection. We do not use advertising, marketing, or analytics cookies. If we introduce analytics in future, we will update this policy and add a consent mechanism where required.
11. Children
Devopsly is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact privacy@devopsly.app and we will delete it.
12. Changes to this policy
We may update this policy as the service evolves or the law changes. Material changes will be notified to the email address on your account at least 30 days before taking effect. The "Last updated" date above always reflects the current version.
13. Contact
Privacy enquiries and data requests: privacy@devopsly.app
General support: support@devopsly.app
Muhammad Hamza, operating as Devopsly
Lahore, Pakistan