Privacy Policy

Privacy Policy for Deva, Genie, and Deva Agent Key.

Written By Deva

Last updated 20 days ago

Effective date: July 8, 2026

Deva (“Deva,” “we,” “our,” or “us”) operates the Deva platform and its products — Genie (the hosted AI agent, delivered through our Mac, web, and mobile apps) and Deva Agent Key (the account and credential surface for developers using Deva models, tools, credits, and metering). This Privacy Policy explains how we collect, use, and protect your information across these services (collectively, the “Service”). It consolidates and supersedes the prior separate Genie and Deva Agent Key privacy policies. By using the Service, you agree to this Privacy Policy.

Information We Collect

  • Account information. When you create an account through Deva single sign-on (SSO), we receive your name, email address, and authentication identifiers. We do not store your SSO password.
  • Conversation and workspace data. Messages you send to and receive from your AI assistant, and the files and data created in your workspace, are processed to provide the Service and stored in your private, isolated cloud workspace.
  • Agent request data. When you call models or tools through Deva Agent Key, your agent request and response content is processed to provide the requested result.
  • Audio data. If you use voice input, audio is processed in real time for transcription only. Audio recordings are not stored after transcription is complete.
  • Credentials. We collect and manage credential metadata, and we handle API keys, provider keys, OAuth tokens, and related secrets as sensitive data.
  • Payment information. Payment processing is handled by Stripe and by Apple App Store and Google Play in-app purchase mechanisms. We do not collect or store your payment card details — we receive only transaction confirmations, subscription status, and credit balances.
  • Usage and technical data. We collect usage metrics (such as session duration, feature usage, and crash reports), usage events, log data, and basic device information (device model, OS version, app version, and IP-derived approximate location) for compatibility, troubleshooting, security, and improvement.

How We Use Your Information

  • To provide, operate, and maintain the Service;
  • To process your AI assistant requests and manage your workspace;
  • To authenticate users, and issue and secure API credentials;
  • To route model and tool requests and meter usage;
  • To manage your account, subscriptions, credits, and billing;
  • To improve performance, reliability, security, and user experience;
  • To communicate important service updates and security notices;
  • To detect, prevent, investigate, and address fraud, abuse, security incidents, violations of our terms, or technical issues;
  • To establish, exercise, or defend legal claims and comply with legal obligations.

Data Ownership and Isolated Infrastructure

All content generated, stored, and processed within your workspace belongs entirely to you — including your configurations, conversation history, files, and any data created through your AI assistant. We claim no ownership rights over your content. Each user’s workspace runs in its own sandboxed environment, isolated from other users, with no shared resources or cross-account data access.

We Do Not Train on Your Content or Sell Your Data

We do not use your conversation content or agent request content to train public foundation models. We do not sell your personal data, and we do not share usage data with third parties for advertising purposes.

Aggregated and De-identified Data

We may create and use aggregated, anonymized, or de-identified data derived from use of the Service — data that does not identify you or any individual and is no longer personal data — for any lawful business purpose, including operating, analyzing, securing, benchmarking, and improving our products and services. We may retain and use such data indefinitely.

Third-Party Processors

We use the following categories of third-party services, which receive only the information needed to deliver their functionality:

  • Anthropic (Claude AI) — messages and agent requests are sent to Anthropic’s API for AI processing. If you connect your own Anthropic API key, your usage is governed directly by your agreement with Anthropic.
  • Groq — used for audio transcription when voice input is enabled; audio is processed in real time and not retained.
  • Stripe — used for payment processing.
  • Apple / Google — in-app purchases are processed through their respective platforms.
  • Model, tool, analytics, and cloud infrastructure providers — used to route requests, deliver features, and operate the Service.

Your use of any provider for which you supply your own key is governed by your direct agreement with that provider.

We may access, preserve, and disclose your information if we believe in good faith that doing so is reasonably necessary to: (a) comply with a law, regulation, legal process, or governmental request; (b) enforce these terms and our policies, including investigation of potential violations; (c) detect, prevent, or address fraud, security, or technical issues; or (d) protect the rights, property, or safety of Deva, our users, or the public as required or permitted by law.

Business Transfers

If Deva is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of its assets, your information may be transferred as part of that transaction, subject to this Privacy Policy or a successor policy with comparable protections.

Data Storage and Security

Your data is stored on secure cloud infrastructure using industry-standard encryption in transit (TLS 1.2+) and at rest (AES-256). Access to production systems is restricted, audited, and follows the principle of least privilege. We take reasonable measures to protect your information; however, no method of transmission or storage is completely secure, and we cannot guarantee the absolute security of your information. You use the Service and provide information at your own risk, and you are responsible for keeping your credentials confidential.

Data Retention

Your conversation history and workspace data are retained as long as your account is active. We retain account, billing, security, usage, and support records as needed to operate the Service, comply with law, resolve disputes, and prevent abuse. Upon account deletion, associated data is permanently removed from our systems within 30 days, except where we are required or permitted to retain it by law. You may request deletion at any time.

Your Rights and Choices

Depending on your jurisdiction, you may:

  • Access, update, or delete your account data;
  • Request export of your workspace data;
  • Rotate credentials and manage subscriptions;
  • Request permanent deletion of your account and all associated data;
  • Opt out of non-essential service communications.

To exercise these rights, contact us at support@deva.me. We may need to verify your identity before acting on a request, and we may decline requests where permitted or required by law, or where an exception applies. We will not discriminate against you for exercising your rights.

Children’s Privacy

The Service is not intended for children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will delete it.

International Users

Your data may be processed and stored in countries outside your own, including countries that may not provide the same level of data protection as your jurisdiction. By using the Service, you consent to such cross-border data transfers where permitted by law.

Connected Accounts and Integrations

The Service lets you connect third-party accounts and services — such as email, messaging, calendar, code-hosting, storage, social, or payment accounts (for example Gmail, Slack, GitHub, Google Drive, or Stripe) — and authorize the Service and your agents to access, read, or act within them. When you connect such an account, we access, process, and store only the data needed to perform the actions you or your agents request, together with the access tokens required to maintain the connection, which we hold in encrypted form. You represent that you are authorized to connect the account and to grant that access, and you may disconnect it at any time through your settings or the relevant provider, after which we stop accessing it. Your use of a connected account remains subject to that third party’s own terms and privacy policy, and we are not responsible for that third party’s data practices.

The Service may link to or integrate with third-party websites and services that we do not control. We are not responsible for the privacy practices or content of those third parties, and this Privacy Policy does not apply to them.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If material changes are made, we will notify you through the app or by email. Continued use of the Service after updates constitutes acceptance of the revised policy.

Contact Us

If you have questions about this Privacy Policy, contact us at support@deva.me.