Last Updated: July 3, 2026. This policy describes how we collect, store, and utilize telemetry across the developerOS suite.
We collect profile credentials (emails, usernames, and avatar files) to authenticate your account. When you join our waitlists, we also record UTM campaign details and referrer origins to measure our outreach.
Specifically, we collect: account information (name, email address, hashed password, profile details like bio, location, and social links you choose to add); payment metadata (plan selected, billing cycle, transaction status, and Razorpay order/payment IDs — we never see or store your full card, UPI, or bank details, since Razorpay handles that data under its own PCI-DSS scope); usage and telemetry data (page views, feature interactions, sandbox/exam events, device and browser category, and approximate location derived from IP); and cookies and local storage as described in our Cookie Policy.
We track basic diagnostics like page views, countries of access, browser categories, and specific platform events (e.g. "started AWS sandbox exam") to ensure system responsiveness. We do not sell or monetize candidate telemetry.
We rely on a small set of trusted vendors to run developerOS, and we only share the minimum data each one needs to do its job:
Razorpay processes all payments and holds your card/UPI/bank details on our behalf — we only receive order status and transaction identifiers. Resend delivers transactional email (password resets, receipts, security alerts) and, if you've opted in, product newsletters. Sentry captures error reports and stack traces so we can fix bugs, and may incidentally include technical request metadata. Vercel hosts our application infrastructure and edge network.
PostHog and Microsoft Clarity are optional, environment-gated analytics providers. They only load and collect data when we have explicitly configured an active project key for them in a given deployment — if unconfigured, no requests are made to these services and no data is collected by them.
We retain account data for as long as your account is active. Billing records and transaction metadata may be kept longer where required for tax, accounting, or dispute-resolution purposes. When you delete your account from Settings, we permanently remove your profile, waitlist entries, sessions, API keys, and entitlement records from our production database. Aggregated or anonymized telemetry that can no longer be tied back to you may be retained for product analytics.
Regardless of where you're located, you have the right to access, correct, delete, and export your personal data. From Settings → Privacy, you can download a full JSON export of your profile at any time, or permanently delete your account and all associated records with a single confirmed action.
These controls are designed to satisfy both the EU General Data Protection Regulation (GDPR) — including rights to access, rectification, erasure, and data portability — and India's Digital Personal Data Protection Act (DPDP Act), which grants similar rights of access, correction, and erasure to data principals. If you believe these self-service tools don't fully address your request, contact us and we'll assist directly.
developerOS is a professional career-preparation platform and is not intended for, nor directed at, individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has created an account, contact us and we will remove it.
developerOS is operated from India, and our infrastructure providers (including Vercel and our database provider) may process and store data on servers located outside India. Where data is transferred internationally, we rely on our providers' standard contractual and security safeguards to protect it in transit and at rest.
We encrypt all traffic to and from developerOS in transit using TLS. Passwords are never stored in plain text — they are hashed with bcrypt before hitting our database. Session tokens are handled via NextAuth using signed, HTTP-only cookies. We follow standard secure-development practices, but no system is completely immune to risk, and we do not claim certifications (such as SOC 2) that we have not independently obtained.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. We'll update the "Last Updated" date above whenever we do, and material changes will be communicated via email or an in-product notice.
You have full rights to access, update, or purge your account details directly from your settings console. Deleting your account will completely delete your database rows, waitlists, and profiles across all products. For any privacy questions, requests, or concerns, reach us at support@developeros.in.