Last updated: September 3, 2026
Overview
DevDeck's local planning features work without an account. Everything you create is stored on your device first, and the app does not sell your data, use it for advertising, or include third-party analytics. An account is required for sync, GitHub integration, collaboration, and account-linked Pro access.
What stays on your device
Projects, tasks and subtasks, notes, tags, scopes, phases, versions and release notes, planned time blocks, focus sessions, and your app preferences are stored in a database on your device.
Files you attach to a task are copied into DevDeck's own storage on that device and stay there. They are not uploaded, and they are not part of account sync — a file attached on one device does not appear on another.
GitHub integration
Connecting GitHub requires a DevDeck account. GitHub then asks you to install the DevDeck GitHub App and choose whether it can access all repositories or only repositories you select. DevDeck requests read-only access to repository metadata and contents. It does not request permission to write to your repositories.
To link the installation to the correct DevDeck account, our server stores your DevDeck account identifier together with the GitHub installation identifier, GitHub account identifier, login and account type, repository-selection setting, selected repository identifiers, names and private/public status, installation status, and webhook delivery identifiers. This lets DevDeck confirm access, list the repositories you installed it on, and notice when that access changes.
During setup, GitHub issues a user authorization token so the server can confirm that you control the installation. The server uses that token once and then asks GitHub to revoke it; it is not stored. When DevDeck reads a repository, the server creates a short-lived installation token, keeps it in memory only, and never sends it to the app.
DevDeck uses that access to read repository metadata, branches, commits, and file changes you open in the app. Repository connections and commit links can be included in account sync. Detailed file changes are fetched when requested and are not part of account sync. DevDeck does not write to your repository.
You can remove repository access or uninstall the GitHub App in GitHub. Disconnecting a repository in DevDeck removes the in-app connection but does not uninstall the GitHub App from GitHub.
Account and sync
You can create an account with an email address and a password so your work survives a reinstall and reaches your other devices. You may add an optional display name and additional email addresses with labels such as Work or Business. A secondary address is normally confirmed with a one-time code. If you arrive through a single-use project invitation link sent to that address, you may choose to add it using possession of the link as proof.
One of your confirmed addresses is primary and is used to sign in. You can make a secondary address primary, change its label, remove an address that is not primary, and choose which address represents you on each shared project. An address can belong to only one DevDeck account at a time, whether it is primary or secondary.
The server stores your primary address, password hash, optional display name, labeled email addresses, how and when each address was confirmed, and the projects assigned to each address. Session records include a one-way hash of the refresh token, an optional device name, expiry and last-use time. Short-lived codes are kept only long enough to complete signup, address confirmation, password recovery or a purchase transfer.
When you are signed in, project records and the repository records described above — but not attached files or detailed GitHub file changes — are stored on our server so they can be sent to your other devices and shared with project members according to their roles.
We use your primary address for sign-in and account messages. For collaboration mail, we use the address you selected for that project, falling back to your primary address. To request deletion of your account and server-held data, email [email protected]. Some purchase, redemption, security or legal records may be kept where necessary. Data already on a device remains there until you clear it or remove the app.
Sharing a project with other people
You can invite somebody to a project by entering their email address. We use that address only to send the invitation and, afterwards, to tell them about the project they joined — a release waiting on their approval, or a comment that mentions them. We do not use it for marketing, and we do not add it to any list. If the invitation is never accepted it expires after seven days.
Inviting somebody means giving them access to that project. What they can see and change depends on the role you give them: a viewer reads, a contributor also edits, a maintainer also manages people. Members of a project can see each other's profile names, when provided, and the email address each person selected for that project. Those same identities appear in release approvals and other project history.
The server stores invitations, membership and roles, comments and resolved mentions, release-approval chains and decisions, and the identities attached to that activity. It uses these records to enforce access, preserve the project's history, and notify the people involved.
Your planned time and your focus sessions are never shared. They stay yours on every project, including one you share, because when you intend to work and how long you sat at your desk are yours rather than the project's.
A shared project's records are stored under the account that owns the project. If you leave a project, or are removed from one, you stop receiving its records; the work itself belongs to the project and stays with its owner.
Notifications
DevDeck asks for notification permission so it can remind you when planned time is about to start and when a task is due. These reminders are scheduled on your device from the schedule you entered.
Signed-in collaboration can also send email for invitations, assignments, mentions, release approvals and release summaries. Project mail goes to the address selected for that project. You can disable optional categories in DevDeck or use the unsubscribe link in an email; invitations and account-security codes are sent when needed to complete the action you requested. There are no marketing notifications.
Purchases
DevDeck Pro is sold through Google Play. Payment is handled by Google; the app never sees your card details. To confirm a purchase, the app sends the purchase token Google issued to our server, which checks it with Google Play and records that this account is entitled. We store the raw purchase token and its hash, the account and install identifiers, product and order identifiers when supplied, purchase state, renewal and expiry information, and when it was last verified. These records let access follow your DevDeck account across supported devices and let store cancellation, refund or revocation updates take effect.
A Google Play purchase can be linked to only one DevDeck account at a time. Moving it to another account requires one-time codes sent to both the current owner's address and the receiving account's address.
Trial access is tied to the account and the server stores its start and end time. If you redeem a promotional code, the server stores a hash and short identifying hint for the code, what it grants, its usage limit, and your account identifier and redemption time. A trial code extends or starts trial access; a lifetime code grants account access without an expiry date.
Diagnostics
DevDeck does not include third-party analytics or advertising software. Requests the app makes to our server are recorded in ordinary server logs, which include the request, the time and the originating IP address, and are kept only as long as they are useful for keeping the service running and secure.
Children
DevDeck is a tool for software development work and is not directed at children.
Changes
If this policy changes in a way that affects what happens to your data, the date above changes with it, and material changes will be made visible in the app.
Contact
Questions, requests to delete data, or anything else: [email protected].