Privacy Policy
Last updated October 6, 2026
DevStash is run by Traversy Media. This page explains what we collect when you use devstash.io, why we collect it, and what you can do about it. Questions go to brad@traversymedia.com.
What we collect
- Account details: your email address, your name if you give one, and a hashed password if you sign up with email (never the password itself). If you sign in with GitHub: your GitHub name, avatar, account ID, and the sign-in tokens GitHub issues, which DevStash stores but does not use.
- Your handle: created from the part of your email before the @ the first time you share something, and shown as @handle on everything you share. You can change it in Settings.
- What you save: your items, collections, tags, and settings.
- Page views: anonymous counts through Vercel Web Analytics, which does not use cookies.
- Rate limit counters: sign-ins, sign-ups, password resets, and verification emails are rate limited by IP address and, for sign-in attempts and verification emails, by email address too. The counters expire within about two hours. Our hosting provider also keeps standard request logs, which include IP addresses, for a limited time.
How we use it
- To run your account and show you your stash.
- To send account emails, such as email verification and password resets. We do not send marketing email.
- To publish what you choose to share. Unlisted items are visible to anyone with the link, and public items can also be indexed by search engines. Sharing a collection shares every item in it, including items that are private on their own; otherwise private items are visible only to you.
We do not sell your data or use it for advertising.
Services that process your data
| Service | What it does |
|---|---|
| Vercel | Hosts the app and counts page views |
| Neon | Stores your account and your stash in a Postgres database |
| Upstash | Holds the short-lived rate limit counters |
| Resend | Sends account emails |
| OpenAI | Runs the AI helpers, only when you click one. It receives the item's title, type, language, the URL for links, and up to 2,000 characters of its content |
| GitHub | Signs you in, if you choose GitHub |
| jsDelivr | Serves the code editor's files to your browser when you open the editor |
| Cloudflare R2 | Stores files and images uploaded while uploads were available |
| Stripe | Handles payments if paid plans return; none are active now |
DevStash sets a few cookies that sign you in and keep you signed in, and two that remember your list layout and page size. There are no advertising or tracking cookies.
Your choices
- Export your items, collections, and tags at any time from Settings, under Data. Files you uploaded download one at a time from their item.
- Make anything you shared private again from the item's drawer, the collection's page, or the Shared page.
- Delete your account from Settings. This deletes your account, items, collections, and shared pages. Copies other people saved to their own stash stay there. If you uploaded files while uploads were available, email us and we will remove the stored files too. Deleted data can remain in database backups for a short time before it is overwritten.
Children
DevStash is not meant for children under 13.
Changes
If this policy changes, we will update it here and change the date at the top.