Privacy Policy

Last updated October 6, 2026

DevStash is run by Traversy Media. This page explains what we collect when you use devstash.io, why we collect it, and what you can do about it. Questions go to brad@traversymedia.com.

What we collect

  • Account details: your email address, your name if you give one, and a hashed password if you sign up with email (never the password itself). If you sign in with GitHub: your GitHub name, avatar, account ID, and the sign-in tokens GitHub issues, which DevStash stores but does not use.
  • Your handle: created from the part of your email before the @ the first time you share something, and shown as @handle on everything you share. You can change it in Settings.
  • What you save: your items, collections, tags, and settings.
  • Page views: anonymous counts through Vercel Web Analytics, which does not use cookies.
  • Rate limit counters: sign-ins, sign-ups, password resets, and verification emails are rate limited by IP address and, for sign-in attempts and verification emails, by email address too. The counters expire within about two hours. Our hosting provider also keeps standard request logs, which include IP addresses, for a limited time.

How we use it

  • To run your account and show you your stash.
  • To send account emails, such as email verification and password resets. We do not send marketing email.
  • To publish what you choose to share. Unlisted items are visible to anyone with the link, and public items can also be indexed by search engines. Sharing a collection shares every item in it, including items that are private on their own; otherwise private items are visible only to you.

We do not sell your data or use it for advertising.

Services that process your data

ServiceWhat it does
VercelHosts the app and counts page views
NeonStores your account and your stash in a Postgres database
UpstashHolds the short-lived rate limit counters
ResendSends account emails
OpenAIRuns the AI helpers, only when you click one. It receives the item's title, type, language, the URL for links, and up to 2,000 characters of its content
GitHubSigns you in, if you choose GitHub
jsDelivrServes the code editor's files to your browser when you open the editor
Cloudflare R2Stores files and images uploaded while uploads were available
StripeHandles payments if paid plans return; none are active now

Cookies

DevStash sets a few cookies that sign you in and keep you signed in, and two that remember your list layout and page size. There are no advertising or tracking cookies.

Your choices

  • Export your items, collections, and tags at any time from Settings, under Data. Files you uploaded download one at a time from their item.
  • Make anything you shared private again from the item's drawer, the collection's page, or the Shared page.
  • Delete your account from Settings. This deletes your account, items, collections, and shared pages. Copies other people saved to their own stash stay there. If you uploaded files while uploads were available, email us and we will remove the stored files too. Deleted data can remain in database backups for a short time before it is overwritten.

Children

DevStash is not meant for children under 13.

Changes

If this policy changes, we will update it here and change the date at the top.