Legal
Privacy Policy
Effective date: May 16, 2025 · MainRobin Pty Ltd
1. Introduction
MainRobin Pty Ltd ("we", "us", or "our") operates DevCortex (https://www.devcortexai.com), a structured intelligence platform for agentic software engineering ("the Service"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use the Service.
By using DevCortex, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Account Information
When you register, we collect your name, email address, organisation name, and password (hashed). We do not store plaintext passwords.
2.2 Project and Requirements Data
We store the product specifications, requirements, user stories, acceptance criteria, issues, and associated metadata you create within DevCortex. This content is owned by you and your organisation.
2.3 Usage Data
We automatically collect information about how you interact with the Service, including IP address, browser type, pages visited, API requests made, and timestamps. This data is used to operate and improve the Service.
2.4 Payment Information
Payments are processed by Stripe. We do not store your credit card number or full payment details. We store your Stripe Customer ID and subscription status to manage your account.
2.5 Communications
If you contact us via email or the in-app feedback form, we retain that correspondence to respond to your enquiry and improve the Service.
3. How We Use Your Information
- To provide, maintain, and improve the Service
- To process your subscription and send billing-related communications
- To authenticate you and maintain the security of your account
- To respond to support requests and feedback
- To send service announcements and product updates (you may opt out)
- To monitor usage patterns and diagnose technical issues
- To comply with legal obligations
We do not sell your data to third parties. We do not use your project content to train AI models.
4. Data Storage and Security
Your data is stored in a PostgreSQL database hosted on Railway infrastructure. We implement industry-standard security measures including encryption in transit (TLS), hashed credentials, and access controls.
While we take reasonable precautions, no method of transmission over the internet is 100% secure. We encourage you to use a strong, unique password and to notify us immediately of any suspected unauthorised access.
We perform daily backups of production data. Backup data is retained for 30 days.
5. Third-Party Services
We use the following third-party services to operate DevCortex:
- Stripe — payment processing and subscription management
- Railway — cloud infrastructure and database hosting
- Sentry — error monitoring and performance tracking
- GitHub — source code management and CI/CD
Each of these services has its own privacy policy governing their use of data.
6. Data Retention
We retain your account and project data for as long as your account is active. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it for legal or financial compliance purposes (e.g. billing records, which are retained for 7 years in accordance with Australian tax law).
7. Your Rights
Under the Australian Privacy Act 1988 and applicable regulations, you have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate or incomplete information
- Request deletion of your personal data, subject to legal retention requirements
- Opt out of non-essential communications
- Lodge a complaint with the Office of the Australian Information Commissioner (OAIC)
To exercise any of these rights, contact us at [email protected].
8. Cookies
DevCortex uses session cookies to authenticate users and maintain login state. We do not use advertising cookies or third-party tracking cookies. You can configure your browser to refuse cookies, but this may prevent you from using the Service.
9. Children's Privacy
The Service is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the effective date. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy, please contact us: