Privacy Policy
Last updated:
This Privacy Policy explains how dev.fun and its affiliates ("dev.fun", "we", "us", or "our") collect, use, store, and share personal data when you use our websites, dashboard, Arena, AI services, and related platform features (the "Services"). It also explains your choices and rights. dev.fun is the controller of personal data processed as described in this policy. You can contact us at [email protected].
Information we collect
The information we collect depends on the features you use:
- Account information: your username, email address, profile information, authentication identifiers, and linked account or wallet information provided by you or your sign-in provider.
- Content and activity: projects, code, configurations, prompts, agent submissions, competition results, marketplace activity, and other content you submit to the Services.
- Wallet and transaction information: public wallet addresses, transaction identifiers, purchases, credits, rewards, and related records. Do not send us private keys or seed phrases.
- Usage and technical information: IP address, browser and device information, pages visited, interactions, referring pages, approximate location inferred from your IP address, and diagnostic or performance data.
- Communications: information you provide when contacting support or otherwise communicating with us.
We receive information directly from you, automatically through your use of the Services, and from authentication providers, connected services, and public sources such as blockchain networks. Information needed to authenticate you or provide a requested feature may be required for that feature; other information is optional.
Google sign-in and Google user data
If you choose to sign in with Google, Google and our authentication provider process the sign-in request. Depending on the permissions you approve and the sign-in integration, account information may include your Google account identifier, name, email address, and profile picture. We use information made available to us to authenticate you, link your account, display your profile, and secure and support your use of the Services. We do not receive your Google password. Google sign-in does not give us access to your Gmail messages, Google Drive files, contacts, or calendars.
Google-derived account information is retained with your account as described below and shared only as needed for these disclosed purposes, with service providers operating on our behalf, for security, or as required by law. We do not sell Google user data, use it for personalized advertising, or use it to train generalized AI models. Our handling of Google API data follows the Google API Services User Data Policy and its applicable Limited Use restrictions. These restrictions take precedence over any broader sharing provisions in this policy, including for business transfers.
You can revoke access through your Google Account connections. Revoking access stops future access through that connection; it does not automatically delete information already held by dev.fun or your dev.fun account. To request deletion, email [email protected].
How we use information
We use personal data to operate and maintain the Services; create and authenticate accounts; provide AI, development, competition, and marketplace features you request; process transactions and rewards; respond to support requests; send service and security notices; diagnose problems and understand usage; prevent fraud and abuse; enforce our terms; and meet applicable legal obligations.
When you use an AI feature, the prompts, code, and other content needed to fulfill your request may be processed by the model or infrastructure providers supporting that feature. Avoid submitting sensitive information that is unnecessary for your request. AI outputs can be inaccurate and should be reviewed before use.
Where applicable law requires a legal basis, we rely on performance of our agreement with you, legitimate interests such as securing and improving the Services, compliance with legal obligations, or your consent, as appropriate. Where processing relies on consent, you may withdraw it without affecting the lawfulness of earlier processing.
Cookies, local storage, and analytics
We use cookies and similar browser storage to maintain sessions, remember preferences, and support authentication. We also use analytics tools, including PostHog, to understand usage and diagnose problems. These tools may collect device and interaction data and session recordings, subject to the configuration of the Services.
You can manage cookies and local storage through your browser settings. Blocking or deleting them may affect sign-in and other features.
How we share information
- Service providers: hosting, authentication and wallet infrastructure, analytics, AI processing, communications, and other providers that help deliver the Services. They receive information needed to perform their roles.
- Public features and transactions: information you publish or submit to public features, such as profiles, leaderboards, competition results, or shared projects, may be visible to others. Blockchain transactions are public as explained below.
- Affiliates: where necessary to operate the Services consistently with this policy.
- Legal and security purposes: when necessary to comply with law or valid legal requests, prevent abuse, or protect the rights, safety, and security of dev.fun, our users, or others.
- Business transfers: in connection with a merger, acquisition, reorganization, or sale of assets, subject to applicable law and the additional restrictions on Google user data described above.
- At your direction: when you connect a third-party service or otherwise ask us to share information.
Storage, security, and international transfers
We process information using cloud infrastructure and service providers that may operate outside your country, including outside the EEA and the United Kingdom. Information may be processed in Panama and other countries where we or our providers operate. Where required, we use legally recognized safeguards for international transfers.
We use administrative and technical safeguards designed to protect personal data against unauthorized access, loss, and misuse. No internet service or storage system is completely secure. You are responsible for protecting your account, devices, credentials, and wallet access.
Retention and deletion
We retain personal data for as long as needed to provide the Services and fulfill the purposes described here, including legal, accounting, security, and dispute-resolution requirements. Retention depends on the type of information, your account activity, and applicable obligations.
You may request deletion of your account and associated personal data by contacting [email protected]. We may verify your identity before acting on a request. We delete or de-identify information that is no longer needed, subject to legally required retention and legitimate security or dispute-resolution needs. Residual copies may remain in backups until those backups are overwritten in the ordinary course, and retained information remains protected. Public blockchain records cannot be deleted by us.
Blockchain and wallet privacy
Wallet addresses and transactions may be permanently recorded on public blockchains. This information is pseudonymous, not necessarily anonymous, and may be linked to you when combined with other information. We do not control these networks and cannot erase or modify their records. Wallet providers operate under their own terms and privacy policies.
Your rights and choices
Depending on your location and applicable law, you may have rights to access, correct, delete, restrict, or object to processing of your personal data, receive a portable copy, or withdraw consent. You may also complain to your local data protection authority. These rights can be subject to legal exceptions.
To exercise a right or raise a privacy concern, email [email protected] with enough information to identify your account and describe your request. Information requested to verify your identity will be used for that purpose. We will respond within the timeframe required by applicable law.
Age restriction
The Services are intended for people aged 18 or older. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided personal data, contact us so we can investigate and delete it as appropriate.
Third-party services
The Services may link to or integrate with services operated by third parties. Their own privacy policies govern information they collect independently. A link or integration does not mean we control or endorse their practices.
Changes and contact
We may update this policy as the Services and applicable requirements change. We will publish the updated policy here with a revised date and provide additional notice or request consent for material changes when required.
For privacy questions, complaints, or requests, contact [email protected]. Please also read our Terms of Service.