PRIVACY POLICY.
How DEV/STATION handles account, portfolio, and community information.
Last updated 9 October 2026Portfolio activity and app updates
When you save, rate, or leave a public rating comment on a portfolio, its owner can receive a private in-app notification showing your public display name and avatar, the portfolio, and the activity. This does not give the owner access to your full saved list or email. Notifications start with new activity after this feature is enabled. The inbox shows up to 200 recent items from the last 90 days; older stored items are removed when new activity arrives. Read status is private to the recipient.
Android checks Expo's update service for compatible app updates on launch and periodically when returning to the app. You can download an available update and choose when to restart. Update requests and asset downloads are processed by Expo and its delivery infrastructure. Some changes require a new APK installation. These notices and portfolio notifications appear inside the app; they are not background push notifications.
Information we handle
DEV/STATION operates this portfolio community. When enabled, Google sign-in supplies your Google identity, name, avatar, email and session information. Discord sign-in supplies your Discord ID, username, display name, avatar, email, and session information. With your Discord authorization, we request permission to join the DEV/STATION Discord server. GitHub sign-in supplies your GitHub identity, username, name, avatar, email, and session information when enabled. GitHub authorization requests profile and email read access, without private repository access or permission to modify your code. Discord is optional for Google and GitHub users. Connected identities share one account; disconnecting a provider preserves your work, while disconnecting Discord removes its derived benefits. Submissions contain a title, description, website and optional GitHub link, category, technology tags, image, and reviewer contact email.
We store ratings, optional public comments, saved portfolios, submission and review status, awards, and verified Discord booster status to operate account features and prevent abuse. If a paid feature is enabled, payment providers process payment details; DEV/STATION keeps payment references and status, not card numbers or security codes.
What is public
Approved portfolios show their creator name, image, title, description, links, category, technology tags, aggregate scores and saves, and recognition labels. Nonempty rating comments are public with the reviewer's display name and date. Active Discord boosters may appear in the contributor list. Developer contact emails are available to authorized reviewers, not the public archive. Saved lists and rating history are account features. Public portfolios can be indexed by search engines.
Android local storage
Android stores downloaded public portfolio details and thumbnails to reduce repeated requests. Incomplete Android submissions and their compressed images remain in an encrypted local database on this phone. Session credentials and the local encryption key use the device's secure credential storage. Drafts are not uploaded or shared with another device until you submit. The system photo picker lets you choose an image without granting broad gallery access.
Local drafts expire 24 hours after your last meaningful edit. Expired drafts are removed when the app next runs or becomes active; Android may delay background execution. Signing out clears private local drafts and account caches. Discard removes the selected draft. Clearing app data or uninstalling can erase local work. Downloaded public content may remain cached after sign-out and is marked as saved content when a network refresh fails. The native app does not send website presence heartbeats or include Vercel web analytics.
Website storage and activity
Website drafts are associated with your account, with a local browser recovery copy, and expire 24 hours after the last saved change. Uploaded draft images use public media URLs. The website can estimate visitors and signed-in members active in the last three minutes through Cloudflare using short-lived, keyed identifiers. Raw IP addresses, account IDs, names, emails, and visited pages are not stored in that presence ledger. Maintenance normally removes expired entries every two minutes; outages and backups can delay removal.
Vercel Web Analytics measures aggregate website page views without analytics cookies, including referrer, approximate location, and browser/device details. Hosting and security systems may process IP addresses, device information, and request logs to deliver and protect the service. Request-limit identifiers expire after seven days and view identifiers after 90 days. We do not sell account or portfolio data or run third-party behavioral advertising pixels.
Infrastructure and retention
Supabase provides authentication and shared database storage. Cloudflare hosts uploaded media and website presence services. Vercel hosts website APIs and website analytics. Google handles Google authorization; GitHub handles GitHub authorization; Discord handles Discord authorization and server membership. These providers process information under their own practices. External portfolio websites have their own privacy policies.
Unused uploaded thumbnails and expired website drafts are eligible for scheduled cleanup; outages or backlogs can delay deletion. Submitted images remain attached to submitted work. Account records, submissions, ratings, saved portfolios, and awards are retained while needed to operate the community, with no automatic deletion date currently. Rating history may retain the rating after its portfolio is removed, displaying that the portfolio is deleted or unavailable.
Your choices
You can sign out, discard Android drafts, and clear app or browser storage. For access, correction, removal, export, or a concern about your data, contact the DEV/STATION team through the community server. We may verify your account before acting on a request. An account-deletion request can be sent from Android Account; a request does not immediately delete the account. Some records may be retained for security, disputes, or award integrity. We update this notice when handling changes materially.
Contact the team.
Terms of service · Privacy · Cookies & storage · Community guidelines · Submission rules