Privacy Policy

Plain English, no legalese. Last updated: 2026-05-15.

What we collect

  • Email address — when you purchase via Stripe or subscribe to updates.
  • Telegram user ID and chat ID — when you start a conversation with @dev_pinger_bot, so we can deliver notifications.
  • Source API tokens — when you connect GitHub, Jira, Stripe, or Sentry. Encrypted at rest with AES-256-GCM.
  • Event metadata — PR titles, payment amounts, error stacks — only the parts needed to render readable Telegram messages.

Where we store it

  • Billing data (email, payment) — Stripe (you can read their Privacy Policy at stripe.com/privacy).
  • Product data (Telegram IDs, source tokens, event history) — Postgres on Hetzner (Germany / EU).
  • Encryption — all source API tokens are encrypted with AES-256-GCM. Keys rotate on a schedule.

How long

For active accounts: as long as the subscription is active. After cancellation or refund: an additional 30 days, then cascade-deleted.

Your right to delete

Send /unsubscribe or /forget_event inside the bot. We support GDPR right-to-erasure. Or email privacy@devpinger.com and we'll handle it within 7 days.

Contact

Questions, complaints, or data requests: privacy@devpinger.com.