Privacy Policy
Last updated 28 August 2026
This policy explains what personal data DevPacs collects, why we collect it, who we share it with, and what you can do about it. It covers the DevPacs mobile apps for iOS and Android, the developer console at app.devpacs.com, and this website.
Contents
1. Who we are
DevPacs is operated by DifferApps, ("DevPacs", "we", "us"). We are the data controller for the personal data described in this policy.
You can reach us about anything in this policy at hello@devpacs.com.
2. What we collect
Information you give us
| Data | When |
|---|---|
| Email address | When you create an account, or from Apple or Google if you sign in with them |
| Display name and profile details | During onboarding, and whenever you edit your profile |
| Your app's name, description and store links | When you add an app to test |
| Screenshots you upload | As proof for daily tasks, bonus tasks and complaints |
| Written feedback and task responses | Each time you submit a task or a day-seven feedback form |
| Reports and complaints | When you report a member, a task or a dispute |
Information we generate about your activity
- Which packs you have joined, in which role, and your status in each
- Task assignments, submission timestamps, and the moment you tapped through to an app
- Review decisions, rejection notes, disputes and their outcomes
- Your token balance and a record of every token transaction
- Inactivity points and any removal or enforcement action on your account
Information collected automatically
- Device push token — stored per user and platform so we can send notifications. You can turn push off at any time.
- Analytics events — via Google Firebase Analytics: screens viewed, and actions such as joining a pack, submitting a task or completing a purchase, together with the device model, operating system version and a resettable app instance identifier.
- Advertising — if you choose to watch a rewarded ad, Google AdMob receives the data described in its own policy in order to serve and verify that ad. We do not show banner or interstitial ads.
- Purchase records — when you buy tokens, a subscription or an inactivity-point clear, Apple or Google processes the payment and sends us the transaction identifier and product purchased. We never receive your card details.
3. Why we use it, and our legal basis
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Creating and running your account | Performance of a contract |
| Assigning daily tasks and running the seven-day pack cycle | Performance of a contract |
| Showing your submissions to the developer whose app you tested | Performance of a contract |
| Operating the token economy and processing purchases | Performance of a contract |
| Sending notifications about your packs and tasks | Performance of a contract, or your consent for optional categories |
| Investigating reports, disputes and policy violations | Legitimate interests — keeping the platform safe and fair |
| Analytics to understand and improve the product | Legitimate interests, or consent where required |
| Serving rewarded ads you have opted into watching | Consent |
| Meeting legal, tax and accounting obligations | Legal obligation |
4. What other members can see
DevPacs only works because members can see each other's work. Be aware that:
- Other members of your pack can see your display name and profile.
- The developer whose app you tested can see your screenshots, written responses and feedback forms, and decides whether to approve them.
- If you dispute a rejection, another member of your pack may be asked to review that dispute, including the original submission and both parties' notes.
- Developers can export all feedback on their own app, including your responses, as a CSV file.
- Administrators can see the full content of any report or complaint, and the submissions it concerns.
Your email address is never shown to other members. Don't put anything in a screenshot or a written response that you wouldn't want the app's developer to keep.
5. Who we share data with
We do not sell your personal data. We share it only with the service providers that run DevPacs:
| Provider | What they handle |
|---|---|
| Supabase | Database, authentication, file storage for screenshots, and server functions |
| Google Firebase | Analytics and push notification delivery |
| Google AdMob | Rewarded video ads, only when you choose to watch one |
| Apple / Google Play | In-app purchases and subscription billing |
| Hostinger | Email for our support and notification addresses |
We may also disclose data where we are legally required to, or to establish, exercise or defend legal claims. If DevPacs is ever acquired or merged, data may transfer to the new owner under this same policy until you are told otherwise.
6. International transfers
Some of our providers process data outside the UK and the European Economic Area, including in the United States. Where that happens we rely on the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, or an adequacy decision, as appropriate to the provider.
7. How long we keep it
- Account data — for as long as your account is open.
- Pack content — submissions, feedback and screenshots stay available to the relevant developer after a pack closes, so that completed packs remain readable.
- Token transactions and purchase records — retained for as long as we need them for accounting and tax purposes.
- Reports, complaints and enforcement records — retained while they remain relevant to platform safety.
- Analytics — retained according to the retention period set in Firebase Analytics.
8. Your rights
If you are in the UK or the EEA, you have the right to:
- Ask what personal data we hold about you, and get a copy
- Have inaccurate data corrected
- Have your data deleted, subject to the limits in section 9
- Object to, or ask us to restrict, processing based on legitimate interests
- Receive your data in a portable format
- Withdraw consent at any time, where consent is the basis we rely on
Email hello@devpacs.com to exercise any of these. We aim to respond within one month. If you are unhappy with our response you can complain to the UK Information Commissioner's Office at ico.org.uk, or to your local supervisory authority in the EEA.
If you are a California resident, you have comparable rights to know, delete, and correct your personal information, and not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined by the CCPA.
9. Deleting your account
You can delete your account from within the app, under your profile settings. Deleting your account removes your profile, your apps, your token balance and your task submissions.
Two things survive deletion, and you should know this before you ask:
- Feedback already exported by a developer as a CSV is in their hands and outside our control.
- Enforcement records — if your account was banned, we keep a record of the ban so the ban can be enforced. This is necessary for our legitimate interest in platform safety.
10. Security
Access to your data is governed by row-level security policies enforced by our database, so members can only read the pack content they are entitled to see. Traffic is encrypted in transit. Passwords are hashed by our authentication provider and are never visible to us. No system is perfectly secure, but we take reasonable and appropriate measures to protect your data, and we will notify you and the relevant regulator of a breach where the law requires it.
11. Children
DevPacs is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove it.
12. Changes to this policy
We will update this page when our practices change, and revise the date at the top. If a change materially affects your rights we will tell you in the app before it takes effect.
13. Contact us
hello@devpacs.com reaches us for anything in this policy, and for everything else.