Legal

Privacy Policy

Last updated: September 23, 2026

1. Introduction

DevFlow is operated by Upton Consulting LLC ("we", "us", "our"). This Privacy Policy explains how we collect, use, and protect your information when you visit digitaldevflow.com or use the DevFlow application at app.digitaldevflow.com.

2. Information We Collect

Information you provide:

  • Name, email, and message when you request a demo or contact support
  • Account information (name, email, organization) when you sign up for the application
  • Content you create within the application (projects, tickets, time entries, comments)

Information collected automatically:

  • Your IP address, used briefly to limit automated signup abuse — it is not stored or linked to your account

3. How We Use Your Information

  • To provide, maintain, and improve the DevFlow service
  • To communicate with you about your account, product updates, and support or demo requests
  • To respond to support requests
  • To detect and prevent fraud or abuse

We do not sell your personal information to third parties.

4. Data Storage and Security

Your data is stored on Microsoft Azure infrastructure in the United States. We use industry-standard encryption in transit and at rest. Access to production systems is restricted to authorized personnel.

5. Third-Party Services

We use the following third-party services that may process your data:

  • Microsoft Entra ID — handles login for staff and portal customers, receiving your email, name, and identity claim, always for any authenticated request.
  • Microsoft Azure — hosts our application database, uploaded file and attachment storage, and secrets, always as our infrastructure provider.
  • Microsoft Graph (email) — sends transactional email (invites, notifications, ticket updates) and, for ticket-by-email, reads inbound mailbox content and attachments, always for any email-triggered flow.
  • Stripe — processes subscription and billing data (plan, seats, payment status, subscription id), always for any tenant with a paid subscription; card details are held by Stripe only.
  • AI providers (OpenAI, Anthropic, or Google Gemini) — using your workspace's own configured provider and API key, receives ticket details (title, description, status, priority, recent comments), or, for status updates, also the project name and hours logged, or ticket titles only for invoice descriptions, only when you use an AI feature — changelog generation, status update generation, or generating invoice descriptions for an accounting export (which asks first).
  • Claude (Anthropic) — if you connect the Claude app or request a personal API token for Claude Code, returns the DevFlow data that client asks for (tickets, boards, priorities, projects, project files, ticket comments, ticket links, users, or AI settings) to your own Claude account.
  • Slack — posts to the Slack workspaces you connect, including your clients' — connected by a workspace admin, or by a client's own Slack admin through an install link you send them. Ticket updates (ticket key, title, project name, priority, who took the action, status changes, approvals) and client-visible comment text (up to 500 characters per comment, with a link back to the full comment in DevFlow) go to a project's channel; a client's workspace receives only what that client can already see in your client portal. Internal note text is posted only to your own workspace's channels that are not shared with an external organisation, and budget and usage alerts go only to your own workspace — only if a workspace admin (or a client's own Slack admin, for their workspace) connects Slack.
  • Intuit QuickBooks — receives client names and invoice line items (hours, dates, project names, and AI-generated descriptions where enabled) only when a workspace admin connects their QuickBooks company.
  • Formspree — receives the name, email, and message you submit through the Support Contact form or the Demo Request form, only when you submit one of those forms.

6. Your Rights

You may request access to, correction of, or deletion of your personal data at any time by contacting us. If you delete your account, we will remove your personal data within 30 days, except where retention is required by law.

7. Cookies

The marketing site (digitaldevflow.com) does not use tracking cookies. The application (app.digitaldevflow.com) keeps you signed in using your browser's local storage rather than cookies; a short-lived cookie is set only while an admin is connecting QuickBooks. Microsoft Entra, our sign-in provider, sets its own cookies on its login page.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and revising the date shown at the top.

9. Contact

Questions about this policy? Email us at privacy@digitaldevflow.com.