Privacy Policy
Last updated: September 21, 2026
Your Privacy Matters
At HyperDevs, we believe privacy is a fundamental right. This policy explains how we handle data. We designed HyperDevs to collect as little data as possible, and we never sell your information to anyone.
If you have questions about this policy, please contact us at privacy@hyperdevs.app.
API Keys
We never see your API keys.
When you add an API key for Claude, Gemini, OpenAI, or any other provider, that key is stored locally on your device in encrypted storage. The key is never transmitted to our servers.
All API calls go directly from your computer to the AI provider's servers. We act as a local client — nothing passes through our infrastructure.
Your Prompts and Generations
This works differently for chat than for image, 3D and animation generation, so we describe them separately rather than make one blanket promise.
Chat and code (the AI assistant)
We do not store these. Your messages go straight to the AI provider you selected — with your own key, directly from your computer to that provider; with our hosted model, streamed through our proxy to the model and back. The proxy does not record message content. We keep no transcript, and there is no copy of your conversation on our servers — unless you choose to attach part of it to a bug report you send us.
Image, 3D and animation generation
For these, we do keep a record of the request. Each generation creates a job row that includes the prompt text you submitted, which model was used, the credits charged, and a link to the finished file at the provider.
We keep it because these jobs are asynchronous and paid for in advance: the record is how we deliver the result back to you, how we refund your credits when a job fails, and how we answer you if you tell us something was charged incorrectly. It is retained while your account exists and is deleted when your account is deleted.
We do not use it to train anything, we do not sell it, and we do not review it except when investigating a specific problem you have raised, a suspected policy violation, or a legal obligation.
Your project files
Your game files, scripts and assets stay on your computer. We have no access to your project, and nothing scans or uploads it.
Your Game Data
Your game files stay on your computer.
When HyperDevs reads your Roblox project for the Memory feature or imports assets via MCP, all processing happens locally. Your game scripts, assets, and project structure are never uploaded to our servers.
The Memory feature builds a knowledge graph from your game's structure, but this data is stored locally and used only to help the AI understand your project context.
Usage Data (HyperDevs Cloud Only)
If you use HyperDevs Cloud (our free or paid tier that provides hosted AI), we collect minimal data to operate the service:
- Email address: if you create an account, we store your email securely and use it to send you account emails, such as the codes that confirm your address when you sign up and let you reset a forgotten password. Those are sent through our email delivery provider and are never used for marketing.
- Birth year: collected at sign-up to enforce our 13+ age requirement. We keep the year only, not the full date.
- Request count: how many requests you have made today, for rate limiting.
- Credits and payments: your balance, purchases, and a ledger of grants and spends.
- Generation job records: as described above — for image, 3D and animation jobs only.
- Interaction events: which screens you open, whether you started or finished the guided tour, and when a request fails. See below.
Interaction events
The app records a small set of named events so we can tell where people get stuck. A typical one is "opened the Coder tab" or "the first message failed with a 401" — the kind of thing that told us a whole group of new users had hit a bug on their very first prompt and left without saying anything.
These events carry only fixed labels, numbers and yes/no values. They never carry your prompts, your code, your file paths, or the text of an error message — the app has nowhere to put that in an event, by design.
Nothing is sent unless you are signed in. If you use HyperDevs with your own API keys and never create an account, no events leave your machine at all. You can also turn this off at any time in Settings → General → Usage Data; switching it off also discards anything still queued on your device.
We still do not collect, in the app:
- Your chat messages or the code you write
- The contents of your project files
- Your screen, keystrokes, or mouse movement — there is no session recording of any kind
- Your IP address (beyond what is necessary for DDoS protection)
- Location data
- Device fingerprinting
App Usage Analytics (v0.1.22 and later)
From v0.1.22 the desktop app can record a small amount of interaction data, so we can find first-run experiences that are broken. We added this because we genuinely could not tell whether people were getting stuck, or where.
What it records:
- Which tabs and screens you open
- Whether you completed or skipped the guided tour
- When a request fails, and a category for why (never the raw error text)
What it never records — and structurally cannot:
- Your prompts, or anything you type into the AI
- Your code, scripts or generated assets
- File paths, project names or anything identifying your game
- Your API keys
Events carry only categories, numbers and true/false values. There is nowhere in the payload to put your content, which is how that guarantee stays true rather than being a promise we ask you to trust.
Signed-in users only. Nothing is ever uploaded without an account session — the database rejects any event not tied to a signed-in user, so this is enforced by the server and not just by the app.
It is on by default, and you can turn it off at any time in Settings → General → “Share anonymous usage data”. Switching it off also discards anything still waiting to be sent.
Website Analytics
This website (hyperdevs.app) uses Cloudflare Web Analytics to understand which pages people find useful. It is privacy-first by design:
- No cookies. It sets none, and stores nothing in your browser.
- No fingerprinting. It does not build a device or browser signature to follow you.
- No cross-site tracking. It cannot see anything you do on other sites.
- Aggregate only. We see page views, referrers, countries and browser types in aggregate — never individual people.
Because it sets no cookies and stores nothing on your device, it does not require a consent banner — which is exactly why we chose it over a conventional analytics product.
This applies to the website only, and the desktop app does not use Cloudflare Web Analytics or any third-party analytics product. What the app itself records is described under Usage Data above, it goes only to our own database, and it never includes your browsing.
We Never Sell Your Data
Period.
We don't sell your data to third parties. We don't use your data for advertising. We don't build "shadow profiles" for sale. Our business model is simple: provide great tools, charge fair prices for optional features.
Account Deletion
If you create a HyperDevs Cloud account, you can delete it at any time from Settings → Account → Delete Account in the app. You will be asked for your password, and the deletion happens straight away.
If you cannot sign in, or the app asks you to contact us, email legal@hyperdevs.app from the address on the account and ask us to delete it. We will action it within 30 days and confirm when it is done.
Deletion removes your email, birth year, credit and payment ledger, generation job records (including the stored prompts) and interaction events. It is permanent and cannot be undone. Unspent credits are forfeited when you delete your account, so spend them first if you want to use them.
Bug reports you have sent us are kept, because they describe a problem with the app rather than you. When you delete your account we remove the link to it and the diagnostic details attached to each report — console logs, click history, browser details and any chat excerpt you chose to include — and keep the description you wrote, with the app version and screen it came from. Our payment processor keeps its own records of payments, as the law requires.
You can also ask us for a copy of the data we hold about you at the same address.
Data Security
We take security seriously:
- Local API keys: Encrypted with your operating system's credential manager (Windows Credential Manager)
- HyperDevs Cloud accounts: Email and usage data stored securely with encryption at rest
- HTTPS: All connections use TLS 1.3 or higher
- No logging: We don't maintain access logs beyond what's necessary for security monitoring
Children's Privacy
HyperDevs is not intended for children under 13, and we do not knowingly collect personal information from them. Please do not create an account or submit personal information through this site if you are under 13. If we learn we've collected data from a child under 13 without verifiable parental consent, we will delete it promptly. Parents or guardians can contact us at privacy@hyperdevs.app.
Changes to This Policy
If we change this privacy policy, we will:
- Update the "Last updated" date at the top
- Notify users via the app (if the change is significant)
- Never retroactively apply new terms to past data collection
Questions or Concerns?
If you have questions about this privacy policy or how we handle your data, please contact us at privacy@hyperdevs.app. We typically respond within 1-2 business days.