Privacy Policy

Last updated: September 26, 2026

Overview

DevKit is an app for iPhone and iPad that watches servers and endpoints from a managed cloud service, sends alerts, opens SSH terminals and runs network diagnostics. It is published by the operator of odbs.tech ("we", "us"). This policy explains what the app keeps on your device, what the cloud service stores about you and your monitors, what is sent to third parties and for how long. DevKit has no advertising, no analytics and no tracking, and it never records what you type in a terminal.

What stays on your device

  • SSH passwords and private keys. Stored only in this device's Keychain, marked device-only, and only if you choose to save them after a successful connection. They are never sent to our servers.
  • Trusted host keys of the servers you connected to, and the Ed25519 key the app can generate for you.
  • Terminal content. Nothing you type or see in a terminal is stored or transmitted anywhere except to the server you connected to.
  • Saved commands and favourites.
  • Results of one-off checks in Tools (ping, traceroute, DNS, TLS and the others) live in memory for the session and are not saved.

Your account and devices

Every installation registers itself with our service and starts as an anonymous user, so that projects and monitors are stored on the server even before you sign in. For each installation we store a random identifier, a hash of its key, the device name and platform, the app version, the time it was last seen and, if you allow notifications, its push token.

When you sign in we store your email address. Sign-in codes are stored hashed and expire after ten minutes; sessions last seven days and can be revoked from the app. We do not store passwords.

Projects, monitors and checks

The cloud service stores what you configure: workspaces, projects, environments and resources (their names, addresses, usernames and notes), monitors (kind, address, interval, thresholds, request headers, request body, expected responses) and maintenance windows. Request header values and other secrets you enter are encrypted at rest.

For every check we store the outcome, the timings by stage, the region it ran from and, when a check fails, the response headers (without cookies) and the first 4 KB of the response body so that you can see why. Failure captures are shown only to people who can manage the monitor. Check history is kept for the period your plan allows and then deleted.

Our servers contact the addresses you monitor on the schedule you choose; the operator of that address sees our server's IP address and the requests you configured. Private and local network addresses are refused and never contacted.

Heartbeats

A heartbeat monitor receives calls from your own jobs. For each call we store the time, the exit code, the duration and the first 10 KB of the request body as a log, keeping the last 100 calls per monitor. Logs are shown only to people who can manage the monitor.

Alerts and notifications

Alert channels you configure (email addresses, webhook URLs and signing secrets, Slack, Discord and Telegram destinations) are encrypted at rest and are never returned in full by the service. When an outage, recovery, expiry or reminder is sent, the message carries the monitor's name, address and the reason. Delivery attempts are logged with their outcome. In-app notifications stay in your inbox until you delete them or your account is deleted.

Status pages

A status page shows only the display names you choose, never addresses, internal names or error text. People who subscribe to a status page give us their email address; we store it with its confirmation status and send only confirmation, outage, recovery and unsubscribe messages. Every message has an unsubscribe link.

Teams

In a team workspace, other members see the projects, environments and monitors they were granted access to, and the owner sees the members, their roles and an access audit (who was granted or removed what, and when). Your email address is visible to the owner of a team you join.

One-off checks from the cloud

When you choose to run a Tools check from the cloud, our server runs it once and returns the result. Nothing about the check is stored. These checks are rate-limited per account.

Network tools on your device

Tools run from your device contact the addresses you enter directly, so those servers see your device's IP address. Depending on the tool, the device also queries public DNS resolvers (1.1.1.1 and 8.8.8.8), the authoritative name servers of the domain, the RDAP service at rdap.org and Team Cymru's DNS-based IP-to-ASN service. These queries carry only the name or address you looked up.

Email

Sign-in codes, alerts and status page messages are sent through Resend, our email delivery provider, from [email protected]. Resend processes the recipient address and the message for delivery.

Hosting

The cloud service runs on servers we rent from Amazon Web Services in Frankfurt, Germany (European Union). Data is transmitted over TLS. Database backups are kept for a limited time to recover from failures.

Analytics, tracking and advertising

DevKit contains no analytics SDK, no crash-reporting SDK and no advertising. It does not track you across apps or websites, does not use the advertising identifier and does not sell or share personal information. The website devkit.odbs.tech sets no cookies and loads no third-party scripts.

Retention and deletion

  • Check history is kept for the period your plan allows, then deleted.
  • Failure captures, heartbeat logs and in-app notifications are deleted with their monitor or account.
  • You can export your data from the app at any time: projects, monitors with their uptime history and outages, channels, status pages and maintenance windows, excluding secrets.
  • You can delete your account from the app. Your workspaces stop immediately; signing in again within 30 days restores them. After 30 days everything is deleted: workspaces and their contents, team memberships, devices, inbox and your email address.

Service providers

  • Apple — App Store distribution and, once enabled, push notification delivery.
  • Resend — email delivery.
  • Amazon Web Services — hosting in Frankfurt, Germany.

Your rights

Depending on where you live (for example under the GDPR or Turkey's KVKK), you may have the right to access, correct, delete or export your personal data and to object to its processing. The export and deletion above cover most requests; for anything else, email [email protected] from the address on your account.

Children

DevKit is not directed at children under 13, and we do not knowingly collect personal information from them.

Support

If you email [email protected], your email address and the information you provide are used only to answer you. Do not send passwords, private keys, tokens or sign-in codes in support messages.

Changes

This policy is updated when the app's data practices change. The date at the top reflects the latest revision.

Contact

DevKit is published by the operator of odbs.tech. Privacy questions: [email protected].