Privacy Policy
1. Introduction
Welcome to DevClub UI (the "Library", "Platform", "Service", "we", "us", or "our").
This Privacy Policy explains how we collect, receive, use, disclose, retain, protect, and otherwise process personal information when you visit or use our website, browse our component documentation, download, install, import, or use our packages, access our source code repositories, communicate with us, submit issues or pull requests, or use our developer tools, APIs, playgrounds, and hosted services.
The Library consists of open-source and component registry software. Components execute entirely in your local environment and do not silently harvest or transmit application data to us. Other services, such as our documentation website, APIs, or community channels, process technical information as described below.
2. Scope of This Privacy Policy
This Privacy Policy applies to personal information processed through services that expressly link to this Policy, including the DevClub UI website, documentation and API reference endpoints, package distribution interfaces, preview and rendering environments, support channels, and community repositories.
Software that runs locally: If you install a component package and use it within your own application, the components do not send information to us. A locally installed UI component that renders a button, accordion, sidebar, or shader operates within your application sandbox. Your application remains solely responsible for the personal information it collects.
Hosted services: If you use a hosted service operated by us, such as a playground, preview environment, or public REST API, we process technical request information necessary to deliver that service.
3. Definitions
"Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identifiable individual, as defined by applicable law.
"Usage Data" means technical or interaction information relating to the use of our websites, packages, documentation, or services.
"Device Information" means information about a computer, browser, operating system, network, or similar device.
"Services" means the websites, software, documentation, hosted products, APIs, developer tools, and related services covered by this Policy.
"You" or "User" means the individual or organization accessing or using the Services.
"Controller" means the entity that determines why and how personal information is processed.
"Processor" or "Service Provider" means an entity that processes personal information on behalf of a controller.
4. Information We Collect
The information we collect depends on how you interact with the Library.
Information you provide directly: You may provide information when you contact support, submit a bug report on GitHub, open a pull request, submit feedback, or communicate via email. This may include your name, GitHub handle, email address, feedback, and technical correspondence.
We do not require you to provide more information than is reasonably necessary for the specific technical purpose.
5. Account and Authentication Information
DevClub UI does not require mandatory account registration to browse documentation, preview interactive showcases, or copy registry components.
If authenticated developer accounts are introduced in future releases, we will process email addresses, usernames, and authentication identifiers through secure, industry-standard authentication providers without storing third-party passwords.
6. Automatically Collected Information
When you access our websites or hosted endpoints, technical information may be recorded transiently in server access logs. This may include IP address, approximate geographic region derived from IP, browser type and version, operating system, referring URL, pages viewed, timestamps, HTTP headers, and error diagnostics.
We use this information solely for delivering the service, diagnosing errors, preventing automated abuse, detecting security threats, and measuring aggregate performance.
7. Cookies and Similar Technologies
Our website utilizes local storage and minimal session mechanisms strictly for essential functions, such as preserving your chosen dark theme preference, remembering dismissed notices, and maintaining playground UI state.
We do not deploy third-party advertising tracking cookies or cross-site profiling pixels.
8. Package, Download, and Repository Information
When you download or clone components via git or fetch them from our registry API, technical network metadata (such as IP address, requested slug, and user agent) is processed by our server infrastructure or host CDN to deliver the requested files.
Third-party package managers (such as npm) independently process download metrics under their own respective privacy policies.
9. Documentation and Website Usage
When you navigate our documentation, we process technical page view events to ensure high-speed caching and accurate content rendering. Documentation search queries are evaluated client-side or transiently without building individualized user profiles.
10. Hosted Playground, Sandbox, and Preview Data
Interactive code studios, WebGL shader previews, and component playgrounds execute in your local browser runtime. Any code changes, props adjustments, or playground values you test remain within your client session and are not saved to remote tracking databases.
Do not input passwords, private API keys, or confidential secrets into interactive playgrounds.
11. Source Code, Issues, Pull Requests, and Public Contributions
If you submit an issue, comment, or pull request to our public GitHub repository, information you publish (including your GitHub username, commit email, code snippets, and comments) becomes publicly accessible and permanently preserved under open-source version control.
Never publish private credentials, API keys, or sensitive customer data in public repositories.
12. Information From Third Parties
We may receive technical data from third-party hosting platforms (such as GitHub, Vercel, or Cloudflare) relating to repository activity, CDN bandwidth delivery, and automated security scanning reports.
13. Information We Do Not Intentionally Collect
We do not intentionally seek or collect passwords entered into component form examples, credit card numbers, biometric data, precise GPS location, government IDs, or private health records.
The component library operates without requiring access to sensitive data handled by the applications into which it is embedded.
14. How We Use Personal Information
We use information to operate websites, deliver documentation, process API requests, detect suspicious traffic, investigate abuse, protect infrastructure, troubleshoot bugs, and comply with legal requirements.
We do not sell personal information to third parties.
15. Legal Bases for Processing
Where required by law, we rely on legitimate interests (maintaining service security, preventing fraud, and delivering open-source software), performance of contracts, compliance with legal obligations, or explicit user consent where applicable.
16. How We Share Personal Information
We may share technical information with trusted service providers who assist with cloud hosting, CDN distribution, security DDoS filtering, and error monitoring under strict confidentiality obligations.
We may also disclose information where required by valid legal process or to protect security and user safety.
17. Third-Party Services
Our services link to external platforms (GitHub, Twitter, npm, Radix UI). Third-party platforms operate under their own independent privacy notices, which you should review before engaging with them.
18. Payment Information
DevClub UI core open-source components are provided free of charge under the MIT License. If paid enterprise tiers or support contracts are purchased, transactions are handled by certified third-party payment processors without DevClub storing payment card numbers.
19. Analytics
Where aggregate performance analytics are gathered, they are configured to anonymize IP addresses and minimize data retention, focusing strictly on high-level page views, load times, and error rates.
20. Error Reporting and Diagnostics
Client-side errors and network failures may generate technical diagnostic stack traces to help us fix component issues. Diagnostic payloads are scrubbed to prevent transmission of sensitive environment variables.
21. Security and Fraud Prevention
We monitor request patterns to protect public API endpoints against automated brute-force attacks, credential stuffing, scraping abuse, and denial-of-service attempts.
22. Children's Privacy
Our developer tools and documentation are not directed at children under the age of 13. We do not knowingly collect personal information from children.
23. Sensitive Personal Information
We do not collect sensitive personal information. Users should not post sensitive financial, medical, or confidential data in issue trackers or public discussions.
24. Data Retention
We retain technical information only for as long as necessary to fulfill operational purposes, ensure server security, maintain error diagnostics, and satisfy legal obligations.
25. Data Deletion
You may request the deletion of personal communications or correspondence by contacting privacy@devclub.co. Certain transient security logs and publicly committed git history cannot be erased immediately due to immutability.
26. Data Accuracy
We endeavor to keep developer records and documentation accurate. You may request corrections to correspondence or documentation via our GitHub repository.
27. Your Privacy Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict processing of your personal information, or lodge a complaint with your local data protection regulator.
28. Rights Under Indian Privacy Law
Where applicable, we adhere to the Digital Personal Data Protection Act, 2023 (DPDP) and provide grievance redressal for data principals via grievance@devclub.co.
29. Rights Under the European Economic Area and United Kingdom
EEA and UK residents possess rights under the GDPR and UK GDPR, including data access, rectification, erasure, restriction, objection, and data portability.
30. Rights Under United States State Privacy Laws
Residents of California, Virginia, Colorado, Connecticut, Utah, and other US states may exercise rights to know, access, delete, and opt-out of regulated data practices under applicable state laws.
31. California Privacy Information
Under the California Consumer Privacy Act (CCPA) and CPRA, California residents have the right to request disclosure of collected categories and request deletion without discriminatory treatment.
32. Exercising Your Rights
To submit a privacy inquiry or exercise your legal rights, email privacy@devclub.co with the subject line "Privacy Rights Request". We verify requests to protect against unauthorized disclosures.
33. Authorized Agents
Where permitted by law, you may designate an authorized agent to submit requests on your behalf with written authorization and verification of identity.
34. Appeals
If we decline to take action on a privacy request, you may appeal the decision by writing to privacy@devclub.co explaining the grounds for appeal.
35. International Data Transfers
Where data is transferred internationally across our global hosting infrastructure, we utilize recognized transfer mechanisms, including Standard Contractual Clauses, to ensure adequate protection.
36. Data Security
We implement technical safeguards including HTTPS/TLS encryption in transit, strict access control, vulnerability scanning, and infrastructure firewalls. However, no internet transmission is 100% secure.
37. Your Responsibilities
You are responsible for keeping your local environment, git credentials, and API tokens secure, and ensuring that any application built with DevClub UI complies with applicable privacy laws.
38. Privacy of Applications Built With the Library
DevClub UI does not control the privacy practices of external applications that integrate our components. Application owners must publish their own privacy notices and obtain necessary end-user consents.
39. Telemetry in Components
DevClub UI components do NOT contain hidden telemetry routines or phoning-home beacons. Components execute locally within your application's domain without reporting user interactions back to our servers.
40. Open Source Components
Our open-source component source code is publicly inspectable on GitHub. Developers can audit every line of TSX and CSS to verify that no unauthorized network requests occur.
41. Third-Party Dependencies
Components rely on standard peer libraries (React, GSAP, Radix UI, OGL, Motion, Tailwind CSS). We recommend reviewing dependency manifests when building systems with high compliance requirements.
42. API and Network Requests
When consuming our public REST API endpoints (/api/components, /api/components/[slug]), requests include standard HTTP metadata needed to serve responses and maintain rate limiting.
43. Logs
Server access logs record request timestamps, IP addresses, requested URLs, and response status codes for operational reliability, DDoS prevention, and debugging.
44. Backups
System backups are maintained for business continuity and disaster recovery. Information in backups is automatically purged or overwritten in accordance with retention schedules.
45. Security Incidents
In the event of a verified security incident affecting personal data, we will take prompt containment and remediation measures and notify affected parties and authorities as required by law.
46. Data Breach Responsibilities for Customers
Organizations utilizing DevClub UI components in their products are responsible for their own internal incident response plans, breach assessments, and regulatory notifications.
47. Marketing Communications
We do not send unsolicited marketing email. If you subscribe to product announcements or release notes, you can opt out at any time using the unsubscribe link provided.
48. Surveys and Feedback
Participation in community surveys or developer feedback forms is voluntary. Feedback is used in aggregate to improve our component library and documentation.
49. Community Participation
Public comments, discussions, and code submitted to our GitHub community forums are publicly visible. Do not share confidential business secrets or private personal data.
50. User-Generated Content
You retain ownership of any custom code or issue submissions you create. By submitting contributions to open-source repositories, you license them under the applicable repository license.
51. Artificial Intelligence Features
If you use AI coding assistants with our Agent Skills or registry endpoints, your interaction with those AI providers is governed by the terms and privacy practices of those respective AI services.
52. Automated Decision-Making
We do not subject users to automated profiling or decision-making that produces legal or similarly significant effects.
53. Do Not Track Signals
Because our website does not engage in cross-site tracking or third-party behavioral profiling, your browsing privacy is respected by default.
54. Global Privacy Control
Where required by law, we recognize legally valid opt-out preference signals such as Global Privacy Control (GPC).
55. Do Not Sell or Share
We do not sell personal information or share personal information for cross-context behavioral advertising under California or other US state privacy laws.
56. Data Minimization
We intentionally restrict data collection to the minimum technical information required to maintain website availability, deliver registry components, and protect system security.
57. Aggregated and De-Identified Information
We may generate anonymous, de-identified metrics (such as aggregate page view counts or component popularity) to guide future component engineering and performance tuning.
58. Enterprise and Business Customers
Enterprise customers with dedicated service contracts may execute customized Data Processing Agreements (DPAs) governing specific operational requirements.
59. Data Processing Agreements
Where required by GDPR or other data protection legislation, we make DPAs available to enterprise clients detailing security safeguards and processing instructions.
60. Subprocessors
We utilize reputable cloud infrastructure providers (such as GitHub, Vercel, and Cloudflare) who adhere to strict data security and privacy compliance standards.
61. Government Requests
We review any governmental or law enforcement data requests rigorously and disclose technical information only when compelled by valid, binding legal process.
62. Legal Claims and Disputes
We may retain correspondence or technical logs when reasonably necessary to defend against legal claims, enforce our Terms of Service, or comply with court orders.
63. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect new features, operational adjustments, or legal changes. Revisions are published on this page with an updated timestamp.
64. Privacy Policy Version History
Version 1.0 published on 23 September 2026. Comprehensive initial release covering developer documentation, registry endpoints, and client-side execution.
65. Contact Us
For privacy questions or rights requests, contact DevClub at privacy@devclub.co or via our website at https://devclub.co.
66. Grievance Redressal
For privacy grievances or complaints under applicable legislation, contact our designated Grievance Officer at grievance@devclub.co.
67. Security Contact
Report security vulnerabilities privately to security@devclub.co before coordinated disclosure.
68. Data Protection Officer
For inquiries regarding data protection oversight, direct communications to our privacy team at privacy@devclub.co.
69. Controller Information
DevClub acts as the data controller for personal information processed directly through the devclub.co website and public documentation channels.
70. Processor Information
Where hosted services are provided to enterprise clients under contract, DevClub acts as a processor subject to agreed contractual terms.
71. Compliance With Applicable Laws
Our data practices are engineered to align with global standards including GDPR, UK GDPR, CCPA/CPRA, and India's DPDP framework.
72. Jurisdiction-Specific Notices
Where localized laws require specific disclosures, this Policy is supplemented by applicable regional statutory protections.
73. Data Protection by Design
We embed privacy by design principles into our software architecture by minimizing default data collection, keeping component code client-side, and avoiding third-party ad tracking.
74. Privacy and Component Architecture
Because our components are distributed as uncompiled TypeScript source code, you have full visibility into state and prop flows. An Input or Accordion component does not send form data to our servers.
75. Browser Storage
Our website utilizes browser local storage solely for non-sensitive UI preferences (such as dark mode theme selection). Do not store unencrypted secrets in browser storage.
76. Authentication Tokens
Developers integrating authentication with their applications should ensure tokens are securely handled using HTTP-only cookies and proper CORS headers.
77. Source Maps, Builds, and Deployment Artifacts
Review production build artifacts and source maps prior to deployment to ensure internal development secrets or staging URLs are not exposed.
78. Error Messages and Public Issues
Before submitting public bug reports or issues, redact all private customer information, access tokens, and sensitive system logs.
79. Children and Educational Applications
Developers building software for educational institutions or minors must independently implement child privacy safeguards under COPPA, FERPA, or GDPR-K.
80. Accessibility and Privacy
Our accessibility features (ARIA attributes, keyboard navigation) operate natively in the browser without collecting assistive technology metadata.
81. Enterprise Security Requirements
Enterprise clients requiring specialized security reviews, custom audit logs, or dedicated compliance documentation should contact enterprise@devclub.co.
82. Data Residency
Public documentation and registry APIs are distributed globally via high-speed edge networks to optimize latency.
83. Data Export
Users may request copies of any personal correspondence retained by our support team by submitting a verified request to privacy@devclub.co.
84. Account Closure
If user accounts are provided in future versions, closing an account will delete eligible personal data while preserving immutable open-source git history.
85. No Guarantee of Absolute Security
While we implement robust safeguards, no digital system is impenetrable. Maintain strong operational security and report suspected bugs responsibly.
86. Third-Party Hosting and Infrastructure
We host our services on reputable cloud providers with ISO/IEC 27001 and SOC 2 Type II certifications.
87. Open Web and Public Information
Information voluntarily published on public GitHub pull requests, commits, or community discussions is accessible to the global open-source community.
88. Changes in Ownership
In the event of a merger, acquisition, or restructuring, information will continue to be governed by the protections outlined in this Privacy Policy.
89. Severability
If any provision of this Privacy Policy is found unenforceable, the remaining provisions continue in full force and effect.
90. Interpretation
Section titles are for organizational convenience only and do not affect legal interpretation.
91. Entire Privacy Notice
This Privacy Policy constitutes the complete privacy disclosure for DevClub UI and its associated public registry endpoints.
92. Implementation Checklist
Before deploying applications built with DevClub UI, verify that dependency licenses, cookie notices, and data handling workflows align with your product requirements.
93. Privacy Principles
We operate by transparency, data minimization, purpose limitation, strong technical security, user control, and privacy by design across all components.
94. Final Notice
This Privacy Policy establishes our commitment to privacy. Component source code is open, inspectable, and runs client-side under your control.