Skip to main content

Privacy

What we collect, and what we do with it

Short version: we collect what you type into a form so we can reply to you, our analytics set no cookies and follow you nowhere, and we do not sell anything to anybody. The detail is below, and contact@devs-core.com reaches a person if it does not answer your question.

Last updated 1 October 2026

Who we are

Devs Core LLC is the controller of the personal data described here. We are registered in Florida at 1815 Pams Way, Geneva, FL 32732, United States, with our engineering team in Dhaka, Bangladesh. You can reach us about anything on this page at contact@devs-core.com.

This policy covers this website. Work we do under a signed agreement is governed by that agreement, which will say more about how your systems and data are handled than a public page can.

What we collect, and only when you give it

We do not ask you to create an account. These are the ways personal data reaches us.

  • When you send an enquiry. A copy is kept alongside the email we receive, so enquiries can be found in one place. The contact form takes your name, email and message; company and phone are optional. The AI Readiness Audit form additionally asks your role, rough headcount, when you want to start, which process you want reviewed and which systems it touches. All of it is what you chose to type. We also note how you found us — the campaign link or referring site, and the first page you landed on — so we know which of our work brings people in.
  • When you subscribe. Only your email address, and only if you tick the box or use the newsletter field.
  • When you use the AI Visibility Checker. The address you enter is scanned and the report kept under an unguessable, unlisted link for 90 days. If you run the AI scan, we also take your email (confirmed with a code), your brand, location, main service and any competitors you name. We use them to run the scan, to email you the report, and to follow up about it, and we record the consent you gave.
  • When you simply visit. Our host records the usual server logs — IP address, browser and device type, the page requested, the time. We also derive a short-lived key from your IP address to rate-limit the forms, so one source cannot flood them.
  • When you allow cookies. Google Analytics and Microsoft Clarity record how the site is used — pages viewed, clicks, scrolling and, in Clarity, a replay of the session with anything typed into a field masked. The LinkedIn Insight Tag lets us measure our LinkedIn campaigns and show our ads to people who have visited. In the UK, the EEA and Switzerland none of these run until you allow them; elsewhere they run by default. Either way you can change your choice at any time under Cookie settings at the foot of every page.

Why we are allowed to hold it

For enquiries and AI Visibility Checker reports: because you asked us for them, and replying to you is our legitimate interest and yours. For the newsletter: your consent, which you can withdraw in one click from any email we send. For analytics and marketing cookies: your consent, which you can change under Cookie settings. For server logs and rate limiting: our legitimate interest in keeping the site up and not being abused.

We never sell personal data and we do not use it to train models. If you allow marketing cookies, LinkedIn and Google receive the visit so we can measure our ads; they never receive what you type into our forms.

Who else sees it

We keep the list of third parties short, and each one does one job. These are the only services that touch data from this site.

Vercel
Hosting, CDN and server logs. Also Vercel Analytics and Speed Insights, which are cookie-less and record no cross-site identifier.
Google Analytics
Measures visits, sources and the actions that matter on this site (an enquiry sent, a call booked). With analytics cookies off, Google receives only cookieless signals with no identifier, under Google Consent Mode.
Microsoft Clarity
Heatmaps and session replays, only with analytics cookies allowed. Text typed into fields is masked before it leaves your browser.
LinkedIn
The LinkedIn Insight Tag, only with marketing cookies allowed: measures our LinkedIn campaigns and lets us show ads to people who visited.
Resend
Delivers your enquiry to us as an email. The notification includes your IP address and browser string alongside what you typed, which is how we tell a real enquiry from a bot.
Upstash
Stores AI Visibility Checker reports for 90 days, the details you entered to unlock the AI scan, a copy of contact and audit form enquiries so we can find them in one place, and the anonymised daily counters that stop the tool being abused. Counter keys are hashed, so no IP address or email appears in them.
Neon
A database where we keep a lasting record of contact and audit enquiries, and of AI Visibility Checker leads with their report. It does not store IP addresses.
OpenAI, Anthropic, Google and Perplexity
Through Vercel AI Gateway, they answer the questions the AI scan asks and grade the answers: your brand, location, service, competitors and text from your public website appear in those requests. Your email address is never sent to them.
Kit
Holds the newsletter list, and only for people who subscribed. Every email carries a one-click unsubscribe.
Cal.com
The booking calendar. If you open it, whatever you enter to book a call is handled by Cal.com under their own privacy policy as well as this one.
Google Workspace
Our email. Once your enquiry arrives at contact@devs-core.com it sits in a mailbox like any other message.

Cookies

Two small cookies are strictly necessary and always set: one remembers your cookie choice (six months), the other records only whether you are in a region where consent is opt-in (thirty days). Neither identifies you.

Everything else depends on your choice, which you can change at any time under Cookie settings at the foot of every page. In the UK, the EEA and Switzerland, nothing below runs until you allow it.

Staff who sign in to the private admin area also get one strictly necessary cookie that keeps them signed in for up to seven days. Visitors to the public site never receive it.

  • Analytics — Google Analytics (_ga, _ga_*) and Microsoft Clarity (_clck, _clsk): how the site is used. Up to 13 months for Google, up to a year for Clarity.
  • Marketing — LinkedIn Insight Tag (li_*, lidc, bcookie and similar): campaign measurement and audiences. Up to a year.
  • With analytics allowed we also keep, in your browser only, how you first found us for up to 90 days, so an enquiry you send later is credited to the right source.

Where your data goes

We are a US company with our engineering team in Bangladesh, so an enquiry you send may be read by a colleague in Dhaka. Our hosting and email providers operate in the United States and may process data in other countries.

If you are in the UK or the EEA, that means your data leaves your region. We rely on the standard contractual clauses our providers offer, and we keep the number of providers small precisely so that chain stays short enough to explain.

How long we keep it

Enquiries live in our email for as long as the conversation is useful — an enquiry that turns into a project stays for the life of the relationship and the period afterwards our accountants need. One that goes nowhere is deleted when we clear out old correspondence.

AI Visibility Checker reports expire after 90 days. The details entered to unlock the AI scan are kept like an enquiry, because that is what they are. Newsletter subscriptions last until you unsubscribe. Server logs are kept for the short window our host retains them, which is a matter of days, not years.

If you would rather not wait for any of that, ask us and we will delete it.

What you can ask us to do

Email contact@devs-core.com and we will act on any of the following. We do not require a form, and we will not ask why.

  • Tell you what we hold about you, and give you a copy.
  • Correct anything that is wrong.
  • Delete it.
  • Stop using it for a particular purpose, or object to our use of it altogether.
  • Unsubscribe — though the link at the bottom of any email is faster.

If we get it wrong

Tell us first and we will fix it. If you are in the UK or the EEA and we have not put it right, you have the right to complain to your national data protection authority.

Security

The site runs over HTTPS with a content security policy, form submissions are validated and rate-limited before anything touches a third-party service, and internal tooling sits behind a secret and is excluded from search engines.

We are not going to claim a certification we do not hold. We hold none. What we will say is that the controls above are real and can be checked in the page headers.

Changes

If we change how we handle personal data, we change this page and move the date at the top. We do not send a notification for a wording fix, and we are not going to pretend otherwise.