Back to Home

Privacy Policy

Last updated: August 2026

1. Overview & Commitment

At DevBox, we value your privacy. This Privacy Policy outlines how we collect, store, and protect your information when you register for an account, authenticate, and use our developer workspace tools.

2. Information We Collect

  • Account Information: When you register manually or sign in via Google OAuth, we store your name, email address, account verification status, and subscription plan (`FREE`).
  • Security Credentials: Passwords are encrypted using high-cost `bcrypt` hashing before being stored in our database. We never store plaintext passwords.
  • One-Time Passwords (OTPs): 6-digit OTP codes are stored as SHA-256 hashes with strict 5-minute expiration limits.

3. Developer Tool Input Processing

All text, JSON payloads, JWT tokens, Base64 strings, and regex patterns entered into our developer tools are processed locally in your browser runtime. We do not store or transmit your sensitive code snippets or API payloads to remote servers.

4. Data Protection & Security

We enforce HTTPS encryption across all API routes, single-use cryptographic tokens, edge middleware route protection, and generic authentication error messages to safeguard your account against unauthorized access.

5. Contact & Inquiries

If you have any questions or concerns regarding this Privacy Policy, please contact our security team.