Dev San Short
Privacy Policy
Dev San Short privacy policy: what data we collect, how we use it, and how first-party account features are handled.
Privacy Policy
Effective date: 2026-08-31
This Privacy Policy describes how Dev San Short (the "Service", operated by DevSan) collects, uses, and shares information when you use our website, dashboard, Telegram bot, Telegram Mini Web App, and related features.
1. Who we are
Dev San Short is a URL shortener and smart-link platform. The Service is operated from Germany. You can contact us at support@devsan.de for general questions, or at privacy@devsan.de for privacy-specific requests.
2. What this service does
The Service lets registered users create short links, password-protected and expiring links, link analytics, notes, QR codes (including dynamic QR codes), QR analytics, UTM-tagged URLs, a bookmarklet, an ad-ordering system for website and Telegram bot ads, billing and invoicing, and an admin abuse-reporting workflow. It also offers a Telegram user bot, a Telegram admin bot, and a Telegram Mini Web App.
3. Information we collect
We collect information you provide directly, information collected automatically when you use the Service, and information from third-party identity providers when you choose to sign in with them.
4. Account information
When you register, we collect your name, email address, a hashed password, login status, and email verification status. Passwords are stored as one-way hashes, never as plain text.
5. Google Sign-In data
When you choose to sign in with Google or link a Google account, we may receive your Google account identifier, email address, name, profile picture URL, and email-verified flag. Google OAuth tokens are not stored by the Service unless a future feature explicitly requires it and is documented at the time of release. Google account data is used only to sign you in, create or link your Dev San Short account, secure your account, and surface basic profile fields that you have asked us to display.
We do not sell Google user data. We do not use Google user data for advertising profiling. We do not share Google user data except as needed to operate the Service, comply with applicable law, prevent abuse or fraud, or with your explicit consent.
6. Apple Sign-In data
If Apple Sign-In is enabled in a future release, Apple may provide us with an Apple user identifier, your name, and either your email address or a private relay email address if you choose Hide My Email. Apple data is used only for sign-in and account management. We honour Apple's relay-email forwarding and do not attempt to resolve the relay back to your real address.
7. Telegram bot and Mini Web App data
When you interact with our Telegram user bot, Telegram admin bot, or Telegram Mini Web App, we may store your Telegram numeric ID, username, first name, last name, language code, account-link status with your Dev San Short account, bot usage actions (such as which command you sent), and Mini Web App authentication status. We rely on Telegram's signed initData payload to verify Mini Web App sessions and do not bypass Telegram's authentication requirements.
8. Link, note, QR and analytics data
For short links, notes, and QR codes, we store the user-submitted content (destination URL, note text, QR target) and metadata required to provide the feature, such as creation time, owner, slug, expiry, password-protection state, and labels. Click and scan analytics may include counts, timestamps, anonymised referrer / user-agent / device-type summaries, and privacy-preserving hashed IP or user-agent values where implemented. We do not attempt to identify individual visitors of public short links beyond what is necessary to detect abuse.
9. Advertising and ad-order data
If you submit an ad order for website ads or Telegram bot ads, we store the order details (title, target URL, banner image if any, requested placements, dates), the message thread between you, our admins, and the system, and the order status. Admins review every order manually before activation.
10. Billing and invoice data
For paid orders, subscriptions, and manual payment workflows we store invoice records, payment status, payment-method metadata (such as the gateway used and whether the order was a bank transfer, manual transfer, preorder, or PayPal-sandbox / future PayPal-live transaction), and the time each transition happened. We do not store full credit card numbers — card-handling is delegated to the payment provider. Bank account details may be displayed only inside an authenticated dashboard or invoice context, only when an admin has configured them, and only to users who are paying that invoice.
11. Payment information
PayPal integration is currently provided in a sandbox / foundation mode. PayPal is enabled for production only when the operator explicitly switches it on; until then, no live PayPal data is processed.
12. Cookies, sessions, and local storage
We use cookies, server-side sessions, and (sparingly) browser local storage for login state, CSRF protection, language and theme preferences, security signals (such as recent login fingerprints), and basic UI state. We do not use third-party advertising cookies for behavioural retargeting on this site.
13. Security logs and abuse prevention
To prevent fraud, spam, phishing, malware, and other abuse, we retain security logs that may include hashed IP address, hashed user agent, timestamp, login outcome, and the originating route or bot command. These logs are used only for security, audit, and operations. They may be retained longer than ordinary product data when an abuse investigation is open.
14. How we use information
We use the information we collect to operate, secure, and improve the Service, to honour your settings, to prevent abuse, to communicate with you about your account and orders, to bill you for paid features, and to comply with our legal obligations.
15. DevSan One account assistant
The DevSan One assistant is a first-party, deterministic account-help feature operated by the Service. It does not send your messages to an external AI model provider. Messages and the minimum account context needed to answer them are processed by our own application backend.
Do not submit passwords, API keys, payment credentials, health information, or other secrets to the assistant. For access, deletion, or other data requests, contact Support at support@devsan.de or our privacy address at privacy@devsan.de.
16. How we share information
We share information only with: (a) infrastructure providers that host the Service or our outbound email; (b) payment providers when you choose to pay; (c) Google, Apple, or Telegram when you have opted to use those identity providers, strictly to verify your identity; (d) law-enforcement or other authorities when we are legally required to do so or to protect users from harm; and (e) other parties only with your explicit consent.
17. Google user data disclosure
Google user data we receive through Google Sign-In is used only to provide and improve the sign-in / account-linking feature you requested. We do not transfer Google user data to third parties except as needed to provide or improve the user-facing features, comply with applicable law, or as part of a merger, acquisition, or asset sale (in which case we will obtain your consent where required). We do not use Google user data to serve advertisements, including retargeting, personalised, or interest-based ads. We do not allow humans to read your Google data unless we have your explicit consent, it is needed for security (such as investigating abuse), it is needed for legal reasons, or the data is aggregated and used for internal operations in accordance with the Google API Services User Data Policy and Limited Use requirements.
18. Apple user data disclosure
If Apple Sign-In is enabled, Apple user data is used only to identify and authenticate you, and to manage your linked Dev San Short account. We do not sell Apple user data, do not use it for advertising profiling, and do not share it with third parties except as needed to operate the Service, comply with law, or with your consent.
19. Data retention
We retain account data while your account is active. When you delete it, user-authored product content and direct profile identifiers are removed or irreversibly de-identified. Accounting books and records may be retained for up to 10 years, booking vouchers including invoices for up to 8 years, and tax-relevant business correspondence or other tax documents for up to 6 years, each measured from the end of the relevant calendar year. A period can extend while a tax limitation period, legal claim, fraud case, abuse report, or security investigation is open. Security and content-safety records are normally retained for no more than 90 days, and revoked DevSan One token hashes for 7 days. Backups age out on a rolling schedule.
20. User choices and account controls
You can edit your profile, manage connected sign-in providers (such as unlinking Google) from your dashboard, change your language, manage your links and QR codes, and download or delete your own content. You can request a copy of the account data we hold about you, or request its deletion, through Support at support@devsan.de or by contacting privacy@devsan.de.
21. Deleting or disconnecting accounts
To submit permanent account deletion in DevSan One, open /app/account, request the one-time code sent to your verified email, and confirm deletion. Disconnecting the app is separate and preserves your website account and data. You can also review account-deletion information, contact Support at support@devsan.de, or email privacy@devsan.de.
22. Children's privacy
The Service is not directed to children under the age at which an individual can provide consent under their local law (for example, 13 in the United States, 16 in many EU jurisdictions). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact privacy@devsan.de and we will take appropriate steps to delete it.
23. International users
The Service is operated from Germany. By using the Service you understand that information you provide may be processed in that jurisdiction and in another jurisdiction where our hosting, outbound-email, payment, or user-selected identity provider operates, subject to applicable safeguards.
24. Security
We use industry-standard practices, including hashed passwords, CSRF protection, HTTPS for the public website, rate limiting on sensitive endpoints, abuse logging, and admin two-factor authentication. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security.
25. Changes to this policy
We may update this Privacy Policy. When we make material changes we will update the effective date above and, where appropriate, notify users in-app or by email. Continued use of the Service after a change means you accept the updated policy.
26. Contact us
Privacy requests: privacy@devsan.de
General support: support@devsan.de
Abuse reports: abuse@devsan.de
The canonical public URL of this policy is https://sh.devsan.de/privacy. The short-link host sh.devsan.de does not serve this document directly.