Privacy Policy

Last updated October 7, 2026

The short version

  • Your skills and memories are private. Only you, and the AI clients you approve, can read them.
  • We do not sell your data, show ads, run third-party analytics or use your content to train AI models.
  • You can export everything as JSON at any time, delete any item, and revoke any client immediately.

This policy explains how DexDev (“DexDev”, “we”, “us”) handles information when you use the DexDev website, its MCP endpoint and the skills marketplace (together, the “Service”).

Information we collect

  • Account. Your email address, used to sign you in with a one-time link or code. If you choose Google sign-in, we receive the basic profile Google shares (email address and, where provided, name and profile picture).
  • Profile. The display name and language preference you set in Settings.
  • Your content. Skills, memories, projects and the files bundled with them (scripts, references, assets), together with their version history, so you can review and restore earlier versions.
  • Connected clients. For each AI client you approve: its OAuth client ID and name, the permissions you granted, and when it was granted, last used or revoked.
  • Access log. Each time a client reads or writes your library we record the operation, the client, the item and version it touched, the result and the time. The log does not copy your content.
  • Usage counters. Short-lived request counters per account and client for rate limiting, and a daily count of in-app assistant messages for plan limits.
  • Billing. If you subscribe, Stripe processes the payment. We store your Stripe customer ID and subscription status (plan, period, cancellation). We never receive or store full card numbers.
  • Marketplace. Listings you publish and their files, purchases and the resulting access, and reports you file about a listing. If you sell, Stripe collects the identity and payout details it requires through Stripe Connect; we store only your connected account ID and whether charges and payouts are enabled.
  • Assistant conversations. When you use the in-app assistant, your messages and the library items it reads to answer are sent to our AI model provider to generate the reply. The conversation is kept in your browser tab, not in our database.
  • Technical data. Our hosting and database providers process standard request data such as IP address, browser user agent and timestamps to deliver and secure the Service.

How we use it

We use this information only to:

  • provide the Service: store your library and serve it to you and to the clients you approve;
  • authenticate you and enforce the permissions you grant each client;
  • process subscriptions, marketplace sales and seller payouts;
  • prevent abuse, enforce plan limits, moderate reported marketplace listings and keep the Service secure;
  • send the sign-in emails you request and messages about your account or billing; and
  • comply with legal obligations.

We do not sell or rent personal information, use it for advertising, or use your content to train AI models.

AI clients you connect

When you connect an AI client such as Claude, ChatGPT, Codex or Cursor, you choose on a consent page what it may do: read skills, read memories or write memories. Data that a client reads is then handled by that client’s provider under its own privacy policy, which we do not control. Memories a client writes stay pending until you confirm them. You can revoke a client at any time in Settings, and it loses access immediately.

Service providers

We share data only with providers that process it on our behalf to run the Service:

  • Supabase. Database, authentication, OAuth server and file storage.
  • Vercel. Website and API hosting.
  • Stripe. Subscription payments, marketplace checkout and seller payouts.
  • MiniMax. Generates in-app assistant replies, and only receives data when you use the assistant.
  • Google. Sign-in, only if you choose to sign in with Google.

We may also disclose information if required by law, to protect the rights and safety of our users or the Service, or as part of a merger or transfer of the Service, in which case this policy continues to apply to your information.

What is public

Everything in your library is private by default. When you publish a skill to the marketplace, the listing (title, description, price and the published skill files) and your display name as the seller become visible to anyone. Buyers receive a copy of the published files. If you have not set a display name, listings show “DexDev creator” instead.

Cookies and browser storage

We use only cookies and browser storage that the Service needs to work: Supabase session cookies that keep you signed in, a local setting that remembers your light or dark theme, and session storage that keeps the current assistant conversation until you close the tab. We do not use advertising or cross-site tracking cookies.

Retention and deletion

  • We keep your account and content for as long as your account exists.
  • When you delete a skill, memory or project, it is permanently removed together with its version history and bundled files.
  • Rate-limit counters are discarded after one day.
  • Billing and transaction records are kept as long as tax and accounting law requires.
  • You can delete your entire account in Settings › Profile. This immediately and permanently deletes your account, content, stored files, connected clients and marketplace listings, and cancels an active subscription. Purchase records are kept without your account as long as the law requires. Skills that buyers already installed stay in their libraries.

Your choices and rights

You can, at any time:

  • view and edit your profile, skills and memories;
  • export your whole account as JSON, or a single skill as Markdown or ZIP, from Settings;
  • delete individual items, revoke any connected client, or delete your whole account from Settings; and
  • ask us to access, correct, delete or port your personal information, or object to or restrict its processing.

Depending on where you live (for example the EU, UK or California), you may have these rights by law. We honor them for every user and will not treat you differently for using them. You may also complain to your local data protection authority.

Security

Data is encrypted in transit. Access to your library is enforced in the database: each request is tied to a verified account, and each client is limited to the permissions you granted it. Server credentials are never exposed to the browser. No system is perfectly secure, so please keep your email account secure, since it is how you sign in.

Where data is processed

The Service is hosted in the United States. If you use it from elsewhere, your information is transferred to and processed in the United States and in the other countries where our providers operate.

Children

DexDev is not directed to children under 13 (or the minimum age of digital consent where you live), and we do not knowingly collect their personal information. If you believe a child has given us information, contact us and we will delete it.

Changes to this policy

If we change this policy, we will update the date at the top of this page. If a change materially affects how we use your information, we will also announce it in the Service.

Contact

For questions about this policy or to exercise your rights, contact us through derekdylu.com.