Draft for review. These documents are not yet in force.
Privacy and cookies
DevNavo processes your development projects on your Mac. This notice also covers the website, licence service, updates, purchases and support.
Version: 2026-10-06
1. Controller and contact
Heinrich Systems
Proprietor: Eugen Heinrich
Neuschellstr. 20
6314 Unterägeri
Switzerland
E-Mail: [email protected]
For privacy requests, email [email protected]. We request only the information needed to identify the request and protect against unauthorised disclosure.
Swiss data protection law applies. Where we offer goods or services to people in the EU/EEA or the United Kingdom and the relevant conditions are met, the GDPR or UK GDPR also applies.
2. Local projects and external connections
Local project management data, logs, test emails and Inspector recordings are not routinely uploaded to Heinrich Systems. The licence service does not need source code or project logs. The app does not send general usage analytics to us.
This does not eliminate every network connection: licensing, the trial, downloads, updates, package sources and integrations you enable can contact external services. Project code may make its own network requests. You or your organisation remain responsible for your projects and their data.
Optional integrations connect to the chosen provider using your credentials. That provider's privacy terms also apply. Support receives project content only if you send it yourself. Check exports for credentials and other people's data before sharing them.
3. Website and regional prices
Page requests involve technical connection data, including IP address, requested address, time, browser information and response status. This supports delivery, troubleshooting and defence against attacks. The public service is delivered through Cloudflare.
Marketing and purchase pages call our region endpoint to display regional prices. Cloudflare derives the country from the connection; only the country code and currency are returned to the website. We do not request precise device location or store the selection in a cookie or browser profile. Unknown regions receive USD. This selection does not determine your billing country or legal rights. Paddle's checkout provides the binding price information.
With your consent, we analyse the use of our marketing pages and store permitted campaign information for later purchase attribution. The following section explains this optional processing.
4. Cookies and embedded services
Optional analytics: We use Google Analytics 4 on suitable marketing pages when you explicitly consent. Before consent or after refusal, we load no Google tags and send no cookieless analytics pings. Purchase and licence pages load no Google Analytics script, even with existing consent. This follows Basic Consent Mode, whose behaviour Google explains here.
We analyse sanitised page views and deliberate download or purchase clicks. This helps us understand which pages and campaigns generate interest in DevNavo. After consent, pseudonymous browser identifiers, technical connection and device data, and permitted campaign information are processed. Campaign fields are utm_source, utm_medium, utm_campaign and utm_content. Campaign values must not contain personal information or credentials. We send page addresses without the original query parameters; raw referrers, email addresses, licence keys and one-time purchase connection keys are not sent to Google. Google Signals and personalised advertising are disabled in our website integration.
We also measure visible content sections, manually selected tour steps, opened FAQ items, selected team size and defined technical error codes. Identifiers do not depend on the wording. Visibility does not prove that text was read. Free-form error messages and form contents are not sent.
Only after consent is permitted campaign information retained through checkout and passed to Paddle. This can link a campaign to a later purchase. Confirmed purchases and actual download starts are not currently sent to Google; the required server integration is not implemented. A measured click confirms neither a purchase nor a successful download. Opening checkout does not replace consent.
You may refuse analytics or withdraw consent through analytics settings available at any time. After consent, a “Turn off analytics” button also appears in the footer. One click stops analytics without another confirmation. The website remains usable without consent. Withdrawal stops future analytics and removes our campaign information and analytics cookies from the browser. It does not automatically delete data already sent to Google. Previously given consent does not cover new purposes.
We do not load advertising pixels, external fonts or embedded social networks. Navigation, language switching and the product tour do not need persistent browser storage.
Paddle loads only when you explicitly open the checkout on the purchase page. Connection data is then transmitted to Paddle, along with the country, language, seat count and, where present, the one-time key used to connect an app purchase. That key supports licence activation, not advertising. Paddle may use its own cookies or similar technologies for payment, session management and fraud prevention. See Paddle's privacy information.
Cloudflare may use technically necessary security cookies when relevant security features are enabled. Enabled features must match the actual deployment; Cloudflare's cookie information explains them.
Protected preview and staging addresses use Cloudflare Access. Sign-in processes the permitted email address and a one-time code sent by email. A technically necessary session cookie keeps you signed in. This restriction does not apply to the public product preview on devnavo.com.
Opening checkout is not consent to optional advertising or analytics.
5. Licensing, trial and transactional email
Purchase and licence: Paddle provides the purchase email address, language, customer, transaction and subscription identifiers, seat count, amounts, currency, term and payment status. We use these to issue the licence key and handle renewals, cancellations and refunds. The licence service does not need full card or banking credentials.
Devices: Activation and synchronisation process the licence key, a derived device identifier, device name, app version and timestamps. The identifier and name are stored for device management. These identifiers are pseudonymous, not automatically anonymous. Authorised team members sharing a key can see the shared device list. Prefer device names without additional personal information.
First 14 days of Pro and subsequent Free access: The service stores a hash of the device identifier and the first and last contact to administer the once-per-device 14 days of Pro. A hash can still distinguish a device. Subsequent Free access does not trigger a paid purchase. Its conditions and the rules for organisations appear in the licence terms.
App purchase: A random one-time key connects the purchase to the app. It may appear in the purchase URL and Paddle's order data. Our licence service stores its hash. It is valid for 24 hours after creation in the service and can be redeemed once. Do not share this link.
Key resend: The submitted email address is processed to locate the licence. The response does not reveal whether a matching licence exists. Keys are sent only to the stored purchase address.
Abuse prevention: Cloudflare processes the IP address for short-term request limits. Additional counters in our database use hashes of IP or email addresses. These hashes are not equivalent to anonymous data.
Transactional email: Postmark sends licence keys and necessary licence, payment or expiry notices. These are not newsletters. Recipient details, subject, message content and delivery information are processed for this purpose.
6. Retention
Optional analytics: Your choice, including refusal, is stored in the browser for no more than 30 days. Optional campaign information is stored only after consent, also for no more than 30 days. Google Analytics cookies set by our integration expire within 30 days without automatic extension. These browser periods do not govern data already sent to Google.
Our Google property is configured to retain the adjustable user and event data for two months. New activity does not reset the period. Google states that changes take effect after 24 hours. Aggregate standard reports are not covered by this setting. Google explains these retention limits.
The following periods apply to the licence service's regular cleanup, which runs daily. Failed runs must be repeated.
- One year after a licence ends, its purchase email and key are replaced and associated devices and device releases are deleted. This does not fully anonymise payment references and transaction records.
- Trial records are deleted 730 days after their last contact.
- Purchase connection records are deleted seven days after their 24-hour validity expires.
- Paddle integration event records are deleted after 90 days. This does not cover the separate transaction records.
- Request-limit counters in our database are cleaned up after two days.
- Successfully sent email content is removed from our sending queue after 30 days. Recipient and delivery metadata and failed messages may remain longer; they must be cleaned up when their purpose is complete or with the related licence.
- Weekly database backups are retained for up to twelve weeks. Deletion from the active database does not immediately remove older backups. Deletions must be reapplied after restoration.
Support correspondence is kept as long as needed to handle and document the matter. Records required for accounting or legal claims may be retained until applicable statutory retention or limitation periods expire. These exceptions do not permit indefinite reuse for unrelated purposes.
Infrastructure logs, update delivery and copies held by email providers are also subject to actual product settings and provider retention rules. In particular, the 30-day period for our own sending queue is not a promise that Postmark deletes all copies after 30 days.
7. Recipients and international processing
Google Analytics: The published European Analytics terms name Google Ireland Limited, Ireland, as the provider. Analytics may involve processing by Google LLC in the United States and other subprocessors. Google describes its processor role in its data processing terms. For international transfers, these provide for recognised transfer mechanisms or standard contractual clauses where applicable, including consideration of Swiss data protection law. Our account is set to Switzerland. The account interface confirms acceptance of the data processing terms on 6 October 2026. Further information: Google on international transfers and how Google uses information from partner websites.
- Cloudflare: Delivery and protection of the website and downloads, licence API, database and backups. Processing may take place particularly in the United States and other countries in Cloudflare's network. Privacy information, data processing terms.
- Postmark: Transactional email delivery; a US service. Privacy information, data processing terms.
- Paddle: An independently responsible reseller for ordering, payments, invoices and associated checks. The applicable entity appears at checkout. Paddle may process data in the United Kingdom, United States and elsewhere. Its purposes and retention periods are explained in Paddle's privacy information.
- Support and advisers: People handling your enquiry and, where needed, email, IT, accounting or legal providers receive the information required for their task. Authorities receive information where disclosure is legally required.
Processing on our behalf requires appropriate data protection agreements. International transfers must have an applicable adequacy basis or suitable safeguards, such as recognised standard contractual clauses with any required Swiss or UK adaptations. Relying on a US data protection framework requires it to cover the recipient and processing concerned. You may request information about the safeguards used and a copy from us.
8. Purposes and legal grounds
Under Swiss law, we observe purpose limitation, proportionality, transparency and data security; a justification must exist where required.
Where the GDPR or UK GDPR applies, providing the trial, licensing and contract-related communication rely on contract performance or pre-contractual steps (Article 6(1)(b)). For business customer contacts, security, abuse prevention, reliable operation and legal claims, we rely on legitimate interests (point (f)), balanced against your interests. Legally required retention relies on point (c). Optional analytics, including its cookies and campaign attribution, rely on your separate consent (point (a)).
Without required licence data, we cannot activate or identify a paid licence. Do not send unnecessary information. We do not sell personal data for advertising or make decisions producing legal or similarly significant effects solely through automated processing under Article 22 GDPR.
9. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction and release or portability of your data. Statutory retention and other people's legitimate rights may impose limits.
You may object to processing based on legitimate interests on grounds relating to your particular situation. You may object to direct marketing at any time. You may withdraw consent for future processing; this does not affect the lawfulness of earlier processing.
Contact [email protected]. You may also contact the Swiss FDPIC, a competent EU/EEA data protection authority or the UK ICO. Your statutory remedies remain available.
10. Changes
We update this notice to reflect actual processing and applicable requirements. Material changes will be communicated appropriately. A new notice does not replace any required consent.