$deals.dev

Legal

Privacy policy

Last updated: June 11, 2026

The short version

deals.dev shows sponsored lines in coding tools and pays developers for verified attention. To do that we need very little: an email address, device API keys, and a log of ad events. We never see your code, your prompts, your files, or what you are working on — the client integrations send only an API key and your platform name (e.g. macOS) when fetching an ad.

What we collect

Account data. Your email address, used for passwordless sign-in links and transactional notifications (campaign status, payouts).

Device data. A name you choose for each device, the agent type (Claude Code, Codex, VS Code, Cursor, terminal), and the operating system reported by the client.

Ad events. Impressions and clicks: which campaign was served to which device, when, and the amounts charged and credited. This is the ledger your earnings are built on, so it is kept accurate and auditable.

Payment data. Payments and payouts are processed by Stripe. We never store card numbers or bank details — we keep only Stripe identifiers and amounts.

What we never collect

Your source code, prompts, transcripts, file paths, project names, keystrokes, or any content of your coding sessions. The integrations are open source — you can verify exactly what leaves your machine.

How we use data

To serve and verify ads, compute and pay your earnings, bill advertisers, prevent fraud (rate limiting, click validation), and send transactional email. We do not sell personal data, and we do not build advertising profiles of developers — targeting is by tool and operating system only, never by identity or behavior.

Cookies

We use a session cookie for authentication after you sign in. No third-party advertising or analytics cookies are set on the public site.

Data sharing

Service providers we rely on: Stripe (payments and payouts), Neon (database hosting), Vercel (application hosting), Resend (transactional email), and Upstash (rate limiting). Each receives only what it needs to perform its function. Advertisers see aggregate campaign statistics — never individual developers.

Retention and deletion

Ledger and ad-event records are retained for as long as your account exists, because they back real money owed to you. You can revoke device API keys at any time from your dashboard. To delete your account and associated data, email us — we will process the request within 30 days, subject to records we must keep for financial compliance.

Your rights

Depending on where you live (including under GDPR and CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to processing. Contact us to exercise any of these rights.

Contact

Questions about this policy: privacy@deals.dev. See also our terms of service.