Privacy Policy

Version 1.0 · Effective July 1, 2026

In plain language

  • We collect only what we need to run your developer identity: your name, email, GitHub username, and what you create on the service.
  • When you opt in to auto-fill your profile, your public GitHub data is sent to a third-party AI provider (currently Groq) to generate a draft.
  • Analytics are cookieless (self-hosted Umami) — no cross-site tracking, no ad profiling.
  • We never sell your data.
  • You can access, correct, or delete your data anytime: privacy@theid.dev.

1. Who is responsible

The data controller is Nathan GNANKADJA, the independent individual operating theid.dev from Benin (the "Operator"). theid.dev is a standalone personal project, not affiliated with any company.

Contact for any privacy matter: privacy@theid.dev.

2. What data we collect

2.1 Account data

  • Name and email address
  • GitHub username
  • Chosen subdomain and plan
  • Authentication identifiers (e.g. GitHub OAuth token, hashed credentials)

2.2 GitHub data (OAuth)

If you sign in with or connect GitHub, we access your public GitHub profile data: bio, public repositories, languages, pinned projects, and contribution activity. We do not access private repositories.

2.3 Payment data

Payments are processed by third-party providers (card, PayPal, or Mobile Money depending on your country). We receive confirmation of payment and billing metadata; we do not store full card numbers — these are handled by the payment provider.

2.4 Content you create

Profile content, mailbox messages, files stored in your drive, short links, and DNS records you configure.

2.5 Technical and usage data

  • Server logs (including IP address) for security and abuse prevention
  • Cookieless analytics on active subdomains (self-hosted Umami): page views, referrers, device type — aggregated, without cross-site tracking
  • On the public marketing site, your approximate location may be derived from your IP (via a third-party lookup) solely to display a local currency and payment methods on the pricing section

3. Why we use it, and our legal basis

PurposeLegal basis (GDPR Art. 6)
Provide and operate your account and servicesPerformance of a contract
AI-assisted profile generation from public GitHub dataYour consent (opt-in)
Billing and renewalPerformance of a contract / legal obligation
Abuse detection, security, fraud preventionLegitimate interest
Aggregated, cookieless analyticsLegitimate interest
Service-related communicationsPerformance of a contract
Currency/payment localization on the marketing siteLegitimate interest

We do not use your data for advertising and we never sell it.

4. AI processing

When you opt in to automated profile setup, your public GitHub data is sent to a third-party AI inference provider (currently Groq) to generate a draft profile. The specific provider and underlying model may change over time; this policy will reflect the provider in use.

  • Only public data is sent — never private repositories or your mailbox/drive.
  • The generated draft is yours to edit or discard.
  • We do not use your content to train our own models.

5. Third-party providers (sub-processors)

theid.dev relies on the following providers to deliver the service:

ProviderRole
CloudflareDNS, subdomain routing, CDN/SSL
Poste.ioEmail hosting (mailboxes)
MinIO (self-hosted, Operator's VPS)File / drive storage
GroqAI profile generation (public GitHub data)
Payment providers (card / PayPal / Mobile Money)Payment processing
Umami (self-hosted)Cookieless analytics

Each provider processes data only as needed to perform its function.

6. Data retention

  • Account and content data: kept while your account is active, and deleted within a reasonable period after account termination or subscription expiry (subject to backup rotation, see Article 8 of the Terms).
  • Billing records: retained as required by applicable accounting/tax law.
  • Server logs: kept for a limited period for security purposes.
  • Backups: rotated regularly; data in backups is purged as backups expire.

7. Your rights

You have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Port your data to another service
  • Object to or restrict certain processing
  • Withdraw consent at any time (e.g. for AI profile generation), without affecting prior processing

To exercise any of these, contact privacy@theid.dev. EU-resident Users also have the right to lodge a complaint with their national data-protection authority.

8. Data location and international transfers

theid.dev operates from Benin and uses providers that may process data outside your country (including the EU and the US). Where data of EU residents is transferred internationally, we rely on appropriate safeguards consistent with the GDPR.

9. Security

We protect data through encryption in transit, access controls, and regular backups. No system is perfectly secure, but we take reasonable measures and aim to address incidents promptly.

10. Children

theid.dev is not intended for anyone under 18. We do not knowingly collect data from minors.

11. Cookies and tracking

theid.dev uses only essential cookies required for authentication and security. Analytics are cookieless and do not track you across other sites. We do not use advertising or third-party tracking cookies.

12. Changes to this policy

We may update this policy. Material changes will be notified by email and/or on theid.dev at least 15 days before they take effect.

13. Contact

  • Data protection: privacy@theid.dev
  • General: hello@theid.dev

Controller: Nathan GNANKADJA — Benin

© 2026 theid.dev — An independent project by Nathan