Privacy

Privacy Policy

This policy covers the DEVI Digital Operations iOS application and the deviops.app website. It describes what we collect, what we deliberately do not, and where information goes when you use the app.

Effective 30 August 2026  ·  Last updated 30 August 2026

The short version

To give you an account we hold your work email address. That is the only personal information we store on a server.

The case details you enter while working stay on your device and are handed to your own email app when you choose to send something. They are not uploaded to us, and we cannot read them.

We do not use advertising, analytics, or tracking of any kind, and we do not sell or share your information with anyone.

Who we are

DEVI builds workflow software for operational teams. DEVI is the controller of the limited account information described below.

You can reach us at [email protected] with any question about this policy or about information held about you.

DEVI Digital Operations is licensed to organizations, and accounts are created by an administrator at your organization. If you are a user, that administrator decides whether you have an account and can remove it.

What we collect

Account information

When an administrator creates your account we store:

  • Your email address. It is your username and the address your sign-in details are sent to.
  • Authentication data — a securely hashed password, and, if you choose to enable a passkey, the public half of that credential. The private half never leaves your device and we never see it.
  • Sign-in records kept by our identity provider, such as the time of a sign-in attempt and whether it succeeded. These exist so that misuse of an account can be detected and investigated.

This information is held on servers in the United States, under our control. We do not store your name, phone number, badge or payroll number, photograph, or location.

Information you enter while working

The details you type into the app while working through a task — including anything you record about a device, an item, a case or an incident — are held in memory on your iPhone or iPad for as long as you are working, and are discarded when you finish or leave. They are not written to a server, and they are not sent to us.

When the app prepares a message for you, it hands that draft to your own email app. Whether it is sent, and to whom, is your decision, and the message then travels through your organization's mail system — not through ours. Because of this, the content of that message is subject to your organization's own policies and records retention, and we have no copy of it.

Preferences saved on your device

A small number of settings you choose — such as the details you would otherwise retype on every request — are saved on your device so you do not have to enter them repeatedly. They stay on the device and are removed when you sign out or delete the app.

Camera

The app can use the camera so you can scan a document and attach it to a message yourself. Scans are not read, analyzed, uploaded, or retained by us. iOS will ask your permission before the camera is used, and you can refuse or withdraw that permission at any time in iOS Settings; the rest of the app continues to work without it.

The website

deviops.app is a static site. It does not set advertising or tracking cookies and does not profile visitors. Our hosting provider processes standard server request data, including IP addresses, to serve the site securely and to mitigate abuse.

What we do not do

  • We do not sell or rent personal information, and we never have.
  • We do not share it with third parties for their own purposes.
  • We do not use it for advertising, and we do not track you across apps or websites.
  • We include no third-party analytics, advertising, or social media software in the app.
  • We do not use your information to train machine learning models.

Why we hold what we hold

We hold account information for one reason: so that only the people your organization has authorized can open the app, and so that access can be withdrawn. We rely on our legitimate interest in securing the service, and on our contract with the organization that licenses it.

Who else is involved

We keep the number of outside parties as small as we can. By category, they are:

  • Our cloud infrastructure provider — operates the servers behind the sign-in service and delivers account email. Data is held in the United States.
  • Our website and DNS provider — serves this website and routes mail sent to our contact address.
  • The mobile app platform — distributes the app and, where you have allowed it in your device settings, supplies crash and performance diagnostics. Those reports reach us from the platform under its own privacy policy; we use them only to fix faults.

These providers act on our instructions for the purposes above. They are not permitted to use your information for their own purposes. We will name the current providers to any customer or account holder who asks us at the address below.

How long we keep it

Account information is kept for as long as your account exists. When an administrator removes your account, the account record and its authentication data are deleted.

Sign-in and administrative security records are retained for up to twelve months so that suspected misuse can still be investigated, and are then deleted.

Information you entered while working is not retained by us at all, because we never receive it.

Security

Traffic between the app and our services is encrypted in transit. Passwords are never stored in readable form. Accounts cannot be created by the public: registration is closed, accounts are created only by an administrator, and only for addresses at an approved organization domain. Password resets are performed by an administrator rather than through a self-service link, and passkeys are offered so that a password need not be typed at all. Administrative activity in our cloud account is logged.

DEVI is a workflow and reference tool. It is not a system of record, and it does not make any claim of CJIS, HIPAA, or similar regulatory certification. Your organization remains responsible for how information it handles is classified, stored, and retained, including any message you choose to send from your own email account.

Your choices and rights

You can ask us to confirm what account information we hold about you, to correct it if it is wrong, or to delete it. Write to [email protected] and we will respond within 30 days.

Because your account belongs to the organization that created it, we will normally direct a deletion request to your administrator, who can remove the account directly. Deleting the app from your device removes everything saved on the device.

Depending on where you live you may have additional rights under laws such as the California Consumer Privacy Act or the GDPR, including the right to object to processing and the right to complain to a supervisory authority. We do not sell or share personal information as those terms are defined under California law, so there is nothing to opt out of, and we do not discriminate against anyone for exercising a right.

Children

DEVI Digital Operations is workplace software intended for adults acting in a professional capacity. It is not directed at children, and we do not knowingly collect information from anyone under 13.

Changes to this policy

If we change this policy we will update the date at the top of this page. If a change materially affects how we handle personal information, we will tell account holders by email before it takes effect.

Contact

Questions, requests, or concerns: [email protected].