Privacy Policy

Last updated 20 August 2026

Draft — pending legal review. This document reflects how DevClimate is built today and is accurate as a technical description, but it has not been reviewed by counsel and is not yet a binding agreement. It must be reviewed before DevClimate is offered outside DevCanopy.

Who we are

DevClimate is operated by DevCanopy LLC. This policy covers devclimate.com and the DevClimate application.

The two kinds of data, and why the distinction matters

DevClimate holds two categories of data that are deliberately never joined, and almost everything else in this policy follows from that separation.

Account and roster data is identifiable. It is the name, email address, team, role, and optional level and start date of each person in an organization, plus the identity record of anyone who signs in.

Survey responses are not identifiable. A stored response records the survey cycle, the responding person's team, the answers themselves, and a one-way HMAC derived from their invitation. It does not record who submitted it — there is no such column. The HMAC exists only so a second submission from the same invitation can be rejected, and it cannot be reversed to recover a person.

What we collect

  • Name, email address, and organization for anyone who creates an account.
  • The roster an administrator imports: names, email addresses, teams, and optional level and tenure start date.
  • Slack workspace and user identifiers, if an organization connects Slack for survey delivery.
  • Survey answers, stored without any link to the person who gave them.
  • Whether an invited person has responded to a cycle — a single boolean, kept apart from the answers, used for reminders and response rates.
  • Marketing-communication preference, where someone has opted in.

What administrators can and cannot see

Administrators see aggregate results per team per cycle, and only when that team returned at least the organization's anonymity threshold of responses — five by default. Below the threshold, scores and open-ended text are withheld entirely rather than shown in a degraded form.

Administrators see a response rate. They do not see, and the product provides no way to derive, which individuals responded or what any individual said. Open-ended answers are returned in randomized order to remove ordering as a signal.

How we use data

Account and roster data is used to operate the service: authenticating administrators, delivering surveys, and sending reminders. Survey responses are used to compute the aggregates an organization sees. We do not sell data, and we do not use one organization's data to build a product for another.

Marketing email is sent only to people who explicitly opted in, and every message carries an unsubscribe link.

Processors

DevClimate runs on Railway (hosting and managed PostgreSQL) and uses Clerk for authentication, Resend for transactional and reminder email, and the Slack API for delivery into workspaces that have connected it. Slack access tokens are encrypted before storage.

Retention and deletion

Removing a person from an organization deactivates their record rather than deleting the row, because historical response rates reference it. A deactivated person is immediately excluded from every future survey and loses all access.

Deleting an organization deletes its account and roster data. Its survey responses are already unlinked from any individual and are deleted along with their cycles.

Your rights

You may request access to, correction of, or deletion of your account and roster data by contacting us. Individual survey responses are a genuine exception: because nothing records who submitted a response, we cannot locate one person's answers to export or delete them, and building the ability to do so would destroy the guarantee the product exists to make.

Contact

Questions about this policy: privacy@devclimate.com.