Back to About

Privacy Policy

Last updated: November 16, 2025

1. Introduction

The AI DevOps Engineer ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at aidevopsengineer.com and use our services.

2. Information We Collect

2.1 Personal Information

We collect information that you provide directly to us:

  • Account Information: First name, last name, email address, and password when you create an account
  • Profile Information: Your profile details and preferences
  • Payment Information: Billing details processed securely through Stripe (we do not store credit card information)
  • Newsletter Subscription: Email address if you subscribe to our newsletter

2.2 OAuth Authentication

When you sign in using GitHub or Google OAuth:

  • Name and email address from your OAuth provider
  • Profile information as permitted by the OAuth provider
  • We do not access or store your OAuth provider passwords

2.3 Automatically Collected Information

We automatically collect certain information about your device and usage:

  • Login History: IP address, user agent, and login timestamps
  • Usage Data: Pages viewed, time spent on pages, and navigation patterns
  • Device Information: Browser type, operating system, and device identifiers

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Account Management: To create and maintain your account, authenticate users, and manage subscriptions
  • Service Delivery: To provide access to content based on your membership tier (Free, Member, or Engineer)
  • Payment Processing: To process payments and manage billing through our payment processor, Stripe
  • Communications: To send newsletters, updates, and important service announcements
  • Security: To monitor and prevent fraudulent activity, unauthorized access, and other illegal activities
  • Improvement: To analyze usage patterns and improve our content and services
  • Legal Compliance: To comply with legal obligations and enforce our terms of service

4. Information Sharing and Disclosure

4.1 Third-Party Service Providers

We share your information with trusted third-party service providers who assist us in operating our website:

  • Stripe: For payment processing and subscription management. Stripe's privacy policy: https://stripe.com/privacy
  • OAuth Providers (GitHub, Google): For authentication services
  • Email Service Provider: For sending newsletters and transactional emails
  • Hosting Provider: For website hosting and infrastructure

4.2 Method of Disclosure

Information is shared with third parties through:

  • API Integration: Secure API connections with encryption in transit
  • OAuth Protocol: Industry-standard OAuth 2.0 authentication
  • Encrypted Webhooks: Verified and encrypted webhook communications

4.3 Legal Requirements

We may disclose your information if required by law or in response to:

  • Valid legal process (subpoenas, court orders)
  • Requests from law enforcement or government authorities
  • Protection of our rights, property, or safety
  • Emergency situations involving potential harm

4.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you via email or prominent notice on our website before your information is transferred and becomes subject to a different privacy policy.

5. Security Practices

We implement comprehensive security measures to protect your information:

5.1 Technical Security

  • Encryption: All data transmitted between your browser and our servers is encrypted using TLS/SSL
  • Password Security: Passwords are hashed using bcrypt with salt before storage
  • Database Security: PostgreSQL database with restricted access and encrypted connections
  • Payment Security: We use Stripe for payment processing; we never store credit card information
  • OAuth Security: Secure token-based authentication with industry-standard OAuth 2.0

5.2 Administrative Security

  • Access Control: Limited access to personal information on a need-to-know basis
  • Monitoring: Regular security audits and monitoring for suspicious activity
  • Login Tracking: We maintain login history to detect and prevent unauthorized access
  • Account Suspension: Ability to suspend accounts showing suspicious activity

5.3 Data Retention

We retain your personal information for as long as your account is active or as needed to provide services. Upon account deletion, we retain certain information as required by law or for legitimate business purposes (e.g., fraud prevention, financial records).

6. Your Rights and Choices

6.1 Account Information

You have the right to:

  • Access and update your account information at any time
  • Request a copy of the personal data we hold about you
  • Request correction of inaccurate information
  • Request deletion of your account and associated data

6.2 Communications

  • Unsubscribe from newsletters at any time using the link in emails
  • Opt out of non-essential communications
  • You will continue to receive essential service-related communications

6.3 Cookies and Tracking

We use essential cookies for authentication and site functionality. You can control cookies through your browser settings, but disabling cookies may affect site functionality.

7. Children's Privacy

Our services are not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If we discover that we have collected information from a child under 13, we will promptly delete such information.

8. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country. We take appropriate steps to ensure your information receives adequate protection wherever it is processed.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the updated policy on this page
  • Updating the "Last updated" date at the top of this policy
  • Sending an email notification for significant changes

Your continued use of our services after such changes constitutes acceptance of the updated policy.

10. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

11. GDPR Compliance (European Users)

If you are located in the European Economic Area (EEA), you have additional rights under GDPR:

  • Right to Access: Obtain confirmation of data processing and access to your data
  • Right to Rectification: Correct inaccurate personal data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent for data processing at any time

To exercise these rights, please contact us at [email protected]

12. California Privacy Rights (CCPA)

California residents have specific rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: Request information about data collection and sharing practices
  • Right to Delete: Request deletion of personal information
  • Right to Opt-Out: Opt out of the sale of personal information (we do not sell personal information)
  • Right to Non-Discrimination: Equal service regardless of privacy right exercise

This privacy policy is effective as of November 16, 2025, and will remain in effect except with respect to any changes in its provisions in the future, which will be in effect immediately after being posted on this page.