Privacy & Data Processing
This page describes how DevGhost handles contributor data in public analytics, what we collect when you submit a support ticket, who processes that data, and how to request export or deletion.
Public analytics
Public (unauthenticated) analytics pages may display public repository names and contributor names, avatars, logins, and profile links from repository or provider data. The /explore catalog contains identified publications. Pseudonymized unlisted pages at /p/… use generated labels such as “Dev A1B2” instead. Email addresses are not displayed.
Only a service administrator can publish a repository to public access. Identified publications intentionally show real public repository and contributor metadata; pseudonymized publications conceal it and are not listed in /explore. Private share links (token URLs) reveal real names only to the people the repository owner shares the link with; these pages are not indexed, but anyone holding the link can view them.
You may request access, removal, or to object to the processing of your data — email support@mail.devghost.pro.
Data processors
| Recipient | Data shared | Purpose | Retention |
|---|---|---|---|
| Resend (US) | Reporter email, subject, message body | Deliver transactional email | 30 days (Resend email log retention) |
| Telegram (Bot API) | Subject, reporter email, ticket link | Notify admin of new tickets | Retained by Telegram inside the admin chat (indefinite) |
| Vercel Blob (US/EU edge) | Files you attach to a ticket | Store ticket attachments | Until ticket is deleted or attachments are purged |
| Upstash Redis (regional) | Reporter IP (rate-limit key) | Anti-spam throttling | Up to 24 hours (TTL) |
| Hetzner Postgres (DE) | Full ticket record (subject, body, email, optional diagnostic context) | Primary support database | Retained indefinitely; deletion on request |
| Google Analytics 4 (Google, US) | Page views, device & browser, approximate location, _ga cookie ID | Aggregate site & product analytics | Up to 14 months (GA4 retention setting) |
| Yandex Metrica (Yandex, RU) | Page views, device & browser, approximate location, click maps, and Session Replay (Webvisor) recordings of on-page behavior | Aggregate site analytics & behavior insight | Retained per Yandex Metrica & Webvisor settings |
Purposes
- Resolve the issue or question you submitted
- Reproduce and debug technical problems
- Anti-spam protection on the submission endpoint
Legal basis
| Surface | Legal basis |
|---|---|
| Ticket record + rate-limit | Legitimate interest (operating a support channel and protecting the service from abuse) |
| Diagnostic context (page URL, browser, Accept-Language, JSON context) | Explicit consent (opt-in checkbox in the support form) |
Your rights
You can request export or deletion of your support tickets and related processor records. Email support@mail.devghost.pro with subject "GDPR: export" or "GDPR: delete" from the same address you used in the ticket.

