Skip to content
Derle
FeaturesGamesAIPlatformsProFAQ
TürkçeTRGet Derle
FeaturesGamesAIPlatformsProFAQ
← Derle

Privacy Policy

Effective date: August 18, 2026

This Privacy Policy explains how Derle (the “App,” “we,” “us,” or “our”) handles information. Derle is designed to keep ordinary project editing, builds, terminals, Git credentials, SSH credentials, and locally configured secrets on your device. Some optional connected features, especially Derle AI, require limited data to be transmitted as described below.

1. Data that stays on your device by default

Unless you deliberately use a connected feature, Derle does not upload your projects, editor buffers, terminal history, SSH keys, Git credentials, passwords, or locally stored API keys to Derle’s servers. Projects, toolchains, settings, chat history, and credentials are stored in the App’s private storage. Credentials are protected using Android’s device-backed security facilities where available and are excluded from cloud backup.

2. Derle AI and other AI providers

When you submit a request to Derle AI, the App sends the information needed to answer that request to ai.derle.app. Depending on what you include and what the assistant needs to complete the task, this may contain:

  • your prompt and recent AI conversation context;
  • project metadata, relevant source-code excerpts, selected or active files, terminal excerpts, and tool results;
  • files or images that you explicitly attach; and
  • model choice, token usage, request identifiers, and diagnostic information needed to operate quotas and prevent abuse.

Derle’s backend processes the request and may send this content to OpenRouter and to the selected model provider. Those providers may process or retain inputs and outputs under their own privacy policies and model terms. Provider practices vary by model. Review OpenRouter’s Privacy Policy, provider data policies, and the policy shown for the selected model before sending sensitive or confidential material.

Derle does not intentionally store AI prompt text, source-code content, attachments, or model responses in its backend database. They are transmitted for request processing. The App stores its chat history locally. Network infrastructure and AI providers may retain data according to their own security, abuse-prevention, and retention policies.

If you configure a custom or direct AI provider, requests go to the endpoint you select. Its terms and privacy practices apply. Custom provider credentials remain encrypted on your device and are sent only to that configured provider when required.

Do not send secrets, personal data, confidential source code, or regulated information to an AI model unless you have the right to do so and accept the selected provider’s data practices.

3. Backend account, security, quota, and subscription data

Derle uses an anonymous service identity rather than asking for your name or email address. To secure the service and enforce quotas, our Cloudflare-based backend may process and retain:

  • a random installation identifier, anonymous user identifier, device public key, authentication sessions, and hashed network identifiers used for rate limiting;
  • request counts, model identifiers, token counts, estimated cost, plan tier, quota balances, timestamps, and error/security events;
  • Google Play subscription product, purchase token, purchase status, expiry information, and an obfuscated account identifier needed to verify and recover entitlements; and
  • Google Play Integrity tokens and verdict data about app recognition, licensing, device integrity, recent request activity, package name, certificate, and app version; and
  • on Apple platforms, App Attest key identifiers, attestation receipts and public-key material, assertion counters, and verification outcomes used to confirm that requests come from a genuine App installation.

We use this information to authenticate the App, prevent fraud and replay attacks, operate free and paid quotas, verify purchases, recover entitlements after reinstall, diagnose failures, and protect the service. We do not sell it or use it for advertising.

4. Analytics, crash reporting, and advertising

The App uses:

  • Google Firebase Analytics and Crashlytics, which may collect app-instance identifiers, app version, device model, operating-system version, language, usage events, and diagnostic crash reports; and
  • Google AdMob, which may collect advertising identifiers, ad interactions, device information, and consent choices to serve and measure ads.

Google processes this data under its own policies. Where required, the App asks for advertising consent and provides privacy controls. Derle does not intentionally include project source code, terminal contents, AI prompts, credentials, or file contents in analytics events.

5. Permissions

  • Internet: downloads toolchains and packages, connects to services you choose, operates Derle AI, verifies subscriptions and integrity, and provides analytics, crash reporting, and ads.
  • Install unknown apps: lets you request installation of an APK you build or select. Android shows the system confirmation UI; Derle does not silently install or self-update.
  • Notifications and foreground service: keeps user-started terminals and builds visible and running while the App is backgrounded.
  • Wake lock: helps a user-started terminal or build continue while appropriate.

The App does not request broad storage access. Import and export use Android’s system file picker.

6. Sharing and international processing

We share data only as needed with service processors described above, including Cloudflare, OpenRouter and selected AI model providers, Google Firebase, Google Crashlytics, Google AdMob, Google Play Billing, Google Play Integrity, and Apple App Attest. These providers may process data in countries outside yours. We may also disclose information when required by law or necessary to protect users, the service, or legal rights.

We do not sell personal information.

7. Retention and deletion

Local projects, chats, settings, and toolchains remain until you delete them or uninstall the App. Backend authentication, quota, security, and subscription records are kept for as long as reasonably necessary to provide the service, prevent abuse, preserve an active entitlement, resolve disputes, and meet legal obligations. Usage counters may be aggregated or deleted when no longer needed.

You may request access to or deletion of backend information associated with your anonymous Derle installation by contacting us. We may ask for an installation identifier or other proof needed to locate the correct record. Provider-controlled information is subject to that provider’s deletion process and retention rules.

8. Security

We use HTTPS, short-lived access credentials, device-key request signatures, request limits, Play Integrity checks, encryption and access controls. No system is completely secure, and we cannot guarantee that data transmitted over the internet will never be accessed, lost, or misused.

9. Children

Derle is not directed to children under 13 or the minimum digital-consent age in their country. We do not knowingly collect personal information from children.

10. Changes

We may update this policy when features, providers, or legal requirements change. The current version and effective date will always be published at https://derle.app/privacy-policy.html.

11. Contact

For privacy questions or requests, contact emreharbutoglu12@gmail.com.

Questions about this document? Emailemreharbutoglu12@gmail.com.

Source: PRIVACY_POLICY.md

Derle

A real IDE for your phone — editor, Linux terminal, Git and an AI assistant that does the work with you.

Product

  • Features
  • AI assistant
  • Android & iOS
  • Derle Pro

Legal

  • Terms of Use
  • Privacy Policy

Contact

  • emreharbutoglu12@gmail.com
© 2026 Derle. All rights reserved.Android and Google Play are trademarks of Google LLC. App Store is a trademark of Apple Inc.