← Back to 9Team.dev
Privacy Policy
Last updated: August 4, 2026
At 9Team.dev, we take your privacy seriously. This Privacy Policy explains how we collect, use, and protect your personal information.
1. Information We Collect
Account Information
- Email address (optional during registration)
- Username
- Password (encrypted)
- Subscription plan and payment status
Usage Data
- Project prompts and descriptions you submit
- Generated code and application builds
- API usage and credit consumption
- Session data (login times, IP addresses)
- Device and browser information
Payment Information
- Processed securely through Stripe
- We do not store full credit card numbers
- We store Stripe customer IDs and subscription data
API Keys (BYOK Plan)
- Encrypted at rest using AES-256
- Used only for your builds, never shared
- You can delete them anytime
2. How We Use Your Information
- Service Delivery: Generate applications, process builds, manage credits
- Account Management: Authentication, subscription billing, support
- Communication: Service updates, billing notifications, security alerts
- Improvement: Analyze usage patterns, optimize AI performance
- Legal Compliance: Prevent fraud, enforce terms, respond to legal requests
3. Information Sharing
We share information only with:
Service Providers (Subprocessors)
We use the following third parties to run the service. They act as data processors under GDPR Art. 28 and CCPA:
| Subprocessor |
Purpose |
Data |
Region |
| Stripe, Inc. | Payment processing, billing portal | Name, email, billing address, payment method | US / EU (DPF) |
| OpenAI, L.L.C. | LLM inference for Pro-Managed builds | Prompt text (no PII by policy) | US |
| Anthropic, PBC | LLM inference for Pro-Managed builds | Prompt text (no PII by policy) | US |
| Cloud infrastructure provider | Application hosting, Postgres database, session storage | All user data at rest | EU (Frankfurt) / US (as configured) |
| Sentry (if enabled) | Error monitoring | Stack traces, user ID (email/password redacted) | US / EU |
Data Processing Addendum: Business customers who need a signed DPA (e.g., for EU GDPR / UK GDPR compliance) can request one by emailing privacy@9team.dev. We use the EU Standard Contractual Clauses (2021/914) for transfers outside the EEA.
BYOK plans: When you supply your own OpenAI/Anthropic key, your prompts are sent directly to that provider under your contract with them; we act only as a passthrough and do not store the responses beyond the build record.
Legal Requirements
- Court orders or subpoenas
- Preventing fraud or illegal activity
- Protecting our rights and safety
We never sell your personal data to third parties.
4. Data Retention
- Active accounts: Data retained while account is active
- Deleted accounts: Personal data and projects are deleted immediately when you confirm account deletion in Settings
- Billing records: Kept for 7 years (tax compliance)
- Session logs: Deleted after 90 days
5. Your Rights (GDPR Compliance)
If you're in the EU/EEA, you have the right to:
- Access: Request a copy of your data
- Rectification: Correct inaccurate information
- Erasure: Delete your account and data
- Portability: Export your data in JSON format from Settings → Account (or GET /api/user/export-my-data while signed in)
- Object: Opt out of marketing communications
- Restrict: Limit processing of your data
Email privacy@9team.dev to exercise these rights.
6. Security Measures
- HTTPS encryption for all data transmission
- Bcrypt password hashing (never stored in plain text)
- AES-256 encryption for API keys
- Regular security audits and updates
- Rate limiting to prevent abuse
- Session cookies expire after 7 days
7. Cookies and Tracking
- Essential cookies: Session management (required)
- Analytics: Google Analytics (anonymized IP)
- No advertising cookies
You can disable non-essential cookies in your browser settings.
8. Third-Party AI Providers
When you use our service:
- BYOK Plan: Your prompts go directly to OpenAI/Claude via your API key
- Pro Plan: Prompts are sent through our account to AI providers
- Review provider privacy policies: OpenAI, Anthropic
- We do not control how AI providers use training data
9. Children's Privacy
Our service is not intended for users under 18. We do not knowingly collect data from minors. If we discover such data, we will delete it immediately.
10. International Data Transfers
Your data may be processed in countries outside your own. We ensure adequate protections through:
- Standard Contractual Clauses (EU-approved)
- GDPR-compliant data processors
- Secure data centers with certifications
11. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you via:
- Email (for material changes)
- In-app notification
- Updated "Last modified" date
12. Data Breach Notification
In the event of a security breach affecting your data, we will:
- Notify affected users within 72 hours
- Describe the nature of the breach
- Explain steps taken to mitigate harm
- Provide guidance on protective measures
13. Contact Us
For privacy-related questions or to exercise your rights:
Email: privacy@9team.dev
Data Protection Officer: dpo@9team.dev
Support: support@9team.dev
14. California Privacy Rights (CCPA)
If you're a California resident, you have additional rights:
- Know what personal information we collect
- Delete personal information
- Opt out of the sale of personal information (we don't sell data)
- Non-discrimination for exercising your rights
By using 9Team.dev, you consent to the collection and use of information as described in this Privacy Policy.