We use privacy-friendly analytics to understand how the site is used. You can opt out any time on our Do Not Sell or Share page. See our Privacy Policy.

Back to home

Privacy Policy

Last updated: July 20, 2026

Who We Are

DevSnipe is operated by Synced Systems, based in Grass Valley, California. For the purposes of data protection law, we are the data controller responsible for your personal information. If you have any questions about how we handle your data, you can reach us at support@devsnipe.com.

Information We Collect

We collect a few categories of information to provide and improve DevSnipe:

  • Account information. Your email address, provided during sign-up via magic link authentication.
  • Skill preferences. The skills and platforms you select (for example, "n8n workflows" or "Claude Code") so we can match you with relevant job postings.
  • Usage data. Which pages you visit, features you interact with, and job alerts you open. This is collected through PostHog and Google Analytics, our analytics tools.
  • Device and browser data. IP address, browser type, operating system, and general location (country/region level), collected automatically through PostHog and Google Analytics.
  • Payment information. If you purchase a paid plan, billing details are collected and processed directly by Stripe. We never see or store your credit card number.
  • AI provider API keys. If you choose to connect your own Anthropic or OpenAI API key to generate proposals, we store it encrypted at rest (AES-256-GCM) and use it only to generate proposals on your behalf. We never display the key back to you and never share it with anyone. You can remove it at any time from your dashboard settings.

Browser Extension (DevSnipe for Upwork)

DevSnipe offers an optional Chrome extension that adds a Draft with DevSnipe button to job listings on Upwork. Its purpose is to draft a proposal tailored to the job you are viewing and type it into the Upwork apply form so you can review and send it. By default the extension stops at the draft and leaves submitting to you. Advanced, opt-in link options can also have it set a Connects boost bid or submit the application automatically after a cancel window. Those actions run only when you explicitly enable them in your apply link.

  • What it reads. When you start a draft (by clicking the DevSnipe button, or by opening an apply link you have set to draft automatically), the extension identifies the job either by reading the public content of the job card you are viewing (its title, description, budget, and skill tags) or, on an apply page, by sending the job's public URL identifier to DevSnipe, which looks up that job's public listing on our servers. It also reads any screening questions on the application so it can draft answers. This content is sent to DevSnipe to generate your proposal.
  • PII redaction. When the extension reads a job card in your browser, it makes a best-effort pass to strip obvious emails and phone numbers from the description before sending it. This is heuristic, may not catch every case, and does not apply to screening-question text or to job content our servers already store.
  • Reliability signal. On Upwork pages the extension loads a small configuration file from DevSnipe so it knows where the apply-form fields are, and when you draft it sends a small technical signal about whether it could locate those fields (the platform and which field, never any page content or personal data) so we can tell when Upwork changes its layout.
  • Application outcome. When you draft an application with the extension, it records what happened to it: whether the platform confirmed the application was sent, or whether it was drafted and never sent. Alongside that it sends the number of Upwork Connects you have left, which the apply page itself displays. This is what powers the optional "Proposal submitted" webhook and your own application stats. It carries the job reference (the job's URL or public id), the URL of the resulting proposal when the platform gives it one, the outcome, and that Connects figure. It never carries your cover letter, your answers, or any message content.
  • Attachments you have uploaded. If you have set a default proposal attachment on your DevSnipe account and you use an apply link that asks for it, the extension requests that file from DevSnipe and attaches it to the application. It only ever retrieves a file you uploaded to your own account, and it does not read or upload files from your computer on its own.
  • Typing preference. Your chosen auto-fill typing speed is saved to your DevSnipe account so the same setting follows you across browsers. It is a single preference value, not a record of what you typed.
  • What it does not do. It does not read your private Upwork messages, your billing or payout details, your saved payment methods, or your contacts. Apart from the Connects figure described above it does not read your account balances. It injects into and reads only Upwork pages, and it communicates only with Upwork and DevSnipe's own servers. Your extension data is never sold and never used for advertising.
  • Sign-in storage. To keep you signed in, the extension stores your DevSnipe sign-in key and email address in your browser's local extension storage on your device. Signing out removes them.

Proposals drafted through the extension are generated by an AI provider. Paid users' proposals use the AI provider key connected to their DevSnipe account, handled exactly as described in the AI provider API keys item above. On the free tier, drafts are generated using DevSnipe's own AI provider access. In both cases the job content is processed by our AI provider (Anthropic), or, for paid users who connected their own key, by the provider they chose (Anthropic or OpenAI), as described in the Third-Party Services section below. Installing and using the extension is entirely optional.

How We Use Your Information

  • Delivering the service. Your email and skill preferences are used to find and deliver job matches relevant to you.
  • Communications. We use your email to send job alert notifications, account updates, and occasional product announcements. You can opt out of non-essential emails from your dashboard.
  • Improving DevSnipe. Usage and device data help us understand which features are most valuable and where we can improve.

Legal Basis for Processing

If you are in the EU/EEA, we process your data under the following legal bases:

  • Contract performance. Processing your account and skill data is necessary to deliver the job matching service you signed up for.
  • Consent and legitimate interests. Our product analytics (PostHog) run by default so we can understand and improve the service, and you can opt out at any time. We honor Global Privacy Control and Do Not Track browser signals automatically. Google Analytics is off by default and loads only if you affirmatively enable it. We also rely on your consent for marketing emails and non-essential communications. You can opt out or withdraw your consent at any time through our Do Not Sell or Share My Personal Information page, or your dashboard settings.

Data Storage and Security

Your data is stored in MongoDB, hosted on secure, encrypted infrastructure in the United States. We take reasonable precautions to protect your information from unauthorized access, loss, or misuse. Access to production databases is restricted to essential personnel only. All data in transit is encrypted via TLS.

Data Retention

We keep your data for as long as your account is active. If you delete your account, we remove your personal data within 30 days. Some information (like billing records) may be retained longer as required by tax and accounting laws. Analytics data is anonymized or deleted after 12 months.

Third-Party Services

We share data with a limited number of third-party services to operate DevSnipe. Each is used for a specific purpose:

  • Stripe processes payments and handles billing information directly. We never store your credit card details on our servers.
  • Resend delivers transactional emails such as magic link logins and job alert notifications.
  • PostHog provides product analytics so we can understand how people use DevSnipe and identify issues. PostHog collects usage data, device info, and IP addresses.
  • Google Analytics (provided by Google) gives us aggregate traffic and usage statistics, such as page views, sessions, and referral sources, so we can measure how the site performs. It sets cookies and collects usage and device data, including IP address. We use Google Analytics for measurement only and have not enabled Google's advertising or audience features.
  • Anthropic (Claude) powers our AI features, including job matching analysis and proposal generation. Your skill preferences and job listing data may be sent to Anthropic for processing.
  • OpenAI provides text embeddings for matching your skills to job listings. Skill profile data may be sent to OpenAI for processing.
  • Vercel hosts the DevSnipe website and application.
  • Discord is used internally to relay user feedback submissions. If you submit feedback through DevSnipe, your message and email address may be sent to Discord for internal processing.

Job listings are sourced from publicly available platforms including Upwork, Skool, LinkedIn, Indeed, and Freelancer. We do not sell your personal data for money. Because our analytics cookies may qualify as a "sale" or "sharing" under California law, you can opt out at any time on our Do Not Sell or Share My Personal Information page.

Cookies and Similar Technologies

DevSnipe uses cookies and browser local storage for the following purposes:

  • Essential cookies. Required for authentication and keeping you logged in. These cannot be disabled without breaking the service.
  • Attribution cookie. If you arrive through a creator or referral link, we set a first-party cookie named ds_attr that records which creator or referral link sent you. We use it only to credit the right creator for sending you to DevSnipe. It is not a third-party or advertising cookie, and it is not used for ad targeting.
  • Traffic source cookie. On your first visit we set a first-party cookie named ds_src recording which site referred you (for example a search engine or a social network), which page you landed on, and any campaign tags in the link you followed (the standard utm_source, utm_medium, and utm_campaign parameters). If you arrive by clicking one of our ads, the link may also carry an ad click identifier (such as Google's gclid or Meta's fbclid), which we store the same way and may use to report back to the ad platform that its ad led to a signup or purchase, so we can measure whether our advertising works. From the referring site we store its address only, never the search terms or other query information attached to it. We use this to understand which channels bring people to DevSnipe. It is a first-party cookie, and it is not used to target you with ads or shared for anyone else's advertising.
  • Analytics cookies and local storage. PostHog uses both cookies and browser local storage, and Google Analytics sets cookies, to track page views, session duration, and feature usage. These help us understand how the product is used so we can improve it. PostHog runs by default and respects Global Privacy Control and Do Not Track signals; Google Analytics loads only if you affirmatively enable it.

You can opt out of analytics at any time on our Do Not Sell or Share My Personal Information page. You can also manage or block cookies and clear local storage through your browser settings. Blocking essential cookies will prevent you from logging in. We do not set third-party advertising cookies or use any cookie to target you with ads. The only marketing-related cookies we set are the first-party ds_attr and ds_src cookies described above, used to credit creators and to measure which channels and ads bring people to DevSnipe.

Your Rights

Depending on where you live, you may have some or all of the following rights regarding your personal data:

  • Access. Request a copy of the personal data we hold about you.
  • Correction. Ask us to fix inaccurate or incomplete information.
  • Deletion. Delete your account and all associated data at any time from your dashboard, or by contacting us.
  • Data portability. Request an export of your data in a machine-readable format.
  • Restrict processing. Ask us to limit how we use your data in certain circumstances.
  • Object. Object to processing based on legitimate interest.
  • Withdraw consent. Where we rely on your consent, you can withdraw it at any time through the Do Not Sell or Share page or your dashboard settings.

To exercise any of these rights, email us at support@devsnipe.com. We will respond within one month. If you are in the EU/EEA, you also have the right to lodge a complaint with your local data protection authority.

California Privacy Rights

If you are a California resident, the California Consumer Privacy Act (CCPA) gives you additional rights:

  • Right to know. You can request details about the categories and specific pieces of personal information we have collected about you.
  • Right to delete. You can request that we delete personal information we have collected from you.
  • Right to opt out of sale or sharing. We do not sell your personal information for money. To the extent our use of analytics cookies (such as Google Analytics) qualifies as a "sale" or "sharing" under California law, you can opt out at any time on our Do Not Sell or Share My Personal Information page.
  • Right to correct. You can request that we correct inaccurate personal information we hold about you.
  • Right to non-discrimination. We will not treat you differently for exercising your privacy rights.

To make a request, email support@devsnipe.com. We will verify your identity and respond within 45 days.

International Data Transfers

DevSnipe is based in the United States, and your data is stored and processed in the US. If you are accessing DevSnipe from outside the US, your information will be transferred to and processed in the US. By using DevSnipe, you consent to this transfer. For EU/EEA users, we rely on standard contractual clauses where required to ensure your data is protected during transfer.

Children's Privacy

DevSnipe is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected data from a child under 13, we will delete it promptly. If you believe a child has provided us with personal information, please contact us at support@devsnipe.com.

Data Breach Notification

In the event of a data breach that affects your personal information, we will notify you and any applicable regulatory authorities as required by law. For EU/EEA users, we will notify the relevant supervisory authority within 72 hours of becoming aware of a qualifying breach.

Changes to This Policy

We may update this privacy policy from time to time. When we make significant changes, we will notify you via email or through a notice on the platform at least 30 days before the changes take effect. Your continued use of DevSnipe after changes take effect constitutes acceptance of the updated policy.

Contact

If you have questions about this privacy policy or how your data is handled, reach out to us at support@devsnipe.com. You can also review our Terms of Service and Refund Policy.