Skip to content
Derle
FeaturesGamesAIProFAQReport
TürkçeTRGet Derle
FeaturesGamesAIProFAQReport
← Derle

Privacy Policy

Effective date: September 24, 2026

Derle is a product of Warethrust, a brand of HARBUTOĞLU YAZILIM OTO İNŞAAT EMLAK SAN. TİC. LTD. ŞTİ., a company registered in Türkiye. Contact: harbutogluyazilim@gmail.com

This Privacy Policy explains how Derle (the “App,” “we,” “us,” or “our”) handles information. Derle is designed to keep ordinary project editing, builds, terminals, Git credentials, SSH credentials, and locally configured secrets on your device. Some optional connected features, especially Derle AI, require limited data to be transmitted as described below.

1. Data that stays on your device by default

Unless you deliberately use a connected feature, Derle does not upload your projects, editor buffers, terminal history, SSH keys, Git credentials, passwords, or locally stored API keys to Derle’s servers. Projects, toolchains, settings, and chat history are stored in the App’s private storage. Credentials are protected using Android Keystore-backed facilities or Apple Keychain, as applicable. On Apple platforms, credentials use device-only Keychain protection and large toolchain resources are excluded from device backup.

2. Derle AI and other AI providers

When you submit a request to Derle AI, the App sends the information needed to answer that request to ai.derle.app. Depending on what you include and what the assistant needs to complete the task, this may contain:

  • your prompt and recent AI conversation context;
  • project metadata, relevant source-code excerpts, selected or active files, terminal excerpts, and tool results;
  • files or images that you explicitly attach; and
  • model choice, token usage, request identifiers, and diagnostic information needed to operate quotas and prevent abuse.

Derle’s backend processes the request and may send this content to OpenRouter and to the selected model provider. Those providers may process or retain inputs and outputs under their own privacy policies and model terms. Provider practices vary by model. Review OpenRouter’s Privacy Policy, provider data policies, and the policy shown for the selected model before sending sensitive or confidential material.

To operate, evaluate, and improve Derle AI, Derle stores a copy of requests answered through Derle AI and the responses returned for them. Requests that you send directly to OpenAI, Anthropic, DeepSeek, MiniMax, your own OpenRouter account, or a local or custom endpoint are not reported or copied to Derle. Your provider API key is never sent to Derle: it travels from your device only to the provider or endpoint you configured. Derle AI records are anonymous. Each one contains the conversation content sent for that request, the model that answered, and the type of project you were working in — for example Android, Flutter, React, Vue, or a static website. Each record deliberately omits your user identifier, installation identifier, session identifier, IP address, and location, so a stored exchange cannot be traced back to you, to your device, or to any other exchange you sent.

Because the assistant works inside your project, a request — and therefore the stored record of it — includes the file excerpts, source code, and tool output that were sent to the model to answer that particular request. Derle does not copy, upload, or store your project as a whole, your repository, your credentials, or your terminal history; only the content of an individual AI request and its response is kept. Derle may use these anonymous records to measure answer quality, diagnose failures, and train or fine-tune the models it offers.

The App stores its chat history locally. Network infrastructure and AI providers may also retain data according to their own security, abuse-prevention, and retention policies.

If you configure a custom or direct AI provider, requests go to the endpoint you select and are never copied to Derle. Its terms and privacy practices apply. Provider credentials remain encrypted on your device and are sent only to that configured provider when required.

Do not send secrets, personal data, confidential source code, or regulated information to an AI model unless you have the right to do so and accept the selected provider’s data practices.

Before the App sends project context to an AI provider or custom endpoint for the first time, it identifies the destination, the categories of information that may be shared, and how the information is used, then asks for explicit permission. Permission is recorded separately for each provider or custom destination and applies across projects, so the App does not ask again for every project or request. The App asks again if the destination or the disclosed data use changes materially. You can revoke all AI data-sharing permissions in Settings; the App will ask again before the next request.

3. Publishing a site to derle.link

If you have Derle Pro, you can publish a static project from the App to an address on derle.link. This is optional and happens only when you choose to publish.

When you publish, the files of that project — the HTML, CSS, JavaScript, images and fonts it contains — are uploaded to Derle and served publicly at the address you chose. A published site is public. Anyone with the address can read it, and search engines may index it. Do not publish anything you would not put on the open web, and do not include credentials, personal data, or private material in a project you publish.

Alongside the files, Derle records which account published the site, the address, the file count and total size, and the time of each publish. This is what makes it possible to enforce the Acceptable Use Policy, respond to a report about a site, and show you your own sites in the App.

Files are screened automatically at publish time, and a site that appears to contain prohibited material is refused. Anyone can report a published site, with or without a Derle account. A site that breaks the policy is taken down and its files are deleted; the record of the address and the takedown is kept, so that the address is not reissued and the decision remains auditable.

Deleting a site from the App removes its files. Publishing records are kept for as long as needed to operate the service and to handle reports and legal obligations.

Publishing is separate from everything in Section 2: a published site is public by design, while the AI records described there are anonymous and never shown to anyone.

4. Backend account, security, quota, and subscription data

Derle uses an anonymous service identity rather than asking for your name or email address. To secure the service and enforce quotas, our Cloudflare-based backend may process and retain:

  • a random installation identifier, anonymous user identifier, device public key, authentication sessions, and hashed network identifiers used for rate limiting;
  • a request activity log for Derle AI requests. Each entry records the IP address the request came from, the approximate location that Cloudflare derives from that address (country, region, and city) and the Cloudflare data center that handled it, the device model, operating-system version, App version, and user agent reported by the App, the installation and anonymous user identifiers, and the result of the request. This location is an estimate based on the IP address, not the position of your device. The App does not request location permission on Android or iOS and never reads GPS or any other device location. The log is used to investigate abuse, diagnose failed requests, and answer support questions, and each entry is deleted automatically 90 days after it is written;
  • request counts, model identifiers, token counts, estimated cost, plan tier, quota balances, timestamps, and error/security events;
  • Google Play subscription product, purchase token, purchase status, expiry information, and an obfuscated account identifier needed to verify and recover entitlements; and
  • Google Play Integrity tokens and verdict data about app recognition, licensing, device integrity, recent request activity, package name, certificate, and app version; and
  • on Apple platforms, App Store product and transaction identifiers, purchase status, expiry and revocation information, an app account token used to associate and recover an entitlement, and signed transaction data used for verification; and
  • on Apple platforms, App Attest key identifiers, attestation receipts and public-key material, assertion counters, and verification outcomes used to confirm that requests come from a genuine App installation.

We use this information to authenticate the App, prevent fraud and replay attacks, operate free and paid quotas, verify purchases, recover entitlements after reinstall, diagnose failures, and protect the service. We do not sell it or use it for advertising.

5. Analytics, crash reporting, and advertising

The App uses:

  • Google Firebase Analytics and Crashlytics, which may collect app-instance identifiers, app version, device model, operating-system version, language, usage events, and diagnostic crash reports; and
  • Google AdMob, which may collect advertising identifiers, ad interactions, device information, and consent choices to serve and measure ads.

Google processes this data under its own policies. Where required, the App asks for advertising consent and provides privacy controls. Derle does not intentionally include project source code, terminal contents, AI prompts, credentials, or file contents in analytics events.

6. Permissions

  • Internet: downloads toolchains and packages, connects to services you choose, operates Derle AI, verifies subscriptions and integrity, and provides optional analytics, crash reporting, and ads.
  • Install unknown apps (Android only): lets you request installation of an APK you build or select. Android shows the system confirmation UI; Derle does not silently install or self-update.
  • Notifications: reports completion of user-started AI or terminal work when you explicitly enable notifications. On Android, a foreground service may also keep user-started work visible while it runs.
  • Local network (Apple platforms): connects to development servers, previews, SSH hosts, or AI endpoints that you choose on your local network.
  • Wake lock (Android only): helps a user-started terminal or build continue while appropriate.

The App does not request broad storage access. Import and export use Android’s system file picker.

7. Sharing and international processing

We share data only as needed with service processors described above, including Cloudflare, OpenRouter and selected AI model providers, Google Firebase, Google Crashlytics, Google AdMob, Google Play Billing, Google Play Integrity, Apple App Store services, and Apple App Attest. These providers may process data in countries outside yours. We may also disclose information when required by law or necessary to protect users, the service, or legal rights.

We do not sell personal information.

8. Retention and deletion

The request activity log described in Section 4 is deleted automatically 90 days after each entry is written. Local projects, chats, settings, and toolchains remain until you delete them or uninstall the App. Backend authentication, quota, security, and subscription records are kept for as long as reasonably necessary to provide the service, prevent abuse, preserve an active entitlement, resolve disputes, and meet legal obligations. Usage counters may be aggregated or deleted when no longer needed.

The anonymous AI request and response records described in Section 2 are kept for as long as they remain useful for evaluating and improving the models. Because they carry no identifier linking them to an installation, an account, or each other, they cannot be located, exported, or deleted for an individual person — which is the same property that keeps them from identifying anyone.

You may request access to or deletion of backend information associated with your anonymous Derle installation by contacting us. We may ask for an installation identifier or other proof needed to locate the correct record. Provider-controlled information is subject to that provider’s deletion process and retention rules.

9. Security

We use HTTPS, short-lived access credentials, device-key request signatures, request limits, Play Integrity or App Attest checks, encryption and access controls. No system is completely secure, and we cannot guarantee that data transmitted over the internet will never be accessed, lost, or misused.

10. Children

Derle is not directed to children under 13 or the minimum digital-consent age in their country. We do not knowingly collect personal information from children.

11. Changes

We may update this policy when features, providers, or legal requirements change. The current version and effective date will always be published at https://derle.app/privacy-policy.html.

12. Contact

For privacy questions or requests, contact harbutogluyazilim@gmail.com.

Questions about this document? Emailharbutogluyazilim@gmail.com.

Source: PRIVACY_POLICY.md

Derle

A real IDE for your phone — editor, Linux terminal, Git and an AI assistant that does the work with you.

Product

  • Features
  • AI assistant
  • iPhone
  • Derle Pro

Legal

  • Terms of Use
  • Privacy Policy

Contact

  • harbutogluyazilim@gmail.com
© 2026 Derle. All rights reserved.Android and Google Play are trademarks of Google LLC. App Store is a trademark of Apple Inc.