What we hold,and what we cannot.
Last updated 2026-08-30 · Document version 2026-08-30
This policy covers our website, our sales and support correspondence, and the software and appliances we sell. The data our software reads on a customer’s premises stays on that customer’s appliance.
This policy explains what personal information DEVEXANA LLC (“Devexana,” “we”) collects, why, and what we do with it. It covers our website, our sales and support correspondence, and the software and appliances we sell. Section 2 explains the part that makes this policy different from most: the data our software reads on a customer’s premises never reaches us.
1. Who this policy applies to
This policy applies to our customers, prospective customers, resellers, partners, and website visitors, and to information collected through our websites, our applications, and the software and appliances we supply (together, “Devexana Resources”).
It does not describe what a customer’s own appliance holds about that customer’s staff and systems. That data belongs to the customer and is governed by the customer’s own policies and by its records-retention obligations. Section 2 explains why.
2. The architecture this policy describes
Devexana is a local-first product. It runs on an appliance inside the customer’s building, inside the customer’s network boundary, under the customer’s physical control.
The software transmits no customer operational data to Devexana. It sends us no usage data, no crash reports, no analytics, and no operational, network, inventory, or monitoring data about a customer or a customer’s systems. There is no vendor-hosted account or mirror of that data, and nothing readable by us leaves the appliance in the ordinary course.
We hold no readable customer data, and we cannot produce readable customer data in response to a subpoena or other legal process directed at us. The only customer-related material that can sit in our custody is the encrypted backup ciphertext described in the next subsection, which we cannot decrypt.
Records read from a customer’s connected systems, and everything derived from them (records, embeddings, summaries, chat history) are stored only on that appliance, in an encrypted local database. A process-wide egress guard blocks unexpected outbound connections, and every outbound call the appliance does make is written to an append-only egress log the customer can read.
One optional capability can send anything off the appliance: the cloud consult. In the Government edition it is hard-blocked in the product’s code: no setting, flag, or role opens it. In the Business edition it is off by default; when an administrator enables it, the first consult in a conversation requires a named user’s explicit consent on a previewed, redacted copy of what would be sent, that consent covers only that conversation, identifiers and secrets are redacted before sending, and every call is recorded in the egress log. Turning it off stops all outbound calls immediately.
We do not represent that the current cloud AI provider operates under a zero-data-retention agreement or a FedRAMP-authorized path. The current escalation partner is a testing endpoint operating without either, and content sent to it may be retained by that provider under its own terms. Our Compliance Disclosure states which agreements are signed and which are not.
We do not train models on customer data, not our models, and not a provider’s through our product. We do not sell or share personal information for advertising or profiling.
2A. Off-site backup storage
Devexana offers an optional off-site backup service. It is off by default and takes effect only where a customer asks for it. Where it is enabled, the appliance uploads its encrypted snapshots to Amazon Web Services storage in United States regions.
What is stored is ciphertext, and only ciphertext. A snapshot is encrypted on the appliance, before it is uploaded, with the appliance’s own database key. That key is held by the customer and the appliance, in the appliance’s operating-system keychain or equivalent local custody, under the customer’s key-escrow arrangements. It is not uploaded, not held in the storage service, and not recoverable from anything an administrator of that storage can reach.
The consequence is that Devexana cannot decrypt or read the contents of a backup. Restoring a backup takes two things from two separate custody chains: the stored ciphertext, and the appliance key that the customer holds. Anyone who obtained the whole storage account would obtain bytes they could not open.
Each appliance’s uploads go to its own storage location, and the appliance’s own credential can write there and nothing else: it cannot list, read back, or delete. A customer whose contract requires that its backups never sit in a vendor-controlled account can instead have them written to the customer’s own storage account, in which case Devexana holds nothing at all.
This also means that losing the appliance key loses the backups. Off-site storage does not soften that; it is why the key-escrow step is part of onboarding and is not optional.
3. What we collect
Personal information means information that identifies a person directly or indirectly. What we collect is the information a person gives us in the course of buying, evaluating, or being supported on our product:
name, job title, employer or agency, business email address, business postal address, and business telephone number;
purchase and billing details, including purchase order numbers, remittance information, and tax-exemption certificates;
the content of support requests, sales correspondence, and any log bundle, screenshot, or export a customer chooses to send us with a support request;
registration details for an appliance, so we know which unit a support request concerns; and
for website visitors, the technical information described in Section 4.
We do not collect payment card numbers ourselves; where a customer pays by card, the card is handled by our payment processor and we receive only the confirmation and the last digits.
4. How we collect it
Directly from the person, when they fill in a form, request a quote, download material, open a support request, or write to us.
From the organization that employs them, when it names staff on an order, a support authorization list, or an appliance registration.
From our website, which records the technical details of a visit: the requesting IP address, the pages requested, the date and time, the referring page, and the browser and operating system reported by the browser.
Not from the software. The appliance sends us nothing. See Section 2.
5. Cookies
Our website uses the cookies it needs to serve pages and to remember a preference a visitor sets. A cookie is an identifier stored by the browser; it cannot execute code or carry a virus. A visitor can refuse or delete cookies in the browser, and the site will still serve its pages, though a remembered preference will be lost.
We use no third-party advertising, analytics, or cross-site tracking cookies.
5A. This website
This section describes devexana.com itself, the site you are reading. It is a set of static pages. There is no account, no sign-in, and no form on it that sends anything to us.
We run no analytics service on this site, no advertising cookies, and no tracking pixels. The site is hosted on Vercel, and the host keeps ordinary server logs of the requests it serves, including the requesting IP address. Those logs are retained by the host under its own terms.
Three things on the site reach a service outside it, and each one happens only when you choose it. The interactive demo loads map tiles from Google when you open it, so Google receives that request under Google’s own privacy policy. The “Book a walkthrough” button opens a Google Calendar booking page, which Google operates under its own terms. Mail sent to abonde@devexana.com arrives in a mailbox we run in Google Workspace.
Nothing on this site connects to a customer appliance, and every record shown in the demo is fictional.
6. Why we collect it
Website visitors. To serve the site, to answer enquiries, to understand which pages are read, and to diagnose problems with the site.
Customers and prospective customers. To quote, to process an order, to ship and register an appliance, to deliver and support the software, to bill and collect, to give notice of updates and of the end of a subscription term, and to meet our own legal and accounting obligations.
Payment information. To take payment. Where a customer pays by purchase order, check, or wire, we hold the remittance details for the period our accounting obligations require.
7. How we use it
We use personal information to perform our contract with a customer; to pursue our legitimate interest in running and supporting the business; to respond to a support request; to tell customers about changes to the product, to these documents, or to a subscription term; to detect and prevent fraud; and to comply with a legal obligation.
We send marketing email only to a person who has asked for it, and every such message carries an unsubscribe link. Unsubscribing does not stop the operational notices a customer needs: an update notice, a renewal notice, or a security advisory.
We do not use personal information to train or tune any model.
8. When and how we disclose it
We disclose personal information to our own personnel who need it, and to service providers who act for us: hosting, email delivery, payment processing, accounting, shipping and logistics, and professional advisers. Those providers are bound to use it only for the purpose we give it to them for.
We disclose personal information where we are required to by law, to a regulator or a court, or to law enforcement acting on lawful process; and in connection with a merger, an acquisition, or a sale of all or substantially all of our assets, subject to this policy continuing to apply.
We cannot disclose what we cannot read. A legal demand served on Devexana for a customer’s operational records, network data, ticket data, or chat history cannot be answered, because that data stays on the customer’s appliance. Where a customer uses the off-site backup service in Section 2A, what we can produce is ciphertext we are unable to decrypt. Such a demand must be directed at the customer, who holds both the data and the key.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
9. Where we store it
We are a New Jersey company and we store and process personal information in the United States. Where a customer enables the off-site backup service, the encrypted snapshots described in Section 2A are stored in United States regions of our cloud storage provider. We do not transfer personal information outside the United States, and we do not ask anyone to consent to an international transfer.
10. How we keep it secure
Personal information we hold sits on systems we or our service providers manage, protected by account authentication, multi-factor authentication where available, access limited to the personnel who need it, and encryption in transit and at rest where appropriate. Paper records, where they exist, are held in a locked location in the United States.
On a customer’s appliance, security is the customer’s to inspect: the local database is encrypted, connector and device credentials are held in the operating system keychain rather than in files or the database, secrets are scrubbed from logs and search indexes, and every privileged action is written to an append-only, hash-chained audit log that an administrator cannot silently edit or truncate.
We do not sell personal information to anyone.
11. Marketing choices
A person who has asked to hear from us can stop at any time using the unsubscribe link in any marketing message, or by writing to the address in Section 19. Cookies are controlled in the browser, as Section 5 describes.
12. Web analytics
Our website records the technical details of a visit listed in Section 4 in its own server logs, and we read those logs in aggregate to understand which pages are used and to diagnose faults. These logs are kept on systems we control.
We use no third-party analytics service. Our website is not instrumented with Google Analytics or any comparable service, and we do not share visit data with an analytics provider.
13. Children
Devexana Resources are intended for use by adults acting for a government or business organization. We do not knowingly collect personal information from anyone under 18; if we learn that we have, we will delete it.
14. Information made public
Where a person publishes information themselves, in a public forum, on social media, or by sending it to another party, we cannot control how it is used. Anyone considering sharing information publicly should read the receiving party’s own privacy policy first.
15. How long we keep it
We keep personal information for as long as we need it to provide and support the product and to meet our legal, accounting, and tax obligations, and then we dispose of it. A person may ask us to correct or erase the information we hold about them, and to close an account, using the contacts in Section 19.
After an erasure request we may keep the minimum record we need to enforce an agreement, resolve a dispute, prevent fraud, or comply with the law, for example the invoice history our accounting obligations require. We will say what we have kept and why.
Data on a customer appliance is a separate matter: it is retained under the municipality’s own records-retention schedule, which its administrators configure and apply. Removing a source stops new reads immediately; stored records are disposed of per that schedule. Decommissioning the appliance removes the data with it, because there is no off-box copy.
16. Governing law
This policy is governed by and construed in accordance with the laws of the State of New Jersey, where Devexana is organized. Where the customer is a New York governmental entity, the laws of the State of New York govern. Where a signed agreement between Devexana and a customer states a governing law, that agreement controls.
17. Things outside our control
No system is beyond reach. Where information is exposed by an event outside our control (a compromise of a third party, an intrusion, or a fault in software we did not write), we will act on it and give the notice the law requires, but we do not warrant against events we cannot control.
18. When this policy changes
We update this policy when the law or our practices change. Where notice is required, we will give it. The current version is always the one published at the address in Section 19 and the one presented in the product, and it carries an effective date and a document version.
Where the product presents this policy, a materially updated version is presented for acceptance before use continues, and the acceptance (account, document version, and timestamp) is recorded in the appliance’s audit log.
19. How to contact us
Privacy questions, and requests to see, correct, or erase what we hold, go to legal@devexana.com, or by post to DEVEXANA LLC, PO Box 1, Demarest, New Jersey 07627, marked for the attention of the privacy contact.
A customer’s own staff and residents should direct requests about data on the appliance to the customer’s system administrator or records officer, who can act on that data directly. Devexana holds none of it.
Security vulnerability reports go to security@devexana.com. We acknowledge reports promptly and do not pursue good-faith researchers.
20. State privacy rights
Where a United States state privacy law gives a resident rights over personal information we hold about them (to know what we hold, to have it corrected, to have it deleted, or to opt out of sale or sharing), we honour those rights. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of on those grounds. Requests go to the contacts in Section 19.
Devexana holds business-contact and billing information about New York residents, and, where a customer enables the service in Section 2A, encrypted backup ciphertext derived from a New York municipality’s systems.
Our municipal customers are subject to the New York Freedom of Information Law. Records held on a customer’s appliance are governed by that customer’s own records obligations, and Devexana holds no copy that could be responsive to a request directed at Devexana. Where such a request reaches material Devexana treats as confidential under its licence terms, Section 16.2 of the Terms of Use governs.
21. How to access your information
To see, update, or ask about the personal information we hold, write to the contacts in Section 19. We will respond within a reasonable time, and in any event within the time the applicable law requires. We will confirm identity before acting on a request.
Where we must keep information to comply with the law, to resolve a dispute, or to enforce an agreement, we will say so and say why rather than deleting silently. Where a request concerns data held on a customer’s appliance rather than data we hold, we will say so and point to the customer’s administrator, who can act on it.