This policy explains what personal data NestJS Devs collects, why, who sees it, and what you can do about it. We've tried to write it the way we'd want to read it: plainly, and only promising what we actually do.
1. Who we are
NestJS Devs (nestjsdevs.com) is run by Cristian Cosenza, a sole trader based in Italy (partita IVA IT06821690820, certified email/PEC: cristiancosenza@pec.it). For your personal data on NestJS Devs, he is the data controller under the EU General Data Protection Regulation (GDPR).
Contact for anything about your data: privacy@nestjsdevs.com
We don't have a Data Protection Officer: at our size the law doesn't require one. Write to the address above and the person who runs the service will answer.
NestJS Devs is an independent project, not affiliated with NestJS or its authors.
2. The short version
- We collect what you give us to run your account and profile, plus a few technical details (like your IP address) needed to keep the service secure.
- Developer profiles are public only after a hand review, and only the parts described in section 5.
- Your email address is never shown to other users. Teams and developers talk through messages on the site.
- We don't use analytics, advertising trackers or tracking cookies.
- We never sell your data, and we never use your profile, messages or files to train AI models, and neither do our providers on our behalf.
- You can delete your account yourself at any time, from Settings.
3. What we collect
When you sign up and use your account
- Name, email address, and profile picture (from GitHub if you sign in with GitHub).
- If you sign in with GitHub: your GitHub username, plus an access token that lets us list your public repositories when you choose to import projects.
- Whether you're a developer or a team.
- Session details: when you logged in, your IP address and browser type, so we can keep you signed in and spot misuse.
If you're a developer
- Your profile: headline, bio, country, city, timezone, availability, seniority, years with NestJS, rates (you can hide them), skills, AI experience and tools, languages, links, and projects.
- A profile photo, if you upload one.
- Your review status and any note our reviewer leaves.
- If you buy Devs Plus: your subscription status and the Stripe customer and subscription identifiers. We never see or store your card details; Stripe does.
If you're a team
- Your team profile: company name, website, location, and description.
- Your credit balance and purchase history. Payments are handled by Stripe; we store amounts and Stripe identifiers, never card details.
When teams and developers talk
- Conversations and messages, including any file you attach (PDF or image).
- Read, archive and block status for each conversation.
Technical data
- Short-lived login links and confirmation tokens sent by email.
- Request counters keyed by IP address, to stop abuse such as repeated login attempts.
- Server logs kept by our hosting provider for a short period (see section 8).
We don't ask for, and you shouldn't put in your profile, sensitive data such as health, religion, political views or ethnicity.
4. Why we use it, and on what legal basis
| What we do | Legal basis (GDPR art. 6) |
|---|---|
| Create and run your account, sign you in, show your profile, let teams and developers message each other, sell and track credits and Devs Plus | Performing our contract with you (6(1)(b)) |
| Hand-review developer profiles before they go live, so the directory stays trustworthy | Our legitimate interest in running a reviewed directory (6(1)(f)) |
| Keep the service secure: sessions, rate limits, logs, blocking abuse and fraud | Our legitimate interest in security (6(1)(f)) |
| Send account emails: login links, email-change confirmations, review decisions | Performing our contract (6(1)(b)) |
| Keep invoices and payment records | Legal obligation under Italian tax and accounting law (6(1)(c)) |
| Load the site's fonts from Google Fonts (see section 6) | Our legitimate interest in consistent typography (6(1)(f)) |
Where we rely on legitimate interest, you can object at any time (section 9).
We don't make decisions about you based solely on automated processing. Profile reviews are done by a person.
5. Who can see your data
Developer profiles are visible only after they pass review. Then:
- Anyone, without an account, can see the profile card: name, username, headline, photo, country and city, timezone, availability, seniority, skills, AI experience and tools, rate (unless you hide it), and whether you have Devs Plus.
- Anyone with a free account, team or developer, can also see the full profile: bio, AI story, years with NestJS, positions and work model you're open to, languages, links and projects.
- A team that spends a credit can start a conversation with you. A team that has contacted you, and you, can then see the messages and files exchanged.
Your email address is never shown to other users.
Teams that contact developers become responsible for the developer data they see, as independent controllers. Our Terms only allow them to use it to evaluate and contact that developer about work: no exporting, reselling, scraping or marketing.
Inside NestJS Devs, the person running the service can technically access the database to operate it. We look at messages only when needed to investigate abuse reported to us, to comply with the law, or with your permission.
We never sell your data.
6. Service providers
We use a small number of providers to run the service. Each one processes data under a data protection agreement, or under its own privacy policy where it acts independently.
| Provider | What for | Where |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, file storage, sending email, security logs | Database in Western Europe; profile photos in Eastern Europe; message attachments in the United States |
| Stripe | Payments, invoices, subscriptions. Stripe also acts as an independent controller for some payment data (see stripe.com/privacy) | EU and United States |
| GitHub, Inc. | Sign-in, and listing your public repositories when you import projects (see GitHub's privacy statement) | United States |
| Google LLC (Google Fonts) | Serving the site's typefaces. Your browser requests the fonts from Google, which receives your IP address (see policies.google.com/privacy) | United States |
None of these providers may use your data for their own purposes beyond providing the service and meeting their legal obligations, and none may use it to train AI models on our behalf.
We may also disclose data when the law requires it, for example to a court or authority with a valid order.
7. Transfers outside the EU
Some of the providers above store or access data in the United States. These transfers rely on the EU-US Data Privacy Framework (an EU adequacy decision) where the provider is certified, and on the European Commission's standard contractual clauses otherwise. You can ask us for more detail at privacy@nestjsdevs.com.
8. How long we keep data
| Data | How long |
|---|---|
| Your account, profile, projects and photo | Until you delete your account, or after 3 years of inactivity (no sign-in). We'll email you 30 days before deleting an inactive account. Accounts with unused credits or an active Devs Plus subscription aren't deleted for inactivity. |
| Messages and attachments | While the conversation exists. If you delete your account, your messages stay visible to the person you were talking to, but your name and profile are removed and shown as a deleted user. |
| Sessions | Up to 30 days, renewed while you're active |
| Login links and confirmation tokens | Minutes to hours, then they expire |
| Rate-limit counters | A short rolling window |
| Hosting logs | A few days, per Cloudflare's log retention [verify] |
| Invoices and payment records | 10 years, as Italian accounting law requires [verify] |
Deleting your account (Settings → Delete account) removes your account, profile, photo, projects, sessions and credits immediately, along with the files you attached to messages. Invoices and payment records stay in Stripe and in our accounting records for the legal retention period.
9. Your rights
Under the GDPR you can:
- Access your data and get a copy.
- Correct it: most of it you can edit yourself in your profile and settings.
- Delete it: delete your account in Settings, or ask us.
- Restrict how we use it in certain cases.
- Object to uses based on our legitimate interest.
- Port it: ask us and we'll send your data in a machine-readable format (JSON).
- Withdraw consent where we rely on it, without affecting what we did before.
To use any of these, write to privacy@nestjsdevs.com from your account's email address. If you write from another address, we'll ask you to confirm from your account's address first. We never ask for ID documents. We answer within one month; for complex requests we may extend by up to two more months and will tell you why within the first month. It's free, unless a request is clearly unfounded or excessive.
You also have the right to complain to a data protection authority. In Italy that's the Garante per la protezione dei dati personali (garanteprivacy.it), or the authority where you live or work.
10. Cookies and similar technologies
We use only what's needed to make the site work:
- A session cookie that keeps you signed in. Strictly necessary, so it needs no consent.
- A setting in your browser's local storage (
nd-theme) that remembers whether you chose light or dark mode. Strictly necessary for a feature you asked for.
We don't use analytics, advertising or tracking cookies. Fonts load from Google Fonts, as described in section 6. If that ever changes, we'll update this policy and ask for consent where the law requires it.
11. Security
Data is encrypted in transit (HTTPS) and stored with Cloudflare. Sign-in uses GitHub or one-time email links, so there are no passwords to leak. Uploaded files are limited in type and size. No system is perfectly secure. If a breach affects your data and puts you at high risk, we'll tell you, and we'll notify the Garante within 72 hours where the law requires it.
12. Age
NestJS Devs is a professional service. You must be at least 18 to use it.
13. Changes to this policy
If we change this policy, we'll update the date at the top. For significant changes, such as new kinds of data, new providers or new purposes, we'll tell you by email or on the site before they take effect.