Skip to main content

Privacy Policy

Last Updated: 8 October 2026•Effective Date: 23 September 2026•Version: 1.1•94 Sections
Important: This Privacy Policy outlines data handling practices for DevClub UI. Components run client-side in your application without silent telemetry. This website uses Microsoft Clarity, Vercel Web Analytics and Vercel Speed Insights, as described in Sections 7 and 19.

1. Introduction

Welcome to DevClub UI (the "Library", "Platform", "Service", "we", "us", or "our").

This Privacy Policy explains how we collect, receive, use, disclose, retain, protect, and otherwise process personal information when you visit or use our website, browse our component documentation, download, install, import, or use our packages, access our source code repositories, communicate with us, submit issues or pull requests, or use our developer tools, APIs, playgrounds, and hosted services.

The Library consists of open-source and component registry software. Components execute entirely in your local environment and do not silently harvest or transmit application data to us. Other services, such as our documentation website, APIs, or community channels, process technical information as described below.

2. Scope of This Privacy Policy

This Privacy Policy applies to personal information processed through services that expressly link to this Policy, including the DevClub UI website, documentation and API reference endpoints, package distribution interfaces, preview and rendering environments, support channels, and community repositories.

Software that runs locally: If you install a component package and use it within your own application, the components do not send information to us. A locally installed UI component that renders a button, accordion, sidebar, or shader operates within your application sandbox. Your application remains solely responsible for the personal information it collects.

Hosted services: If you use a hosted service operated by us, such as a playground, preview environment, or public REST API, we process technical request information necessary to deliver that service.

3. Definitions

"Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identifiable individual, as defined by applicable law.

"Usage Data" means technical or interaction information relating to the use of our websites, packages, documentation, or services.

"Device Information" means information about a computer, browser, operating system, network, or similar device.

"Services" means the websites, software, documentation, hosted products, APIs, developer tools, and related services covered by this Policy.

"You" or "User" means the individual or organization accessing or using the Services.

"Controller" means the entity that determines why and how personal information is processed.

"Processor" or "Service Provider" means an entity that processes personal information on behalf of a controller.

4. Information We Collect

The information we collect depends on how you interact with the Library.

Information you provide directly: You may provide information when you contact support, submit a bug report on GitHub, open a pull request, submit feedback, or communicate via email. This may include your name, GitHub handle, email address, feedback, and technical correspondence.

We do not require you to provide more information than is reasonably necessary for the specific technical purpose.

5. Account and Authentication Information

DevClub UI does not require mandatory account registration to browse documentation, preview interactive showcases, or copy registry components.

If authenticated developer accounts are introduced in future releases, we will process email addresses, usernames, and authentication identifiers through secure, industry-standard authentication providers without storing third-party passwords.

6. Automatically Collected Information

When you access our websites or hosted endpoints, technical information may be recorded transiently in server access logs. This may include IP address, approximate geographic region derived from IP, browser type and version, operating system, referring URL, pages viewed, timestamps, HTTP headers, and error diagnostics.

We use this information solely for delivering the service, diagnosing errors, preventing automated abuse, detecting security threats, and measuring aggregate performance.

7. Cookies and Similar Technologies

Our website uses browser local storage for interface preferences, such as your chosen light or dark theme and your preferred code language and styling options.

Our website also loads Microsoft Clarity on every page. Clarity sets the following cookies when the page loads: _clck (first-party, stores the Clarity user ID and preferences, observed lifetime of about one year), _clsk (first-party, connects page views into a single Clarity session, observed lifetime of one day), and the third-party cookies MUID, CLID, MR, SM and ANONCHK on the clarity.ms and bing.com domains (observed lifetime of up to about thirteen months). Microsoft describes these cookies at https://learn.microsoft.com/en-us/clarity/setup-and-installation/clarity-cookies.

Vercel Web Analytics and Vercel Speed Insights do not set cookies. See Section 19 for details of both services and how to opt out.

8. Package, Download, and Repository Information

When you download or clone components via git or fetch them from our registry API, technical network metadata (such as IP address, requested slug, and user agent) is processed by our server infrastructure or host CDN to deliver the requested files.

Third-party package managers (such as npm) independently process download metrics under their own respective privacy policies.

9. Documentation and Website Usage

When you navigate our documentation, we process technical page view events to ensure high-speed caching and accurate content rendering. Documentation search queries are evaluated client-side or transiently without building individualized user profiles.

10. Hosted Playground, Sandbox, and Preview Data

Interactive code studios, WebGL shader previews, and component playgrounds execute in your local browser runtime. Any code changes, props adjustments, or playground values you test remain within your client session and are not saved to remote tracking databases.

Do not input passwords, private API keys, or confidential secrets into interactive playgrounds.

11. Source Code, Issues, Pull Requests, and Public Contributions

If you submit an issue, comment, or pull request to our public GitHub repository, information you publish (including your GitHub username, commit email, code snippets, and comments) becomes publicly accessible and permanently preserved under open-source version control.

Never publish private credentials, API keys, or sensitive customer data in public repositories.

12. Information From Third Parties

We may receive technical data from third-party hosting platforms (such as GitHub, Vercel, or Cloudflare) relating to repository activity, CDN bandwidth delivery, and automated security scanning reports.

13. Information We Do Not Intentionally Collect

We do not intentionally seek or collect passwords entered into component form examples, credit card numbers, biometric data, precise GPS location, government IDs, or private health records.

The component library operates without requiring access to sensitive data handled by the applications into which it is embedded.

14. How We Use Personal Information

We use information to operate websites, deliver documentation, process API requests, detect suspicious traffic, investigate abuse, protect infrastructure, troubleshoot bugs, and comply with legal requirements.

We do not sell personal information to third parties.

15. Legal Bases for Processing

Where required by law, we rely on legitimate interests (maintaining service security, preventing fraud, and delivering open-source software), performance of contracts, compliance with legal obligations, or explicit user consent where applicable.

16. How We Share Personal Information

We may share technical information with trusted service providers who assist with cloud hosting, CDN distribution, security DDoS filtering, and error monitoring under strict confidentiality obligations.

We may also disclose information where required by valid legal process or to protect security and user safety.

17. Third-Party Services

Our services link to external platforms (GitHub, Twitter, npm, Radix UI). Third-party platforms operate under their own independent privacy notices, which you should review before engaging with them.

Some component previews load images and media directly from third-party hosts, including i.pinimg.com (Pinterest), images.unsplash.com (Unsplash), pbs.twimg.com and api.fxtwitter.com (X/Twitter content), and cdn.21st.dev. When your browser requests these files, the host receives your IP address, browser user agent and the referring page, as with any web request.

18. Payment Information

DevClub UI core open-source components are provided free of charge under the MIT License. If paid enterprise tiers or support contracts are purchased, transactions are handled by certified third-party payment processors without DevClub storing payment card numbers.

19. Analytics

We use the following analytics services on this website:

Microsoft Clarity (provided by Microsoft Corporation). Purpose: session replays, heatmaps and aggregated usage statistics that show how visitors use the site. Clarity records page views and interactions such as clicks, scrolling and mouse movement, together with device and browser information, and uses the cookies listed in Section 7 to link page views to a pseudonymous ID. Microsoft privacy statement: https://privacy.microsoft.com/privacystatement. Clarity documentation: https://learn.microsoft.com/en-us/clarity/.

Vercel Web Analytics (provided by Vercel Inc.). Purpose: aggregated page view statistics. According to Vercel, it does not use cookies; visitors are identified by a hash of the incoming request that is discarded after 24 hours, and each data point may include the page URL, referrer, approximate location, device type, operating system and browser. Details: https://vercel.com/docs/analytics/privacy-policy.

Vercel Speed Insights (provided by Vercel Inc.). Purpose: measuring page performance (Core Web Vitals). According to Vercel, it does not use cookies and records the page route and URL, network speed, browser, device type, operating system, country and performance metrics. Details: https://vercel.com/docs/speed-insights/privacy-policy. Vercel privacy notice: https://vercel.com/legal/privacy-policy.

How to opt out: you can block or delete cookies for clarity.ms, bing.com and this website in your browser settings, and you can block requests to clarity.ms and to the Vercel analytics scripts with a content blocker or privacy extension. Blocking these services does not affect your ability to browse the documentation or copy components.

20. Error Reporting and Diagnostics

Client-side errors and network failures may generate technical diagnostic stack traces to help us fix component issues. Diagnostic payloads are scrubbed to prevent transmission of sensitive environment variables.

21. Security and Fraud Prevention

We monitor request patterns to protect public API endpoints against automated brute-force attacks, credential stuffing, scraping abuse, and denial-of-service attempts.

22. Children's Privacy

Our developer tools and documentation are not directed at children under the age of 13. We do not knowingly collect personal information from children.

23. Sensitive Personal Information

We do not collect sensitive personal information. Users should not post sensitive financial, medical, or confidential data in issue trackers or public discussions.

24. Data Retention

We retain technical information only for as long as necessary to fulfill operational purposes, ensure server security, maintain error diagnostics, and satisfy legal obligations.

25. Data Deletion

You may request the deletion of personal communications or correspondence by contacting softwaredevg.club@rishihood.edu.in. Certain transient security logs and publicly committed git history cannot be erased immediately due to immutability.

26. Data Accuracy

We endeavor to keep developer records and documentation accurate. You may request corrections to correspondence or documentation via our GitHub repository.

27. Your Privacy Rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict processing of your personal information, or lodge a complaint with your local data protection regulator.

28. Rights Under Indian Privacy Law

Where applicable, we adhere to the Digital Personal Data Protection Act, 2023 (DPDP) and provide grievance redressal for data principals via softwaredevg.club@rishihood.edu.in.

29. Rights Under the European Economic Area and United Kingdom

EEA and UK residents possess rights under the GDPR and UK GDPR, including data access, rectification, erasure, restriction, objection, and data portability.

30. Rights Under United States State Privacy Laws

Residents of California, Virginia, Colorado, Connecticut, Utah, and other US states may exercise rights to know, access, delete, and opt-out of regulated data practices under applicable state laws.

31. California Privacy Information

Under the California Consumer Privacy Act (CCPA) and CPRA, California residents have the right to request disclosure of collected categories and request deletion without discriminatory treatment.

32. Exercising Your Rights

To submit a privacy inquiry or exercise your legal rights, email softwaredevg.club@rishihood.edu.in with the subject line "Privacy Rights Request". We verify requests to protect against unauthorized disclosures.

33. Authorized Agents

Where permitted by law, you may designate an authorized agent to submit requests on your behalf with written authorization and verification of identity.

34. Appeals

If we decline to take action on a privacy request, you may appeal the decision by writing to softwaredevg.club@rishihood.edu.in explaining the grounds for appeal.

35. International Data Transfers

Where data is transferred internationally across our global hosting infrastructure, we utilize recognized transfer mechanisms, including Standard Contractual Clauses, to ensure adequate protection.

36. Data Security

We implement technical safeguards including HTTPS/TLS encryption in transit, strict access control, vulnerability scanning, and infrastructure firewalls. However, no internet transmission is 100% secure.

37. Your Responsibilities

You are responsible for keeping your local environment, git credentials, and API tokens secure, and ensuring that any application built with DevClub UI complies with applicable privacy laws.

38. Privacy of Applications Built With the Library

DevClub UI does not control the privacy practices of external applications that integrate our components. Application owners must publish their own privacy notices and obtain necessary end-user consents.

39. Telemetry in Components

DevClub UI components do NOT contain hidden telemetry routines or phoning-home beacons. Components execute locally within your application's domain without reporting user interactions back to our servers.

40. Open Source Components

Our open-source component source code is publicly inspectable on GitHub. Developers can audit every line of TSX and CSS to verify that no unauthorized network requests occur.

41. Third-Party Dependencies

Components rely on standard peer libraries (React, GSAP, Radix UI, OGL, Motion, Tailwind CSS). We recommend reviewing dependency manifests when building systems with high compliance requirements.

42. API and Network Requests

When consuming our public REST API endpoints (/api/components, /api/components/[slug]), requests include standard HTTP metadata needed to serve responses and maintain rate limiting.

43. Logs

Server access logs record request timestamps, IP addresses, requested URLs, and response status codes for operational reliability, DDoS prevention, and debugging.

44. Backups

System backups are maintained for business continuity and disaster recovery. Information in backups is automatically purged or overwritten in accordance with retention schedules.

45. Security Incidents

In the event of a verified security incident affecting personal data, we will take prompt containment and remediation measures and notify affected parties and authorities as required by law.

46. Data Breach Responsibilities for Customers

Organizations utilizing DevClub UI components in their products are responsible for their own internal incident response plans, breach assessments, and regulatory notifications.

47. Marketing Communications

We do not send unsolicited marketing email. If you subscribe to product announcements or release notes, you can opt out at any time using the unsubscribe link provided.

48. Surveys and Feedback

Participation in community surveys or developer feedback forms is voluntary. Feedback is used in aggregate to improve our component library and documentation.

49. Community Participation

Public comments, discussions, and code submitted to our GitHub community forums are publicly visible. Do not share confidential business secrets or private personal data.

50. User-Generated Content

You retain ownership of any custom code or issue submissions you create. By submitting contributions to open-source repositories, you license them under the applicable repository license.

51. Artificial Intelligence Features

If you use AI coding assistants with our Agent Skills or registry endpoints, your interaction with those AI providers is governed by the terms and privacy practices of those respective AI services.

52. Automated Decision-Making

We do not subject users to automated profiling or decision-making that produces legal or similarly significant effects.

53. Do Not Track Signals

Our website does not currently change its behavior in response to Do Not Track browser signals. The analytics services we use are described in Section 19, together with instructions for opting out.

54. Global Privacy Control

Where required by law, we recognize legally valid opt-out preference signals such as Global Privacy Control (GPC).

55. Do Not Sell or Share

We do not sell personal information or share personal information for cross-context behavioral advertising under California or other US state privacy laws.

56. Data Minimization

We intentionally restrict data collection to the minimum technical information required to maintain website availability, deliver registry components, and protect system security.

57. Aggregated and De-Identified Information

We may generate anonymous, de-identified metrics (such as aggregate page view counts or component popularity) to guide future component engineering and performance tuning.

58. Enterprise and Business Customers

Enterprise customers with dedicated service contracts may execute customized Data Processing Agreements (DPAs) governing specific operational requirements.

59. Data Processing Agreements

Where required by GDPR or other data protection legislation, we make DPAs available to enterprise clients detailing security safeguards and processing instructions.

60. Subprocessors

We utilize reputable cloud infrastructure providers (such as GitHub, Vercel, and Cloudflare) who adhere to strict data security and privacy compliance standards. Website analytics are provided by Microsoft (Clarity) and Vercel (Web Analytics and Speed Insights), as described in Section 19.

61. Government Requests

We review any governmental or law enforcement data requests rigorously and disclose technical information only when compelled by valid, binding legal process.

62. Legal Claims and Disputes

We may retain correspondence or technical logs when reasonably necessary to defend against legal claims, enforce our Terms of Service, or comply with court orders.

63. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect new features, operational adjustments, or legal changes. Revisions are published on this page with an updated timestamp.

64. Privacy Policy Version History

Version 1.0 published on 23 September 2026. Comprehensive initial release covering developer documentation, registry endpoints, and client-side execution.

Version 1.1 published on 8 October 2026. Discloses the analytics services used on this website (Microsoft Clarity, Vercel Web Analytics and Vercel Speed Insights), the cookies Clarity sets, and third-party image hosts used by component previews.

65. Contact Us

For privacy questions or rights requests, contact DevClub at softwaredevg.club@rishihood.edu.in or via our website at https://ui.devclubxnst.online.

66. Grievance Redressal

For privacy grievances or complaints under applicable legislation, contact our designated Grievance Officer at softwaredevg.club@rishihood.edu.in.

67. Security Contact

Report security vulnerabilities privately to softwaredevg.club@rishihood.edu.in before coordinated disclosure.

68. Data Protection Officer

For inquiries regarding data protection oversight, direct communications to our privacy team at softwaredevg.club@rishihood.edu.in.

69. Controller Information

DevClub acts as the data controller for personal information processed directly through the devclubxnst.online website and public documentation channels.

70. Processor Information

Where hosted services are provided to enterprise clients under contract, DevClub acts as a processor subject to agreed contractual terms.

71. Compliance With Applicable Laws

Our data practices are engineered to align with global standards including GDPR, UK GDPR, CCPA/CPRA, and India's DPDP framework.

72. Jurisdiction-Specific Notices

Where localized laws require specific disclosures, this Policy is supplemented by applicable regional statutory protections.

73. Data Protection by Design

We embed privacy by design principles into our software architecture by minimizing default data collection, keeping component code client-side, and avoiding third-party ad tracking.

74. Privacy and Component Architecture

Because our components are distributed as uncompiled TypeScript source code, you have full visibility into state and prop flows. An Input or Accordion component does not send form data to our servers.

75. Browser Storage

Our website uses browser local storage for non-sensitive UI preferences (such as dark mode theme selection). Cookies set by Microsoft Clarity are described in Section 7. Do not store unencrypted secrets in browser storage.

76. Authentication Tokens

Developers integrating authentication with their applications should ensure tokens are securely handled using HTTP-only cookies and proper CORS headers.

77. Source Maps, Builds, and Deployment Artifacts

Review production build artifacts and source maps prior to deployment to ensure internal development secrets or staging URLs are not exposed.

78. Error Messages and Public Issues

Before submitting public bug reports or issues, redact all private customer information, access tokens, and sensitive system logs.

79. Children and Educational Applications

Developers building software for educational institutions or minors must independently implement child privacy safeguards under COPPA, FERPA, or GDPR-K.

80. Accessibility and Privacy

Our accessibility features (ARIA attributes, keyboard navigation) operate natively in the browser without collecting assistive technology metadata.

81. Enterprise Security Requirements

Enterprise clients requiring specialized security reviews, custom audit logs, or dedicated compliance documentation should contact softwaredevg.club@rishihood.edu.in.

82. Data Residency

Public documentation and registry APIs are distributed globally via high-speed edge networks to optimize latency.

83. Data Export

Users may request copies of any personal correspondence retained by our support team by submitting a verified request to softwaredevg.club@rishihood.edu.in.

84. Account Closure

If user accounts are provided in future versions, closing an account will delete eligible personal data while preserving immutable open-source git history.

85. No Guarantee of Absolute Security

While we implement robust safeguards, no digital system is impenetrable. Maintain strong operational security and report suspected bugs responsibly.

86. Third-Party Hosting and Infrastructure

We host our services on reputable cloud providers with ISO/IEC 27001 and SOC 2 Type II certifications.

87. Open Web and Public Information

Information voluntarily published on public GitHub pull requests, commits, or community discussions is accessible to the global open-source community.

88. Changes in Ownership

In the event of a merger, acquisition, or restructuring, information will continue to be governed by the protections outlined in this Privacy Policy.

89. Severability

If any provision of this Privacy Policy is found unenforceable, the remaining provisions continue in full force and effect.

90. Interpretation

Section titles are for organizational convenience only and do not affect legal interpretation.

91. Entire Privacy Notice

This Privacy Policy constitutes the complete privacy disclosure for DevClub UI and its associated public registry endpoints.

92. Implementation Checklist

Before deploying applications built with DevClub UI, verify that dependency licenses, cookie notices, and data handling workflows align with your product requirements.

93. Privacy Principles

We operate by transparency, data minimization, purpose limitation, strong technical security, user control, and privacy by design across all components.

94. Final Notice

This Privacy Policy establishes our commitment to privacy. Component source code is open, inspectable, and runs client-side under your control.