Privacy Policy

Effective date:August 14, 2026

This policy explains how DevPeek (desktop app, website, and related services) handles information about you. DevPeek is a local HTTP(S) debugging tool for developers and testers. We aim to keep debug data on your device by default.

1. Scope

This policy applies to the DevPeek desktop app (including builds distributed via Microsoft Store and other channels), the website devpeek.ypgao.com, and backend services that support accounts, downloads, and analytics (such as api.ypgao.com and auth.ypgao.com).

If you use DevPeek to capture, decrypt, or debug third-party apps and sites, you must also comply with those parties and your organization. This policy does not replace your obligation to obtain authorization for systems under test.

2. Local debug data

Data generated by DevPeek core features—HTTPS capture, Mock, scripts, breakpoints, recordings, WebSocket Mock, configs, and project files—is stored locally on your device by default, not on DevPeek cloud storage.

Local data may be highly sensitive (URLs, request/response headers and bodies, cookies, tokens, personal data, or business secrets). Protect your device, backups, and exports, and use DevPeek only in environments you are authorized to test.

  • When SSL proxy decryption is enabled, matching HTTPS traffic may be inspected in plaintext on this machine
  • LAN collaboration sends session-related data only when you explicitly enable it and connect authorized devices
  • We do not remotely read or back up capture bodies unless you later opt into clearly labeled cloud sync or similar features (with separate encryption and storage details)

3. Anonymous usage analytics

To improve stability and understand feature usage, DevPeek sends anonymous usage analytics by default to our analytics endpoint (api.ypgao.com/devpeek/events). Analytics do not include capture bodies, full URLs, or request/response payloads.

Event properties are scrubbed before upload (e.g. token, password, body, and full URL fields are filtered). To opt out, contact us via the website Contact page, or disable the feature in app settings when available.

  • Anonymous device identifier (random UUID stored in local config)
  • Operating system platform and app version
  • Event names (e.g. app open/close, feature usage) and scrubbed properties
  • If you are signed in, analytics requests may include a session cookie to associate events with your account—they never upload capture content

4. Account and sign-in

You may sign in with email one-time codes for membership, feedback tied to your account, and related features. We process your email, verification codes, session identifiers, and profile data (such as membership tier, subscription status, and product beta access).

Account data is handled by our auth and API services for authentication, account management, and cloud features you choose to use.

5. Website and feedback

When you visit devpeek.ypgao.com, hosting and CDN providers may log standard web access data (IP address, browser type, time, and page path) for security and operations.

If you submit feedback via Contact, we process the category you select, email (optional or from your signed-in account), and your message to respond and improve the product.

6. Sharing and disclosure

We do not sell your personal information or capture/debug content. We share personal data only in these cases:

  • With your explicit consent
  • With infrastructure providers (hosting, CDN, email) who process data only as needed to provide the service
  • When required by law, court order, or when reasonably necessary to protect DevPeek, users, or the public

7. Security

We use reasonable technical and organizational measures for account and analytics data we process. Because most debug data stays on your device, its security also depends on your device permissions, disk encryption, backups, and network environment.

Future or optional Pro/Team cloud services are designed with end-to-end encryption (E2EE); DevPeek servers cannot decrypt synced content. Keep your local keys safe.

8. Retention

Local debug data is under your control; how long it is kept depends on your use and deletion actions.

Anonymous analytics and account-related data are kept for a reasonable period to fulfill the purposes above, or longer when required by law, then deleted or anonymized.

9. Your choices

You can remove local debug data by uninstalling the app and deleting local projects and config files.

To opt out of analytics, or to request access or deletion of account-related data, contact us via the website Contact page. We will respond within a reasonable time where applicable law requires.

10. Children

DevPeek is intended for authorized developers and testers, not children. If you believe we collected a child’s personal information without parental consent, please contact us and we will address it promptly.

11. Changes

We may update this policy from time to time. For material changes, we will publish an updated version on the website with a new effective date; the desktop app may also ask you to re-acknowledge terms on launch.

Continued use of DevPeek after an update means you understand and accept the revised policy.

12. Contact us

Questions about this privacy policy or our data practices? Submit feedback via the Contact page on devpeek.ypgao.com.

Appendix: Terms of use (summary)

DevPeek is provided “as is.” You are responsible for how you use it, and may use it only on systems, apps, and environments you own or are explicitly authorized to debug.

Do not use DevPeek for unauthorized capture, data theft, bypassing others’ security controls, or any unlawful purpose. We are not liable for misuse or indirect damages.

The in-app “Terms and privacy notice” shown on first launch is authoritative for bundled terms; for data processing, this privacy policy controls where they differ.

Back to home · Contact