This Privacy Policy explains how DeviceRent ("we", "us", "our") collects, uses, discloses, and safeguards personal data when you use our Service. We process personal data in accordance with the EU General Data Protection Regulation 2016/679 ("GDPR") and other applicable data protection laws. Our physical Android device fleet is hosted in the Netherlands (EU), so the devices you rent — and the data you put on them during a session — stay within the European Union.
1. Data Controller
For the purposes of the GDPR, DeviceRent acts as the data controller for the personal data described in this Policy. Questions, requests, or complaints can be sent to info@devicerent.net.
2. Personal Data We Collect
We collect the following categories of personal data:
- Account data: email address, display name, and any optional profile information you provide.
- Authentication data: hashed passwords, multi-factor authentication factors and recovery codes (TOTP), and session tokens. Plaintext passwords are never stored.
- Billing data: subscription status, plan, billing cycle, and a reference to your customer record at our payment processor (Stripe). Your full payment card number is collected and stored by Stripe; DeviceRent does not have access to it.
- Usage data: session start and end times, device selections, credit balance changes, and similar product telemetry needed to operate the Service.
- Technical data: IP address, browser type, operating system, referrer, and similar information collected automatically through server logs and analytics, used in aggregated form for security and product improvement.
- Communications: the content of any messages you send us through email or in-app channels.
3. Legal Bases for Processing
We rely on the following legal bases under Article 6 of the GDPR:
- Contractual necessity (Art. 6(1)(b)): to create your account, deliver the Service, process your subscription, and provide support.
- Legitimate interests (Art. 6(1)(f)): to keep the Service secure, prevent fraud and abuse, debug problems, and improve the product. We balance these interests against your rights and freedoms.
- Consent (Art. 6(1)(a)): for non-essential cookies and any optional marketing communications. You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)): to retain billing records and respond to lawful requests by public authorities.
4. How We Use Your Data
We process personal data to:
- create and authenticate your account;
- operate device sessions and bill the corresponding fees;
- send transactional emails (e.g., receipts, security alerts);
- provide customer support;
- monitor and protect the Service against abuse;
- comply with applicable legal and tax obligations;
- improve and develop our products in aggregated form.
5. Data Sharing and Sub-Processors
We do not sell personal data. We share it only with sub-processors that help us operate the Service, under written agreements requiring confidentiality and GDPR-compliant safeguards:
- Supabase — authentication and database hosting.
- Stripe — payment processing and subscription billing.
- Vercel — application and edge hosting.
- Resend — transactional email delivery.
- Google Analytics — aggregated usage analytics with IP anonymization where supported.
- AI model providers — Anthropic, OpenAI, Google and Mistral, used only when you start a DeviceyAI session. See section 9 for exactly what is sent.
We may also disclose personal data when required by law, regulation, court order, or to enforce our Terms or protect the rights, property, or safety of DeviceRent, our users, or others.
6. International Data Transfers
Our physical device fleet is located in the Netherlands, and we prioritize EU-based infrastructure for the core Service. Some of our sub-processors operate outside the European Economic Area. Where personal data is transferred to a country that has not received an adequacy decision from the European Commission, we rely on Standard Contractual Clauses or another lawful transfer mechanism, and we apply additional safeguards as appropriate. The AI model providers listed in section 5 are US-based; using the AI DeviceyAI is optional, and starting a session means accepting that its contents are processed outside the EEA on that basis.
7. Data Retention
We retain personal data for as long as your account is active and for a reasonable wind-down period after deletion to handle backups, dispute resolution, and security investigations. Billing and tax records are retained for the period required by applicable law (typically several years). DeviceyAI transcripts, including any screenshots captured during a session, are kept with the account that created them so the actions taken on a device can be reviewed, and are removed when the account is deleted. When personal data is no longer needed, we delete or anonymize it.
8. Your Rights Under the GDPR
If you are in the EEA, the UK, or a comparable jurisdiction, you have the right to:
- access the personal data we hold about you;
- request rectification of inaccurate or incomplete data;
- request erasure of your personal data ("right to be forgotten"), subject to legal retention obligations;
- request restriction of processing in certain situations;
- receive a portable copy of the data you provided to us in a structured, commonly used, machine-readable format;
- object to processing based on legitimate interests;
- withdraw consent at any time without affecting the lawfulness of prior processing;
- lodge a complaint with the data protection supervisory authority of your country.
To exercise any of these rights, email info@devicerent.net. We will respond within the time limits set by applicable law. We may need to verify your identity before fulfilling certain requests.
9. Automated Processing and DeviceyAI
Two parts of the Service process data automatically. Neither produces a decision with legal or similarly significant effects that is made without human involvement, and we do not profile you for advertising or scoring purposes.
Payment-risk automation. If a payment is charged back or is flagged as fraudulent, your account may be placed under review or suspended automatically to protect the fleet and other customers. You can contest any such action by contacting us, and a person will review it.
DeviceyAI. This is optional and off unless you start it. When you do, the following is sent to the AI provider you selected — Anthropic, OpenAI, Google or Mistral:
- the instructions you type, and the model’s replies;
- a text description of what is on the rented phone’s screen, and, when you or DeviceyAI requests one, a screenshot of it;
- the results of the actions it performs on the device, such as command output and the list of installed apps.
Anything you type or display on the rented device during a DeviceyAI session may therefore be transmitted to that provider. Do not sign in to personal accounts or enter real personal data on a rented device while DeviceyAI is running. DeviceyAI has no access beyond what you have in that same session, and it cannot act on the device at all until you explicitly enable actions.
If you supply your own provider API key (“bring your own key”), that data is sent to your own account with that provider and is governed by your agreement with them, not ours. Your key is encrypted at rest and is used only for your own sessions.
Copilot transcripts are stored with your account so that you and our support team can see what DeviceyAI did on a device. They are retained under section 7 and are deleted when you delete your account.
10. Security
We apply reasonable technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, and loss. These include encryption in transit (TLS), hashed credential storage, optional multi-factor authentication for users, row-level security at the database layer, and least-privilege access for our team. No system is perfectly secure; if you believe your account has been compromised, contact us immediately at info@devicerent.net.
11. Shared Devices: What Persists Between Sessions
The Android devices in our fleet are shared, physical hardware that is rented to one customer at a time. Between rentals each device is automatically wiped: applications you installed are removed, shared storage is erased and verified to be empty, the temporary directory is cleared, and settings a session can change — including accessibility services, the selected keyboard, and any always-on VPN — are reset. A device that fails any of these checks is taken out of service rather than handed to the next customer.
You should nevertheless treat a rented device as a public, untrusted computer. Please do not sign in to personal accounts, enter passwords or payment details, or place personal data on a device. Anything you do put on one is processed as described in this Policy, but a shared device is not a private environment and we ask you not to use it as one.
Two specifics we think you are entitled to know rather than discover:
- The devices carry an operator-owned Google account. It exists so that Google Play and related services work during your session, it is ours rather than yours, and it is not removed by the between-rental wipe. It is shared by every customer who rents that device. Do not use it to make purchases, and do not rely on it for storage — anything associated with it may be visible to, or altered by, other customers. Do not add your own Google account to a device.
- Some system-level changes cannot be verified as reversed. A rented device gives you developer-level access, which is the product. Certain changes that level of access permits — most notably installing a user certificate authority — are stored in a location our wipe process cannot read or clear on these devices. We do not claim to detect or undo them, and we log each wipe accordingly rather than reporting a device clean when we cannot prove it. This is one of the reasons for the guidance above.
Where a device is used to process personal data, our Terms govern your own obligations as a controller of that data.
12. Children's Privacy
The Service is not directed at children under the age of 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so that we can delete it.
13. Cookies
We use cookies and similar technologies as described in our Cookie Policy.
14. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will give reasonable notice before they take effect (for example, by email or in-app notice). The "Effective" date at the top of this page reflects the most recent revision.
15. Contact
For privacy questions or to exercise your rights, email info@devicerent.net.