Privacy policy
Local analysis should stay local.
This notice explains what Developer Defence keeps on your device, what limited information reaches our service, and the choices available to you.
Effective:
23 July 2026
Controller:
Jam Data Solutions Ltd
Scope and controller
This policy covers the Developer Defence desktop application and the public website and service at developerdefence.com.
Developer Defence is operated by Jam Data Solutions Ltd, company number 14075684, of 102-116 Windmill Road, Croydon, England, CR0 2XQ. Jam Data Solutions Ltd is the data controller for the personal data described here.
The current scanner does not upload your source code, local package inventory, project paths, lockfiles, findings, scan history, or vault contents to Developer Defence.
Data kept on your device
Package discovery and vulnerability matching run on your computer. The application reads directory metadata and supported package manifests or lockfiles inside the scan boundaries you configure.
The mutable application-state PersonalDB stores information needed to operate the app, including:
- scan roots, exclusions, traversal limits, schedule, and ecosystem choices;
- discovered projects, package coordinates, local occurrences, findings, suppressions, and scan history;
- intelligence release identifiers and digests used for each finding;
- application preferences and pseudonymous device-authority state.
A separate, read-only PersonalDB contains signed threat intelligence. Encryption and device signing keys are stored through the operating system's secure credential store. Where protected paths and vaults are available, vault contents remain encrypted locally and are not sent to our service.
Data sent to our service
The application makes bounded network requests for device authority, signed intelligence updates, downloads, and features you explicitly request.
- DataPseudonymous device dataPurpose and legal basisA random device identifier, device DID and public key, installation nonce, platform, architecture, and app version let us issue and verify device authority. We process this to provide and secure the service.WhenOn first enrolment and credential refresh.
- DataIntelligence request dataPurpose and legal basisRequested release or ecosystem profile, protocol metadata, IP address, time, response status, and app version support signed updates, reliability, and abuse prevention. We rely on service performance and our legitimate security interests.WhenWhen checking for or downloading updates.
- DataOptional email noticesPurpose and legal basisIf you subscribe, we store your email address, platform, locale, app version, subscription source, and timestamps to send the notice you requested. We rely on your consent.WhenOnly after you submit the form.
- DataSupport communicationsPurpose and legal basisYour email, message, and attachments let us investigate and respond. We rely on taking steps at your request and our legitimate interest in supporting the product.WhenWhen you contact support.
Data | Purpose and legal basis | When |
|---|---|---|
Pseudonymous device data | A random device identifier, device DID and public key, installation nonce, platform, architecture, and app version let us issue and verify device authority. We process this to provide and secure the service. | On first enrolment and credential refresh. |
Intelligence request data | Requested release or ecosystem profile, protocol metadata, IP address, time, response status, and app version support signed updates, reliability, and abuse prevention. We rely on service performance and our legitimate security interests. | When checking for or downloading updates. |
Optional email notices | If you subscribe, we store your email address, platform, locale, app version, subscription source, and timestamps to send the notice you requested. We rely on your consent. | Only after you submit the form. |
Support communications | Your email, message, and attachments let us investigate and respond. We rely on taking steps at your request and our legitimate interest in supporting the product. | When you contact support. |
Standard network infrastructure may necessarily process your IP address to deliver a response. We do not use device enrolment or intelligence requests to create advertising profiles.
Website analytics and storage
Optional analytics are off until you choose Allow analytics. If you allow them, the site loads Google Tag Manager, which may enable configured analytics tags to process page URLs, referral information, browser and device details, approximate location derived from IP address, and analytics identifiers.
Your choice is stored in local browser storage under developer-defence-analytics-consent-v1. Selecting Continue without analytics does not limit the website. You can withdraw or change the choice using the Cookie settings button on this page or in the footer.
Essential delivery logs may still record IP address, request time, requested path, user agent, and response status for security and reliability.
Sharing and international transfers
We use service providers for infrastructure, release distribution, email delivery, error investigation, and consented website analytics. They process data only for the relevant service and under their own contractual and legal obligations.
Signed application installers may be delivered through our download proxy from private GitHub releases. Google may process consented website analytics in countries outside the United Kingdom. Where personal data is transferred internationally, we use an applicable adequacy decision or approved contractual safeguards.
We may disclose information when required by law, to protect users or the service, or as part of a corporate transaction with appropriate confidentiality safeguards. We do not sell personal data.
Retention and deletion
Local scanner data remains on your device until you remove it through the product or uninstall and delete its application data. Secure credential items may require separate removal through the operating system credential manager.
We retain active device-authority records while a device is enrolled, with limited security and audit records retained only as needed to prevent replay, investigate abuse, meet legal obligations, and prove revocation. Operational request logs are retained for a limited period based on security and reliability needs.
Email subscriptions remain active until you withdraw consent or the requested notice has been delivered and no continuing purpose remains. Support records are kept for as long as needed to resolve the request, maintain an appropriate history, and meet legal obligations.
Your choices and rights
Depending on where you live, you may have rights to access, correct, erase, restrict, or receive personal data, and to object to certain processing. You may withdraw consent at any time without affecting processing that was lawful before withdrawal.
- Change scan roots, exclusions, schedules, and intelligence ecosystems in the app.
- Decline or reset optional website analytics.
- Ask us to unsubscribe an email address.
- Request access to or deletion of cloud-held device or account information.
Contact [email protected] to exercise a right. We may need to verify that you control the relevant device, account, or email address. You may also complain to the UK Information Commissioner's Office.
Security
Developer Defence separates mutable local state from signed read-only intelligence. Intelligence metadata and application release descriptors are verified against trusted signing keys before activation. Device private keys and local encryption keys are kept in operating-system secure storage, and network requests use encrypted transport.
No system can guarantee absolute security. If you believe you found a security issue, contact [email protected] with the subject Security report. Do not include live credentials, private source code, or exploit data that could put others at risk.
Changes and contact
We will update this page when our data practices materially change and revise the effective date above. Material changes will be explained in the application or on this site where appropriate.
Jam Data Solutions Ltd, trading as Developer Defence
Company number 14075684
102-116 Windmill Road, Croydon, England, CR0 2XQ
Privacy and support: [email protected]
Scope and controller
This policy covers the Developer Defence desktop application and the public website and service at developerdefence.com.
Developer Defence is operated by Jam Data Solutions Ltd, company number 14075684, of 102-116 Windmill Road, Croydon, England, CR0 2XQ. Jam Data Solutions Ltd is the data controller for the personal data described here.
The current scanner does not upload your source code, local package inventory, project paths, lockfiles, findings, scan history, or vault contents to Developer Defence.
Data kept on your device
Package discovery and vulnerability matching run on your computer. The application reads directory metadata and supported package manifests or lockfiles inside the scan boundaries you configure.
The mutable application-state PersonalDB stores information needed to operate the app, including:
- scan roots, exclusions, traversal limits, schedule, and ecosystem choices;
- discovered projects, package coordinates, local occurrences, findings, suppressions, and scan history;
- intelligence release identifiers and digests used for each finding;
- application preferences and pseudonymous device-authority state.
A separate, read-only PersonalDB contains signed threat intelligence. Encryption and device signing keys are stored through the operating system's secure credential store. Where protected paths and vaults are available, vault contents remain encrypted locally and are not sent to our service.
Data sent to our service
The application makes bounded network requests for device authority, signed intelligence updates, downloads, and features you explicitly request.
- DataPseudonymous device dataPurpose and legal basisA random device identifier, device DID and public key, installation nonce, platform, architecture, and app version let us issue and verify device authority. We process this to provide and secure the service.WhenOn first enrolment and credential refresh.
- DataIntelligence request dataPurpose and legal basisRequested release or ecosystem profile, protocol metadata, IP address, time, response status, and app version support signed updates, reliability, and abuse prevention. We rely on service performance and our legitimate security interests.WhenWhen checking for or downloading updates.
- DataOptional email noticesPurpose and legal basisIf you subscribe, we store your email address, platform, locale, app version, subscription source, and timestamps to send the notice you requested. We rely on your consent.WhenOnly after you submit the form.
- DataSupport communicationsPurpose and legal basisYour email, message, and attachments let us investigate and respond. We rely on taking steps at your request and our legitimate interest in supporting the product.WhenWhen you contact support.
Data | Purpose and legal basis | When |
|---|---|---|
Pseudonymous device data | A random device identifier, device DID and public key, installation nonce, platform, architecture, and app version let us issue and verify device authority. We process this to provide and secure the service. | On first enrolment and credential refresh. |
Intelligence request data | Requested release or ecosystem profile, protocol metadata, IP address, time, response status, and app version support signed updates, reliability, and abuse prevention. We rely on service performance and our legitimate security interests. | When checking for or downloading updates. |
Optional email notices | If you subscribe, we store your email address, platform, locale, app version, subscription source, and timestamps to send the notice you requested. We rely on your consent. | Only after you submit the form. |
Support communications | Your email, message, and attachments let us investigate and respond. We rely on taking steps at your request and our legitimate interest in supporting the product. | When you contact support. |
Standard network infrastructure may necessarily process your IP address to deliver a response. We do not use device enrolment or intelligence requests to create advertising profiles.
Website analytics and storage
Optional analytics are off until you choose Allow analytics. If you allow them, the site loads Google Tag Manager, which may enable configured analytics tags to process page URLs, referral information, browser and device details, approximate location derived from IP address, and analytics identifiers.
Your choice is stored in local browser storage under developer-defence-analytics-consent-v1. Selecting Continue without analytics does not limit the website. You can withdraw or change the choice using the Cookie settings button on this page or in the footer.
Essential delivery logs may still record IP address, request time, requested path, user agent, and response status for security and reliability.
Sharing and international transfers
We use service providers for infrastructure, release distribution, email delivery, error investigation, and consented website analytics. They process data only for the relevant service and under their own contractual and legal obligations.
Signed application installers may be delivered through our download proxy from private GitHub releases. Google may process consented website analytics in countries outside the United Kingdom. Where personal data is transferred internationally, we use an applicable adequacy decision or approved contractual safeguards.
We may disclose information when required by law, to protect users or the service, or as part of a corporate transaction with appropriate confidentiality safeguards. We do not sell personal data.
Retention and deletion
Local scanner data remains on your device until you remove it through the product or uninstall and delete its application data. Secure credential items may require separate removal through the operating system credential manager.
We retain active device-authority records while a device is enrolled, with limited security and audit records retained only as needed to prevent replay, investigate abuse, meet legal obligations, and prove revocation. Operational request logs are retained for a limited period based on security and reliability needs.
Email subscriptions remain active until you withdraw consent or the requested notice has been delivered and no continuing purpose remains. Support records are kept for as long as needed to resolve the request, maintain an appropriate history, and meet legal obligations.
Your choices and rights
Depending on where you live, you may have rights to access, correct, erase, restrict, or receive personal data, and to object to certain processing. You may withdraw consent at any time without affecting processing that was lawful before withdrawal.
- Change scan roots, exclusions, schedules, and intelligence ecosystems in the app.
- Decline or reset optional website analytics.
- Ask us to unsubscribe an email address.
- Request access to or deletion of cloud-held device or account information.
Contact [email protected] to exercise a right. We may need to verify that you control the relevant device, account, or email address. You may also complain to the UK Information Commissioner's Office.
Security
Developer Defence separates mutable local state from signed read-only intelligence. Intelligence metadata and application release descriptors are verified against trusted signing keys before activation. Device private keys and local encryption keys are kept in operating-system secure storage, and network requests use encrypted transport.
No system can guarantee absolute security. If you believe you found a security issue, contact [email protected] with the subject Security report. Do not include live credentials, private source code, or exploit data that could put others at risk.
Changes and contact
We will update this page when our data practices materially change and revise the effective date above. Material changes will be explained in the application or on this site where appropriate.
Jam Data Solutions Ltd, trading as Developer Defence
Company number 14075684
102-116 Windmill Road, Croydon, England, CR0 2XQ
Privacy and support: [email protected]