Privacy Policy
Last updated: 13 September 2026
1. Who we are
Druve (“we”, “us”) operates this marketplace connecting businesses that hire AI agents with the independent developers who build them. For any privacy question or request, contact us at druve.support@gmail.com.
2. What we collect
- Account data: your email address, and, if you provide them, your name and company name. Your password is handled entirely by our authentication provider (Supabase); it is stored only as a secure one-way hash and is never visible to us.
- Role: whether you use Druve as a customer (hiring agents) or a developer (building them).
- Marketplace content you create: agents you publish, orders you post, bids you place, hires you make, and messages you send to a hired agent.
- Usage counters: the number of requests made against an agent you hired, so we can display your usage meter. Each run is stored as a timestamp against the hire, nothing else. Neither the prompt nor the output passes through Druve: the agent runs on your machine and talks to your own model provider.
- Device seats:when you activate a hired agent on a computer, we store a server-issued random device id and the label you give it (e.g. “Work laptop”). It is not a hardware fingerprint.
- Reviews and outcomes: the star rating and comment you leave on a hire, and whether you marked a job complete or flagged it (with the reason you typed).
- Payments: PayPal order and subscription identifiers for hires, and Paddle subscription and customer identifiers for developer plans and the Certified badge, with amounts and timestamps, so we can show what you paid and pay developers their share. Card numbers never reach us. For a Certified review application we also keep the PayPal payer id from that payment, to stop one person applying through several Druve accounts.
- Bug reports: what you type into the report form, the page you were on, your browser name, operating system and window size, and, if you choose to leave it or you were signed in, your email so we can tell you when it is fixed. Read only by Druve staff.
- Developer data:for developers, the PayPal or Venmo address you verify for payouts (and, while you verify it, a hashed one-time code that expires in ten minutes), the GitHub file link behind each listing and a copy of that file at the exact commit you published (Druve serves this copy to your customers, so a private repository works and a later change to the repository does not change what they run), automated security-scan findings on that code, a reviewer’s notes on a Certified application, and, on Pro and Max, sandbox test runs you choose to save (the code, input, and output). If you give us a GitHub token to read a private repository, it is used for that one download and is not stored.
- Things you send us: waitlist emails, enterprise enquiries (company, name, email, message), and support emails.
2a. What we measure, and the statistics we show
Some numbers on Druve are computed from the data above. This is every one of them, and what feeds it. None of it uses cookies, IP addresses, or anything from outside Druve.
- Listing views:opening an agent’s page records one anonymous row: the agent and a timestamp. No account id, no IP address, no browser details. The developer sees only totals over time.
- Developer analytics(Pro and Max): views, hires, trial starts and trial-to-paid conversions for that developer’s own listings, as counts. A developer never sees which customer hired them beyond what the hire itself shows.
- Reputation on a listing: average rating, number of reviews, jobs marked complete, and jobs flagged, computed from the reviews and outcomes above.
- Certified statistics: we compare, in aggregate over the last 90 days, how often Certified listings are hired versus other listings, and show that figure to developers considering a review. It is a ratio across all listings, never a per-customer or per-listing disclosure, and it is only shown once enough hires exist for the number to mean something.
- Your activity calendar (developers, on your own Build page): built from the dates you created agents and the dates your agents were hired. Only you see it.
- Rate limits:the CLI’s license-resolve endpoint keeps the caller’s IP address with a timestamp for a short window to limit abuse, and for nothing else. Sandbox and run endpoints count requests per account or per hire.
- Marketplace ranking uses none of this: listings are ordered by what you choose in the sort control (newest, price, rating), and a paid plan or a Certified badge never changes ranking or search relevance.
If we ever add a new statistic, it will be listed here before it is shown anywhere on the site.
3. What we do NOT collect
- No advertising or third-party tracking cookies.
- No analytics profiles, fingerprinting, or cross-site tracking. The only counting we do is listed in section 2a, and none of it identifies you.
- No API keys, prompts, or agent outputs: those stay between your machine and your model provider.
- No selling or renting of personal information to anyone, ever.
- No payment card numbers are stored by us. Paid billing is handled by PayPal (hires) and Paddle (developer plans and the Certified badge), both PCI-compliant processors, and card details never pass through our servers.
4. Cookies & local storage
Every item below is first-party, functional, and never used for advertising or cross-site tracking. None of them leave your device or get read by anyone but Druve.
- Essential login cookie (set by Supabase Auth): keeps you signed in. The site cannot function without it, so it is exempt from consent requirements under most cookie laws.
- Theme preference (
druve_theme, cookie and local storage): remembers light/dark mode. - Reduced motion (
druve_reduce_motion, local storage): remembers a preference to minimize animation. - Marketplace view density (
druve_compact_marketplace, cookie): remembers whether you prefer the compact or default listing layout. - Billing cadence (
druve_billing_interval, cookie): remembers whether you last viewed developer-plan pricing as weekly or monthly. - Cookie notice acknowledgment (
druve_cookie_ack, local storage): remembers that you have dismissed the cookie notice banner.
5. How we use your data
Solely to operate the service: to authenticate you, show your agents/hires/orders, run the marketplace matching, display reputation and usage, and keep the platform secure. The legal bases are performance of our contract with you (running your account) and our legitimate interest in operating and securing the platform.
6. Who processes it
Data is stored with Supabase (our database and authentication provider), payments run through PayPal and Paddle, the site is served from Vercel, and the one email Druve itself sends, a payout-address verification code, goes through Resend. If a developer configures a webhook URL for their listings (Pro and Max), we send hire and review events (agent, hire id, rating) to that URL they chose; that is the developer’s own endpoint, not a third party of ours. Agents themselves run on your machine and call your own model provider directly; Druve is not in that path and never receives your key, your prompts, or the agent’s output. These processors handle data on our behalf under their own security commitments. Depending on the hosting region, your data may be processed outside your country; where required, we rely on appropriate safeguards for such transfers.
7. How long we keep it
We keep your account data for as long as your account is active. Marketplace content is retained while relevant to the service. When you delete your account, we delete your personal data (records tied to your account cascade-delete), except where we must retain limited records to comply with the law.
8. Your rights
Depending on where you live (e.g. under the EU/UK GDPR, California’s CCPA/CPRA, or South Korea’s PIPA), you may have the right to access, correct, delete, or export your personal data, to object to or restrict processing, and to opt out of any sale or sharing (note: we do not sell or share your data). To exercise any right, email druve.support@gmail.com and we will respond within the timeframe your local law requires.
9. Children
Druve is not intended for anyone under 16, and we do not knowingly collect data from children.
10. Changes
We may update this policy; we will revise the “last updated” date above and, for material changes, notify you.