1. Introduction
DevelopedByGolds ("DBG," "we," "us," or "our") operates the DBG Ecosystem, a collection of free digital applications accessible through a unified account system. This Privacy Policy describes how we collect, use, store, and protect your information across all DBG applications, including but not limited to:
- DBG Account (account.developedbygolds.qzz.io) — Unified authentication portal
- DBG Tools (tools.developedbygolds.qzz.io) — Digital utility platform
- DBG Music (musics.developedbygolds.qzz.io) — Music player
- DBG Holds (holds.developedbygolds.qzz.io) — Expense tracker
- DBG Chats (chats.developedbygolds.qzz.io) — Messaging platform
- DBGCoin (credits.developedbygolds.qzz.io) — Crypto dashboard
By using any DBG application, you agree to the practices described in this policy. If you do not agree, please do not use our services.
2. Information We Collect
Account Information: When you create a DBG account, we collect your email address, display name, and authentication provider (email/password or GitHub OAuth). We do not collect or store your password in plaintext — authentication is handled securely by Firebase Authentication.
Usage Data: We collect minimal usage data necessary to provide our services, including:
- Login timestamps and device metadata (browser, OS) for security auditing
- Tool usage analytics (which tools you use, session duration) for product improvement
- XP/activity records for the ecosystem rewards system
Local Data: Certain DBG tools store data locally in your browser (localStorage, IndexedDB) for offline functionality. This data never leaves your device unless you explicitly sync it to our servers.
We Do NOT Collect:
- Payment information (all services are free)
- Location data
- Biometric data
- Third-party tracking cookies
- Social media profiles (beyond OAuth authentication)
3. How We Use Your Information
We use the information we collect solely for:
- Authentication: Verifying your identity and maintaining your session across DBG applications
- Service Delivery: Providing the features and tools you request
- Security: Detecting and preventing unauthorized access, abuse, and fraud
- Improvement: Understanding how our tools are used to improve functionality
- Communication: Sending security alerts and account-related notifications (you can opt out of non-essential notifications)
4. Data Storage & Security
Your data is stored in Google Cloud Firestore, a SOC 2 and ISO 27001 compliant database service. We implement the following security measures:
- Encryption in Transit: All data is transmitted over TLS 1.3 (HTTPS)
- Encryption at Rest: Firestore encrypts all data at rest using AES-256
- Access Control: Firestore Security Rules enforce that users can only access their own data
- Session Security: Session cookies use Secure, HttpOnly, and SameSite=Lax attributes
- Content Security Policy: Strict CSP headers prevent cross-site scripting attacks
- Brute-Force Protection: Rate limiting and exponential backoff on authentication attempts
5. Cross-Domain SSO (Single Sign-On)
The DBG Ecosystem uses a cross-domain Single Sign-On mechanism to allow you to access all applications with one account. This works as follows:
- When you sign in, a session token is stored in an HttpOnly cookie scoped to
.developedbygolds.qzz.io
- Each DBG application verifies this token to confirm your authentication state
- The token expires after 55 minutes and is automatically refreshed while you are active
- You can revoke all sessions at any time from the Security settings in your dashboard
6. Third-Party Services
We use the following third-party services that may process data on our behalf:
- Firebase (Google): Authentication, database, and hosting
- Netlify: Website hosting and edge functions
- Google Fonts: Font delivery (subject to Google's Privacy Policy)
These services are bound by their own privacy policies and are contractually obligated to protect your data.
7. Data Retention
We retain your data for as long as your account is active. When you delete your account:
- Your Firebase Authentication account is permanently deleted
- Your Firestore user profile and all subcollections are deleted within 30 days
- Activity logs may be retained for up to 90 days for security auditing
- Local browser data (localStorage, cookies) is your responsibility to clear
8. Your Rights
You have the right to:
- Access: View all data we hold about you (available in your dashboard under Data Export)
- Correction: Update your display name and profile information at any time
- Deletion: Delete your account and all associated data permanently
- Export: Download your data in JSON or CSV format from your dashboard
- Opt-Out: Disable email notifications and cloud sync in your settings
9. Children's Privacy
DBG services are not directed to individuals under the age of 13. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take steps to delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification. The "Last Updated" date at the top of this page indicates when the policy was last revised.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at: