Legal
What Appeeky collects, why, where it is stored, who processes it, and the choices you have across the web dashboard, API, MCP server, mobile app, and desktop app.
Last updated: June 10, 2026
Appeeky ("Appeeky", "we", "us") operates an app-store intelligence platform for mobile app teams: the web dashboard at appeeky.com, the Appeeky REST API, the Appeeky MCP server, the mobile app, the desktop app, and the AI co-founder. This policy covers all of them.
It applies to visitors of our website, account holders, API key holders, and people whose data is processed because a customer connected a third-party account. It does not cover the public app pages that our customers publish under their own name through Appeeky; those are governed by the customer's own policies.
Appeeky is the data controller for account, billing, and usage data. For data you pull from your own store, ads, or analytics accounts, you are the controller and Appeeky processes it on your instructions.
We collect the following categories of information.
Much of what Appeeky shows you is aggregated from publicly available sources: the Apple App Store, Google Play, iTunes Search, RSS charts, public web pages, and licensed third-party data providers. That data describes apps and developers, not individual end users of those apps. Where public reviews carry an author name, we display it as the store displays it and do not link it to any Appeeky account.
We store, cache, and derive estimates from this data to run the service. Section 8 of the Terms of Service governs how you may use it.
Where the GDPR, the UK GDPR, or a similar law applies, we rely on the legal bases named below.
The AI co-founder, keyword and review analysis, creative generation, and similar features send relevant context from your account and connected data to third-party model providers so they can produce the output you requested. Providers we use include Anthropic, OpenAI, Google, DeepSeek, Moonshot, and Perplexity. Each is bound by contract to use the data only to serve the request and not to train their models on it.
We do not use your connected-platform credentials or your private store data to train any model, and we do not sell prompts or outputs. Where a provider offers a zero-data-retention option, we use it.
AI outputs are estimates and suggestions, not facts. Automated actions (for example, the co-founder pausing a keyword bid or replying to a review) run only within the permissions you enabled and are logged in your workspace.
We do not make decisions about you that have legal or similarly significant effects based solely on automated processing.
We do not sell personal information and we do not share it with data brokers. We share it only as follows.
Customer data is stored in Supabase (PostgreSQL) in the European Union (AWS eu-west-1, Ireland). The API and background workers run on Railway in the United States (us-west2) and on Trigger.dev. Caches and rate-limit counters live in Redis on Railway. The current subprocessor list is:
When personal data leaves the EU or UK we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, together with the subprocessor's own security certifications. Email us for a copy of the current transfer terms.
We will update this list and, for material additions, notify workspace owners by email at least 14 days before the new subprocessor processes customer data.
We keep data only as long as it serves the purpose it was collected for.
We protect data with encryption in transit (TLS 1.2 or higher), encryption at rest, application-level encryption of platform credentials with a separately managed key, role-based access inside the company, row-level security in the database, per-key rate limits and burst caps on the API, and audit logging of privileged operations.
Production access is limited to named staff, uses multi-factor authentication, and is reviewed regularly. Secrets are never stored in source control.
No system is perfectly secure. If we learn of a breach affecting your personal data we will notify you and the relevant authority without undue delay, and where the law requires within 72 hours of becoming aware.
The web dashboard uses strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. Our marketing site uses privacy-respecting, cookie-free analytics where enabled and Sentry for error reporting. We do not run third-party advertising trackers.
The desktop and mobile apps store session tokens in the operating system keychain or secure storage, not in cookies.
The desktop app caches store and ads data locally so that analysis works offline. Local databases and credentials remain on your device, in the operating system's secure credential store where available, and are not uploaded unless you use a cloud feature. You can clear caches and remove credentials from the desktop settings at any time.
The mobile app requests notification permission only if you enable alerts, and does not access contacts, photos, or location.
Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, to object to processing based on legitimate interest, to withdraw consent, and to lodge a complaint with a supervisory authority.
Residents of California and other US states with comprehensive privacy laws have the right to know what we collect, to delete it, to correct it, and to opt out of sale or sharing. We do not sell or share personal information as those laws define it, and we do not discriminate against anyone who exercises their rights.
You can update account details, disconnect integrations, export data, and delete your account from the dashboard. For anything else, email hey@appeeky.com from the address on your account; we answer within 30 days and may ask you to verify your identity.
If you are an end user of a customer's app and your data reached Appeeky through that customer, contact the customer first. We will help them respond.
Google user data received through Google APIs (Google Play Console, Google sign-in) is used only to provide the features you enabled, is never sold or used for advertising, and is never used to train generalised AI models. Our use complies with the Google API Services User Data Policy, including its Limited Use requirements.
Apple data received through App Store Connect and Apple Search Ads is used only for your workspace and is handled under Apple's developer program terms. We do not use Apple analytics data to build profiles of app end users.
Appeeky is a business tool and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
We may update this policy as the service and the law change. Each version carries a number and an effective date and is archived in our records. For material changes we email workspace owners at least 14 days before the effective date; for other changes we update the date at the top of this page.
Privacy questions, requests, and complaints: hey@appeeky.com. Include "Privacy" in the subject line so it reaches the right person quickly.
Questions? Contact hey@appeeky.com.