appeeky

Legal

Privacy Policy

What Appeeky collects, why, where it is stored, who processes it, and the choices you have across the web dashboard, API, MCP server, mobile app, and desktop app.

Last updated: June 10, 2026

1. Who we are and what this policy covers

Appeeky ("Appeeky", "we", "us") operates an app-store intelligence platform for mobile app teams: the web dashboard at appeeky.com, the Appeeky REST API, the Appeeky MCP server, the mobile app, the desktop app, and the AI co-founder. This policy covers all of them.

It applies to visitors of our website, account holders, API key holders, and people whose data is processed because a customer connected a third-party account. It does not cover the public app pages that our customers publish under their own name through Appeeky; those are governed by the customer's own policies.

Appeeky is the data controller for account, billing, and usage data. For data you pull from your own store, ads, or analytics accounts, you are the controller and Appeeky processes it on your instructions.

2. Information we collect

We collect the following categories of information.

  • Account data: name, email address, avatar, workspace name, and the identifier returned by the sign-in provider you choose (Google, GitHub, or Apple). We never see your password for those providers.
  • Billing data: plan, subscription status, invoices, and the last four digits and brand of your payment card. Card numbers are handled only by Stripe.
  • Connected-platform credentials: App Store Connect API keys, Google Play service-account keys and report-bucket names, Apple Search Ads certificates, RevenueCat, Meta Ads, TikTok Ads, Pinterest, LinkedIn, Slack, Notion, Linear, GitHub, Reddit, and Telegram tokens that you choose to connect. Credentials are encrypted at rest with a key that is separate from the database.
  • Connected-platform data: sales, subscription, download, install, crash, rating, review, keyword, search-term, campaign, and spend data that we retrieve on your behalf from the platforms above.
  • Product usage data: pages viewed, features used, API endpoints called, credits consumed, error reports, and the prompts and outputs of AI features you run.
  • API access logs: for every API or MCP request we record the API key, endpoint, response status, duration, source IP address, user agent, and timestamp. We use these to bill credits, enforce rate limits, detect abuse, and debug incidents.
  • Technical data: IP address, device type, operating system, browser or app version, and approximate location derived from the IP address.
  • Support data: messages you send us by email or through integrations, and any attachments.

3. Public store and market data

Much of what Appeeky shows you is aggregated from publicly available sources: the Apple App Store, Google Play, iTunes Search, RSS charts, public web pages, and licensed third-party data providers. That data describes apps and developers, not individual end users of those apps. Where public reviews carry an author name, we display it as the store displays it and do not link it to any Appeeky account.

We store, cache, and derive estimates from this data to run the service. Section 8 of the Terms of Service governs how you may use it.

4. How we use information and on what legal basis

Where the GDPR, the UK GDPR, or a similar law applies, we rely on the legal bases named below.

  • To provide the service you signed up for, including syncing and displaying connected-platform data, running AI features you trigger, and answering support requests (performance of a contract).
  • To bill you, keep accounting records, and prevent fraud (contract and legal obligation).
  • To secure the platform, enforce rate limits and burst caps, investigate abuse, and protect other customers (legitimate interest).
  • To measure, debug, and improve the product, including analysing aggregate usage patterns (legitimate interest).
  • To send service notices such as security alerts, billing notices, and material changes to these terms (legitimate interest and legal obligation).
  • To send product news and marketing email, which you can opt out of at any time (consent, or legitimate interest for existing customers where the law allows).
  • To comply with the law and respond to lawful requests (legal obligation).

5. AI features and automated processing

The AI co-founder, keyword and review analysis, creative generation, and similar features send relevant context from your account and connected data to third-party model providers so they can produce the output you requested. Providers we use include Anthropic, OpenAI, Google, DeepSeek, Moonshot, and Perplexity. Each is bound by contract to use the data only to serve the request and not to train their models on it.

We do not use your connected-platform credentials or your private store data to train any model, and we do not sell prompts or outputs. Where a provider offers a zero-data-retention option, we use it.

AI outputs are estimates and suggestions, not facts. Automated actions (for example, the co-founder pausing a keyword bid or replying to a review) run only within the permissions you enabled and are logged in your workspace.

We do not make decisions about you that have legal or similarly significant effects based solely on automated processing.

6. How we share information

We do not sell personal information and we do not share it with data brokers. We share it only as follows.

  • With subprocessors that host and run the service (section 7).
  • With the store, ads, and productivity platforms you connect, when you authorise Appeeky to act on your behalf.
  • With other members of your workspace, according to the roles you assign.
  • With professional advisers, insurers, and auditors under confidentiality obligations.
  • With law enforcement or regulators when required by law, or to protect the rights, property, or safety of Appeeky, our customers, or the public.
  • With a successor in a merger, acquisition, financing, or asset sale, in which case this policy continues to apply to the transferred data.

7. Subprocessors and data location

Customer data is stored in Supabase (PostgreSQL) in the European Union (AWS eu-west-1, Ireland). The API and background workers run on Railway in the United States (us-west2) and on Trigger.dev. Caches and rate-limit counters live in Redis on Railway. The current subprocessor list is:

  • Supabase: database, authentication, and file storage (EU).
  • Railway: API hosting, Redis, and logs (US).
  • Vercel: web dashboard hosting and edge network (global).
  • Trigger.dev: background jobs such as store syncs and co-founder runs (US).
  • Stripe: payments and invoicing (US, EU entities).
  • Resend: transactional email (US).
  • Sentry: error monitoring (US, EU region where configured).
  • Anthropic, OpenAI, Google, DeepSeek, Moonshot, Perplexity, Exa: AI models and web research (US and other regions).
  • DataForSEO and similar market-data providers: keyword and search data (US, EU).
  • Composio and Postiz: social and productivity integrations you enable (US, EU).
  • Residential and datacenter proxy providers: used only to fetch public store pages; they see the public URL, never your account data.

When personal data leaves the EU or UK we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, together with the subprocessor's own security certifications. Email us for a copy of the current transfer terms.

We will update this list and, for material additions, notify workspace owners by email at least 14 days before the new subprocessor processes customer data.

8. Data retention

We keep data only as long as it serves the purpose it was collected for.

  • Account and workspace data: for the life of the account, then deleted within 30 days of a verified deletion request or 90 days after the account is closed.
  • Connected-platform credentials: until you disconnect the integration or delete the account; deleted immediately on disconnect.
  • Synced connected-platform data: for the life of the connection, then deleted within 30 days of disconnect.
  • API access logs: 13 months, so that yearly usage can be reconciled and abuse patterns detected.
  • AI prompts and outputs: for the life of the workspace, or 90 days for features that store nothing in the workspace.
  • Billing records: 10 years, as required by tax and accounting law.
  • Backups: rolling 30-day backups, after which deleted data is gone from backups as well.
  • Public store and market data: retained indefinitely as an aggregate dataset; it does not identify Appeeky users.

9. Security

We protect data with encryption in transit (TLS 1.2 or higher), encryption at rest, application-level encryption of platform credentials with a separately managed key, role-based access inside the company, row-level security in the database, per-key rate limits and burst caps on the API, and audit logging of privileged operations.

Production access is limited to named staff, uses multi-factor authentication, and is reviewed regularly. Secrets are never stored in source control.

No system is perfectly secure. If we learn of a breach affecting your personal data we will notify you and the relevant authority without undue delay, and where the law requires within 72 hours of becoming aware.

10. Cookies and similar technologies

The web dashboard uses strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. Our marketing site uses privacy-respecting, cookie-free analytics where enabled and Sentry for error reporting. We do not run third-party advertising trackers.

The desktop and mobile apps store session tokens in the operating system keychain or secure storage, not in cookies.

11. Desktop and mobile apps

The desktop app caches store and ads data locally so that analysis works offline. Local databases and credentials remain on your device, in the operating system's secure credential store where available, and are not uploaded unless you use a cloud feature. You can clear caches and remove credentials from the desktop settings at any time.

The mobile app requests notification permission only if you enable alerts, and does not access contacts, photos, or location.

12. Your rights

Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, to object to processing based on legitimate interest, to withdraw consent, and to lodge a complaint with a supervisory authority.

Residents of California and other US states with comprehensive privacy laws have the right to know what we collect, to delete it, to correct it, and to opt out of sale or sharing. We do not sell or share personal information as those laws define it, and we do not discriminate against anyone who exercises their rights.

You can update account details, disconnect integrations, export data, and delete your account from the dashboard. For anything else, email hey@appeeky.com from the address on your account; we answer within 30 days and may ask you to verify your identity.

If you are an end user of a customer's app and your data reached Appeeky through that customer, contact the customer first. We will help them respond.

13. Platform-specific commitments

Google user data received through Google APIs (Google Play Console, Google sign-in) is used only to provide the features you enabled, is never sold or used for advertising, and is never used to train generalised AI models. Our use complies with the Google API Services User Data Policy, including its Limited Use requirements.

Apple data received through App Store Connect and Apple Search Ads is used only for your workspace and is handled under Apple's developer program terms. We do not use Apple analytics data to build profiles of app end users.

14. Children

Appeeky is a business tool and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

15. Changes to this policy

We may update this policy as the service and the law change. Each version carries a number and an effective date and is archived in our records. For material changes we email workspace owners at least 14 days before the effective date; for other changes we update the date at the top of this page.

16. Contact

Privacy questions, requests, and complaints: hey@appeeky.com. Include "Privacy" in the subject line so it reaches the right person quickly.

Questions? Contact hey@appeeky.com.