This page says what we collect, why, and what we will never do with it. It is written to be read, not skimmed past. Where our practice changes, this page changes first.
What we collect on this website
- Waitlist signups: your email address and, if you answer the optional question, what you tell us about your last rejection.
- Contact form: name, work email, company, subject, how many apps you ship, and your message.
- We do not use Google Analytics or advertising trackers. If we measure site usage, it is with cookieless, EU-hosted analytics.
What we collect when you scan a build
- The build you upload is processed to run the scan and destroyed the moment the scan finishes. We never keep your binary.
- The findings and their evidence are stored for your plan's retention window, so you can compare releases and export reports.
- Account data: your email, team members and roles, and billing details processed by Stripe.
What we never do
- We never sell your data.
- We never use your builds, code or findings to train AI models.
- We never ask for your source code, signing keys or repository access.
Where your data lives
Everything runs on EU infrastructure with EU vendors. The single exception is payments, which run through Stripe. The full picture is on the EU-first data handling page.
Your rights
Under the GDPR you can ask what we hold about you, have it corrected or deleted, and take your data with you. Mail info@appcompliance.io and we handle it within the legal terms, usually much faster.