Privacy Policy
Last updated [DATE] · Effective [DATE]
1. Two different roles
This is the most important thing to understand about how Apprvd.app handles personal data, because it changes who is responsible for what.
- For your workspace account, we are the controller. That means the people at your organisation who sign in, and your billing relationship with us.
- For your end users’ data, we are a processor. Analytics identifiers, device tokens and app events belong to you. We only touch them to run the product on your instruction. You decide why and how they are processed — we do not use them for our own purposes, ever, and we do not sell them or use them to train models.
If you are an end user of an app that uses Apprvd.app, we are not your point of contact: the operator of that app is. Ask them, and they can instruct us on your behalf.
2. Data we hold as controller
| Data | Why | Legal basis |
|---|---|---|
| Email address, workspace membership | Sign-in and access control | Contract |
| Email address left on the waitlist | Telling you when Apprvd.app opens | Consent — ask us and we delete it |
| Google account email of a connected account | Showing you which account a project is connected through | Contract |
| Billing status, subscription and invoice records | Taking payment and meeting accounting obligations | Contract; legal obligation |
| Server and error logs (IP, path, timestamp, error) | Keeping the service running and secure | Legitimate interests |
Payment card details are entered directly with Stripe and never reach our servers. We see only the subscription status and the last-four/brand that Stripe reports.
3. Data we process as processor
On your instruction, Apprvd.app processes:
- Aggregate analytics from your Google Analytics property — read through Google’s Analytics Data API and kept in our database so dashboards load without waiting on Google: totals such as active and new users, event counts, revenue, retention and funnel step counts, broken down by date, platform, country, app version and device brand. Google Analytics returns no individual users or events through these reports, and we store none from it.
- Device push tokens — read from the Firestore collection you nominate, matched to the audience you defined, and used to send the notification you composed. They are not retained after the send.
- First-party tracker events — if you install our SDK: event name, your user identifier, a device identifier, event parameters and timestamps. These are individual events, stored in our database; they are what push audiences are built from.
- An identity map — which device ids and Firebase app instance ids belong to which of your user ids, so one person counts once and can be deleted as one.
- Audience definitions and send history — the cohorts you build and a record of what was sent, when, to how many, and how many opened.
The identifiers involved are the ones your app supplies. If you send us direct identifiers such as email addresses in event parameters, they will be stored as sent — we recommend you do not.
4. Credentials and encryption
Your Google OAuth refresh token, and any third-party source credentials you add (for example Mixpanel or RevenueCat keys), are encrypted at rest with AES-256-GCM using a key held in our application environment and not in the database. They are decrypted only in memory, to make the API call you asked for. All traffic to Apprvd.app is over TLS.
5. Sub-processors
We use the following providers. We will give notice before adding a new one, so you can object.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication | [REGION] |
| Vercel | Application hosting and logs | [REGION] |
| Stripe | Payments and invoicing | EU / US |
| Google Cloud & Firebase | Your own project, accessed on your behalf; Cloud Messaging delivery | As configured by you |
6. International transfers
Where personal data leaves the [EEA/UK], we rely on the European Commission’s Standard Contractual Clauses, or another lawful transfer mechanism, together with the safeguards each provider offers. Copies are available on request.
7. How long we keep things
- Account data — for as long as your workspace exists, then deleted within [30] days of closure.
- Tracker events — deleted automatically, a month at a time, once they are older than [12 months]. Tell us if you want a shorter window.
- The identity map — until you delete the app, or the person. A deletion request for one person removes their tracker events and identity entries from our database; deleting them in your own Google Analytics property stays with you.
- Aggregate analytics — refreshed hourly, and dropped once nothing has asked for them in [7] days.
- Configuration and send history — until you delete the app or workspace. Deleting an app deletes its experiments, funnels, cohorts, events and send history with it.
- Waitlist emails — until launch, or sooner if you ask; then deleted unless you sign up.
- Invoices — retained as long as tax law requires, typically [7] years.
- Logs — [30] days.
8. Cookies
Apprvd.app sets only strictly necessary cookies: a session cookie so you stay signed in, and a short-lived cookie protecting the Google connection flow against cross-site request forgery. We run no advertising, tracking or third-party analytics cookies on this site, which is why you are not being asked to accept any.
9. Your rights
If you are in the EEA or UK you have the right to access, correct, delete, restrict or object to processing of your personal data, and to receive it in a portable format. Where we rely on legitimate interests you may object at any time. Write to [PRIVACY EMAIL] and we will respond within one month.
For end-user data we hold as a processor, contact the operator of the app instead — we will act on their instruction. You also have the right to complain to your local supervisory authority, in our case [SUPERVISORY AUTHORITY].
10. Security
Access to production data is limited to people who need it. Credentials are encrypted at rest, traffic is encrypted in transit, and machine endpoints authenticate with signatures or per-source keys rather than session cookies. No system is perfectly secure; if a breach affects your personal data we will notify you and, where required, the supervisory authority, without undue delay and within 72 hours of becoming aware.
11. Automated decision-making
Apprvd.app does not make automated decisions producing legal or similarly significant effects about individuals. The statistics it computes — conversion rates, significance tests, cohort membership — are decision support for you, not decisions about your users.
12. Changes
We will post changes here and update the date above. For material changes affecting your rights we will give notice by email.
13. Contact
Controller: [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Privacy contact: [PRIVACY EMAIL]. [DPO NAME, IF APPOINTED].
Business customers who need a signed Data Processing Agreement can request one at the same address.