Privacy Policy
Welcome to Appocado ("we", "our", or "us"). We respect your privacy and are committed to protecting personal data for both App Creators (users who build and publish applications on Appocado) and End Users (people who visit and interact with applications hosted on Appocado custom subdomains).
1. Information We Collect from App Creators
When you register, build, and deploy apps using Appocado, we collect details necessary to provision your workspace:
- Account Credentials: Name, email address, password hash, and OAuth profile identifiers.
- Project & Prompt Data: Text prompts, UI customizations, database schema definitions, and custom source code files generated or edited in the platform.
- Domain & Custom Subdomain Metadata: Assigned subdomains (e.g.
store.appocado.dev), custom domain SSL settings, and routing configurations. - Billing & API Keys: Payment processing details (handled via secure PCI-compliant processors) and integrated third-party API keys (e.g., Stripe, OpenAI, Resend).
2. Data Collected from End Users of Hosted Apps
Appocado acts as a data processor on behalf of App Creators. When end-users visit or submit forms on apps hosted on *.appocado.dev:
- Form Submissions & Database Rows: User orders, user feedback, account records, and custom table rows created within the hosted application.
- In-App AI Copilot Chat Logs: Messages exchanged with the embedded AI assistant inside generated apps, used strictly to handle user queries and place in-app requests.
- Technical Telemetry: IP address, user-agent headers, timestamp logs, and request paths to enforce DDOS protection, rate limits, and multi-tenant security.
3. AI Prompt & Training Data Policies
We take prompt privacy and intellectual property seriously:
- No Public Model Training: Your private prompts, app blueprints, proprietary source code, and end-user database content are NEVER submitted to public AI models for general model training.
- Isolated Context: Prompt processing is scoped strictly to compiling your workspace assets and powering your in-app AI Copilot instance.
4. Data Isolation & Tenant Scoping
Every Appocado project operates inside a multi-tenant isolated container. Database records, session tokens, and uploaded media files are partitioned by workspace ID, ensuring that one creator's application data can never be accessed or leaked to another tenant.
5. Third-Party Service Providers & Subprocessors
We do not sell data. We share minimal required telemetry with trusted infrastructure providers only to operate services, such as edge hosting networks, SSL certificate providers, and secure database storage clusters.
6. Data Retention, Export & Deletion Rights
- Code & DB Export: Creators can export full source code bundles and raw database snapshots at any time.
- Account & App Deletion: Deleting a project permanently purges associated code bundles, database tables, and subdomain bindings from our primary edge servers within 30 days.
7. Contact & Privacy Inquiries
For questions regarding our privacy practices or to submit a data subject request, please contact our Data Protection Officer at privacy@appocado.dev.