Legal
Privacy Policy
Effective May 15, 2026 · Version 1.0
Jump to section
Early-access build
App Preview Kit is in early access. The legal entity name, registered address, and governing jurisdiction will be published here before general availability. We will give you 30 days’ advance in-product notice of any material change to this policy.
The short version
- What we collect: Your email, the screenshots and URLs you upload, and your billing tier. We never see your card number — our payment processor handles that.
- What we don't do: We don't sell your data. We don't train AI models on your content. Your screenshots and captions stay yours.
- Your rights: Access, correct, export, or delete your data at any time. Email us and we'll respond within 30 days.
- How to reach us: privacy@apppreviewkit.com — we aim to respond within 2 business days.
Who we are
App Preview Kit is a developer tool that generates compliant App Store and Google Play screenshot sets from a product URL. It is currently operated by an individual founder; the legal entity will be incorporated and named here before general availability.
References to "we," "us," or "our" mean the operator of App Preview Kit. References to "you" mean the person or company using the service.
Data we collect
Account data
- Email address — collected via Supabase Auth (email/password or OAuth).
- OAuth provider display name and avatar URL when you sign in with Google or GitHub.
- Workspace name you set during onboarding.
Product content
- Raw screenshots you upload (stored in Cloudflare R2 under a workspace-scoped key).
- Product URLs you paste for AI-assisted caption generation.
- Generated captions and listing copy produced for your projects.
- Template selections and layout configuration for each project.
Billing metadata
- Your subscription tier and status.
- Invoice and payment events relayed from our payment processor (who is the Merchant of Record).
- We never receive, store, or process raw card numbers, expiry dates, or CVVs — those remain with the payment processor.
Usage and technical data
- API request logs: endpoint, HTTP status, timestamp, workspace ID. Request bodies are not logged.
- MCP access token activity: token ID, last-used timestamp, scope.
- Render job metadata: device preset, locale, render duration. Screenshot pixel data is not retained in logs.
- Session cookies required for authentication (see Cookies section).
How we use your data
We process data only for the purposes below. Where EU/UK GDPR applies, the legal basis under Article 6(1) is noted.
| Purpose | How | Legal basis |
|---|---|---|
| Provide the service | Serve your projects, renders, and exports. | Contract — Art. 6(1)(b) |
| Account management | Authenticate you; send billing and transactional emails. | Contract — Art. 6(1)(b) |
| AI caption generation | Send your product URL to an AI model via our gateway to draft captions. | Contract — Art. 6(1)(b) |
| Security and fraud prevention | Log anomalous API activity; rate-limit repeated failures. | Legitimate interests — Art. 6(1)(f) |
| Service improvement | Aggregate usage metrics (workspace-level, not personal) to improve render quality. | Legitimate interests — Art. 6(1)(f) |
| Legal compliance | Retain billing records for the statutory minimum period. | Legal obligation — Art. 6(1)(c) |
AI processing
When you request caption generation, your product URL is forwarded to an AI language model via Vercel AI Gateway. The gateway is configured with zero-data-retention (ZDR) — every provider we route through has contractually agreed not to store, log, or use your content for any purpose after the inference call returns.
We do not use your uploaded screenshots, pasted URLs, or generated captions to fine-tune or pre-train any machine-learning model — in-house or via a third party — without your explicit written consent.
Under the EU AI Act (effective August 2026 for high-risk systems), App Preview Kit’s caption-generation use case falls below the high-risk threshold. AI-generated outputs are suggestions that you review and approve before submission. You are responsible for ensuring all copy complies with Apple App Store Review Guidelines and Google Play policies.
Sub-processors
We share data with the following third-party processors, each bound by a Data Processing Agreement. We will notify you 30 days before adding any new sub-processor that handles personal data.
Data retention
- Account data
- Kept while your account is active, plus 30 days after deletion (grace period for accidental deletes).
- Project content
- Kept while the project exists, plus 7 days after project deletion.
- Billing records
- Kept for 7 years (US) or 10 years (EU/UK) to meet statutory accounting obligations.
- Usage logs
- Rolling 90-day window; anonymized aggregate metrics retained indefinitely.
International data transfers
Some sub-processors operate outside the European Economic Area (EEA). Where data is transferred to a third country without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent safeguards, as the transfer mechanism.
You can request details of the specific safeguards in place for any transfer by emailing privacy@apppreviewkit.com.
Your rights
Where GDPR or UK GDPR applies, you have the rights listed below. Email us to exercise any of them — we aim to respond within 30 days.
- Access
- Request a copy of the personal data we hold about you.
- Rectification
- Ask us to correct inaccurate or incomplete data.
- Erasure
- Ask us to delete your data ("right to be forgotten"). We will comply unless a legal obligation requires retention.
- Portability
- Receive your data in a machine-readable format, or ask us to transfer it to another controller.
- Objection
- Object to processing that relies on our legitimate interests.
- Restriction
- Ask us to restrict processing while a dispute is resolved.
- Withdraw consent
- Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
- Lodge a complaint
- Complain to your local supervisory authority. A list of EU/EEA authorities is maintained by the EDPB at edpb.europa.eu.
California residents (CCPA)
If you are a California resident, the California Consumer Privacy Act as amended by CPRA (effective January 1, 2026) grants you additional rights.
We do not sell or share your personal information for cross-context behavioral advertising. We do not use sensitive personal information beyond what is necessary to provide the service.
Categories of personal information we collect: Identifiers (email address); Commercial information (subscription tier, billing status); Internet or electronic network activity (API request logs); Geolocation data (country-level, derived from IP at authentication only — not stored separately).
To exercise your CCPA rights (know, delete, correct, opt-out, non-discrimination), email privacy@apppreviewkit.com with the subject line "CCPA Request."
Security
We use industry-standard safeguards: TLS 1.2+ encryption for all network traffic, encryption at rest for database storage, row-level access controls so each workspace can only access its own data, and short-lived signed URLs for file delivery — no guessable asset paths.
Secrets are never embedded in client-side JavaScript. We maintain an audit log of administrative actions. In the event of a personal data breach that is likely to result in a risk to individuals, we will notify affected users and the relevant supervisory authority within 72 hours of becoming aware.
To report a security vulnerability, please email security@apppreviewkit.com.
Children
App Preview Kit is not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with their data, contact privacy@apppreviewkit.com and we will delete it promptly.
Changes to this policy
We may update this policy from time to time. For material changes — those that expand what data we collect, introduce new processing purposes, or reduce your rights — we will give you at least 30 days’ advance notice via an in-product banner and email.
The effective date at the top of this page is updated with each revision. Continued use of the service after the effective date of a revised policy constitutes acceptance of the changes.
Contact
Privacy questions and data rights requests:
privacy@apppreviewkit.comApp Preview Kit · Registered address: to be published before general availability.
Also see: Terms of Use