Legal
Privacy Policy
Effective 14 September 2026 · version 2026-09-14 · accepted in the dashboard at sign-up
In short: We keep the minimum needed to run a hosting service: your email and sign-in identity (never a password), the content you publish, security logs, and a billing reference from our payment partner. We set one essential cookie on the dashboard and none anywhere else. Visitors of hosted pages are counted, not tracked. Account-deletion requests submitted on a hosted page are stored for the developer and relayed to them; we never delete data in a developer's systems. You can ask for a copy or deletion of your data at any time. This summary is for orientation only; the full text below is what applies.
Draft for human and legal review. Wording in square brackets is a placeholder that must be filled in before this page is published. See
docs/legal-stance.mdfor the list of open points.
1. Who this policy covers
This policy explains how AppFoyer, operated by [Operator legal name, registered address] (the “Operator”, “we”), handles personal data in three situations:
- Account holders — app developers who use the dashboard at
app.appfoyer.com, its API, the/mcpendpoint or the AppFoyer plugin (“you”). - Visitors of
appfoyer.com— this website. - Visitors of Hosted Sites — the pages we host for developers on
appfoyer.pagesubdomains, including anyone who submits an account-deletion request there.
For account holders and for visitors of this website we are the data controller. For visitors of a Hosted Site, the developer who publishes it is the controller of the content and of the account-deletion requests it collects; we act as the developer’s processor for that data, and section 5 explains what that means in practice. The developer’s own privacy policy — which is usually one of the pages we host — describes what the developer’s app does with data. We do not write, check or control that policy.
2. Data we collect from account holders
| Data | Where it comes from | Why |
|---|---|---|
| Email address, display name, sign-in provider (email, Google or X) and the provider’s user identifier | The identity provider you sign in with | To create and secure your account and send account notices. We never receive your password. |
| Email-verification status | The identity provider | A store-facing page may only be published from a verified account (anti-abuse). |
| Terms acceptance: version, date, IP address | The dashboard, when you tick the box | To prove which agreement applies to your account. |
| Session records: a hashed session identifier, IP address, browser user agent, timestamps | Your browser, on sign-in and use | To keep you signed in for up to 30 days and let you revoke sessions. |
| Audit log: who did what and when — sign-ins, publishes, key creation and revocation, plan changes, consent — with IP address | Your actions in the dashboard, API or agent | Security, abuse investigation, take-down response and support. |
| API keys (stored as a hash and a short prefix), their scopes and last-used time | Created by you | To authenticate coding agents. The full key is shown once and cannot be recovered by us. |
Your Content: app name, developer name, support email, store links, jurisdiction, data-collection categories, page text, app-ads.txt, app icon, chosen subdomain | Entered by you, or drafted by an agent from your codebase and confirmed by you | This is the service: we host and publish it. Parts of it (developer name, support email, store links) are public on your Hosted Site by design. |
| Billing reference: payment-partner customer id and subscription id, plan, status, renewal date | Our payment partner, Paddle, via signed webhooks | To apply your plan. No card or bank details ever reach us. |
| Notification channels: an email address, a Telegram chat identifier, or a Slack webhook URL | Entered or linked by you | To notify you of account-deletion requests. Stored encrypted; shown to you only in masked form. |
| Store-listing verification result | The public App Store lookup service, on your request | To show that the listing you entered matches your Hosted Site. |
What the plugin sends. When a coding agent uses the AppFoyer plugin on your machine, only derived facts reach our servers: app name, platform, bundle or application id, the names of SDKs and permissions found, the answers you confirm, and the page text the agent drafts. Source code, file contents and secrets are not sent. Your API key travels only in the request header your agent tooling fills in. Every agent action is recorded in your audit log as an agent action.
We do not collect data from your device, run analytics or advertising scripts in the dashboard, or buy data about you from anyone.
3. Visitors of appfoyer.com
This website sets no cookies, runs no third-party scripts and includes no tracking. Our infrastructure provider records standard access logs (IP address, requested URL, user agent, time) for security and capacity purposes and keeps them for a short period as described in their own documentation. We may see aggregate traffic figures (page views per page, by country) with no individual identifiers.
4. Visitors of Hosted Sites
Hosted Sites are static pages. They set no cookies and load no third-party scripts, with one exception: the account-deletion form runs a bot-protection challenge (see section 5).
For each page view we record only the app, the page type, the visitor’s country and a count. No IP address, identifier or cookie is stored for this purpose. The developer sees the totals; nobody sees individual visits.
Our infrastructure provider records standard access logs at the network edge, as for every website served through a content-delivery network, and keeps them under their own retention policy. We do not use these logs except to investigate abuse or attacks.
5. Account-deletion requests submitted on a Hosted Site
Google Play requires developers to offer a web page where users can request deletion of their
account. The /account-deletion page on every Hosted Site is that page. When you submit it we
store:
- the email address you enter and the optional note (up to 500 characters, plain text only — the form refuses notes that look like a password, code, card number or identity document, and asks you never to enter those);
- a hashed form of your IP address, used only to limit abuse of the form for a short period;
- the time of the request and which app it concerns.
What happens next — read this carefully. We forward your request to the developer on the notification channels they have set up (email, Telegram or Slack, at their choice) and show it in their dashboard. We do not have access to the developer’s systems and we do not delete anything. The developer is responsible for acting on your request; contact them at the support address shown on the same Hosted Site if you do not hear back. We never contact you about your request and we never share your request with anyone but that developer, except as required by law or to investigate abuse of the form.
The request is kept for the developer’s records until the developer deletes it, or until the developer’s account is deleted (section 8). Our operators can see requests when investigating abuse of the form (section 9).
The form is protected by a bot-detection challenge provided by our infrastructure provider. The challenge script runs in your browser and may process your IP address and browser characteristics to decide whether you are a human; it does not set tracking cookies and is not used for advertising.
6. Why we may process your data (legal bases)
Where the GDPR or a similar law applies, we rely on:
- Performance of a contract — everything needed to provide the Service you signed up for (section 2, most rows).
- Legitimate interests — keeping the Service secure, preventing and investigating abuse of a free public hosting platform, defending legal claims, and understanding aggregate usage. We have weighed these interests against your rights; the data involved is minimal and the alternative (an unprotected platform) would harm you and your users more.
- Legal obligation — tax and accounting records held by our payment partner, and responses to lawful requests from authorities.
- Consent — only where we ask for it explicitly. We do not send marketing email and do not use your data for advertising.
7. Who else processes your data
We use a small number of service providers (“sub-processors”) that process data on our behalf. We do not sell personal data and we do not share it with anyone else except as required by law.
| Provider | What they do for us | Data involved |
|---|---|---|
| Cloudflare, Inc. (United States, global network) | Hosting and running the Service, storing its database, files and caches, delivering Hosted Sites worldwide, sending our transactional email, and bot protection on the account-deletion form | All data in sections 2, 4 and 5, processed on servers around the world |
| Google LLC — Firebase Authentication (United States) | Sign-in: verifying your email, password, Google or X identity | Email, name, sign-in provider, provider user id; your password, if you use one, is held by Google and never by us |
| Paddle.com Market Ltd / Paddle.com Inc. (United Kingdom / United States) | Merchant of record for paid plans: checkout, tax, invoicing, refunds, card processing | Billing details you enter at checkout, handled under Paddle’s own privacy policy; we receive only the references listed in section 2 |
| Telegram and Slack | Only if you connect them as a notification channel | The notification text (the requester’s email and note) is sent to the chat or channel you chose, at your instruction |
Where a provider is located outside the European Economic Area, the United Kingdom or your country, transfers are covered by that provider’s standard contractual clauses or an equivalent recognised mechanism. We will update this table before adding a provider that processes personal data.
8. How long we keep data
| Data | Retention |
|---|---|
| Account, content and settings | For the life of the account. After you close it, soft-deleted immediately and permanently removed within 30 days. |
| Sessions | Expire after 30 days without use, or immediately when you sign out or revoke them. |
| Audit log | For the life of the account and up to [12 months] after closure, for security and legal defence. |
| Account-deletion requests on your Hosted Site | Until you delete them, or until your account is purged. |
| Subdomains you held | The subdomain names themselves (not your personal data) are kept indefinitely as reserved, so they can never be re-used by someone else. |
| Backups | Daily encrypted backups of the database are kept for [30 days] and then overwritten; deleted data disappears from backups on that schedule. |
| Billing records | Kept by our payment partner for the period tax law requires. |
| Abuse and take-down records | Up to [24 months] after the event, to defend against repeat abuse. |
9. Our operators’ access to your data
A small number of our operators can access account data and published content in an internal administration tool to provide support you request, to investigate abuse reports, to keep the Service secure and to comply with the law. Every such access, and every action taken (approve, disable, plan adjustment, edit on your behalf), is logged with the operator’s identity and a reason. We do not read your content for any other purpose, we do not use it to train anything, and we do not sell it.
10. Security
All traffic to the Service is encrypted in transit (HTTPS with HSTS). Your dashboard session is an
HttpOnly, Secure cookie that no script can read; we store no password and no long-lived token in
your browser. API keys are stored as hashes. Notification-channel secrets are encrypted at rest.
Published pages are rendered from Markdown on our servers and cannot contain scripts. Access to
production systems is limited to named operators with multi-factor authentication. If a breach
affects your data we will notify you and, where required, the competent authority without undue
delay.
11. Your rights
Depending on where you live you may have the right to access, correct, export, restrict or delete
your personal data, to object to processing based on legitimate interests, and to complain to a
supervisory authority. To exercise a right, email support@appfoyer.com from your account address;
we answer within 30 days. You can also:
- edit your content and settings in the dashboard at any time;
- sign out of all sessions from the dashboard;
- close your account by emailing us (a self-service button will replace this), which takes your Hosted Sites offline and starts the 30-day deletion described above.
If you submitted an account-deletion request on a Hosted Site, the developer of that app is the
controller of your request; please contact them. We will nevertheless help you if you cannot reach
them: write to support@appfoyer.com and we will forward your message or, where appropriate, remove
your request from our storage.
12. Children
The Service is for app developers and is not directed at anyone under 18. We do not knowingly hold an account for a minor; if you believe we do, tell us and we will close it. Account-deletion forms on Hosted Sites may be used by anyone the developer’s app serves; we store only what the form collects (section 5).
13. Changes to this policy
We will email account holders at least 14 days before a change that affects them takes effect, and ask for renewed acceptance in the dashboard where the change requires it. The effective date at the top of this page identifies the version; every version is preserved in the public change history of this website.
14. Contact
- Privacy requests and questions:
support@appfoyer.com - Abuse on a Hosted Site:
abuse@appfoyer.com - Controller: [Operator legal name, registered address]
- [EU / UK representative or data protection officer, if required]
Questions about this document: support@appfoyer.com. Previous versions are in the public change history of this site.