The short version
- We collect what we need to run your account: who you are, what you publish, and how the service is used.
- We don't sell personal information, and we don't build advertising profiles.
- When a visitor loads a site carrying your tag, our servers see the request. We use it to serve the file and keep the service secure.
- The code you publish is yours, and what it does on your clients' sites is your responsibility.
- Ask us anything about your data: [email protected].
1. Who we are
Appster is an online service for hosting and serving code and websites. You can reach the people who operate it at [email protected]. This policy explains what we do with personal information when you visit our website, create an account, or use Appster.
2. Two different roles
Appster handles two kinds of data, and it matters which is which.
- Your data. Information about you and your workspace. We decide how it's used, within this policy, which makes us the controller of it.
- Data your code touches. Anything your published code collects on the sites where your tags run, and the requests those sites make to us. You decide what your code does, which makes you the controller; we process it for you under our terms.
If you're a visitor to a site that carries someone's Appster Tag, that site's own privacy policy governs what happens there. Section 4 explains the part we see.
3. What we collect from you
- Account information: your name, email address, a hashed password, and your workspace details.
- What you publish: the code, values, files, and functions you keep in Appster, with their versions and summaries. Please don't store passwords, API keys, or other people's personal data in them.
- Billing: your plan, subscription status, and transaction references. Payments run through PayPal, so we never see your card details.
- Usage and logs: IP address, browser and device details, pages viewed, actions taken, and timestamps, including the audit trail of publishes, restores, and shares in your workspace.
- Support: the messages you send us and what we reply.
4. Visitors to sites running your tags
When someone opens a page that carries one of your tags, their browser asks our servers for what that tag serves. That request reaches us with the visitor's IP address, browser and device details, the referring site, and the time. We use it to serve the right version, to keep the service secure and available, and to produce aggregate counts such as how often a tag is served.
We don't use it to build profiles of those visitors, we don't sell it, and we don't use it for advertising. We delete these request records after 90 days.
Two features store more than the request, on behalf of whoever owns the site or code. If a site uses Appster's contact form, the message a visitor sends is kept for the site's owner and emailed to them. If a request calls a webhook function, the request and what the function logged are kept so its owner can see what happened. Both stay until the owner deletes them, or deletes the site or function.
Anything else that happens on those pages comes from the code you publish. If your code sets cookies, records behaviour, or collects form data, that's yours to disclose in the site's own privacy notice, and to obtain consent for where the law requires it.
5. How we use it
- To run the service: your account, your workspace, and serving what your tags ask for.
- To take payment and keep records of it.
- To answer support requests.
- To keep the service secure: detecting abuse, debugging failures, and investigating incidents.
- To understand how the product is used, so we can improve it.
- To send service messages. Marketing email only if you've opted in, and every one has an unsubscribe link.
- To meet legal obligations.
6. Our legal bases
If the UK or EU GDPR applies to you, we rely on: performing our contract with you (running the service and billing); our legitimate interests (security, abuse prevention, product improvement, and business records); your consent (marketing email and any non-essential cookies); and legal obligations (tax and accounting).
7. Cookies
Our website and app use cookies that are necessary to sign you in and keep your session secure. We don't use analytics, advertising, or tracking cookies. The app also keeps a few preferences in your browser's own storage, which are never sent to us. Our public pages load their fonts from Google Fonts, so your browser contacts Google to fetch them.
The tag itself doesn't set cookies on your clients' sites. Code you publish through it may, and that's covered by their site's notice.
8. AI features
When you connect an outside AI service, such as Claude or ChatGPT, it reads and changes the code in your workspace through our API, under your own account with that service. Please keep secrets and personal data out of what it will read.
Appster has no AI provider of its own. Version summaries are written only in a workspace whose owner has added their own Anthropic API key; the code being summarised is then sent to Anthropic under that key, and Anthropic's terms for that key apply. Whichever AI service you connect, its own terms and privacy policy apply to what it receives.
9. Who we share it with
We don't sell personal information and we don't share it for cross-context behavioural advertising. We do use service providers who process data on our behalf:
| Provider | What for |
|---|---|
| PayPal | Taking subscription payments |
| DigitalOcean (with Cloudflare at its network edge) | Running the service, storing its data, and serving what tags request |
| Resend | Sending account email and contact-form notifications |
| Anthropic | Version summaries, only in workspaces that add their own Anthropic key |
We also share information when the law requires it, to protect our rights or someone's safety, and with a buyer if our business is sold, in which case we'll tell you first.
10. International transfers
Our providers may process data in countries other than yours, including the United States. Where personal data leaves the UK or EEA, we rely on appropriate safeguards such as the European Commission's standard contractual clauses. Our application servers are in Singapore and our database is in the United States, both with DigitalOcean.
11. How long we keep it
- Account and workspace content: while your account is open. Deleting a code or a workspace removes it from the live service straight away; copies may remain in routine backups for a short time before they are overwritten.
- Versions: as your plan describes, up to 25 per code.
- Tag request records: 90 days.
- Function run logs and contact-form messages: until their owner deletes them, or the function or site they belong to.
- Sign-in sessions: until you sign out, or 180 days after you were last active.
- Billing records: as long as tax and accounting law requires.
12. Security
We protect data in transit with encryption, restrict access to the people who need it, and keep an audit trail of changes inside your workspace. No service can promise perfect security, so please use a strong, unique password, keep API credentials private, and tell us straight away if something looks wrong.
13. Your rights
Depending on where you live, you can ask us to give you a copy of your personal information, correct it, delete it, export it, restrict or object to how we use it, or withdraw consent you've given. Email [email protected] and we'll respond within the time the law allows.
If you're in California: we don't sell or share personal information as those terms are defined by the CCPA, we don't discriminate against anyone who exercises their rights, and the categories we collect and why are set out in sections 3 to 5.
If you're in the UK or EEA, you can also complain to your data protection authority.
14. Children
Appster is a business tool and isn't for children. We don't knowingly collect personal information from anyone under 16. If you think a child has given us data, email us and we'll delete it.
15. Changes to this policy
We'll update this page when our practices change, and the date at the top will tell you when. If a change is significant, we'll let you know in the app or by email.
16. Contact us
Appster
Privacy: [email protected]