Who we are and our role
This Privacy Policy explains how Appsanic (“Appsanic”, “we”, “us”, or “our”) collects, uses, stores, secures, and discloses your personal information when you visit appsanic.com, create an account, use our AI mobile-app builder, connect a third-party service, or communicate with us.
Appsanic is operated by Encode Digital Software Solutions Pty Ltd (ACN 690 774 719), a company registered in New South Wales, Australia. In this document, references to Appsanic are references to that company. Our contact details are at the end of this document and on our contact page.
What Appsanic is. Appsanic is an agentic AI mobile-app builder. You describe an app in plain language, and an AI agent plans, writes, and helps you launch a real React Native (Expo) application. The agent generates source code and, only at your direction, can connect your project to third-party services.
Our role. For the personal information we handle about you, Appsanic is the entity bound by the Australian Privacy Principles (APPs). The service providers (sub-processors) we engage act on our behalf and under written contracts that require them to protect your information and to use it only to provide their service to us. We remain accountable to you for how those providers handle your data.
We are bound by the Australian Privacy Principles set out in Schedule 1 of the Privacy Act 1988 (Cth). Where applicable to users outside Australia, we also have regard to other privacy laws, including the EU and UK General Data Protection Regulation (GDPR) and the California Privacy Rights Act (CPRA). This policy is structured to track the APPs so you, your procurement team, and regulators can map our practices to each principle.
Anonymity and pseudonymity (APP 2)
Where it is lawful and practicable, you may deal with us anonymously or under a pseudonym.
- You can browse our public marketing website, documentation, pricing, and legal pages without creating an account or telling us who you are.
- When you create an account, you choose your display name, and you may use a pseudonym for it. If you register through an OAuth provider, an email address may not be associated with your profile.
It is not practicable for us to deal with you anonymously for the core service. We need a verified email address (or an OAuth identity) to authenticate you, secure your account, recover access, send transactional notices, and meet billing and tax obligations. Paid plans also require billing details processed by our payments provider.
What we collect (APP 3)
We collect only the personal information we reasonably need to provide, secure, support, and bill for the service. The table below lists each category we handle, representative examples, and why we collect it.
| Category | Examples | Why we collect it |
|---|---|---|
| Account profile | Email address (may be empty for OAuth-only sign-ups), display name, avatar URL, and account timestamps. Passwords are stored only as bcrypt hashes (we keep the last ten hashes to block reuse of recent passwords); we never store a password in plain text. | Registration, log-in, identity verification, account recovery, and service communications. |
| Authentication events | An append-only record of events such as sign-in, OAuth sign-in, magic-link use, sign-out, session revocation, password and email changes, account creation and deletion, and OAuth linking, together with the IP address, user-agent string, timestamp, and structured event details. | Account security, new-device alerts, abuse prevention, and audit logging. |
| Sessions | Session identifier, device and user-agent, IP address, session times, and multi-factor or assurance-level state. | Keeping you logged in, and letting you list and revoke active sessions. |
| Billing | Plan, subscription status and period, payments-provider customer and subscription identifiers, latest invoice, card brand, last four digits and expiry, and your storage usage. We never hold full card numbers. | Taking payment, issuing invoices, metering usage, fraud prevention, and meeting Australian record-keeping and tax obligations. |
| Credits and ledger | Credit balances, and an append-only credit ledger of allowances, top-ups, and usage. A payments-provider event log is also kept for idempotency and audit. | Metering AI usage accurately and maintaining a tamper- evident financial audit trail. |
| Account container | Account container identifiers and billing email, plus membership data such as role and joined and last-active times. One account container is created automatically when you sign up; team invitations, when offered, attach to it. | Organising your projects and, for teams, managing access and collaboration. |
| Projects, conversations and agent messages | Project name, description, interface state, preview status and thumbnail; your conversations with the agent; and append-only agent messages (role, model, content in the model provider’s wire format, and token counts). Streaming agent events and job records are also kept while a build runs. | Running the build agent, preserving your project history, and supporting and improving reliability. |
| Project files and assets | Generated source code files (stored in object storage; up to 50 MB per file and 1,000 files per project), and media you upload (up to 25 MB per asset, de-duplicated by content hash). | Delivering the application you asked us to build and previewing it. |
| Brand kits | Colours, fonts, voice, and logo URLs you configure. | Applying your branding to projects when you choose to use a brand kit. |
| Connector credentials | Third-party API keys and OAuth tokens that you choose to supply (for example for GitHub, Supabase, or Stripe). Stored encrypted at rest with AES-256-GCM. Some short-lived OAuth-flow state is held briefly in encrypted, HttpOnly cookies. | Connecting your project to the third-party services you direct us to use. |
| Communications | Emails and support messages you send us, and contact-form submissions. | Providing support and responding to your enquiries. |
| Usage and operational data | Credits consumed, feature interactions, request metadata, rate-limit counters (scoped by user or IP for short windows), and error diagnostics. | Metering, billing, reliability, security, and abuse prevention. |
| Cookies and device data | A small set of cookies and similar technologies described in our Cookie Policy, plus request metadata such as IP address and user-agent. | Keeping you logged in, protecting forms, recording your consent choices, and basic operation. We do not use advertising or cross-site tracking. |
We collect personal information by lawful and fair means, and only where it is reasonably necessary for one or more of our functions or activities. We do not collect sensitive information (as defined in the Privacy Act 1988) as a routine part of the service, and we ask that you do not enter sensitive information into prompts or project content unless it is genuinely required.
How we collect, and notice at collection (APP 3 and APP 5)
We collect personal information:
- Directly from you when you create an account, complete a form, send us a message, describe an app, upload an asset, or otherwise use the service.
- From your device or browser through standard web technologies such as cookies, request metadata, IP address, and user-agent strings, when you visit our site or use the app.
- From third parties you authorise, such as an OAuth identity provider when you sign in, or a connector such as GitHub, Supabase, or Stripe when you connect it. These disclosures happen only at your direction.
- From our payments provider (Stripe), limited to summary payment information such as your plan, subscription state, and the card brand, last four digits and expiry. We never receive full card numbers.
This policy is the notice we give you at or before the time we collect your personal information (APP 5). It describes the kinds of information we collect, the purposes of collection, the sub-processors and overseas recipients involved, how to access and correct your information, and how to make a complaint.
How we use your information (APP 6)
We use your personal information for the primary purpose of providing the service, and for directly related secondary purposes you would reasonably expect. In particular, we use it to:
- Provide, operate, maintain, and improve the service.
- Authenticate you and keep your account secure.
- Run the AI build agent so it can plan, write, preview, and help you launch your application (see the AI section below).
- Process subscription payments, meter credit usage, issue invoices, and meet our Australian tax and record-keeping obligations.
- Communicate with you about the service, including confirmation emails, password resets, new-device and security alerts, billing notices, team invitations, and important product changes.
- Provide customer support and respond to your enquiries.
- Detect, investigate, and prevent fraud, abuse, security incidents, and misuse of the service.
- Comply with our legal obligations, respond to lawful requests, and enforce our Terms of Service and Acceptable Use Policy.
AI processing. When the agent runs, your prompts, prior conversation turns, the project files the agent reads as context, and any brand kit you have applied are processed by our inference provider, Anthropic PBC, using commercial Claude models. A Next.js route spawns an ephemeral, single-job worker machine on Fly.io in Sydney, Australia, which calls the Anthropic API; your conversation history is stored in our database. As part of a research sub-step, the agent may use Anthropic’s server-side web search and fetch, which can send search queries out to the public web. Do not include personal or confidential information in prompts that you would not want used in a web search query.
We do not sell your personal information, and we do not use the content of your prompts or your generated code to train any AI model. Prompts and generated code are processed ephemerally under a commercial API agreement that does not permit model training on your data.
Direct marketing and opt-out (APP 7 and the Spam Act 2003)
Most of the email we send is transactional and necessary to operate the service: account confirmations, password resets, new-device and security alerts, billing notices, team invitations, and replies to your contact-form messages. These are sent from noreply@appsanic.com and you cannot opt out of essential transactional messages while you hold an account.
If we send you product updates, feature announcements, or marketing email, every such message will identify us and include a functional unsubscribe facility, as required by the Spam Act 2003 (Cth). You can opt out at any time by using the unsubscribe link in the message or by emailing contact@appsanic.com. We do not sell or rent your contact details to third parties for their own marketing.
Disclosure and sub-processors
We share personal information only in the following situations:
- With service providers (sub-processors) who help us run the service under written contracts that require them to protect your data and use it only to provide their service to us. Our current sub-processors include our database, authentication, storage and realtime provider (Supabase), our frontend hosting and edge provider (Netlify), the provider that runs our ephemeral AI agent worker machines in Sydney, Australia (Fly.io), our payments and tax provider (Stripe), our transactional email provider (Resend), and our foundation-model provider (Anthropic). A current and detailed list, with the data each receives and its region, is published at https://appsanic.com/sub-processors.
- At your direction, to on-demand distribution and build providers that you explicitly connect, such as GitHub (code export, repositories, and pull requests), Expo / EAS (cloud iOS and Android builds), Apple (App Store), and Google (Play). These providers process your data only when you connect them, and they do so under their own terms.
- To meet a legal requirement, such as a valid subpoena, court order, or regulator request.
- To protect rights and safety, including preventing fraud, security incidents, or serious harm.
- In connection with a business transfer, if Appsanic is acquired by or merges with another entity; we will notify you before your personal information becomes subject to a materially different privacy policy.
Overseas disclosure (APP 8)
Some of our sub-processors are located outside Australia. Before disclosing your personal information to an overseas recipient, we take reasonable steps to ensure they handle it in a way consistent with the APPs, including through written contractual protections.
Locations where your personal information may be processed include:
- Australia (Sydney). The AI build agent runs on ephemeral Fly.io worker machines in Sydney. This means the processing of your prompts and project context by the agent takes place in Australia, which is a data-residency benefit for Australian users.
- United States. Our payments and tax provider (Stripe), our transactional email provider (Resend), and our foundation-model provider (Anthropic); and, depending on the region elected, our database and storage provider (Supabase) and our frontend hosting provider (Netlify, which is global with a United States primary region).
- European Union. Our database and storage provider (Supabase), where EU data residency is elected for a project.
A full, current list of sub-processors and their regions is maintained at https://appsanic.com/sub-processors.
Government related identifiers (APP 9)
We do not adopt a government related identifier (such as a tax file number, Medicare number, or driver licence number) as our own means of identifying you, and we do not use or disclose such identifiers except where permitted by law. We do not collect a tax or business identifier (such as an ABN) at checkout.
Keeping your information accurate (APP 10)
We take reasonable steps to ensure the personal information we collect is accurate, up to date, and complete, and that the information we use or disclose is, having regard to its purpose, accurate, up to date, complete, and relevant. You can update most of your information directly from your account settings, and you can ask us to correct anything else (see your rights, below). Please keep your account details current so that important service and security notices reach you.
How we protect your information (APP 11)
We take reasonable steps to protect your personal information from misuse, interference, and loss, and from unauthorised access, modification, or disclosure. In practice, this includes:
- Row Level Security enabled (and, on user-facing tables, forced) in our database, scoped to the authenticated user, typically through account-membership checks that resolve to your authenticated identity. Note that the AI agent worker uses a service-role key that bypasses Row Level Security; isolation in the worker is enforced at the application layer by scoping each query to your project.
- Connector secrets encrypted at rest with AES-256-GCM using a versioned key envelope with key rotation. Only the database service role can read them, and client access is gated by an allowed-user list. The only credential ever exposed to your browser is the Supabase anonymous (public) key, which is designed to be public.
- The AI never sees decrypted connector secrets. Secrets are decrypted only server-side, on the worker, for direct calls to the relevant third-party API; a redaction layer strips secret-like fields from tool results before they reach the model; and the agent’s instructions forbid it from requesting credentials.
- CSRF protection using a double-submit token (a cookie plus a matching request header) on state-changing routes.
- Rate limits on log-in, sign-up, password reset, account deletion, and data export.
- HTTPS everywhere, with session cookies set HttpOnly, Secure (in production), and SameSite=Lax.
- Append-only audit tables for authentication events, the credit ledger, the payments-provider event log, and account deletions.
A fuller description of our security practices is published at https://appsanic.com/security.
No online service can guarantee perfect security. Despite our precautions, sophisticated attacks, newly discovered vulnerabilities, or incidents affecting our sub-processors may occur. Parts of the service rely on third-party infrastructure whose security posture is outside our direct control, and we cannot guarantee against every possible threat. We do not currently hold a formal security certification such as SOC 2 or ISO 27001, and we do not claim one.
You are responsible for protecting your own account credentials, the API keys and access tokens you supply, and the devices you use to access the service.
How long we keep your information
We retain personal information only for as long as we need it for the purposes described in this policy, or as required by law, and then we delete or de-identify it.
- Account and project data are kept while your account is active, and are purged after the 72-hour deletion confirmation window once you confirm deletion (see your rights, below).
- Authentication events are kept for the life of the account and are deleted when the account is deleted. They are not held for any fixed multi-year period.
- Streaming agent events are automatically purged 30 days after the related job completes.
- Soft-deleted projects are hard-deleted after a short grace window of about five minutes.
- Financial and forensic records - including the credit ledger, the payments-provider event log, and the account-deletion log - are retained as required for audit and legal or tax purposes, and survive account deletion.
- Tax and financial records are retained to meet Australian record-keeping obligations, commonly for at least five years.
- Backupsare rotated on our provider’s schedule and are overwritten over time.
- The hash used to enforce the 30-day re-signup cooldown after deletion auto-expires.
Your rights (APP 12 and APP 13)
Under the Australian Privacy Principles, and where applicable the GDPR and CPRA, you have the following rights.
- Access (APP 12). You can ask for access to the personal information we hold about you. You can also use our self-serve data export (see below) to download most of your data yourself.
- Correction (APP 13). You can ask us to correct personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading, and you can update most details directly in your account settings.
- Deletion. You can delete your account yourself through a two-step, email-confirmed flow: from Account → Security → Delete account, you request deletion (email-and-password users re-enter their password; the request is rate-limited), then you click the link in a confirmation email within a 72-hour window. On confirmation, we cancel any active subscriptions, purge your stored files, and hard-delete your profile, your account container and its projects, conversations, messages, files, assets, connectors, and billing data. A 30-day re-signup cooldown applies, and a permanent forensic deletion log and the financial credit ledger are retained for audit as described above.
- Data export and portability.You can download a JSON export of your data yourself. It includes your profile, recent authentication events, and your account’s projects, conversations, agent messages, files, and assets (download links are valid for about one hour). The export is rate-limited. For your protection, it excludes raw authentication internals and connector secrets, which are never decrypted on the client.
- Objection and withdrawing consent. You can object to certain uses of your information and withdraw consent where we rely on it (for example by disconnecting a connector, changing your cookie consent, or unsubscribing from non-essential email). Withdrawing consent does not affect processing that took place before withdrawal, and some processing is necessary to keep providing the service.
- Session management. You can list your active sessions and revoke them individually, or log out everywhere, from Account → Security.
To exercise any right that is not self-serve, email contact@appsanic.com. We respond to privacy requests within 30 days, consistent with APP 12. We may need to verify your identity before acting on a request, and in limited cases the law permits us to decline access or correction (in which case we will explain why and how you can complain).
Children
Appsanic is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact contact@appsanic.com and we will promptly delete it.
Automated decision-making and AI transparency
The core of the service is an AI agent that generates content - such as source code, plans, and screens - from the inputs you provide. These outputs are probabilistic: the agent predicts likely useful content based on your prompts and project context, and it can be incomplete or incorrect. You should review and test what it produces before relying on it or publishing it.
We do not use solely-automated processing to make decisions about you that produce legal effects concerning you or that significantly affect you in a similar way. Operational automations (such as metering credits, applying rate limits, or flagging suspected abuse) support human-overseeable processes and you can contact us to query any outcome.
Data breaches and the Notifiable Data Breaches scheme
Appsanic is subject to the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). If we become aware of an eligible data breach that is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, with a description of the incident, the kinds of information involved, and recommended steps you can take. Where a sub-processor we use reports a breach affecting your data, we will pass that notification through to you promptly.
Complaints
If you believe we have breached the APPs or mishandled your personal information, please contact us first by emailing contact@appsanic.com. We aim to acknowledge your complaint promptly and to respond within 30 days, consistent with the Privacy Act.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5288, Sydney NSW 2001
Changes to this policy
We may update this policy from time to time. Where changes are material, we will notify you by email or through a prominent notice in the service before they take effect. The “Last updated” date at the top of this page always reflects the current version.
Contact us
For any privacy matter - including access, correction, deletion, export, objection, or a complaint - email contact@appsanic.com. This address handles all privacy and legal correspondence; a postal address is available on request.
Appsanic is operated by Encode Digital Software Solutions Pty Ltd (ACN 690 774 719), registered in New South Wales, Australia. For general support and other ways to reach us, see our contact page.
