1. Information We Collect
To provide and improve the Service, we collect the following types of information:
- Account and sign-in information:your name, email address, salted password hash, and other profile information; if you sign in with Google, we also receive your verified email address, name, and Google account identifier.
- Project content:the prompts you enter, files you upload, and generated code and previews, used to carry out the build tasks you request.
- Usage and security data:access times, page paths, referrers, a random visitor identifier, device and browser information, IP address, request outcomes, sign-in events, and feature usage. Page analytics do not record URL query strings.
- Payment information:if you subscribe to a paid plan, payment details are processed by a licensed third-party payment provider; we do not store full card numbers.
2. Purposes and Legal Bases
We process information only as permitted by applicable law, including to provide the Service you request, perform our contract, protect network and account security, comply with legal obligations, or with your consent. We use it primarily to:
- Provide, maintain, and improve App0's core build and preview functionality;
- Process account registration, authentication, and customer support requests;
- Monitor service performance, diagnose issues, and protect system and data security;
- Send necessary notices related to your account, subscription, or service changes;
- With your consent, send product updates and marketing communications, which you may opt out of at any time.
3. AI and Project Data Processing
Each build task runs in an isolated sandbox, and workspaces are kept separate. To carry out your instructions, prompts, uploaded files, relevant project content, and generated results may be sent to AI model providers for processing. The sandbox may also access package registries and other necessary third-party services. Do not submit personal information, trade secrets, or sensitive material that you are not authorized to process.
Project content is used to provide, maintain, and improve the relevant services and to investigate security or technical issues. We do not use it to train general-purpose public models without your separate explicit consent. Third-party providers' processing is also governed by their applicable terms and privacy rules.
4. Sharing and Disclosure of Information
We do not sell or rent your personal information to third parties, except in the following circumstances:
- With your explicit consent;
- With trusted service providers who help us operate the Service (such as cloud hosting, payment processing, or email delivery), who are required to comply with equivalent confidentiality obligations;
- To comply with laws, court orders, or lawful requests from government authorities;
- As necessary to protect the rights, property, or safety of App0, our users, or the public.
5. Data Storage, International Processing, and Security
App0's primary servers are located in the Hong Kong Special Administrative Region, and your information may be stored and processed there. To provide model access, payments, email, or other necessary functions, information may also be processed by trusted service providers in other countries or regions. We take reasonable measures to protect cross-border transfers as required by applicable law.
We use industry-standard technical and organizational measures—including encryption in transit, access controls, and the principle of least privilege—to protect your information. While we work hard to keep your data secure, no method of transmission or storage over the internet is completely secure, and we cannot guarantee absolute security.
6. Data Retention
Sign-in sessions generally expire 30 days after creation; access and authentication audit logs are retained for 90 days by default; uploads not linked to a project, message, or support ticket are deleted after 30 days by default. Account information, projects, conversations, tickets, and transaction records are generally retained until the account or relevant content is deleted, and may be kept longer where reasonably necessary to perform a contract, resolve disputes, conduct security audits, rotate backups, or comply with law. These periods may vary with configuration or legal requirements but will not exceed what is reasonably necessary for the relevant purpose.
7. Your Rights
Depending on applicable law, you may have the right to:
- Access, correct, or update your personal information;
- Request deletion of your personal information or export of your data;
- Withdraw previously given consent, or object to specific processing activities;
- Lodge a complaint about our data processing practices.
Submit requests to privacy@app0.ai. We may verify control of your account or request reasonable identity information. We generally respond within 30 days and will notify you of a reasonable extension if a request is complex or unusually numerous. Where permitted by law, we may limit or deny a request because identity cannot be verified, another person's rights are affected, or records are needed for fraud prevention, disputes, or legal retention, and we will explain why. You may also complain to a competent privacy or data protection authority.
8. Cookies and Analytics
We use a necessary cookie to keep you signed in and local storage to remember language, theme, and color preferences. We also use a random visitor identifier to measure page paths without query strings, referrers, and basic visit data. When your browser sends a Do Not Track (DNT) signal, we do not create that identifier or send optional page analytics. You may also clear site data or disable cookies; disabling the necessary cookie will affect sign-in and related features.
9. Children's Privacy
The Service is not directed to people under 16 and is not targeted at children under 14. A user below the age at which they may independently consent to data processing where they live must have a parent or guardian review the Service and provide valid consent where required. If we learn that we collected a minor's information without required authorization, we will take reasonable steps to delete it.
10. Security Incidents
If a personal information security incident is likely to create a risk to your rights and interests, we will take remedial steps and, where required by applicable law, notify you by email, in-app notice, or another effective method about the nature and likely impact of the incident, the measures taken, and how to contact us. We will also report it to competent authorities when required.
11. Changes to This Policy
We may update this Policy as our business evolves or as required by law. We will notify you of material changes via a website notice or email. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
If you have any questions about this document, contact privacy@app0.ai.