Privacy Policy
1. Controller
[TODO: Betreibername], [TODO: Straße Nr.], [TODO: PLZ Ort, Land] — email: [TODO: kontakt@example.com]
2. What data we process
When you visit the website we process technically necessary data (IP address, timestamp, requested page, user agent) to deliver and secure the service (Art. 6(1)(f) GDPR). When you register, we process your email address and authentication data via Supabase (Art. 6(1)(b) GDPR). When you use the build service, we process the app descriptions (prompts) you enter and the generated results to perform the contract. For paid subscriptions, Stripe processes your payment data; we never store credit card details ourselves.
3. Prompts and AI processing
Your app descriptions are transmitted to LLM providers (see processors) for generation. Do not enter sensitive personal data in prompts. Build results and quality metrics are evaluated to improve the service (Art. 6(1)(f) GDPR).
4. Processors / recipients
| Provider | Purpose | Location |
|---|---|---|
| Vercel Inc. | Frontend hosting, CDN | USA (EU SCCs) |
| Railway Corp. | Backend hosting (API, build pipeline) | USA (EU SCCs) |
| Supabase Inc. | Authentication, database (account, credits, subscription state) | EU-Region konfigurierbar |
| Stripe Payments Europe Ltd. | Payment processing, invoices | Irland / USA (EU SCCs) |
| LLM-API-Anbieter (u. a. Anthropic, Google, OpenRouter, Groq) | Processing of build prompts for app generation | USA (EU SCCs) |
Transfers to third countries are based on EU Standard Contractual Clauses (SCCs) or adequacy decisions.
5. Retention
Account data is stored until you delete your account. Build data and metrics are deleted or anonymized once no longer needed. Statutory retention obligations (e.g. for invoice data) remain unaffected.
6. Cookies and local storage
We only use technically necessary cookies (authentication session) and localStorage (e.g. theme, local app history). There is no advertising-network tracking.
7. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR), and the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). Contact the email address above to exercise these rights.
Last updated: 2026. This policy is updated when processing changes.