Privacy Policy
1. Introduction
Appzentic Inc. ("Appzentic", "we", "us", or "our") operates appzentic.com and related services (the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our Service.
By using the Service, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Account Information
When you create an account we collect your name, email address, and password (stored as a hashed value).
2.2 Usage Data
We automatically collect information about how you interact with the Service, including pages visited, features used, chat messages sent (for AI processing), and timestamps.
2.3 App Build Data
When you build apps through AI Build Console, we store the generated source code, build artifacts (APK, IPA, AAB), and associated project files on your behalf.
2.4 Payment Information
Payment transactions are processed by third-party payment processors. We do not store full credit card numbers. We retain transaction records and billing history.
2.5 Cookies & Tracking
We use essential cookies to maintain your session and preferences. We do not use third-party advertising cookies.
2.6 App Testing & Publishing Credentials (Optional)
To enable app testing and distribution, you may voluntarily provide the following. We collect these only when you explicitly submit them, and use them solely for the stated purpose.
- Device UDID โ your iPhone's unique device identifier, used to register your device for Ad Hoc distribution so you can install and test your app directly, without going through the App Store. We also record which Apple Developer account the device was registered under, because Apple caps each account at 100 registered devices per year.
- Apple ID โ your Apple account email address. This is stored only if you enter it, and is used for Apple beta-distribution invitations. Ad Hoc is currently the only iOS testing path we offer, so in normal use this field is not required.
- Apple Developer signing certificate (.p12) โ your iOS distribution certificate, required to sign and package your app under your own Apple Developer account for App Store submission.
- Provisioning profile (.mobileprovision) โ your app's distribution provisioning profile, required together with the .p12 certificate to build a publishable IPA under your account.
- App Store Connect API key (.p8) โ if you publish under your own Apple Developer account, this key lets our build system upload the finished build to App Store Connect on your behalf. It is used for that purpose only.
These credentials are used exclusively to build and sign your app. They are never shared with third parties and are deleted from our servers immediately after the build process completes, unless you choose to save them to your profile for future builds.
2.7 User-Provided API Keys (Optional)
If you prefer to use your own AI model or cloud infrastructure instead of ours, you may optionally provide your own API keys and credentials. These are entirely optional โ the Service works without them using our shared infrastructure.
- AI model API keys โ such as
ANTHROPIC_API_KEY,OPENAI_API_KEY,GEMINI_API_KEY,DEEPSEEK_API_KEY, or other supported providers. Used to call AI models on your behalf using your own account quota. - Cloud platform credentials โ an AWS Access Key / Secret Key or an Alibaba Cloud AccessKey pair. These are used to create and manage infrastructure inside your own cloud account at your direction, and the scope is broader than a deployment key: launching and terminating a server instance, creating the network and firewall rules it needs, creating an SSH key pair, reading the list of domains in your account, and writing DNS records for the domain you choose. See section 2.8 for what we do with the resources this creates.
Please understand what you are handing over. A credential able to create servers can generally do a great deal else in that account. We recommend creating a dedicated sub-account or IAM user with the narrowest permissions that still work, rather than using a root or administrator credential. If you would rather not provide cloud credentials at all, you can attach a server you already run instead โ that path requires none, and is described in section 2.8.
All keys and credentials you provide are encrypted at rest using AES-256 and in transit using TLS. They are used only to execute the specific operations you request (AI calls or cloud deployments) and are never shared with third parties. You can view, update, or delete your stored keys at any time from your account settings.
2.8 Your Own Server โ MyCloud (Optional)
If you connect a server of your own โ either a machine you already run, or one we launch inside your cloud account on your instruction โ we collect and store the following in order to operate it for you. None of this applies if you only use our shared infrastructure.
- Machine records โ the instance identifier, cloud provider, region, size, hostname and network address of the server, and which of your apps are deployed to it. For a machine we launched, this record is the only evidence that a billable resource exists in your account, so we keep it until the machine is terminated.
- SSH private key โ when we launch a machine for you, a key pair is created for it. Cloud providers return the private half exactly once and cannot re-issue it, so we store it and make it downloadable from your profile. It is generated for your machine, belongs to you, and is never used to grant access to anyone else.
- Domain names and TLS material โ the domain you point at your server, and the HTTPS certificate and private key we obtain on your behalf so that your apps can be served securely. We hold these in order to renew the certificate before it expires and to install it on your machine.
- Machine health data โ the agent running on your server reports processor, memory and disk usage, its own version, and the identity of the machine, so the console can show you whether it is healthy and how loaded it is.
- Database access for your live app โ so that you can inspect the data your deployed app is collecting, we create a read-only database account scoped to that single app and store its credentials. It can run queries and nothing else; it cannot modify or delete your data.
The connection only runs one way. The agent on your server calls out to us to ask whether there is work to do; we never open a connection into your machine. We hold no login to it beyond the key described above, and we do not require you to open any inbound port for us.
You can remove your cloud credentials, your stored key, and the machine record at any time from your profile. Removing a credential stops us from managing anything further in that account.
3. How We Use Your Information
- To provide, maintain, and improve the Service
- To process your app build requests via AI
- To send transactional emails (account confirmation, build completion)
- To respond to support requests
- To create and operate infrastructure inside your own cloud account, when and as you instruct us to
- To detect and prevent fraud or abuse
- To comply with legal obligations
4. Data Sharing
We do not sell your personal data. We share data only with:
- Service providers โ hosting, payments, email delivery โ under strict confidentiality agreements
- AI providers โ your chat messages and app requirements are sent to AI model APIs to generate code; these providers are subject to their own privacy policies
- Volcengine (voice assistant) โ if you use the voice assistant in our iOS or Android app, the audio of that call is streamed to Volcengine (ByteDance's cloud platform) for real-time speech recognition, speech synthesis and the assistant's responses. To give useful answers, the assistant is also sent context from the conversation you opened it in, such as recent messages and the state of the project. This processing takes place on Volcengine's servers in mainland China. We do not record calls or keep transcripts, and cloud recording on Volcengine is switched off; the only thing kept is the message the assistant sends into your chat, which becomes part of your conversation like any other. The voice assistant is optional, and typing works without it
- Your cloud provider โ if you use MyCloud, we make API calls to AWS or Alibaba Cloud using the credentials you supplied. Those calls, and the resources they create, are visible to you and governed by your agreement with that provider, not by us
- Certificate authority โ to issue an HTTPS certificate for your domain we request one from Let's Encrypt. Certificate authorities publish every certificate they issue to public Certificate Transparency logs, which means the domain name you use becomes publicly discoverable. This is how the certificate system works everywhere, not something specific to us, but you should know it before pointing a private domain at your server
- Legal requirements โ if required by law, court order, or to protect the rights and safety of users
5. Your Rights
Depending on your location, you may have the following rights:
- Access โ request a copy of the data we hold about you
- Correction โ request correction of inaccurate data
- Deletion โ request deletion of your account and associated data
- Portability โ export your app code and project files at any time
- Objection โ object to certain processing activities
To exercise these rights, contact us at privacy@appzentic.com.
6. Data Retention
We retain your account data for as long as your account is active. App build artifacts are retained for 90 days after project deletion unless you export them. You may delete your account and all associated data at any time from your account settings.
Credentials and keys you provide โ AI API keys, cloud credentials, signing certificates โ are retained until you delete them, because they exist to be reused across builds and deployments. Records relating to a server of your own are kept while that machine exists; terminating the machine from your profile removes them. Deleting your account removes all of the above from our systems, but it does not shut down a machine running in your own cloud account โ that remains yours to keep or terminate.
7. Security
We implement industry-standard security measures including encryption in transit (TLS), encrypted storage for sensitive fields, and access controls. No method of transmission over the Internet is 100% secure.
Particularly sensitive credentials โ including Apple Developer certificates, provisioning profiles, AI API keys, and cloud access keys โ are stored with AES-256 encryption. Access is strictly limited to the automated build and deployment systems that require them to fulfill your request. No Appzentic employee has routine access to these credentials in plain text.
For servers of your own, the console never initiates a connection into your machine. The agent installed on it polls us for work, which means we hold no inbound access to your server and you are not asked to open a port to us. Revoking the cloud credential, or removing the agent, ends our access entirely.
8. Children's Privacy
The Service is not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a notice on the Service. Continued use of the Service after changes constitutes acceptance.
10. Contact
Appzentic Inc.
Email: privacy@appzentic.com