Privacy Policy
What we collect when you build an app with AppyMakr, why we need it, and who else sees it.
Last updated: 25 July 2026
1. Who we are
AppyMakr ("we", "us", "our") provides a service at appymakr.com and app.appymakr.com that turns a website you own into native Android and iOS applications. For data protection purposes we are the controller of the personal data described in this policy. You can reach us at support@appymakr.com.
This policy explains what we collect when you use AppyMakr, why, who else sees it, and what you can ask us to do about it. It covers our own service only. It does not cover the apps you build with AppyMakr — see section 5.
2. What we collect
Information you give us
- Account details — your email address and a password. Passwords are stored as a one-way hash; we cannot read them.
- App configuration — the app name, the website address you want wrapped, colours, orientation, navigation layout, which device permissions your app requests, and any images you upload (app icon, launch screen, drawer background).
- Push notification credentials — if you choose to enable push notifications, the OneSignal App ID and REST API key you supply.
- Anything you send us by email.
Information we generate
- Build records — when a build runs, we store its status, timestamps and the resulting app files so you can download them.
- Subscription records — which plan you are on, and the customer and subscription identifiers issued by Stripe. We never see or store your card details — those go directly to Stripe.
Information collected automatically
- Server logs — your IP address, browser user-agent, the pages or API endpoints requested, and the date and time. These are ordinary web server logs used for security and debugging.
- Sign-in tokens — stored in your browser so you stay signed in. See section 6.
We do not run analytics or advertising trackers. There is no Google Analytics, no Meta pixel, and no advertising cookie on this site. We do not sell personal data, and we never have.
3. Why we use it
| What we use | What for | Our lawful basis (UK/EU GDPR) |
|---|---|---|
| Email, password hash | Creating your account and signing you in | Performance of our contract with you |
| App configuration and uploaded images | Building your app; showing you a preview | Performance of our contract |
| Subscription and plan records | Taking payment, managing renewals, invoicing | Performance of our contract; legal obligation (tax records) |
| Server logs | Keeping the service secure and diagnosing faults | Legitimate interests (running a secure service) |
| Your email address | Service messages such as build results or billing problems | Performance of our contract |
We do not use your data to train machine learning models, and we do not send marketing email unless you have asked us to.
4. Who else processes it
Running AppyMakr means passing certain data to specialist providers. Each one receives only what it needs:
| Provider | What it receives | Why |
|---|---|---|
| Stripe | Your email and payment details, entered directly into Stripe's own fields | Taking subscription payments |
| Codemagic | Your app configuration and uploaded assets | Compiling your Android and iOS app files |
| OneSignal | The credentials you supply, plus device tokens from your app's users | Delivering push notifications you send |
| Expo | Your app configuration and the preview template, uploaded when you use the phone preview | Letting you preview your app in Expo Go before building |
| Our hosting provider | Everything, as the operator of the servers and databases | Hosting the service in an EU data centre |
| Cloudflare | Your IP address and request metadata | DNS and protection for our domains |
The marketing pages on appymakr.com load web fonts from Google Fonts and a stylesheet from the Tailwind CDN. Loading those files reveals your IP address to those providers. The signed-in application at app.appymakr.com serves its fonts from our own server.
We may also disclose data where we are legally required to, or to establish or defend legal claims.
5. Your app's own users
This is worth being clear about. When you publish an app built with AppyMakr, you — not us — are the controller of any personal data that app collects from the people who install it. That includes push notification tokens, any location, camera or microphone access your app requests, and anything your own website collects once it loads inside the app.
You are responsible for having your own privacy policy for your app, and for meeting Apple's and Google's disclosure requirements. If your app requests device permissions, you must explain why in the descriptions you configure.
6. Cookies and browser storage
We use browser storage only to keep you signed in and to remember your language choice. These are strictly necessary for the service to work, so no consent banner is required. There are no analytics, advertising or profiling cookies of any kind.
Signing out, or clearing your browser storage, removes these.
7. How long we keep it
- Account and app configuration — while your account is open. If you delete an app or your account, we mark the record deleted and remove it from our active systems.
- Build files — retained so you can re-download them, and removed when the app or account is deleted.
- Billing records — kept for as long as tax law requires (currently six years in the UK), even after you close your account.
- Server logs — rotated and deleted in the normal course, typically within a few months.
- Backups — we keep encrypted backups; deleted data may persist in a backup for a short period before it ages out.
Ask us at support@appymakr.com and we will delete your account and its data, except where we must keep billing records.
8. Where your data goes
Our servers are in the European Union. Several providers in section 4 — including Stripe, OneSignal, Expo, Codemagic and Cloudflare — process data in the United States or other countries outside the UK and EEA. Where that happens, transfers rely on the safeguards those providers put in place, such as the UK International Data Transfer Addendum or the EU Standard Contractual Clauses.
9. Your rights
Under UK and EU data protection law you can ask us to:
- give you a copy of the personal data we hold about you;
- correct anything inaccurate;
- delete your data (subject to records we must keep);
- restrict or object to how we use it;
- send your data to you or another provider in a portable format;
- withdraw consent, where we relied on consent.
Email support@appymakr.com and we will respond within one month. If you are unhappy with our response you can complain to the UK Information Commissioner's Office at ico.org.uk, or to your local supervisory authority in the EEA.
10. Security
Traffic to and from our sites is encrypted with TLS. Passwords are stored as one-way hashes. Access to the servers and database is restricted to administrators, and sign-in tokens are short-lived and refreshed automatically. Payment card details never reach our servers.
No system is perfectly secure. If a breach affects your personal data and is likely to present a risk to you, we will tell you and the relevant regulator as the law requires.
11. Children
AppyMakr is a business tool and is not intended for children. You must be at least 16 to hold an account. We do not knowingly collect data from children; if you believe a child has given us personal data, contact us and we will remove it.
12. Changes to this policy
If we change this policy we will update the date at the top of the page. Where a change materially affects how we handle your data, we will email account holders rather than rely on you noticing.
Questions?
Email support@appymakr.com and we'll come back to you.