Privacy Policy
Last updated: 22 July 2026
This policy explains how AppNGen ("AppNGen", "we", "us") — a business based in the United Kingdom and the data controller for the personal data described here — collects, uses and protects information when you use appngen.ai, studio.appngen.ai, account.appngen.ai and the AppNGen service (together, the "Service"). Questions or requests: privacy@appngen.ai.
1. What we collect
- Account data — your email address, a hashed password (or your OAuth identity if you sign in with a third-party provider), email-verification status and plan details.
- Project content — the prompts, briefs, designs, files and source code in your projects, including code generated for you by the Service and the git history of each project.
- Usage data — build and sprint activity, feature usage, model/credit consumption, approximate region (for currency selection), device and log data such as IP address, browser type and timestamps, and diagnostic records of errors.
- Billing data — plan, invoices, credit balance and transaction history. Card details are collected and held by our payment providers, not by us.
2. How we use it
We use this data to provide and operate the Service (including generating, building, previewing and deploying your applications), to meter usage and bill you, to secure the platform and prevent abuse, to provide support, to send service messages such as verification codes and billing notices, and to improve the Service. Our legal bases under UK GDPR are performance of our contract with you, our legitimate interests (service security, improvement and fraud prevention), legal obligations (e.g. tax and accounting), and consent where required (e.g. optional marketing).
3. Who processes it
We share personal data with processors and providers who help us run the Service:
- Hosting — Amazon Web Services; the Service and your project data are hosted in the AWS eu-west-2 (London) region.
- Payments — Stripe and Polar process payments and, as merchant of record where applicable, handle your card details, billing address and tax determination under their own privacy policies.
- AI model providers — to generate plans, designs and code, your prompts and relevant project content (including source code) are sent to the large-language-model providers we use for generation. They process this data to provide the generation service to us; we do not permit them to use your content to train their models except where a provider's terms we have accepted say otherwise.
- Email delivery — transactional-email providers used to send verification codes and service messages.
Some providers (including AI model providers) may process data outside the UK. Where they do, we rely on appropriate safeguards such as UK adequacy regulations or the standard contractual clauses / UK International Data Transfer Addendum. We do not sell your personal data.
4. Retention
Account and project data are kept while your account is active. If you delete a project, or close your account, we delete the associated content within a reasonable period, except where we must keep records longer for legal, tax, billing-dispute or security purposes. Server logs and diagnostic data are kept for short rolling periods. Backups expire on a rolling schedule.
5. Your rights (UK GDPR)
You have the right to request access to your personal data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw consent where processing is based on consent. To exercise a right, email privacy@appngen.ai. You can also export your project repositories directly from the Service at any time. If you are unhappy with how we handle your data you may complain to the UK Information Commissioner's Office (ico.org.uk).
6. Cookies and local storage
The Service uses browser local storage for essential purposes: keeping you signed in on account.appngen.ai and remembering preferences such as your theme. We do not use third-party advertising cookies on the marketing site.
7. Security
We protect data with technical and organisational measures including encryption in transit, access controls, workload isolation and monitoring. No online service can be guaranteed 100% secure; see our Terms of Service for how responsibility is allocated between us.
8. Changes and contact
We may update this policy from time to time; material changes will be notified by email or in-product. Contact us at privacy@appngen.ai.