Privacy Policy
Last updated: 14 August 2026
This Privacy Policy explains how apppricer handles personal data when you use the website at apppricer.com, our account and subscription features, and our MCP server (the "Service"). We keep the amount of personal data we hold deliberately small.
1. Who is responsible for your data
The data controller is APPPRICER, based in Spain. For any privacy request, contact [email protected].
2. What this policy covers
This policy is about your personal data as a visitor or customer. The app information the Service publishes — prices, products, ratings and metadata of apps on the App Store — is public information about those apps and their developers, not personal data we collect about you, and it is not the subject of this policy.
3. What we collect and why
| Data | Why |
|---|---|
| Account data — your email address and an internal user identifier, the workspace you belong to, and your subscription status | To create and run your account, give access to paid features, and provide the Service |
| Authentication data — handled by Supabase; if you sign in with Google, we receive your email address and basic profile from Google | To sign you in securely and keep your session |
| Billing data — a customer/subscription identifier and plan status from Paddle. We do not receive or store your full card number; Paddle handles payment details as merchant of record | To manage subscriptions, renewals and invoices |
| Usage and device data — product-analytics events, approximate location from IP address, browser and device information, and server logs | To keep the Service secure, diagnose errors, and understand and improve how it is used |
| Cookies — an essential session cookie and analytics cookies (see section 8) | To keep you signed in and measure usage |
We do not collect special-category ("sensitive") personal data — such as data about your health, ethnicity, religion or sexual orientation. We also do not buy or obtain personal data about you from data brokers; the only third party we receive personal data from is Google, and only if you choose to sign in with it, in which case we get your email address and basic profile.
4. Legal bases (GDPR)
- Performance of a contract — creating and running your account, giving access to paid features, and processing your subscription.
- Legitimate interests — keeping the Service secure, preventing abuse, and analysing and improving the product, balanced against your rights.
- Consent — where required, for non-essential analytics cookies; you can withdraw it at any time.
- Legal obligation — keeping records we are required to keep, for example for tax and accounting.
5. Who processes data on our behalf
We share personal data only with the service providers we need to run the Service, each acting as our processor or as an independent controller for its part:
| Provider | Role | Location |
|---|---|---|
| OVHcloud | Hosting of the application and databases | United States |
| Supabase | Authentication and user identity | United States |
| PostHog | Product analytics and error logs | United States |
| Paddle | Payments, as merchant of record | United Kingdom / EU |
| Cloudflare | Frontend delivery (CDN / edge) | Global |
| Optional "Sign in with Google" | United States |
We do not sell your personal data, and we do not share it for third-party advertising.
6. International transfers
We are established in the EU, but our hosting, authentication and analytics run in the United States. Using the Service therefore involves transferring your personal data outside the European Economic Area. We rely on appropriate safeguards for these transfers — the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework. You can ask us for more detail about the safeguards in place using the contact address above.
7. How long we keep it
We keep account and subscription data for as long as your account exists and then only as long as needed for our legal and accounting obligations. Billing records are retained for the period required by tax law. Analytics and log data are kept for a limited period and then deleted or aggregated. When you close your account we delete or anonymise your personal data unless we must keep some of it by law.
8. Cookies
We use a strictly necessary, httpOnly session cookie to keep you
signed in — this cannot be turned off without breaking sign-in. We also use
analytics (PostHog) to understand usage. Public app pages that need no account
ship no JavaScript by default. Where consent is required for non-essential
cookies, we ask for it and you can change your choice at any time.
Do Not Track. Some browsers can send a "Do Not Track" (DNT) signal. There is no common industry standard for how to respond to it, so we do not currently act on DNT signals. If a standard is adopted, we will follow it and update this policy.
9. Your rights
If the GDPR applies to you, you have the right to access your data, to correct or delete it, to restrict or object to processing, to data portability, and to withdraw consent where processing is based on it. To exercise any of these, email [email protected]. You also have the right to complain to a supervisory authority — in Spain, the Agencia Española de Protección de Datos (AEPD).
If you are a California resident, you have the right to know what personal information we collect, to request its deletion, and not to be discriminated against for exercising these rights. We do not sell your personal information. Use the same contact address to make a request.
10. Security
We protect data with encrypted connections, tokens validated on our side, session cookies that scripts on the page cannot read, and access limited to what each part of the system needs. No method of transmission or storage is completely secure, but we take reasonable measures to protect your data.
11. Children
The Service is not directed to children and is not intended for anyone under 16. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy. When we do, we will change the "last updated" date above and, for material changes, take reasonable steps to notify account holders.
13. Contact
Questions or requests about your data: [email protected]