Legal

Privacy Policy

Last updated: July 17, 2026

1. What this covers

This policy explains what data Appial Labs (“we”, “us”) collects when you use the Service, why we collect it, and the choices you have. It applies to the marketing site and the logged-in product.

2. Data we collect

  • Account data — name, email, password (stored as a hash), organization membership.
  • Product data you provide — your app’s details (store links, website, description), brand information, uploaded images (for example inspiration screenshots), and edits you make to generated content.
  • Generated content — the strategy, copy, images and videos the Service produces for you.
  • Connected-account tokens — when you connect a social account we store the OAuth access token, encrypted, used only to publish content you approve.
  • Billing data — your plan, credit usage, and subscription status. Card details go directly to Stripe; we never see or store full card numbers.
  • Usage data — product events (for example “app created”, “content published”), server logs, and privacy-friendly, cookieless traffic analytics on the marketing site.

3. How we use it

We use your data to operate the Service: generate content, publish to accounts you connect, meter credits, bill subscriptions, send transactional email (verification, invitations, receipts, service notices), prevent abuse, and improve the product. We do not sell your personal data and we do not use your content to train our own AI models.

4. AI processing

To generate content, relevant inputs (your app description, brand profile, ideas, and any inspiration material you attach) are sent to AI providers — currently Google (Gemini), OpenAI (voice and transcription), fal.ai (images) and Shotstack (video rendering) — under their API terms, which restrict them from using API data to train their models in the configurations we use. Only what is needed for the specific generation is sent.

5. Service providers

We rely on a small set of processors to run the Service:

  • Cloudflare — hosting, storage and traffic analytics
  • Neon — database
  • Stripe — payments and subscriptions
  • Resend — transactional email
  • Google, OpenAI, fal.ai, Shotstack — AI generation and rendering
  • The social platforms you choose to connect (for example X, LinkedIn)

6. Cookies

We use essential cookies only: a session cookie to keep you signed in and a preference for your theme. Marketing-site traffic analytics are cookieless. We do not run third-party advertising trackers.

7. Retention and deletion

We keep your data while your account is active. If you delete your account or an organization, associated data is retained for up to 30 days (so you can recover or export it) and then deleted from active systems; encrypted connected-account tokens are deleted immediately when you disconnect a platform. Billing records are kept as long as tax and accounting law requires.

8. Your rights

Depending on where you live (for example under the GDPR or CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. Contact us through your account dashboard or the contact details on this site and we will respond within 30 days. You can also disconnect social accounts or delete apps and their content directly in the product at any time.

9. Security

Data is encrypted in transit, social tokens are encrypted at rest, and access to production systems is restricted. No system is perfectly secure — if we learn of a breach affecting your personal data we will notify you as required by law.

10. Children

The Service is not directed to children and may not be used by anyone under 16.

11. Changes

We will post updates to this policy here and, for material changes, notify you by email or in-product notice before they take effect.