AppStaged · AppEcho Labs
Privacy Policy
Effective and last updated:
AppStaged is owned and operated by AppEcho Labs, based in Alexandria, VA 22304, United States. This Privacy Policy explains how we handle information when you visit appstaged.com, use the screenshot editor, connect an agent, or use our related services.
1. Information we collect
- Account information: your email address, account identifier, profile and preference information, and authentication records. If you sign in with Google, we receive account information such as your name, email address, and profile picture. Firebase Authentication processes email/password sign-in credentials.
- Your work: app names and descriptions, screenshot sets, uploaded images, logos, text, design settings, saved templates, project versions, and generated exports that you save or process through the service. Screenshots can contain personal information; use sample data or remove information you do not need to share.
- AI requests: prompts, selected text, app descriptions, relevant design information, and screenshots or previews needed for an AI feature, together with its response and usage information.
- Connections and API access: store identifiers, connection metadata, credentials you provide for App Store Connect or Google Play, and API-key records, permissions, and usage. Store credentials are stored encrypted and used to carry out the connection and publishing functions you request.
- Billing information: subscription status, purchases, credit balances, and Stripe customer, transaction, and invoice references. Payment details are collected by Stripe; AppStaged does not store your full payment-card number or security code.
- Technical and support information: request and error logs, timestamps, usage counts, browser and device information, IP addresses processed by our hosting and service providers, and information you send when contacting support.
2. How we use information
We use information to authenticate you, save and recover your work, render exports, fulfill AI and publishing requests, process payments, manage subscriptions and credits, respond to support requests, and send account or service notices. We also use it to troubleshoot problems, maintain security, prevent abuse, enforce usage limits and our Terms, and meet legal obligations.
We do not sell your personal information or share it for cross-context behavioral advertising. AppStaged does not use advertising trackers. When enabled, PostHog helps us understand visits, signups, project creation, exports, and checkout starts so we can improve the product. Analytics events use account identifiers rather than names or email addresses. We also record a broad acquisition category (such as Google search or ChatGPT referral) and the public page where a visit began. These categories are derived in your browser; full referring URLs and campaign values are not sent. We do not send screenshot content, project names, or URL query strings in these events, and session recording is disabled.
3. Service providers and optional connections
We disclose information as needed to providers that support the service:
- Google Firebase and Google Cloud provide authentication, databases, file storage, hosting, and server-side rendering infrastructure. See Google's Privacy Policy.
- Stripe processes payments and supports subscriptions, invoices, billing management, and fraud prevention. See Stripe's Privacy Policy.
- PostHog processes product analytics events, account identifiers, and browser/device information when analytics is enabled. See PostHog's Privacy Policy.
- Anthropic processes relevant inputs when you use AppStaged's built-in AI features. See the AI section below.
- Apple and Google receive credentials or authorization tokens, app identifiers, screenshots, and related listing information when you connect their stores or request publishing. Their own terms and privacy policies govern their services.
- Third-party agents you connect can access information and perform actions allowed by the API key you give them. Their providers may receive your documents, prompts, images, or exports. Review that provider's privacy settings and policies before connecting it.
Your browser also requests fonts from Google Fonts and may load remote images included in your work or profile. These requests reveal connection information, such as your IP address, to the relevant host.
We may disclose information when reasonably necessary to comply with law or valid legal process, protect rights and safety, investigate abuse, or complete a merger, acquisition, or sale of business assets subject to appropriate confidentiality protections. We may also share information at your direction.
4. AI features
Using an AI feature sends the information needed for that feature to Anthropic's API. Depending on the action, this can include screenshots, rendered previews, text, app details, and design structure. Avoid including sensitive personal information or confidential information you are not authorized to disclose.
AppEcho Labs does not use your private project content to train its own general-purpose AI models. Anthropic's commercial API data practices, including retention and any applicable exceptions, are described in its API data-retention documentation. We do not promise zero provider retention. A separately connected agent is governed by its own provider's policies and your account settings there.
5. Cookies and browser storage
AppStaged and its authentication or payment providers may use cookies or similar technologies for sign-in, security, and payment functionality. The editor uses local storage and IndexedDB for preferences, offline document caching, and recovery checkpoints. When analytics is enabled, PostHog uses browser storage to associate visits and product events. Analytics does not initialize when the browser sends Do Not Track or Global Privacy Control.
You can clear site data through your browser settings, but doing so can sign you out and remove unsynced work or local recovery copies. Signing out or deleting cloud data does not necessarily remove copies stored on every device. On a shared device, sign out and clear the site's browser data when finished.
6. Retention and deletion
We retain account information and saved work while needed to provide your account and the features you use. You can delete projects, remove store connections, revoke API keys, and request account deletion through the app. Account deletion is available in Settings → Account and requires recent authentication. It removes associated active account data and saved cloud work and cancels an associated subscription as part of that process.
Some information may remain where needed for tax and accounting obligations, payment disputes, fraud prevention, security, legal claims, or other legal requirements. Provider records, operational logs, and any backup copies may follow separate retention schedules. Retention depends on the purpose, sensitivity, legal requirements, and whether information is needed to resolve an outstanding issue; we do not promise immediate deletion from every system.
Deleting an AppStaged account does not remove files you downloaded, information already sent to a third-party agent, or screenshots already published to a store. Manage those copies with the relevant service. Clear browser site data to remove local copies on your devices.
7. Your choices and privacy requests
You can update available profile settings, export your designs, disconnect stores, revoke API keys, and delete your account. For a request to access, correct, obtain a copy of, or delete personal information, email support@appstaged.com. Where applicable law provides rights to restrict or object to processing, withdraw consent, or opt out of certain processing, you can use the same address. Withdrawing consent does not affect earlier lawful processing.
We may need to verify your identity and clarify your request before acting. We respond within the time required by applicable law, subject to permitted exceptions, and do not discriminate against you for exercising applicable privacy rights. If we decline a request, you may ask for a review by replying with “Privacy appeal” and explaining your concern. Where applicable, you may also complain to your local privacy regulator or the Virginia Attorney General.
8. Security and international processing
We use access controls, encrypted connections, and encryption for stored store-connection credentials to help protect information. No system can guarantee complete security. Protect your password and API keys, and notify us if you suspect unauthorized access.
AppEcho Labs is based in the United States. We and our providers may process information in the United States and other countries where we operate; privacy protections may differ from those in your country. Where required, international processing must be covered by applicable legal safeguards.
9. Children
AppStaged is intended for adults creating app marketing materials and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided it, contact us so we can investigate and remove it as appropriate.
10. Changes to this policy
We may update this policy as the service or our practices change. We will update the date above and provide notice of material changes through the service or by email where appropriate or required. Where a change requires consent under applicable law, we will obtain it before applying that change.
Contact us
For questions about these terms or our privacy practices, contact:
AppEcho LabsAlexandria, VA 22304, United States
support@appstaged.com