Privacy Policy
Effective August 14, 2026
What we collect
When you register with email, we store your email address, verification status, and a one-way salted password hash; we do not store your password in plain text. Random tokens used for email verification and password recovery are stored only as hashes and work once. When you sign in with Google, GitHub, or Apple, we store the account identifier, email address, display name, and avatar when provided. We also process session identifiers, IP address, browser information, and access time as needed to maintain sessions and prevent abuse.
How we use information
We use this information only to create and protect accounts, provide Applode, troubleshoot issues, and prevent abuse. We do not sell personal information or combine public App Store data with personal profiles for advertising.
AI questions
Questions submitted through Ask AI, together with the necessary app data retrieved by the system, are sent to our model provider, AWS Bedrock, to estimate tokens and generate responses. To support pre-run confirmation, the question and context are stored temporarily in Applode's authentication database. The text is cleared immediately after confirmation, and unconfirmed content is cleared after the estimate expires. We retain usage, model, billing, and abuse-prevention records that do not contain conversation text. Infrastructure providers may still process short-term logs under their security and operational policies.
Payments and Stripe
When you buy credits, Stripe processes the payment. We provide Stripe with the account-linking identifier, email when available, selected product, and checkout information needed for the transaction. Stripe collects full payment credentials such as card numbers directly; Applode does not store them. We retain Stripe customer, order, payment-status, amount, currency, refund, and credit-ledger records for fulfillment, reconciliation, fraud prevention, and disputes. Stripe processes payment data under its own privacy policy.
Cookies and sessions
We use one necessary security cookie to maintain your login. It uses Secure, HttpOnly, and SameSite protections and is not used for cross-site advertising. Login sessions last up to 30 days, expire earlier after seven days of inactivity, and are invalidated when you log out.
Verification, email, and providers
Email registration, login, and password recovery use Cloudflare Turnstile to distinguish legitimate users from automated abuse; Cloudflare processes network and device signals needed for that check under its privacy terms. Verification and password-reset emails are delivered through Resend, which receives the destination address and email content for delivery. Use only links sent from Applode's official email domain.
Retention and sharing
Account and identity-linking information is retained until the account is deleted or the service ends. Used and expired one-time token records are periodically removed, while security and abuse-prevention records are retained for a limited operational period. We share necessary data only with infrastructure, email, and identity providers required to operate the service, or when disclosure is legally required.
Your choices
You may log out and revoke Applode's access through your login provider. To access, correct, or delete account data, contact us using the account you use to sign in to Applode. We will process these requests manually until in-product account controls are available.
Changes
If this policy changes materially, we will update the effective date on this page and provide an in-product notice when appropriate.