1. Overview
AppsBrains (“AppsBrains”, “we”, “us” or “our”) builds and publishes mobile applications for iOS and Android and operates this website. We respect your privacy and are committed to handling your personal information transparently and lawfully.
This Privacy Policy applies to:
- Our website and any subdomains (the “Site”);
- Mobile applications published by AppsBrains on the Apple App Store and Google Play (the “Apps”);
- Sales, support and consultation communications with us (together with the Site and Apps, the “Services”).
For the purposes of the UK GDPR and the EU GDPR, AppsBrains is the data controller for personal data processed through our own Site and Apps. Where we build or maintain an app on behalf of a client, that client is the controller and we act as a data processor under a written data processing agreement; that app’s own privacy policy governs it, not this one.
2. Information We Collect
2.1 Information you give us
- Contact and enquiry data — first and last name, email address, phone number, company name, budget range, and the content of the message you submit through our contact or support forms.
- Account data — where an App offers accounts: your email address, display name, password (stored only as a salted hash), and any profile details you choose to add.
- Support data — the content of emails, bug reports, screenshots and attachments you send to our support team.
- User content — files, text, images or other content you create or upload within an App, where that App offers such a feature.
2.2 Information collected automatically
- Device and technical data — device model, operating system and version, app version, language, time zone, screen size, and a resettable device or installation identifier.
- Usage and diagnostics data — screens viewed, features used, session duration, crash logs, stack traces and performance metrics.
- Log data — IP address, browser type, referring page and timestamps, recorded by our hosting provider for security and abuse prevention.
- Approximate location — coarse location inferred from your IP address. We do not collect precise GPS location unless an App explicitly asks for it and you grant the permission.
2.3 Information we do not collect
We do not knowingly collect government identification numbers, biometric identifiers, precise health data, or payment card numbers. All purchases in our Apps are processed by Apple or Google — we never see or store your full card details.
3. How We Use Your Information
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Provide, operate and maintain the Services | Account, device, usage data | Performance of a contract |
| Respond to enquiries, quotes and support requests | Contact and support data | Legitimate interests / pre-contractual steps |
| Diagnose crashes and improve stability | Diagnostics, device data | Legitimate interests |
| Understand feature usage and improve the product | Aggregated usage analytics | Consent (where required) or legitimate interests |
| Prevent fraud, abuse and security incidents | Log data, IP address | Legitimate interests / legal obligation |
| Send service notices (e.g. policy changes, outages) | Email address | Performance of a contract |
| Send marketing emails | Email address, name | Consent (withdrawable at any time) |
| Comply with legal, tax and accounting obligations | Transaction and contact records | Legal obligation |
We do not sell your personal information, and we do not share it with third parties for cross-context behavioural advertising. We do not use your personal data to train machine learning models.
5. Third-Party Services We Use
The exact set of services used varies by App; the table below covers the providers we may rely on. Each App’s store listing carries a Data Safety / App Privacy label describing the data that specific App handles.
| Provider | Purpose | Data involved |
|---|---|---|
| Google Firebase (Hosting, Firestore, Authentication) | Website hosting, data storage, account sign-in | Contact data, account data, IP address |
| Firebase Crashlytics | Crash reporting and stability | Crash logs, device model, OS version |
| Google Analytics for Firebase | Aggregated product analytics | Usage events, device identifiers |
| Apple App Store / Google Play | App distribution, payments, subscriptions | Purchase records (handled by Apple/Google) |
| Google Fonts & Cloudflare CDN | Serving fonts and icon assets on the Site | IP address, browser user-agent |
| Email provider | Delivering support and transactional email | Email address, message content |
Each provider operates under its own privacy policy. We select providers that offer appropriate technical and organisational security measures and, where relevant, sign data processing agreements incorporating Standard Contractual Clauses.
6. Device Permissions
Our Apps request device permissions only when a feature needs them, and always with an in-context explanation. You may decline or later revoke any permission in your device settings; the App will continue to work, minus the feature that depends on it.
| Permission | Why it may be requested |
|---|---|
| Camera | Taking a photo or scanning a code inside the App |
| Photo library | Selecting an image you choose to upload |
| Notifications | Sending alerts you have opted into |
| Location | Location-dependent features, only while using the App |
| Storage / Files | Saving or importing documents you select |
| Microphone | Recording audio when you initiate it |
Permission data is used solely for the stated feature and is never sold or used for advertising.
7. Data Retention
| Data category | Retention period |
|---|---|
| Account data | For the life of the account, then deleted within 30 days of a deletion request |
| User content | Until you delete it, or within 30 days of account deletion |
| Contact / enquiry form submissions | 24 months from last contact |
| Support correspondence | 24 months after the ticket is closed |
| Crash and diagnostic logs | Up to 90 days |
| Aggregated, anonymised analytics | Retained indefinitely (no longer personal data) |
| Invoices and tax records | As required by law, typically 7 years |
| Server access logs | Up to 30 days |
Backups are rotated on a rolling schedule and any residual copies of deleted data are purged within 90 days.
8. Your Privacy Rights
Depending on where you live, you may have the right to:
- Access — obtain a copy of the personal data we hold about you;
- Rectify — correct inaccurate or incomplete data;
- Erase — request deletion of your data (see section 9);
- Restrict or object — limit or object to certain processing, including direct marketing;
- Port — receive your data in a structured, machine-readable format;
- Withdraw consent — at any time, without affecting processing already carried out;
- Opt out of sale/sharing — under the CCPA/CPRA. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of;
- Non-discrimination — we will not deny service or degrade quality because you exercised a privacy right;
- Complain — lodge a complaint with a supervisory authority. Our lead authority is the UK Information Commissioner’s Office (ICO); if you are in the EEA you may also complain to your national data protection authority.
To exercise any right, email apps@appsbrains.co or use the account & data deletion form. We respond within 30 days (extendable by a further 60 days for complex requests, with notice). We may ask you to verify your identity before acting on a request.
9. Deleting Your Account and Data
You can delete your account and associated data at any time:
- In-app — where the App offers accounts, open Settings → Account → Delete Account.
- On the web — submit the form on our Delete Account & Data page.
- By email — write to apps@appsbrains.co from the address linked to your account.
Deletion removes your profile, credentials, user content and usage history from our active systems within 30 days and from backups within 90 days. Anonymised aggregate statistics and records we are legally required to keep (such as invoices) are retained. Deletion is permanent and cannot be undone.
Deleting your account does not automatically cancel a subscription purchased through the App Store or Google Play. Cancel it in your Apple or Google account settings — see our Refund & Cancellation Policy.
10. Children’s Privacy
Our Services are not directed to children under 13 (or under 16 in the EEA/UK, where local law sets a higher age), and we do not knowingly collect personal information from them. Apps that are rated for children comply with the Children’s Online Privacy Protection Act (COPPA), Google Play’s Families Policy and Apple’s Kids Category requirements: no behavioural advertising, no third-party analytics that build profiles, and no collection of persistent identifiers beyond what is needed for internal operations.
If you believe a child has provided us with personal data, contact apps@appsbrains.co and we will delete it promptly. See also our Child Safety Standards.
11. Security
We apply technical and organisational safeguards proportionate to the risk, including:
- TLS 1.2+ encryption for all data in transit;
- Encryption at rest for stored data on our cloud infrastructure;
- Passwords stored only as salted one-way hashes — never in plain text;
- Role-based access control and least-privilege access for staff;
- Mandatory two-factor authentication on administrative accounts;
- Regular dependency patching and security review of releases.
No system is perfectly secure. If a breach affects your personal data and poses a risk to your rights, we will notify you and the relevant supervisory authority without undue delay and, where required, within 72 hours of becoming aware of it.
12. International Data Transfers
We are based in the United Kingdom and use cloud infrastructure that may store or process data in the United Kingdom, the European Union, the United States and other regions. Where personal data is transferred out of the UK or the EEA, we rely on UK adequacy regulations, the UK International Data Transfer Agreement or Addendum, or the European Commission’s Standard Contractual Clauses, together with supplementary technical measures such as encryption.
14. Changes to This Policy
We may update this policy to reflect changes in our Services or the law. The “Last updated” date at the top always reflects the current version. For material changes we will give prominent notice — an in-app notice, a banner on the Site, or an email to registered users — at least 14 days before the change takes effect. Continuing to use the Services after that date means you accept the updated policy.
15. Contact Us
Questions, requests or complaints about privacy? Reach our privacy team — we reply within two business days.