Privacy
Last updated 17 September 2026
Who controls your data
AppCrafter is operated by Blissfulplan Publishing Ltd., registered at Covent Garden, 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom. That company is the data controller for the information described below.
Your AI provider keys
AppCrafter runs on your own AI accounts. This is the part of the product with the most privacy consequence, so it is stated first and plainly.
- When you run research, your key is sent to our server, used to call that provider on your behalf, and discarded when the request ends. It is never written to our database.
- If you tick Remember my keys in this browser, the key is stored in your own browser’s local storage. That is unencrypted and readable by any script running on the page. The box is off by default, and leaving it off on a shared computer is the right choice.
- Keys an administrator saves in the platform integrations vault are encrypted with AES-256-GCM before storage, and are never returned to a browser — only a masked preview such as
sk-ant…4f2a. - Your prompts and the research they produce are sent to the provider you chose. Their handling is governed by their terms, not ours.
What we store
- Account. Email address, display name, optional bio, and notification preferences.
- Work. Research runs and the evidence behind them, generated concepts, competitive maps, name candidates, verified domains, brand assets, and project configuration.
- Usage. A record of each research run, name, identity and logo generation, so plan limits can be enforced. This records that a run happened, with the provider and model, not its content.
- Billing. A Stripe customer identifier and subscription status. Card details are held by Stripe and never reach our servers.
What we never store
- Your AI provider API keys, when used for your own runs.
- Card numbers or payment credentials.
- Passwords in readable form. Authentication is handled by Supabase.
Who else sees it
We do not sell data or share it for advertising. Data reaches third parties only where the product needs it to work: Supabase hosts the database and authentication, Stripeprocesses payments, the AI provider you select receives your prompts, and RDAP registries receive the domain names checked for availability.
Deleting your account
Settings → Danger Zone deletes your account. Removing it cascades to every project, research run, saved concept, brand asset and integration credential you own, and removes your generated files from storage. This is immediate and cannot be undone.
Your rights
You can ask us for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. Deletion is also available directly in the product, under Settings → Danger Zone. If you are in the UK or EU and believe we have handled your data improperly, you may complain to your data protection authority; in the UK that is the Information Commissioner’s Office.
Contact
Questions about any of this, or a request about your data, go to support@appcrafter.app, or through the contact page.
Blissfulplan Publishing Ltd.Covent Garden
71-75 Shelton Street
London
WC2H 9JQ
United Kingdom