Privacy Policy
Last updated: July 13, 2026
This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.
We use Your Personal Data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.
Interpretation and Definitions
Interpretation
The words whose initial letters are capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
For the purposes of this Privacy Policy:
Account means a unique account created for You to access our Service or parts of our Service.
Affiliate means an entity that controls, is controlled by, or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.
Application means the web-based software dashboard provided by the Company and accessible at app.appthunder.io, which You use to configure, generate and manage Your Generated Applications.
Business, for the purpose of CCPA/CPRA, refers to the Company as the legal entity that collects Consumers' personal information and determines the purposes and means of the processing of Consumers' personal information, that does business in the State of California.
CCPA and/or CPRA refers to the California Consumer Privacy Act (the "CCPA") as amended by the California Privacy Rights Act of 2020 (the "CPRA").
Company (referred to as either "the Company", "We", "Us" or "Our" in this Privacy Policy) refers to AMDMarketing (sole proprietor: Alejandro Morillo Diaz), Am Markt 14, 23769 Fehmarn, Germany.
For the purposes of the GDPR, the Company is the Data Controller.
Consumer, for the purpose of the CCPA/CPRA, means a natural person who is a California resident.
Country refers to: Germany.
Data Controller, for the purposes of the GDPR (General Data Protection Regulation), refers to the Company as the legal person which alone or jointly with others determines the purposes and means of the processing of Personal Data.
Device means any device that can access the Service such as a computer, a cell phone or a digital tablet.
Do Not Track (DNT) is a concept that has been promoted by US regulatory authorities, in particular the U.S. Federal Trade Commission (FTC), for the Internet industry to develop and implement a mechanism for allowing internet users to control the tracking of their online activities across websites.
Generated Application means the compiled iOS and/or Android application binaries (and, where applicable, the underlying source code) produced by the Service from Your Content.
GDPR refers to EU General Data Protection Regulation.
Personal Data (or "Personal Information") is any information that relates to an identified or identifiable individual.
For the purposes of GDPR, Personal Data means any information relating to You such as a name, an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity.
We use "Personal Data" and "Personal Information" interchangeably unless a law uses a specific term.
Service refers to the Application or the Website or both.
Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used. For the purposes of the GDPR, Service Providers are considered Data Processors.
Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
Website refers to AppThunder, accessible from appthunder.io.
You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
Under GDPR, You can be referred to as the Data Subject or as the User as you are the individual using the Service.
Collecting and Using Your Personal Data
Types of Data Collected
Personal Data
While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:
Email address
First name and last name (optional)
Content You Submit for App Generation
To provide the Service, We process the URL and content of the website or web application You submit for conversion into a Generated Application, along with the configuration You provide (app name, package identifier, branding, declared permissions, and similar build settings).
App Signing Credentials You Provide (Not Stored)
Depending on the platforms You choose to build for, You may enter, at the moment You start a build:
Apple Developer / App Store Connect credentials (Issuer ID, Key ID, and private signing key), and/or an Android signing keystore.
These are used solely to sign and build Your Generated Application via Our cloud build provider, Codemagic, for that specific build. They are transmitted directly with Your build request over an encrypted connection and are not written to Our database or any other persistent storage — We do not retain a copy after the build completes. You need to re-enter them for each subsequent build.
We do not use a GitHub account or token belonging to You. Generated project files are pushed to a repository We own and control (see "Detailed Information on the Processing of Your Personal Data" below).
Payment Data
When You make a purchase, payment is processed directly by Stripe, Our payment processor. We do not receive or store Your full card details; We retain only order-level information (the Plan or Build Credit package purchased, amount, and date) for accounting, tax, and support purposes.
Usage Data
Usage Data is collected automatically when using the Service.
Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
We may also collect information that Your browser sends whenever You visit Our Service or when You access the Service by or through a mobile device.
Use of Your Personal Data
The Company may use Personal Data for the following purposes:
To provide and maintain our Service, including to monitor the usage of our Service, generate Your Generated Application, and run the cloud builds You request.
To manage Your Account: to manage Your registration as a user of the Service and Your available Build Credits.
For the performance of a contract: the development, compliance and undertaking of the purchase contract for the Plans or Build Credits You have purchased or of any other contract with Us through the Service.
To contact You: To contact You by email regarding updates, build status, or informative communications related to the functionalities of the Service, including security updates, when necessary or reasonable for their implementation.
To provide You with news, special offers, and general information about other services which We offer that are similar to those that you have already purchased or inquired about, unless You have opted not to receive such information.
To manage Your requests: To attend and manage Your requests to Us, including support requests.
For business transfers: We may use Your Personal Data to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets, in which Personal Data held by Us about our Service users is among the assets transferred.
For other purposes: We may use Your information for other purposes, such as data analysis, identifying usage trends, determining the effectiveness of our promotional campaigns and to evaluate and improve our Service.
We may share Your Personal Data in the following situations:
With Service Providers: We share Your Personal Data with the Service Providers listed under "Detailed Information on the Processing of Your Personal Data" below, to operate the Service, process payments, run cloud builds, and provide customer support.
For business transfers: We may share or transfer Your Personal Data in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of Our business to another company.
With Your consent: We may disclose Your Personal Data for any other purpose with Your consent.
Retention of Your Personal Data
The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our legal agreements and policies.
Account Information: retained for the duration of Your account relationship plus up to 24 months after account closure to handle any post-termination issues or resolve disputes.
App Signing Credentials (Apple/Android): not retained at all — used only in-memory to process the build You requested and discarded immediately after; see "App Signing Credentials You Provide" above.
Customer Support Data: support correspondence retained for up to 24 months from the date of resolution.
Usage Data: retained for up to 24 months for security monitoring, troubleshooting, and service-improvement purposes.
Financial and Transaction Data: We retain order and transaction records (Plan/credits purchased, amounts, dates) for up to 10 years from the date of transaction to comply with German tax and commercial record-keeping obligations (§ 147 AO, § 257 HGB). Payment card details are not stored on Our servers; see "Payment Data" above.
We may retain Personal Data beyond the periods stated above where required by law, to establish or defend legal claims, at Your explicit request, or where data exists in backup systems scheduled for routine deletion. You may request information about how long We will retain Your Personal Data by contacting Us.
Transfer of Your Personal Data
Your information, including Personal Data, is processed at the Company's operating location in Germany and by the Service Providers listed below, some of which are located outside the European Economic Area ("EEA"). See "International Transfer of Personal Data" below for the safeguards that apply to such transfers.
Delete Your Personal Data
You have the right to delete or request that We assist in deleting the Personal Data that We have collected about You.
You may update, amend, or delete Your information at any time by signing in to Your Account and visiting the account settings section, or by contacting Us to request access to, correct, or delete any Personal Data that You have provided to Us.
Please note, however, that We may need to retain certain information when we have a legal obligation or lawful basis to do so (see "Retention of Your Personal Data" above).
Disclosure of Your Personal Data
Business Transactions
If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.
Law enforcement
Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
Other legal requirements
The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:
Comply with a legal obligation
Protect and defend the rights or property of the Company
Prevent or investigate possible wrongdoing in connection with the Service
Protect the personal safety of Users of the Service or the public
Protect against legal liability
Security of Your Personal Data
The security of Your Personal Data is important to Us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. App signing credentials You provide (Apple/Android) are transmitted only over encrypted connections (TLS) and, as described above, are never written to Our database. While We strive to use commercially reasonable means to protect Your Personal Data, We cannot guarantee its absolute security.
Detailed Information on the Processing of Your Personal Data
The Service Providers We use may have access to Your Personal Data. These third-party vendors collect, store, use, process and transfer information about Your activity on Our Service in accordance with their own Privacy Policies:
Supabase — database hosting, authentication and file storage. https://supabase.com/privacy
Stripe — payment processing. https://stripe.com/privacy
Vercel — hosting of the Website and Application. https://vercel.com/legal/privacy-policy
GitHub (Microsoft) — hosts the repository We own, to which Your Generated Application's project files are pushed. https://docs.github.com/en/site-policy/privacy-policies/github-privacy-statement
Codemagic (Nevercode OÜ, Estonia) — cloud build infrastructure that compiles Your Generated Application, using the credentials You provide. https://codemagic.io/privacy/
Google (Gemini API) — if You use the optional App Store Guideline Checker feature, the URL and public content of the website You submit is sent to Google's Gemini API for automated analysis. https://policies.google.com/privacy
Payments
We use Stripe for payment processing. We do not store or collect Your payment card details; that information is provided directly to Stripe, whose use of Your personal information is governed by its own Privacy Policy. Stripe adheres to the standards set by PCI-DSS as managed by the PCI Security Standards Council.
GDPR Privacy
Legal Basis for Processing Personal Data under GDPR
We may process Personal Data under the following conditions:
Consent: You have given Your consent for processing Personal Data for one or more specific purposes.
Performance of a contract: Provision of Personal Data is necessary for the performance of an agreement with You and/or for any pre-contractual obligations thereof.
Legal obligations: Processing Personal Data is necessary for compliance with a legal obligation to which the Company is subject.
Legitimate interests: Processing Personal Data is necessary for the purposes of the legitimate interests pursued by the Company (for example, fraud prevention and Service security).
In any case, the Company will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
International Transfer of Personal Data (EU-US Data Privacy Framework)
We use Service Providers based in the United States to operate the Service, including Vercel Inc. (hosting), Stripe Inc. (payment processing), Supabase Inc. (database hosting), Microsoft/GitHub Inc. (repository hosting), and Google LLC (the optional Guideline Checker feature). Under EU data protection law, the United States is considered a third country. A transfer of Personal Data to the United States is nonetheless permitted where the recipient is certified under the "EU-US Data Privacy Framework" (DPF), which the European Commission has recognized as ensuring an adequate level of data protection under the GDPR.
The Service Providers listed above are, to the best of our knowledge, DPF-certified at the time of writing; We additionally rely on the European Commission's Standard Contractual Clauses ("SCCs") with these providers as a supplementary safeguard. Our cloud build provider, Codemagic, is operated by Nevercode OÜ in Estonia (within the EEA) and does not involve a transfer outside the EEA.
You may contact Us using the details in the "Contact Us" section to request further information about the safeguards We use for international transfers, including copies of relevant contractual protections (redacted where necessary).
Your Rights under the GDPR
The Company undertakes to respect the confidentiality of Your Personal Data and to guarantee You can exercise Your rights.
You have the right under this Privacy Policy, and by law if You are within the EU, to:
Request access to Your Personal Data.
Request restriction of processing of Your Personal Data.
Request correction of the Personal Data that We hold about You.
Object to processing of Your Personal Data.
Request erasure of Your Personal Data.
Request the transfer of Your Personal Data to You or to a third party.
Withdraw Your consent on using Your Personal Data.
Exercising of Your GDPR Data Protection Rights
You may exercise Your rights of access, rectification, cancellation and opposition by contacting Us. We may ask You to verify Your identity before responding to such requests. We generally respond within one month, and may extend by two further months where necessary, in accordance with applicable law.
You have the right to complain to a Data Protection Authority about Our collection and use of Your Personal Data. If You are in the European Economic Area (EEA), please contact Your local data protection authority.
California Privacy Rights (CCPA/CPRA)
This section supplements Our Privacy Policy for California residents. We collect limited categories of personal information about California residents — primarily identifiers (email, name) and commercial information (Your purchase history) — directly from You and automatically through Your use of the Service.
We do not sell Your personal information for money, and We do not use tracking technologies for cross-context behavioral advertising.
If You are a California resident, You have the right to know what personal information We hold about You, to request its correction or deletion, and to not be discriminated against for exercising these rights. To exercise any of these rights, contact Us using the details in "Contact Us" below; We will verify Your identity before responding, generally within 45 days.
Our Service does not knowingly collect personal information from minors under 16 years of age.
"Do Not Track" Policy
Our Service does not respond to Do Not Track (DNT) signals. Some third-party websites may keep track of Your browsing activities; You can manage this through Your browser's preferences.
Children's Privacy
Our Service is not directed at anyone under the age of 18 (see Our Terms and Conditions), and We do not knowingly collect personal information from anyone under the age of 16. If You are a parent or guardian and are aware that Your child has provided Us with Personal Data, please contact Us; We will take steps to remove that information from Our servers.
Links to Other Websites
Our Service may contain links to other websites that are not operated by Us, including the Apple App Store and Google Play Store. If You click on a third-party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Policy of every site You visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third-party sites or services.
Changes to this Privacy Policy
We may update Our Privacy Policy from time to time. If a change is material, We will notify You by posting a notice on the Service prior to the change becoming effective and updating the "Last updated" date at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Contact Us
If you have any questions about this Privacy Policy, You can contact us:
By email: support@appthunder.io
By post: (Alejandro Morillo Diaz), Am Markt 14, 23769 Fehmarn, Germany
VAT ID (USt-IdNr.): DE462576138