Privacy Policy

Last updated: August 31, 2026

1. Data Controller

AcceptMyApp is operated by Grisey Alexandre, located at 7 Allées de Chartres, 33000 Bordeaux, France (SIRET: 83978643100024).

Contact: contact@acceptmy.app

2. Data We Collect

  • Account information: When you sign in with GitHub or Google, we receive your display name, email address, user ID, and (if provided) profile photo. We use these providers only for authentication. Sign-in does not request GitHub repository access. If you use Code Checker, you may separately grant a one-time, read-only access to a repository you choose (see section 3a).
  • App data: Information you provide or import about your iOS applications (title, subtitle, description, keywords, URLs, business model, features, permissions, bundle ID, and related App Store Connect metadata).
  • Rejection messages: Text you paste from Apple's App Store Review correspondence.
  • Screenshots: Images you upload, and screenshot URLs imported from App Store Connect. Uploaded files are stored in Firebase Storage. When you run a screenshot analysis, those images are sent to our AI provider.
  • Analysis and generated outputs: Prechecks, rejection analyses, checklists, metadata rewrites, screenshot reviews, code checks, and similar results stored with your account.
  • Payment information: Processed by Stripe. We store customer and transaction identifiers, amounts, and subscription status. We never see or store your card details.
  • Emails you give us: Your account email, plus any address you submit to a feature waitlist. We also record whether you have unsubscribed from product emails.
  • Usage data: Page views, feature usage, and similar analytics collected via DataFast (including first-party visitor/session identifiers used for product analytics and payment attribution).
  • Rate-limit data: For anonymous use of AI free tools, we store a short, non-reversible hash of your IP address for about two days so we can enforce daily caps. Signed-in users are limited by account instead.
  • Feedback: Comments you choose to send through our public feedback widget (LiteFeedback) or in-app support chat (Heyo).

3. App Store Connect Credentials

If you import apps from App Store Connect, you send us an Issuer ID, Key ID, and .p8 private key so we can call Apple's API on your behalf. We mint a short-lived token, fetch the apps you select, and do not store the private key or the token. Imported app metadata and screenshot URLs are saved on the apps in your account.

3a. GitHub repository access (Code Checker)

Code Checker is optional. When you connect a repository, GitHub asks you to grant read-only access to the repo you select (or, if we fall back to a classic OAuth App, repository read access so you can pick one). We mint a short-lived token, fetch relevant source and config files (for example Info.plist and PrivacyInfo.xcprivacy), send excerpts to our AI provider for the scan, and do not store the GitHub token or the source files. We keep the scan result (risk summary, issues, suggested fixes, and the list of file paths we looked at) on the app in your account. You can revoke the GitHub grant at any time in your GitHub settings.

4. Free Tools

Many free tools (validators, formatters, resizers, and similar utilities) run entirely in your browser. The files and text you paste there are not uploaded to our servers.

AI-backed free tools (for example idea generation, idea validation, metadata writing, and rejection helpers) send the input you submit to our servers and to OpenAI to produce a result. We do not attach that input to an account unless you are signed in and the feature stores a result for you.

Ideas produced by the iOS App Idea Generator may be published on our public iOS App Ideas gallery. We store the generated idea, not the optional context you typed.

5. How We Use Your Data

  • To provide the product: analyses, checklists, metadata rewrites, screenshot reviews, code checks, App Store Connect import, exports, and free tools.
  • To process payments, manage unlocks and subscriptions, and prevent abuse (including rate limits).
  • To send service emails (welcome, activation reminders, feedback requests, and similar product messages) and, if you joined a waitlist, to notify you about that feature.
  • To improve the service, understand usage, attribute purchases, and fix issues.
  • To communicate with you about your account when necessary.

6. Emails

If you create an account, we may send transactional and product emails (for example a welcome message, a nudge to add an app or run an analysis, and a follow-up after you use the product). Every such email includes an unsubscribe link. Waitlist sign-ups are used only to email you about that specific feature unless you later create an account.

7. Legal Bases (GDPR)

We process personal data on these bases:

  • Contract: creating an account, running analyses, importing apps, and processing payments.
  • Legitimate interests: securing the service, rate-limiting anonymous tools, product analytics, and sending relevant product emails to account holders.
  • Consent: waitlist emails and any optional communications you opt into. You can withdraw consent at any time.
  • Legal obligation: retaining billing records as required by law.

8. Third-Party Services

We use the following processors to operate AcceptMyApp:

  • Firebase (Google): Authentication, database, file storage, Cloud Functions, and hosting. Privacy Policy
  • OpenAI: AI processing. App metadata, rejection text, screenshot images, code excerpts from a repository you connect for Code Checker, and free-tool prompts you submit to an AI feature are sent to OpenAI's API. Privacy Policy
  • Stripe: Payment processing. Privacy Policy
  • DataFast: Product analytics and purchase attribution. Privacy Policy
  • SendGrid (Twilio): Sending transactional and product emails. Privacy Policy
  • Heyo: In-app support chat for signed-in users (identified by email and user ID). Privacy Policy
  • LiteFeedback: Optional public feedback widget on non-authenticated pages. Website
  • GitHub: Sign-in (display name, email, user ID) and, only if you use Code Checker, a one-time read of the repository you select. Privacy Statement

Some of these providers process data outside the European Economic Area (including the United States). Transfers rely on the safeguards those providers offer, such as Standard Contractual Clauses where applicable.

9. Cookies

We use essential cookies and similar storage required for authentication and session management. DataFast sets first-party cookies on acceptmy.app (visitor and session identifiers) for analytics and to attribute purchases. Support and feedback widgets may set their own cookies if you interact with them. We do not use advertising cookies or sell your data.

10. Data Retention

Account data, apps, screenshots, and analysis history are retained as long as your account is active. Rate-limit records expire after about two days. Billing records may be kept for the period required by tax and accounting law. Waitlist emails are kept until you ask us to delete them or the campaign ends.

You may request deletion of your account and associated data at any time by contacting contact@acceptmy.app.

11. Your Rights (GDPR)

Under the EU General Data Protection Regulation, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Request erasure of your data.
  • Restrict or object to processing of your data.
  • Data portability (receive your data in a structured format).
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés) or your local supervisory authority.

To exercise any of these rights, contact us at contact@acceptmy.app.

12. Security

We implement industry-standard security measures including encrypted connections (HTTPS), Firebase security rules restricting data access to authenticated owners, hashed identifiers for anonymous rate limits, and server-side validation of all operations. App Store Connect private keys are processed in memory and are not written to our database. GitHub tokens used for Code Checker are processed in memory and are not written to our database. No system is 100% secure, and we cannot guarantee absolute security.

13. Children

AcceptMyApp is not directed at individuals under 16. We do not knowingly collect personal data from children.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. Continued use of the service after changes constitutes acceptance of the revised policy.