AppFly

Privacy Policy

This policy explains what AppFly collects when you use our AI Shopify app builder, why we collect it, and the choices you have.

Last updated: September 14, 2026

1. Who we are

AppFly (“AppFly”, “we”, “us”) provides a browser-based platform that turns a natural-language description into a working Shopify application and helps you deploy it. This policy covers our website and the AppFly platform (together, the “Service”).

For privacy questions, contact us at privacy@appfly.dev.

2. Information we collect

Account information

Your name, email address, password hash (or the identifier from the single sign-on provider you use), and billing details if you subscribe to a paid plan. Payments are processed by our payment provider; we do not store full card numbers.

Project content

The prompts and instructions you send to the AI agent, the source code and files in your projects, build and terminal output, and any assets you upload. This content is stored so your projects persist between sessions.

Connected Shopify accounts

If you connect a Shopify Partner account or a development store, we receive OAuth access tokens and the account, organization, store and app identifiers needed to create and deploy apps on your behalf. We use these tokens only to carry out actions you initiate.

Usage and device data

Log data such as IP address, browser and device type, pages viewed, features used, timestamps, and error diagnostics. We use this to operate the Service, investigate problems, and improve reliability.

Cookies

We use strictly necessary cookies for authentication and security, and preference cookies to remember settings such as your theme. Where required by law, analytics cookies are used only with your consent. You can control cookies in your browser settings, though disabling necessary cookies will prevent you from signing in.

3. How we use your information

  • To provide the Service — generating, editing, running and deploying your apps.
  • To authenticate you and keep accounts secure.
  • To process payments and manage subscriptions.
  • To provide support and respond to your requests.
  • To monitor performance, debug failures, and prevent abuse or fraud.
  • To send service notices and, where you have opted in, product updates.
  • To comply with legal obligations and enforce our terms.

4. AI processing of your content

To build and modify your app, we send your prompts and the relevant portions of your project to third-party large language model providers that act as our processors. Those providers process the content solely to return a response to us.

We do not use your private project code or prompts to train our own models, and our model providers are contractually bound not to train on content submitted through our API accounts. We may use aggregated, de-identified metrics — such as how often a feature is used or how often a build fails — to improve the Service.

5. When we share information

We do not sell your personal information. We share it only with:

  • Service providers who host our infrastructure, process payments, send email, provide error monitoring, and supply AI model inference — each bound by contract to protect your data.
  • Shopify, when you deploy an app or call Shopify APIs, to the extent required to complete the action you requested.
  • Authorities, where we are legally required to disclose information, or to protect our rights, users, or the public.
  • A successor entity, in connection with a merger, acquisition or sale of assets, subject to this policy.

6. Data retention

We keep account and project data for as long as your account is active. If you delete a project, it is removed from active systems promptly and purged from backups within 30 days. If you delete your account, we delete or anonymise your personal data within 30 days, except where we must retain records for legal, tax or fraud-prevention purposes. Logs are retained for a limited period for security and debugging.

7. Security

We encrypt data in transit with TLS and at rest, store credentials and OAuth tokens encrypted, restrict internal access on a need-to-know basis, and run generated code in isolated environments. No system is perfectly secure, but we work to protect your data and will notify you of a breach affecting your personal data as required by law.

8. Your rights

Depending on where you live, you may have the right to access, correct, export, delete or restrict the processing of your personal data, to object to certain processing, and to withdraw consent. Residents of the EEA and UK have these rights under the GDPR; California residents have rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them.

To exercise any of these rights, email privacy@appfly.dev. We respond within the period required by applicable law. You may also lodge a complaint with your local data protection authority.

9. International transfers

We operate globally and may process data in countries other than your own, including the United States. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

10. Children

The Service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us information, contact us and we will delete it.

11. Changes to this policy

We may update this policy from time to time. If we make a material change we will update the date above and notify you by email or in the Service before the change takes effect. Continued use after that date means you accept the updated policy.

12. Contact

AppFly privacy@appfly.dev