This Privacy Policy explains how APPKITEKT ("we", "us") processes personal data when you use the Appkitekt AI platform and related websites (the "Service"). We act as a data controller for account and usage data, and as a data processor for content you submit through the Service on behalf of your organization.
1. Data we collect
- Account data: name, email, authentication identifiers, organization, role.
- Customer Content: domains, URLs, prompts, configuration, and connected-account metadata you provide.
- Usage data: pages viewed, features used, audit jobs, timestamps, device and browser information, IP address.
- Billing data: plan, transaction identifiers, and limited payment metadata returned by our payment processor. We do not store full card numbers.
- Support data: messages and attachments you send us.
2. How we use data
- To provide, secure, and improve the Service.
- To run audits, generate scores, recommendations, and other Output.
- To authenticate users, prevent abuse, and enforce our Terms.
- To process payments and manage subscriptions.
- To communicate about your account, service updates, and security.
- To comply with legal obligations.
3. Legal bases (EEA/UK)
We process personal data based on (a) performance of a contract, (b) our legitimate interests in operating and securing the Service, (c) your consent where required (for example for non-essential cookies and marketing), and (d) compliance with legal obligations.
4. AI processing
To produce Output we send relevant inputs (such as URLs, prompts, and limited account context) to third-party AI model providers. We instruct these providers not to train their public models on your inputs where such controls are available. We do not sell personal data.
5. Sharing
We share data only with:
- Sub-processors that help us run the Service (hosting, database, authentication, AI model providers, search/SEO data providers, email, analytics, payments).
- Authorities when required by law or to protect rights, safety, and security.
- A successor in case of merger, acquisition, or asset sale, subject to equivalent protection.
6. International transfers
Personal data may be processed outside your country. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.
7. Retention
We keep personal data for as long as your account is active and for a limited period afterwards to meet legal, accounting, and security requirements. Audit results and related Customer Content are retained for the lifetime of your workspace unless you delete them.
8. Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, port, restrict, or object to processing of your personal data, and to lodge a complaint with your supervisory authority. Contact privacy@appkitekt.com to exercise your rights.
9. Security
We use industry-standard measures including encryption in transit, access controls, row-level security, and audit logging. No system is perfectly secure; you are responsible for protecting your credentials.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect their data.
11. Changes
We will update this Policy as the Service evolves. Material changes will be notified in-product or by email.
12. Contact
Data controller: APPKITEKT — privacy@appkitekt.com.