Privacy Policy
Last updated: July 9, 2026
This Privacy Policy explains how FreeBraavos LTD ("AppDeploy", "we", "us") collects, uses, and shares information when you use:
- our website and landing page (the "Website"), and
- our integrations, connectors, and APIs for third-party AI platforms and agent clients (the "Integrations"), which let you deploy apps from within your AI platform or agent client of choice.
Third-party AI platforms and agent clients (each, a "Third-Party Platform") are separate services. Their privacy practices are governed by their own policies and terms.
Data minimization and free-service data license: We collect information necessary to provide, secure, operate, improve, train, evaluate, benchmark, commercialize and support AppDeploy and related AI coding, QA, repair, evaluation, deployment and reliability systems. The free version of AppDeploy is provided at no monetary charge; use of the Service is governed by the data-license terms described in our Terms of Service. Paid users may be subject to different data-use terms, restrictions or controls if specified in the paid plan or written purchase terms. We do not collect unrelated conversation history from Third-Party Platforms.
Related trust docs: Security overview, DPA and Subprocessors.
1) Information we collect
A. Identifiers and account info
- User identifier: when you use the Integrations, we receive an identifier used to associate deployments with your account, such as a guest identifier or an authenticated user ID.
- Social sign-in (optional): if you choose to sign in via Google, Apple, or X on our sign-in page, we receive an identity token and derive a stable user ID. Your email address may be present in the token; we do not require it to provide the core service.
B. Content, Deployment Data and Feedback Data
When you use AppDeploy, we may collect the information needed to deploy, test, repair and operate your app, including project files, source code, configuration files, static assets, app names, app descriptions, app intent, acceptance criteria, deployment instructions, generated code, patches, corrected code, build logs, deployment logs, runtime logs, automated QA observations, browser observations, DOM observations, console logs, network logs, screenshots, repair instructions, diagnostic explanations, deployment outcomes, QA outcomes, repair outcomes, reliability labels, originating client or model metadata, timing metadata, usage metadata and related technical information.
We refer to this information as "Deployment and Feedback Data" where it is generated through deployment, QA, repair, reliability or operation of your app.
In this Privacy Policy, "User Content" and "Derived Data" have the meanings given in our Terms of Service. Deployment Data and Feedback Data are described in this section and in our Terms of Service.
Important: Do not include secrets, API keys, passwords, private tokens, payment card data, government IDs, PHI/ePHI, access credentials or other sensitive information in your project files, app content, prompts, messages, source code, logs, screenshots or deployments, except through a dedicated AppDeploy secrets or configuration flow where available. Secret values and credentials submitted through an approved AppDeploy secrets or configuration flow are used for app operation and are not used for model-improvement, third-party model training or partner-training datasets. If we detect sensitive data outside approved flows, we may take steps such as rejecting the deployment, redacting the data, deleting it where feasible or excluding it from model-improvement datasets. We do not guarantee that we will detect, redact, delete or exclude all sensitive data.
C. Usage and technical data
- Request metadata: request IDs, timestamps, session identifiers and basic logs needed to operate, secure, troubleshoot and improve the Service.
- Device/browser data: standard HTTP logs, approximate location derived from IP at the infrastructure layer and diagnostic information for the Website.
We do not request or collect your precise device location. Any geographic information is limited to standard IP-based inference at the infrastructure level for security and compliance purposes.
Cookies and analytics: The Website may use third-party analytics and marketing technologies, including Google services, to measure traffic and campaign performance. Where required by applicable law, we present a consent banner and do not enable optional analytics or marketing cookies until you opt in. In other regions, these technologies may be enabled by default, subject to applicable law. We may also use essential cookies or local storage for basic functionality, such as authentication state.
D. Communications
If you contact support, we collect the information you provide, such as your email address, message content and any attachments.
E. What we do not collect
The Integrations receive only the specific project files, configuration, metadata, deployment instructions and related information that you, your AI platform or your agent client explicitly submit to AppDeploy. We do not pull your broader conversation history from Third-Party Platforms and we do not attempt to reconstruct unrelated chat context. We may receive a structured app brief, deployment intent, acceptance criteria or project description if you, your AI platform or your agent client sends it to AppDeploy for deployment, QA, repair or model-improvement purposes.
2) How we use information
- Provide the Service: create deployments, host your app, show deployment status and URLs, test deployments, troubleshoot failures and support Service operations.
- Authenticate and prevent abuse: secure the Service, validate requests, detect fraud or misuse and enforce our Terms.
- Troubleshoot and improve: diagnose failures, improve reliability, enhance product experience and improve deployment and repair quality.
- Model improvement, evaluation and feedback systems: as part of the free-service data license, we may use User Content, Deployment Data, Feedback Data and Derived Data to train, fine-tune, evaluate, benchmark and improve AppDeploy's QA, verification, repair, deployment, safety, abuse-detection and reliability models and related AI systems.
- Feedback and reward signals: we may use User Content, Deployment Data, Feedback Data and Derived Data to generate defect labels, repair labels, pass/fail labels, evaluation sets, benchmarks, reward signals, reliability metrics and other derived data.
- Service, commercial and cost improvement: we may use User Content, Deployment Data, Feedback Data and Derived Data to improve deployment success, repair quality, safety, abuse detection, latency, reliability, cost efficiency, commercial licensing opportunities and related product development.
- Communicate with you: respond to support requests and send service-related notices.
- Comply with law: comply with legal obligations and protect rights and safety.
Lawful bases (EEA/UK)
- Contract: to provide the free Service under the Terms of Service, including the data-license terms that apply when you use AppDeploy.
- Legitimate interests: to secure the Service, prevent abuse, troubleshoot deployments, improve reliability, maintain service quality, develop and improve AppDeploy, and support the commercial viability of a free service, except where consent is required by applicable law or by our commitments to you.
- Legal obligations: to comply with applicable laws and lawful requests.
- Consent: for optional analytics or marketing cookies and for any data use where applicable law requires consent despite the free-service data-license model.
Response data: Tool responses may include deployment status, URLs, validation messages, error messages, logs, QA or test results, timestamps, debugging identifiers and related diagnostic metadata when useful to complete, troubleshoot or support your request. We avoid including unrelated internal metadata where it is not needed for the response.
Analytics and marketing limits: We do not use deployment content or Integration data to build advertising profiles. Website analytics and marketing technologies are limited to site traffic measurement, campaign attribution and similar website operations, subject to your consent choices and applicable law.
If you choose not to provide data: Certain information is required to provide the full scope of the Service. If you do not provide the required information, we may not be able to offer such features.
3) How we share information
We may share information with:
- Infrastructure providers: we use AWS services, including compute, storage, database and CDN, to deploy and host apps.
- Authentication providers: if you choose Google, Apple or X sign-in, we use Firebase Authentication and related OAuth providers to help authenticate you.
- Analytics and marketing providers: the Website uses Google Analytics and Google Ads to measure site traffic and campaign performance. These services may set cookies and process pseudonymized usage data, subject to your consent choices and applicable law.
- Package registries and build dependencies: during deployment, build tools may download dependencies from public package registries, such as npm, based on your project's configuration.
- AI, coding, QA, evaluation, research, infrastructure, commercial and similar partners: as part of the free-service data license, we may share, license, transfer, disclose or otherwise make available User Content, Deployment Data, Feedback Data, Derived Data, benchmarks, evaluation outputs and reliability metrics with selected AI model providers, coding-agent providers, app-generation platforms, QA or evaluation providers, research partners, infrastructure providers, commercial partners and similar partners to train, fine-tune, evaluate, benchmark, commercialize or improve AI coding, QA, repair, deployment, safety and reliability systems, subject to appropriate safeguards and applicable law. Where feasible, we may share de-identified, anonymized, aggregated, pseudonymized or otherwise protected forms of this data. We may share raw or identifiable materials where permitted by law, subject to appropriate safeguards, confidentiality obligations and this Privacy Policy.
- Business transfers and diligence: we may disclose or transfer information, including Deployment and Feedback Data, in connection with a merger, acquisition, financing, corporate reorganization, sale of assets, due diligence process or similar transaction, subject to appropriate confidentiality and data protection safeguards. Potential acquirers may receive information for diligence and evaluation purposes under confidentiality and safeguards. Training, fine-tuning or commercialization rights for an acquirer or strategic partner will be granted only through a completed transaction or separate written agreement.
- Professional advisors: legal, security and compliance advisors as needed.
- Legal and safety: to comply with law or protect FreeBraavos LTD, our users or others.
- Third-Party Platforms and agent clients: when you use the Integrations, we send responses, such as deployment status, logs and URLs, back to the Third-Party Platform or agent client you are using so it can display them to you. That platform may process those responses under its own terms and privacy policy.
Subprocessors: Our primary subprocessors include AWS (hosting, storage, database, CDN, logging and related infrastructure), Google services such as Firebase Authentication, Google Gemini API and Google Cloud Vertex AI where used for authentication, AI features, automated QA, evaluation, repair, redaction, model improvement, training, fine-tuning or benchmarking, Apple Inc. for Apple sign-in and X Corp. for X OAuth sign-in. A current list is available at appdeploy.ai/subprocessors.
International transfers: We process and store data in the United States (us-east-1). Where data is transferred from the EEA, UK or Switzerland to a country not recognized as providing an adequate level of protection, we rely on the European Commission's Standard Contractual Clauses (SCCs), the UK IDTA or UK Addendum to the EU SCCs, as applicable, or other valid transfer mechanisms. You may request more information about the safeguards we use by contacting support@appdeploy.ai.
Data Processing Agreement: A DPA is available at appdeploy.ai/dpa or on request.
We do not use deployment content or Integration data to build advertising profiles, and we do not operate as a data broker. The free Service is provided in exchange for the data rights described in our Terms of Service and this Privacy Policy, including the rights to use, share, license, transfer and otherwise process User Content, Deployment Data, Feedback Data and Derived Data as described above. We do not offer a separate opt-out from those free-service data-license rights while continuing to use the free Service, except where an opt-out or other right cannot be waived under applicable law. If you do not want AppDeploy to use that data as described, do not use the Service. To the extent that User Content, Deployment Data, Feedback Data or Derived Data contains personal information, we process that personal information as described in this Privacy Policy and subject to applicable law.
4) Public deployments and visitor data
Controller and processor roles: Depending on how you use AppDeploy, FreeBraavos LTD may act as a data controller for account, billing (if applicable), security, service operations, website analytics and data uses under the free-service data license, and as a data processor when hosting and processing data on your behalf in connection with deployed apps. Where we act as a processor, our processing is governed by our DPA.
Apps you deploy are hosted at a public URL and may be accessible to anyone who has the link, or to the public, depending on how you share it. You are responsible for the content you deploy and for ensuring it does not contain sensitive data.
Data processed when your deployed app is used: When you deploy an app through AppDeploy, we host and serve it. As part of providing hosting, we may process technical data from requests to your deployed app, such as IP address, request headers and server logs, for security, abuse prevention and reliability. AppDeploy acts as a hosting provider; you determine what your app collects from its visitors and are responsible for providing appropriate notices and obtaining required consents for your deployed app.
Visitor data limitation: AppDeploy does not need visitor personal data for the free-service feedback loop, and does not use personal data collected from visitors to your deployed app for third-party model training or partner-training datasets. If runtime logs, QA artifacts, screenshots or diagnostic outputs contain visitor personal data, we will exclude that visitor personal data from third-party model training and partner-training datasets where we identify it. You are responsible for providing any required notices and obtaining any required consents for data collection or processing that your deployed app performs.
Primary region: United States (us-east-1). CDN/edge delivery: may involve global edge locations for content delivery.
5) Data retention
We retain data for varying periods depending on the type:
- Deployment content and active operational data: retained while your deployment is active and deleted upon request, subject to legal obligations and the limits below.
- Deployment and Feedback Data for model improvement and partner use: as part of the free-service data license, we may retain User Content, Deployment Data and Feedback Data for as long as reasonably necessary to operate, secure, develop, train, evaluate, benchmark, commercialize and improve AppDeploy's models, systems and services and related AI coding, QA, repair, evaluation, deployment and reliability systems.
- Derived data and model outputs: we may retain Derived Data, aggregated data, de-identified data, anonymized data, evaluation results, benchmarks, statistical outputs, technical learnings and trained model weights for longer periods, including after deletion of the original deployment, where such data no longer identifies you, your users or your deployed app.
- Build logs: retained for debugging and reliability purposes.
- Security and access logs: retained as reasonably necessary for security, compliance, abuse prevention and reliability.
- Authentication data: AppDeploy OAuth connector authorization codes expire after 10 minutes; MCP OAuth connector access tokens expire after 1 hour and MCP OAuth connector refresh tokens expire after 30 days. For deployed-app end-user authentication, app access tokens expire after 15 minutes and app refresh tokens expire after 30 days.
- Backups: retained for up to 30 days after deletion for disaster recovery.
Deletion requests: If you request deletion, we will handle the request as described in this policy and applicable law. Deletion does not require us to delete aggregated statistics, de-identified or anonymized Derived Data, technical learnings, evaluation results, benchmarks or model weights already created, except where required by applicable law. Deletion requests remove data from primary systems; backups are overwritten on a rolling basis within 30 days.
6) Security
We use reasonable administrative, technical and organizational safeguards designed to protect information. No method of transmission or storage is 100% secure.
We take steps to reduce sensitive data in logs, for example by redacting obvious secrets and personal data where feasible, and we avoid storing unnecessary message content.
7) Your choices and rights
Free-service data license and deletion choices
The free version of AppDeploy is provided at no monetary charge and the data license is part of the Service terms. Paid users may be subject to different data-use terms, restrictions or controls if specified in the paid plan or written purchase terms. If you do not agree to the applicable data-license model, do not use AppDeploy.
This does not limit privacy rights you may have under applicable law, including rights to access, delete, correct, object to or opt out of certain processing, sale or sharing of personal data where those rights apply.
You may request deletion of deployments and associated personal data through available AppDeploy tools, including by asking your AI platform or agent client to delete your app, or by contacting support@appdeploy.ai if you cannot use the tool flow. Deletion requests do not require AppDeploy to delete aggregated statistics, de-identified or anonymized Derived Data, technical learnings, evaluation results, benchmarks or model weights already created, except where required by applicable law.
- Disconnecting from Third-Party Platforms: you can disconnect or remove AppDeploy from your AI platform or agent client at any time through that platform's settings, such as connected apps, connectors settings or an MCP configuration. After you disconnect, we will no longer receive new data from that platform for your account unless you reconnect. Disconnecting does not automatically delete existing deployments or data already stored; you can request deletion as described below.
- Deletion requests: you can request deletion of your deployments and associated personal data through available AppDeploy tools, including by asking your AI platform or agent client to delete your app, or by contacting us if you cannot use the tool flow.
- Access and correction: you may request access to or correction of certain information we hold about you.
EEA/UK rights
- Access, rectification, deletion, restriction, portability and objection.
- Withdraw consent at any time for processing based on consent, including by using the "Manage cookies" control where available or by contacting us as described below.
Cookie preferences
Where a consent banner is presented, you can update your optional analytics and marketing choices at any time by using the "Manage cookies" control in the site footer on our main website pages.
How to make a request
Email support@appdeploy.ai with the subject line "Privacy Request" and include your request details. We may verify your identity before fulfilling a request. We respond within 30 days, and may extend that timeline where permitted by law with notice.
If you are located in the EEA/UK, you also have the right to lodge a complaint with your local supervisory authority.
We may need to verify your request before fulfilling it.
8) Children's privacy
The Service is intended for users who are at least 18 years old. It is not directed to children or minors, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided personal information to AppDeploy, contact support@appdeploy.ai so we can take appropriate steps.
9) Changes to this policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date above. If changes are material, including material changes to the free-service data license or data-use terms, we will provide prominent additional notice, such as by email, website banner or in-product notice, where reasonably practicable, and in any event as required by law.
10) Contact
FreeBraavos LTD, Menakhem Begin Rd 121, Tel Aviv-Yafo, Azrieli Sarona Tower, Israel.
Questions or privacy requests? Email support@appdeploy.ai.