Privacy Policy
How AppListingLab handles account, uploaded content, analytics, and product usage data.
Last updated: August 12, 2026
1. Owner and data controller
DigitMind Technologies LLP, Astana, Kazakhstan.
Contact: info@digit-mind.com
This Policy covers the AppListingLab website, the free tools under /tools, and the authenticated studio under /app. It supplements the Terms of Service.
2. Data we collect
Account data
- Firebase user ID, email address, display name, email-verification status, and profile picture where provided. Firebase Authentication processes email/password and Google sign-in credentials; the AppListingLab backend never receives or stores your password.
Content you provide
- App screenshots and images you upload, App Store / Google Play URLs you submit for ingestion, app profile details (name, description, brand colors, audience, tone), and text you enter for generation.
- Assets the Service generates for you (screenshot sets, listing copy, icons, media), stored so you can return to them.
Usage and technical data
- Product events (pages viewed, tools used, generation actions), browser and device type, IP address, and referring pages. Analytics is first-party: events are sent to our own backend and are never shared with third-party analytics providers. We do not use session recording.
- Monthly project, generation, and AI-credit counters per account, kept to enforce plan limits.
Billing data
- If you subscribe to a paid plan, checkout is handled entirely by our reseller Paddle in their own hosted overlay — your card number and other payment details are entered directly into Paddle and never reach our servers. We receive your subscription status, plan, renewal date, and billing history from Paddle so we can grant the right limits and show them to you in Billing.
Communications
- Messages you send us by email, and our replies.
The free tools (icon generator, image sets, screenshot resizer) process your images entirely in your browser; those files are not uploaded to our servers.
3. How we use data
- to provide the Service: accounts, generation, storage, exports;
- to run AI generation — your relevant content is sent to the processors listed below for the sole purpose of producing your assets;
- to understand and improve the product (first-party funnel analytics and error diagnostics);
- to enforce usage limits and protect the Service from abuse;
- to respond to your requests and to comply with legal obligations.
We process data on the legal bases of performance of a contract (the Service itself), our legitimate interests (analytics, security, abuse prevention), your consent where required, and compliance with legal obligations. We do not sell personal data, and we do not use your content to train AI models.
4. Processors and services we use
- OpenAI — text and vision AI generation (listing copy, screenshot planning). Receives the app context and images needed for the specific generation.
- fal.ai — image and video generation for icons and promotional media. Receives your generation prompts.
- Amazon Web Services (S3) — storage of uploaded and generated assets.
- MongoDB — application database (accounts, projects, generated copy, usage counters).
- Firebase Authentication (Google) — email/password and optional Google sign-in, account authentication, and browser session persistence.
- Paddle — payment processing, invoicing, and tax collection for paid plans, and our reseller of record for those sales. Receives the billing details needed to process your subscription; see Paddle's Privacy Policy.
- Apple App Store / Google Play public endpoints — when you submit a store URL, we fetch the public listing metadata and screenshots of that app on your behalf.
Each provider processes data under its own privacy terms; we share only what the specific function requires.
5. Cookies and local storage
- Essential authentication: Firebase persists your signed-in session in browser storage and refreshes its ID token. We also set a first-party
ms_sessioncookie containing only a presence marker so protected navigation can redirect correctly; it does not contain an access token or password. - Analytics — only with your consent: if you accept, a random first-party identifier is stored in your browser's localStorage to distinguish returning visitors for our own funnel statistics. It is never shared with third parties and is not used for advertising, and no third-party analytics scripts run on this site. Until you accept, nothing is stored and no events are recorded.
We ask on your first visit, whichever page you arrive at. You can change your mind at any time with Cookie preferences in the footer of any page: declining removes the identifier already stored and stops any further events. The essential items above are not covered by that choice — without them you could not stay signed in.
6. Retention
- Account data and stored content: for the lifetime of your account, deleted upon account deletion (backup copies purge on rotation shortly after).
- Usage counters: rolling short-term windows for limit enforcement.
- Raw analytics events: automatically deleted after 90 days.
7. Sharing and international transfers
Data is shared only with the processors above, with authorities where legally required, and in the context of a business transfer (merger, acquisition) under equivalent protections. Our processors operate internationally (including the United States and the European Union); we take commercially reasonable steps to ensure transfers comply with applicable legal requirements.
8. Your rights
Subject to applicable law, you may request access to, correction of, deletion of, or a portable copy of your personal data, restrict or object to certain processing, and withdraw consent where processing is based on it. Write to info@digit-mind.com; we respond within a reasonable time and verify your identity before acting. You may also lodge a complaint with a supervisory authority where you live.
9. Children
The Service is not directed to children and may only be used by adults under applicable law. We do not knowingly collect data from anyone under 13; if you believe a minor has provided us data, contact us and we will delete it.
10. Security
Authentication credentials are managed by Firebase Authentication; AppListingLab does not store password hashes. Transport is encrypted (TLS), access to production data is restricted, and API access is rate-limited. No system is perfectly secure; notify us immediately at info@digit-mind.com if you suspect a breach of your account.
11. Changes to this Policy
We may update this Policy; changes appear on this page with an updated date. Material changes are additionally announced in the product or by email where reasonably possible.