// privacy

Privacy, in plain English.

// last updated: July 2026

This page is maintained by App Legendary to describe how we handle personal information on applegendary.com and during client engagements. It is not a legal certification and not a substitute for a signed data-processing agreement โ€” request one at hello@applegendary.com.

What we collect

  • โ†’Form submissions. Name, work email, company, role, monthly downloads band, monthly budget band, an optional app URL, and an optional free-text message โ€” collected when you request an audit, book a Sprint, or subscribe to the Library.
  • โ†’Newsletter opt-ins. Email address only, when you subscribe from the footer or a library/data page.
  • โ†’Server access logs. IP address, user agent, timestamps, and request paths โ€” kept for security and abuse prevention.
  • โ†’During engagements. App store metadata, analytics exports, review data, and any documents you share to run the work.

What we do not collect

  • โ†’No third-party advertising cookies. No cross-site tracking pixels.
  • โ†’No sensitive personal data (health, financial account, government-ID) โ€” do not send us these.
  • โ†’No child data โ€” the service is not directed at anyone under 16.

How we use it

  • โ†’Respond to your request and deliver the audit, Sprint, or retainer you asked for.
  • โ†’Send the specific newsletters you subscribed to. One-click unsubscribe on every email.
  • โ†’Aggregate, de-identified analytics on which pages perform, to improve the site.
  • โ†’Meet tax, legal, and accounting obligations.

Who processes it

We use a small set of subprocessors to run the site and the practice. If a subprocessor changes, we update this page.

  • โ†’Hosting + database. The site is hosted on Lovable Cloud (backed by Supabase and Cloudflare). Form submissions are stored in a Postgres database with row-level security enabled.
  • โ†’Email delivery. Transactional and newsletter email via a standard email provider.
  • โ†’Analytics. Privacy-respecting, aggregate analytics โ€” no personal identifiers.

How long we keep it

  • โ†’Leads that don't convert: up to 24 months, then deleted.
  • โ†’Client records: for the duration of engagement + 7 years for tax and legal compliance.
  • โ†’Newsletter list: until you unsubscribe.
  • โ†’Server logs: 30 days.

Your rights

No matter where you are based, you can email privacy@applegendary.com to:

  • โ†’Access the personal data we hold about you.
  • โ†’Correct or update it.
  • โ†’Ask us to delete it, subject to legal retention requirements.
  • โ†’Export it in a portable format.
  • โ†’Object to specific uses.

We respond within 30 days.

Security

Data is transmitted over TLS. The database uses row-level security and is accessible only to authorised personnel. We do not export lead data to spreadsheets. This page is not a security certification โ€” request our current security posture summary at security@applegendary.com.

Changes

We'll update this page whenever practices change and update the "last updated" date at the top. Substantial changes are announced to newsletter subscribers.

Contact