Appspansion · version 2026-09-09-draft · draft pending legal review
Privacy and data retention
What we collect
Account email, name and workspace membership; app configuration and content you create; reports you import or connect; first-party app events sent by your app’s SDK (pseudonymous installation identifiers, event names and allow-listed properties, never emails, health answers, card details or device advertising identifiers); verified purchase records from the stores and payment providers you connect; and hosted funnel visits (step path, no answer text). With a visitor’s consent, hosted funnels share visit, completion, checkout and purchase events with the advertising platforms you configure.
How long we keep it
- App events: 90 days.
- Funnel visits, experiment assignments and Apple postbacks: 400 days.
- Activity log: 24 months.
- Workspace exports: 7 days.
- Client address and browser identity used for ad measurement: 7 days.
- Financial records (payments, journals, invoices, fees, escrow deals): for the statutory period, also after a workspace is deleted, under an anonymized workspace.
Credentials
Provider credentials you supply or grant are sealed with keys held outside the database, are never shown again, and are used only for the syncs and deliveries you configured. A rejected credential stops its syncs until you reconnect.
Export and deletion
Workspace owners can export the whole workspace as JSON from Settings. Deleting a workspace starts a thirty-day grace period, then removes content and anonymizes the workspace; deleting an account removes memberships and sign-in immediately and anonymizes the profile.
Sub-processors
Cloudflare (edge, tunnel, object storage), the hosting provider of the platform’s servers, Stripe (billing and escrow), Resend (email), Sentry (error reporting, no personal data) and the providers you connect for your own workspace.
Contact
Support access to your data is limited to identifiers and counts and is recorded in your activity log.