Privacy Policy
Privacy Policy
Applies to: the Apptime platform at apptime.ai, including the Apptime web application, the Apptime API, and the sites and materials published through them.
Controller: Apptime Serviços de Internet Ltda ("Apptime", "we", "us"), a company incorporated in Brazil.
Privacy contact: team@apptime.ai
1. Introduction and Commitment
Apptime Serviços de Internet Ltda is dedicated to protecting the privacy, security, and personal data of our Users and Customers. This Privacy Policy clearly explains how we collect, use, store, share, and protect your information when you use our services and artificial intelligence tools.
Apptime is a platform that turns a plain-language description of a business into a finished digital presence: a brand, websites and landing pages, social creatives, and sales materials. To do that we need an account for you, the content you ask us to create, and the technical data required to run and secure the service. This policy describes exactly what that means.
Our privacy practices comply with applicable data protection regulations, including the Brazilian General Data Protection Law (LGPD - Law No. 13,709/2018), the Brazilian Civil Rights Framework for the Internet (Law No. 12,965/2014), and, where applicable, the European Union General Data Protection Regulation (GDPR).
2. Information We Collect
To operate the platform and deliver high-quality outputs quickly, we collect:
2.1. Account and Registration Data
- Full name or social identifier
- Email address and profile picture
- Authentication credentials (secure email login tokens or identity provider credentials)
- Business details (business name, niche, and direct contact channels)
2.2. Creation Inputs and Interaction Content
- Prompts, descriptions, project ideas, and instructions sent to AI assistants
- Media files uploaded voluntarily (brand logos, product photography, reference documents)
- Style preferences, color palettes, and formatting instructions
2.3. Device and Technical Information
- IP address and approximate geolocation
- Browser type and version, operating system, and display settings
- Access logs, duration, pages visited, and platform interactions
- Essential cookies and session tokens to maintain authentication
2.4. Financial and Billing Information
- Transaction history, active plans, credit balance, and invoices
- Note: Sensitive payment details (such as full credit card numbers and CVV) are handled directly by our certified payment processors (Mercado Pago, Asaas and AbacatePay) and are never stored on our servers.
2.5. Data from Accounts You Choose to Connect
If you sign in with Google or connect a third-party account (such as GitHub), we receive only the information covered by the permissions you approve on that provider's consent screen. Section 4 describes the Google case in full detail. Connecting an account is always optional, is never required to browse the site, and can be undone at any time from Account → Integrations.
3. How We Use Your Information
We process personal data for the following legitimate purposes:
- Service Delivery and Artifact Generation: Processing your prompts to create, edit, host, and publish websites, PDF documents, visual media, video scripts, and copy.
- Account Creation and Authentication: Creating your account, signing you in, keeping your session valid, and recognizing you across devices.
- Platform Operations and Security: Maintaining system stability, network security, fraud prevention, abuse and rate-limit enforcement, and performance monitoring.
- Customer Support: Responding to inquiries, resolving issues, and providing onboarding assistance.
- Operational Communications: Sending critical account notices, project updates, security alerts, and billing confirmations.
- Billing and Tax Compliance: Processing payments, issuing invoices, and keeping the records the law requires us to keep.
- Continuous Product Improvement: Conducting aggregated, anonymized analysis to optimize platform speed and user experience.
We rely on the performance of our contract with you (to run the service you signed up for), our legitimate interests (to keep the platform secure and working), your consent (for optional integrations and marketing communications), and legal obligations (for tax and record-keeping duties) as the legal bases for this processing.
We do not use your personal data for automated decisions that produce legal effects on you, and we do not sell it.
4. Google User Data ("Sign in with Google" and Google Integrations)
Apptime offers Sign in with Google as a way to create an account and sign in without a password. This section explains, specifically, what Google data we request, why, and what we do with it.
4.1. Permissions We Request
When you choose "Continue with Google", Google shows you a consent screen for the application named Apptime. We request only these scopes:
| Google scope | What it gives us | Why we ask for it |
|---|---|---|
openid | A stable, anonymous identifier for your Google Account | To recognize you as the same user on every sign-in |
.../auth/userinfo.email | Your Google Account email address and whether it is verified | To create and identify your Apptime account, and to send account, security, and billing emails |
.../auth/userinfo.profile | Your name and profile picture | To fill in your Apptime profile so you do not have to retype it |
We do not request access to your Gmail messages, Google Drive files, Google Calendar, Google Contacts, Google Photos, or any other Google service. We never ask for your Google password — authentication happens entirely on Google's own pages.
Google sends its response to auth.apptime.app, a host Apptime operates for exactly this step. It carries only a signed record of which Apptime site started the sign-in, and hands you straight back to that site; no personal data is stored there.
4.2. What We Store and For How Long
- Your email address, name, profile picture, and Google Account identifier are stored on your Apptime account for as long as the account exists.
- OAuth tokens (the access token and, when Google issues one, the refresh token) are stored encrypted at rest and used only to complete sign-in and to keep your connection to Google valid. They are deleted when you disconnect Google or delete your Apptime account.
- Your profile picture is copied once to our storage so the platform does not have to call Google every time your avatar is displayed.
4.3. How We Use Google User Data
Google user data is used only to:
- Create your Apptime account and sign you in.
- Pre-fill your display name and profile picture.
- Send transactional email (security alerts, billing receipts, account notices) to the address on the account.
Google user data is never used for advertising, ad targeting, ad personalization, credit assessment, lending, resale, or any purpose unrelated to the features you can see in the product.
4.4. Limited Use Disclosure
Apptime's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular:
- We do not sell, rent, or transfer Google user data to data brokers, advertisers, or any third party for their own purposes.
- We do not use Google user data to train, fine-tune, or otherwise improve generalized or standalone artificial intelligence models, our own or anyone else's. Google user data is never sent to any AI model provider.
- Humans do not read your Google user data, except with your explicit consent (for example, when you ask support to look into a sign-in problem), when it is necessary for security or to investigate abuse, or when the law requires it.
4.5. Revoking Access and Deleting Google Data
You are in control at any time:
- Disconnect inside Apptime: go to Account → Integrations and disconnect Google. We delete the stored tokens immediately.
- Revoke at Google: visit myaccount.google.com/permissions and remove Apptime's access.
- Delete everything: request account deletion from Account → Settings, or write to team@apptime.ai. Deleting your Apptime account deletes the Google data described above, subject only to the legal retention duties in section 11.
Revoking Google access does not delete your Apptime account. If Google sign-in was your only sign-in method, you can still get in with an email login code sent to the same address.
5. Artificial Intelligence Data Processing
Apptime integrates cutting-edge generative AI models to fulfill requests in real time. Regarding AI data handling:
- Purpose-Specific: Inputs and prompt instructions are processed strictly to generate your requested outputs.
- No Sale of User Data: Apptime does not sell, rent, or monetize your personal data, prompts, or uploaded assets to third parties or advertisers.
- No Training on Your Data: We do not use your prompts, uploaded files, or generated artifacts to train generalized AI models, and our model providers are engaged under agreements that forbid using our traffic for training.
- No Google User Data in Prompts: The data we obtain through Google sign-in (section 4) is never included in prompts or sent to any AI model provider.
- Enterprise Infrastructure: AI integrations operate via enterprise-grade, secure APIs (such as Google Cloud / Vertex AI, OpenAI, and equivalent providers) under strict confidentiality and data protection standards.
6. Personal Data Collected Through Users' Published Artifacts
When you use Apptime to publish websites, landing pages, lead capture forms, WhatsApp buttons, or checkouts, those artifacts may collect personal data from third parties who visit or interact with them (for example, name, email, phone number, or submitted messages).
With respect to that data, the User who created and published the artifact acts as the Data Controller under applicable law (including the LGPD), and is responsible for determining the purpose and legal basis for processing, providing adequate notice to their own visitors, and responding to those individuals' data subject requests.
Apptime acts in these cases solely as a Data Processor, handling and storing such data strictly as needed to host and operate the artifact published by the User, without determining the purpose of the processing. Data subject requests received directly by Apptime regarding visitor data will be forwarded to the responsible User whenever possible, who is responsible for fulfilling them.
For more detail on your obligations as a Data Controller in these cases, see section 5.2 of our Terms of Service.
7. Information Sharing
We share data only when necessary to provide our core services, and only with providers bound by contract to protect it. We do not sell personal data.
| Category | Providers | What they receive |
|---|---|---|
| Cloud, hosting, and CDN | Google Cloud Platform / Firebase | Account records, project content, uploaded media, logs |
| AI model providers | Google (Vertex AI / Gemini), OpenAI, and equivalent gateways | Only the prompts and files you submit for generation — never Google sign-in data |
| Payments | Mercado Pago, Asaas, AbacatePay | Name, email, and transaction data (card details go straight to them, never to us) |
| Transactional email and messaging | Our email delivery provider | Name and email address |
| Product analytics and tagging | Google Tag Manager and connected analytics | Pseudonymous usage events and device data |
| Legal compliance | Courts and competent authorities | Only what a valid legal order requires, strictly within statutory limits |
8. International Data Transfers
Apptime is operated from Brazil and runs on cloud infrastructure that may store or process data in other countries, including the United States and the European Union. When personal data leaves your country, we rely on the transfer mechanisms permitted by applicable law — such as standard contractual clauses and our providers' data processing addenda — so that the protection described in this policy travels with the data.
9. Cookies and Similar Technologies
We use a small set of cookies and browser storage:
- Essential: session and authentication tokens, security and anti-abuse signals, and your language and theme preferences. The platform cannot work without these.
- Analytics: pseudonymous measurement of page views and feature usage, so we can see what to improve.
- Marketing/attribution: used only where you have consented, to understand which campaign brought you to Apptime.
You can clear or block cookies in your browser settings. Blocking essential cookies will sign you out and prevent the platform from working.
10. Security and Data Protection
We employ rigorous technical and organizational security controls:
- Encryption in transit (HTTPS / TLS) and at rest across databases and object storage
- OAuth tokens and secrets stored encrypted, never exposed to the browser
- Least-privilege access control and audited administrative access
- Rate limiting and abuse detection on authentication endpoints
- Continuous vulnerability scanning and threat detection
We advise users never to submit sensitive confidential data (such as passwords or private medical records) in open prompts or public web pages.
If a security incident affects your personal data, we will notify you and the competent authority within the deadlines set by applicable law.
11. Data Retention and Account Deletion
Personal data is retained as long as your account remains active or as needed to fulfill the purposes described herein. In practice:
| Data | Retention |
|---|---|
| Account and profile data | While the account exists |
| Google OAuth tokens and connected-account data | Until you disconnect the integration or delete the account |
| Projects, prompts, and generated artifacts | While the account exists, or until you delete them |
| Billing and tax records | As long as tax and commercial law requires |
| Access logs | At least 6 months, as required by the Brazilian Civil Rights Framework for the Internet |
When you request account deletion, your personal data and private artifacts will be permanently removed, except where retention is legally mandated. You can request deletion from Account → Settings or by writing to team@apptime.ai; we complete the request within 30 days.
12. Your Rights
Under applicable privacy legislation (such as LGPD/GDPR), you have the right to:
- Confirm the processing of your personal data
- Access your data held by us and obtain a portable copy
- Request correction of inaccurate, incomplete, or outdated data
- Request anonymization, blocking, or deletion of unnecessary data
- Object to processing based on our legitimate interests
- Revoke previously given consents, including the Google connection
- Request permanent deletion of your account
- Lodge a complaint with a supervisory authority (in Brazil, the ANPD)
To exercise your rights, write to team@apptime.ai or submit a request via our Help Center. We answer within the deadlines set by applicable law and never charge for a first request.
13. Children's Privacy
Apptime is not directed to children. You must be at least 18 years old, or of legal age in your country, to create an account. We do not knowingly collect personal data from children; if we learn that we have, we delete it and close the account.
14. Policy Updates
We may update this Privacy Policy periodically. Significant changes will be announced on the platform or by email, and the "Last Updated" date below will always reflect the current version.
15. Contact Us
For questions, requests, or concerns regarding your privacy:
- Controller: Apptime Serviços de Internet Ltda (Brazil)
- Data Protection Officer (DPO): Apptime Privacy Team
- Email: team@apptime.ai
- Support Channel: Apptime Help Center