Participate in our anonymous Starting Web App Research 2026 & Get 10 Credits🔥 It only takes 3 minutes!🚀

Privacy Policy

Who we are and our roles

For purposes of this Privacy Policy, the "Company" is the entity identified as the Company in the Terms of Service for the Website and Services you use. Unless an Order or checkout page identifies a different contracting provider, the Company is Flatlogic Poland, LLC for flatlogic.com. The Company is a controller of personal data processed for Website operation, Account administration, subscriptions, service management, support, security, abuse prevention, and legal compliance where it determines the purposes and means of that processing.

AppWizzy Inc. ("AppWizzy") (490 Post Street, Ste. 526, San Francisco, CA 94102, USA) owns and licenses the Web App Generator, operates the AppWizzy multi-provider AI proxy, and receives online payments for the Services using Stripe or another payment service provider identified at checkout. AppWizzy is a controller of payment and transaction records and of AI-proxy billing, security, and operational records where it determines the purposes and means of processing.

Flatlogic Poland, LLC (Konstruktorska 11 / 44, 02-673 Warsaw, Poland) provides Website operations, customer support, and, where applicable, custom development and other operational services. Flatlogic is a controller of personal data processed for its own Website-operation, support, custom-development, and legal-compliance purposes. When Flatlogic performs services solely on AppWizzy's documented instructions, it acts as AppWizzy's service provider or processor for that activity.

If a Customer uses a customer-controlled development VM to process personal data and determines why and how that personal data is processed, the Customer acts as the controller or business and the Company processes that personal data on the Customer's behalf as a processor or service provider. The Company remains a controller for processing it undertakes for its own Account administration, billing, security, abuse-prevention, and legal-compliance purposes.

This privacy policy is meant to clarify the use of ‘Personally Identifiable Information’ (PII). PII, as defined in the US Privacy Law and information security, is information that can be used on its own or with other information to identify, contact, or locate a single person, or to identify an individual in context. Please take a close look at our privacy policy in order to get transparency over how we collect, use, protect or otherwise handle your Personally Identifiable Information on our website.

What personal information do we collect via our blog, website and app?

We do not collect optional analytics/advertising data without your consent. We may process strictly necessary technical data and cookies (e.g., security, authentication, session) to operate the Website and Services. We collect:

  • Account data: name, email, password hash, organization name, role.
  • Billing data: Stripe or another payment service provider identified at checkout processes card and other payment details. AppWizzy may receive transaction identifiers, payment status, amounts, billing contact information, and limited payment-method details, but we do not store full card numbers on our servers.
  • Device & log data: IP address, browser/OS, referring URLs, timestamps, and basic event logs for security, fraud prevention, and service reliability.
  • Cookies & similar tech: strictly necessary cookies are always on; analytics/functional/advertising cookies are optional and only set with your consent via the Cookie Settings widget.
  • Customer Content: source code, repositories, files, prompts, AI responses, terminal and application data, and other information that you or your tools create, upload, access, or store in a development VM. Customer Content may include personal data about you or others.
  • Development VM telemetry & service data: VM identifiers, start/stop events, resource usage metadata, abuse‑prevention signals, and AI usage metadata (e.g., selected model and, where available, provider, token counts, latency, status, and tool call metrics).

When do we collect information?

We collect information when you: create an account, make a purchase, start or manage development VMs, store or access Customer Content, submit an AI request, request support, subscribe to communications, or interact with our Website. Technical and security logs are collected when you access the site or Services. Optional analytics/advertising data are collected only if you consent in the Cookie Settings.

How do we use your information?

We use information to:

  • Provide and operate the Services (including provisioning Dev VMs, executing AI edits, and delivering downloads/hosting).
  • Secure the Services (fraud/abuse detection, rate‑limiting, incident response).
  • Measure & improve performance and user experience (analytics if you consent).
  • Administer payments, Credits, transactions, and accounting through AppWizzy and the payment service provider identified at checkout.
  • Communicate with you (product updates, support, service messages, and-with your consent-marketing).
  • Comply with law, enforce Terms of Service, and protect our users and systems.

How do we protect visitor information?

Our website is scanned on a regular basis for potential security issues and known vulnerabilities in order to make your visit to our site as safe as possible. We use regular Malware Scanning. Your personal information is contained within a secure network and is only accessible by a limited number of people who have special access rights to such systems, and are required to keep the information confidential. In addition, all sensitive/credit information you supply is encrypted via Secure Socket Layer (SSL) technology. We implement a variety of security measures when a user enters, submits, or accesses their information to maintain the safety of your personal information. All transactions are processed through a gateway provider and are not stored on our servers.

We host on reputable cloud providers with network segmentation, access controls, and encryption in transit (and at rest where supported). Access to production systems is restricted to authorized personnel. We regularly review subprocessors and apply contractual and technical safeguards for international transfers where required (e.g., SCCs).

Do we use ‘cookies’?

Yes. We use a Cookie Settings banner that lets you choose:

  • Strictly necessary (always on): security, sign‑in, core features.
  • Analytics (opt‑in): helps us understand usage to improve the product.
  • Functional (opt‑in): enhances features and personalization.
  • Advertising (opt‑in): shows relevant ads and measures performance (currently off by default; only set if you choose it).

You can Accept all, Reject all, or Customize choices at any time via the banner link ("Cookie Settings") in the footer. Your choices control whether non‑essential cookies/SDKs are loaded. Note: disabling cookies may impact some features.

Third-party disclosure

We do not sell your personal information. AppWizzy and Flatlogic may share information with each other as necessary to perform the roles described above. We also disclose information to service providers and subprocessors to provide, secure, support, and administer the Services, including Stripe or another payment service provider identified at checkout, cloud and network infrastructure providers, email delivery providers, analytics providers if you consent, and error or incident tooling. These providers are subject to contractual confidentiality, security, and use restrictions appropriate to their role. We disclose AI request content and related technical data to the AI provider selected for a request, as described below.

AI services and provider choices

By default, AI requests are sent through AppWizzy's multi-provider proxy. AppWizzy receives the request content and related technical metadata, forwards the request content to the AI provider selected for that request, receives the provider's response, and returns it to you. AppWizzy also measures usage, charges the applicable credits to your account, and displays usage and billing information.

Request content may include prompts, source code, files, tool inputs and outputs, images, audio, and other context that you or an automated tool directs the Service to send. The selected AI provider receives the request content and technical data necessary to process the request.

Where a feature supports it, you may instead use your own ChatGPT account or an API key for a supported AI provider. In that case, the provider processes requests under your account and its own terms, privacy policy, data controls, and retention practices. Provider credentials that you add to a development VM may be stored or used in that hosted environment as part of Customer Content.

For billing, support, security, abuse prevention, and service reliability, AppWizzy records usage and operational metadata such as account or project identifiers, the selected model and, where available, provider, timestamps, token or other usage measurements, request status and errors, latency, and tool call metrics. Depending on the AI feature, operational records may also contain the full request or response, or excerpts such as prompt previews and error or response-body previews.

Third-party links

Our Services may integrate with, link to, or allow you to access third-party products and services, including AI providers and services that you choose to use from a development VM. Those third parties' terms and privacy practices apply to their services. Third-party sites, services, content, and cookies are outside our control.

Google

We may use Google Analytics (only with your consent in the EEA/UK and where required). IP anonymization is enabled where supported. We do not run Google AdSense at this time; if that changes, we will request consent and update this section.

California Online Privacy Protection Act

CalOPPA is the first state law in the nation to require commercial websites and online services to post a privacy policy. The law’s reach stretches well beyond California to require a person or company in the United States (and conceivably the world) that operates websites collecting personally identifiable information from California consumers to post a conspicuous privacy policy on its website stating exactly the information being collected and those individuals with whom it is being shared, and to comply with this policy. - See more at: http://consumercal.org/california-online-privacy-protection-act-caloppa/#sthash.0FdRbT51.dpuf

According to CalOPPA we agree to the following:

Users can visit our site anonymously. Once this privacy policy is created, we will add a link to it on our home page or it will also be displayed on any initial page a user sees after entering our website. Our Privacy Policy link can be easily be found on the page specified above. Users will be notified of any privacy policy changes on our website. Users are able to change their personal information at any given time by emailing this request to us directly.

We recognize Global Privacy Control (GPC) signals where legally required and treat them as an opt‑out of selling/sharing for cross‑context behavioral advertising (if applicable).

"Do Not Track" (DNT) is not standardized; we rely on your Cookie Settings and, where applicable, GPC.

How does our site handle Do Not Track signals?

We honor Global Privacy Control (GPC) where required and rely on your Cookie Settings to control non‑essential cookies. Because DNT is not standardized, we do not rely on DNT alone.

Does our site allow third-party behavioral tracking?

We do not allow third-party behavioral tracking.

COPPA (Children Online Privacy Protection Act)

When it comes to the collection of personal information from children under 13, the Children’s Online Privacy Protection Act (COPPA) puts parents in control. The Federal Trade Commission, the nation’s consumer protection agency, enforces the COPPA Rule, which spells out what operators of websites and online services must do to protect children’s privacy and safety online. We do not specifically market to children under 13.

Fair Information Practices

The Fair Information Practices Principles form the backbone of privacy law in the United States and the concepts they include have played a significant role in the development of data protection laws around the globe. Understanding the Fair Information Practice Principles and how they should be implemented is critical to comply with the various privacy laws that protect personal information.

In order to be in line with Fair Information Practices we will take the following responsive action, should a data breach occur:

We will notify the users via in-site notification within 7 business days. We also agree to the Individual Redress Principle, which requires that individuals have a right to pursue legally enforceable actions against data collectors and processors who fail to adhere to the law. This principle requires not only that individuals have enforceable rights against data users, but also that individuals have recourse to courts or government agencies to investigate and/or prosecute non-compliance by data processors.

Development VMs and Customer Content

Development VMs are hosted computing environments. We host and process Customer Content at your direction to provide the VM, remote access, AI features, support, security, and other functions that you request. You decide what Customer Content to create, upload, access, or store and are responsible for having the rights and legal basis needed to process personal data included in that content.

Where the Company processes personal data in Customer Content on a Customer's behalf, the Customer's use and configuration of the Services, the Terms of Service, and any applicable data processing agreement constitute the Customer's instructions. The Customer is responsible for providing required privacy notices, establishing a lawful basis, responding to data-subject requests, and configuring the VM appropriately for the personal data the Customer chooses to process.

We also process service and security metadata (e.g., VM identifiers, start/stop events, resource usage, abuse‑prevention signals) and AI usage metadata (e.g., token counts, latency, status, and tool call metrics) for billing, support, reliability, and abuse prevention. We may suspend or terminate VMs and delete VM data if suspicious, abusive, or illegal activity is detected or reasonably suspected, consistent with our Terms of Service.

Data retention and deletion

We retain personal data for as long as reasonably necessary for the purposes described in this Privacy Policy, including providing the Services, maintaining Accounts, recording usage and transactions, complying with tax and accounting obligations, resolving disputes, preventing abuse, maintaining security, and complying with law. Retention periods vary by category and may be extended where information is subject to a legal obligation, dispute, investigation, or legal hold. Aggregated and de-identified information that no longer identifies a person or Customer may be retained for analysis and product improvement.

Closing an Account disables access but does not necessarily erase every Account, transaction, usage, support, security, or legal-compliance record immediately. Deleting a project or VM removes the active VM infrastructure and Customer Content stored only on that VM, but does not necessarily delete related Account, AI usage, billing, support, security, or legal records. You may request deletion of personal data as described under "Your rights," subject to applicable legal exceptions.

When a VM is paused or otherwise scheduled for cleanup, the Company ordinarily provides at least 7 calendar days before permanent deletion is attempted. An additional one-day operational grace window ordinarily applies, and the timing of the deletion process may extend that period. Successfully resuming or renewing the VM before deletion ordinarily cancels the scheduled cleanup. A Customer-requested project or Account deletion, or suspension or termination for security, abuse, or legal reasons, may result in earlier removal. Customers should export or independently back up any Customer Content they wish to retain.

We do not guarantee that infrastructure backups or snapshots include an individual VM, are current, or can be restored for a Customer. Deletion from active systems may not immediately remove limited residual copies contained in operational backups or retained by infrastructure providers. Such copies may remain until they are overwritten or deleted under the applicable backup process or may be retained where required by law. They ordinarily are not available as a Customer restoration service.

AI request records may include request or response content, excerpts, or summaries. AI usage and billing records may include the selected model and, where available, provider, token counts, timestamps, identifiers, request status, and charges. We retain these records as reasonably necessary for billing, support, security, abuse prevention, dispute resolution, and legal compliance. AI providers may retain request content and related data according to their own terms, policies, account settings, and the configuration used for the request.

Your rights

Subject to applicable law, you may request access, correction, deletion, portability, or restriction of your personal data, and you may withdraw consent for optional cookies/processing at any time via Cookie Settings. To exercise rights, contact us at the addresses below.

Payments

Online payments for the Services are received through AppWizzy and technically processed by Stripe or another payment service provider identified at checkout. The payment service provider processes payment details under its privacy notice and applicable contractual role. Flatlogic provides Website operations, customer support, and, where applicable, custom development and other operational services as described above.