legal

Privacy Policy

last updated · Sept 29, 2026

This Privacy Policy describes how Plainwork, S.L. (“Plainwork”, “we”, “us”, or “our”) collects, uses, and protects information when you use AppDen, its website and dashboard, and the apps you publish with it (together, the “Service”). AppDen lets the AI assistant you already use (such as Claude or ChatGPT) build small web apps and publish them privately, for you and the people you share them with. By using the Service, you agree to the practices described in this policy.

1. Information We Collect

1.1 Account Information

When you create an account, we collect your email address and, if you provide them, your name and profile picture. Sign-in is handled by our authentication provider, which may let you sign in with another account, such as Google. If you do, we receive your name, email address, and profile picture from it and use them only to identify your account. We do not access any other services on that account.

1.2 Customer Content

Customer Content is what you and your AI assistant put into the Service: the files and code of the apps you publish and every version of them; the data your apps store in their databases and file storage, including what the people you share them with enter; the keys and passwords you save for your apps; and the email addresses of the people you share apps with. To show you what each app looks like, we take screenshots of its pages as you see them, and to show you how it’s doing, we keep a record of its requests and errors. We process Customer Content only as needed to provide and maintain the Service.

1.3 Usage Data

We automatically collect information about how you interact with the Service, including feature usage, session duration, device type, browser, operating system, IP address, the page that referred you, and any marketing campaign parameters (such as UTM tags) in the link you arrived from. On AppDen’s website and dashboard, our analytics provider (PostHog) records the pages you visit and where you click and scroll, which we use to see how people use AppDen and where it is hard to use. When you are signed in, this is linked to your account and email address. We also measure how much each app is used (its requests, computing time, and storage) to apply your plan’s limits and bill for usage. Usage data is collected in aggregated form and does not identify you personally when disclosed to others.

1.4 Cookies and Similar Technologies

We use a small number of cookies to keep you signed in, to remember your preferences, and to measure how AppDen is used. We do not use advertising cookies or pixels. Specifically:

  • Authentication cookies: Essential cookies that keep you signed in to the dashboard and to each app you open.
  • Analytics: Cookies and browser storage set by PostHog on AppDen’s website and dashboard, to recognise your visits over time. The apps you publish do not include them.
  • Preferences: Your display settings (e.g., theme) and the AI assistant you picked, stored in your browser.

2. How We Use Your Information

2.1 To Provide the Service

We use your account information to authenticate you, your Customer Content to run, store, and show your apps and to let the people you choose open them, and your usage data to maintain and monitor service performance and to apply your plan.

2.2 To Improve the Service

We use aggregated and de-identified usage data to maintain, improve, enhance, and promote our products and services. We may freely use such aggregated data without restriction or obligation, provided it does not identify you or your users.

2.3 To Communicate With You

We use your email address to send transactional messages (e.g., account verification and billing receipts) and important service announcements. When you share an app with someone, we email them its link on your behalf, and their replies go to you. We will not send marketing emails without your consent.

2.4 Machine Learning

We do not train machine-learning models on your Customer Content. When you ask a question in plain words on an app’s Database page, we send your question and the database’s structure (its tables and columns, never its rows) to an AI provider, which writes the query we then run for you. If we use usage data to develop or improve AI/ML features within the Service, we will only use aggregated and de-identified data. Nothing in this section reduces or limits our obligations regarding personal data under applicable data protection laws.

2.5 Your AI Assistant

When you connect an AI assistant to AppDen, it can read and change your apps through the Service at your request. What the assistant’s provider does with that information is governed by its own terms and privacy policy.

3. How We Share Your Information

3.1 No Sale of Personal Data

We do not sell, rent, or share your personal data with advertisers or data brokers.

3.2 Service Providers

We may share information with third-party service providers who assist us in operating the Service (e.g., cloud hosting, payment processing, email delivery). These providers are bound by confidentiality obligations and may only process data as instructed by us. See our Subprocessors page for the current list. A Data Processing Agreement is available on request.

3.3 Legal Requirements

We may disclose your information to the extent required by applicable laws, regulations, court orders, or other legal processes. Unless prohibited by law, we will provide you reasonable advance notice of any required disclosure.

3.4 Business Transfers

If Plainwork undergoes a merger, acquisition, reorganization, or sale of all or substantially all its assets, your information may be transferred as part of that transaction. We will notify you of any such change.

4. Data Storage and Security

4.1 Encryption

Customer Content is transmitted using TLS encryption in transit and stored encrypted at rest by our infrastructure providers. The keys and passwords you save for your apps are stored encrypted and are never shown again, including to your AI assistant.

4.2 Infrastructure

The Service is hosted on industry-standard cloud infrastructure. We implement appropriate technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction.

4.3 Prohibited Data

You should not submit to the Service any: (a) protected health information regulated by HIPAA; (b) financial account numbers; (c) government ID numbers; (d) special categories of data as defined in the GDPR; or (e) other similar categories of sensitive information, unless expressly authorized in writing.

5. Data Retention and Deletion

5.1 Active Accounts

We retain your data for as long as your account is active and as needed to provide the Service. Records of your apps’ requests and errors are kept for 3 days.

5.2 Account Deletion

You can download your apps’ data and delete any app at any time from the dashboard. To delete your account, email us. Upon account deletion, Plainwork will delete your Customer Content within 60 days. We may retain aggregated, de-identified data that does not identify you.

5.3 Legal Retention

We may retain certain information as required by applicable laws (e.g., tax records, billing history) even after account deletion, in which case we will continue to protect it in accordance with this policy.

6. International Data Transfers

If you are located outside the United States, your data may be transferred to and processed in the United States or other countries where our service providers operate. Where required by GDPR or UK GDPR, we implement appropriate safeguards for such transfers, including EU Standard Contractual Clauses and the UK International Data Transfer Addendum.

7. Your Rights

Depending on your location and applicable data protection laws, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict certain processing
  • Request data portability
  • Withdraw consent at any time (where processing is based on consent)
  • Lodge a complaint with a supervisory authority

To exercise any of these rights, contact us at legal@plainwork.com.

8. Children’s Privacy

The Service is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe we have collected such data, please contact us and we will promptly delete it.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced by email or in-product notice at least 14 days before taking effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

10. Contact

Questions about this policy? Email legal@plainwork.com.

Plainwork, S.L.
Plainwork Privacy Team