Data protection and deletion
The concrete version of our privacy policy: what is actually stored, what is protected how, what you can remove yourself, and what happens when you ask us to delete everything.
What we hold
AppIn is a link service, so what we hold is small and it is worth listing exactly:
- Your account — name, email, password as a hash, subscription status.
- Your links — the slug, the destinations, the campaign parameters, the landing page settings, and any custom domain you have connected.
- Your sign-in sessions — including the IP address and browser each was created from.
- Click analytics — one aggregate row per tap: the link, the country, the platform, the in-app browser if there was one, the outcome, the referring address and the time.
- Fault records — when our software hits a bug, the error and the point in our code it came from. One raised while you were signed in also carries your internal account id, and nothing else about you. What such a record can and cannot hold is set out under Diagnostics.
What we deliberately do not hold
There is no visitor record. A click row carries no IP address, no user agent string, no device or advertising identifier and no cookie, so the same person tapping the same link twice produces two rows with nothing linking them. There is no SDK collecting anything from inside your app, because there is no SDK. And we hold no copy of your app store data beyond the listing fields used to draw your landing page.
How it is separated and protected
- Everything travels over encrypted connections.
- Passwords are stored only as hashes and are never recoverable.
- The click path — the part of the system exposed to the whole internet — reads a read-only mirror of your link settings and cannot reach the database holding accounts. The busiest surface is not the sensitive one.
- Payment details never arrive here at all: Dodo Payments is merchant of record and processes them.
- Access to production systems is limited to the people who operate the service.
What you can delete yourself
A link. Deleting a link removes it from the click path immediately — the next tap on that address resolves to nothing. The link’s click history is kept, because deleting a link is not a request to lose the numbers you have collected from it, and those numbers identify no one.
A sign-in session. Signing out ends the session it was created for.
Deleting your account and everything in it
Email hello@getappin.com from the address on the account, with “Data deletion” in the subject line. If you cannot send from that address, tell us the account email and we will verify ownership another way before doing anything.
What happens then:
- Your links stop resolving. This happens first, because it is the part with immediate consequences for anyone who has published one.
- Your sessions end. Thirty days later, if you have not come back and reopened it, your sign-in is erased — the email address, the name and the password go, and after that nobody can reach the account, us included. Your links stay dark from the first day and are never handed to anyone else.
- Click rows are one exception, and it is a small one: they are held in an analytics store that has no way to remove an individual row. They contain no identifier of you or of any visitor — a link id, a country, a platform, an outcome — and they become unreadable as anyone’s data the moment the account they belonged to is gone.
- Fault records are another, and a smaller one. A bug our software hit while you were signed in carries your internal account id, which points at nothing once the account is gone. They are kept by count rather than by time — the 10,000 most recent per service — and fall away on their own as newer ones arrive.
- Analytics records are the third. How many people signed up and subscribed is how we understand our own growth, so those counts stay; they carry an account number and no name or address.
- Encrypted backups age out on their own schedule and are never used to restore a deleted account.
- We write back to confirm when it is done.
We answer requests within one month, the period GDPR sets, and we will tell you if a request needs longer than that.
What deletion does not reach
- Statutory financial records. Invoices and the accounting records behind them have to be kept for the period tax law sets, and a deletion request does not override that.
- Your own app store listing. AppIn reads your app’s public listing to build a landing page; it does not own anything in the store. Deleting your AppIn account has no effect on your app, which is what you would want.
If you tapped a link and want your data removed
You can ask, and the honest answer is that there is nothing to find. A click row holds a link id, a country, a platform, an in-app browser name and an outcome — no IP address, no user agent, no identifier of any kind — so nothing in it points at you and no search of it can be run on your behalf. That is a property of how the click path is built, not a refusal. If you think we hold something about you anyway, write to hello@getappin.com and we will look and tell you what we find.
Your rights
Under GDPR and Türkiye’s KVKK you can ask for a copy of your personal data, ask us to correct it, ask us to delete it, ask for it in a portable form, or restrict or object to processing. The same address handles all of them: hello@getappin.com. If you are not satisfied with our answer you can complain to your local supervisory authority — in Türkiye, the Personal Data Protection Authority (KVKK).
The legal bases for each kind of processing are set out in our Privacy Policy.
Contact
Zeisoft Yazılım Limited Şirketi
hello@getappin.com