Privacy policy

What we collect, why we collect it, who processes it, and how to access, correct or delete it.

Last updated 14 August 2026

1. Data we collect

Account data. An email address is required to sign in, either through a one-time code or through a connected Google, Apple or X account, which also supplies your name and profile picture. We store a username and the provider's account identifier. Appllama does not use passwords.

Profile data. A display name is required. Country, date of birth, website and social handles are optional and can be cleared at any time.

Sign-in records. Each sign-in records the method, time, IP address, browser, operating system, and the country and city resolved from that address. This is used to detect unauthorised account use.

Content you create. Boards and the screens, apps and flows saved to them, an uploaded profile picture, and messages sent through the contact form.

Appllama MCP. If you connect an AI coding agent to the library through Appllama MCP, we record the client you authorised (its name and the details it registers with us) and issue it access tokens; we store only a one-way hash of each token, never the token itself. For every call the agent makes we log which tool was used, the credits it spent, whether it succeeded, and when. We do not log the content of your queries or the arguments your agent sends. Your credit balance and monthly usage are shown to you in account settings.

Usage data. In production we use Google Analytics to record page views, loading performance and a small number of product events.

2. Data we do not collect

  • Passwords. The service does not use them.
  • Card or bank details. Payment details are handled by the payment provider and do not reach our servers.
  • Session recordings, error-tracking data, advertising or marketing pixels. We do not sell personal data.
  • Images and videos submitted to visual search. They are used for that search only and are not stored.

3. Cookies and local storage

We use cookies to keep you signed in, to remember whether your account is free or Pro, and to store your light or dark preference. Our analytics provider sets its own cookies.

Your browser also keeps a copy of basic account and preference data so the interface loads without a delay. Clearing site data removes all of it and signs you out.

4. Service providers

Running Appllama involves a small number of providers covering hosting and email, content delivery and media storage, analytics, search, and payment processing.

Each receives only the data needed for its part of the service, and none of them are permitted to use it for their own purposes. We do not sell personal data or share it with advertisers or data brokers.

5. Public information

Your profile page is publicly visible, including to search engines, along with any boards marked public. This covers your username, display name, profile picture, website and social links. Your email address, date of birth and country are not published. Setting your profile to private in account settings also makes every board under it private.

6. Retention

Account data, boards and sign-in history are retained for as long as the account exists. A replaced profile picture is deleted from storage when the new one is saved. Content deleted in the product is deleted on our side.

MCP access tokens expire on their own — access tokens after 60 days and refresh tokens after 180 — and a token that has been rotated or revoked cannot be used again. Authorised client records, credit history and the per-call usage log are retained for as long as the account exists, and are deleted with it.

7. Your rights

Most profile data can be edited in account settings. For a copy of the data we hold, a correction, an export, or deletion of your account and associated data, contact hey@appllama.io. Deletion is handled on request rather than through a self-serve control.

Deleting an account also deletes its boards, and revokes every MCP connection authorised under it. Request an export first if you want to retain your boards.

To disconnect an agent from your account without deleting the account, contact us and we will revoke its tokens. You can also revoke Appllama from within the connecting client itself; the tokens then expire on the schedule in section 6.

8. Security

We apply appropriate technical and organisational measures to protect your account and the data we hold, including limits on repeated sign-in attempts and checks on uploaded files. Where an incident affects your data, we will notify you.

9. Children

Appllama is intended for professional use and is not directed at anyone under 16, or under the age of digital consent in their jurisdiction. We do not knowingly hold data relating to children. If you believe a child holds an account, contact us and we will remove it.

10. Where your data is processed

Appllama's data is stored and processed in the European Union. This covers account data, saved boards, uploaded media and email delivery.

Antmind Ventures Private Limited is registered in India, and a small number of service providers may process limited technical data in other regions. If you are located outside the European Union, your data is processed outside your own jurisdiction.

11. Changes and contact

When this policy changes, the date above is updated. Material changes will be notified by email or within the product.

For access, correction, export and deletion requests, or any question about this policy: hey@appllama.io.

Appllama is a creation of Antmind Ventures Private Limited.