Legal
Privacy Policy
Last updated 26 September 2026
Who we are
This Privacy Policy is issued by Appitomic, a sole proprietorship operated by Hira Muhammad Iqbal, trading as Appitomic("Appitomic", "we", "us"). Appitomic designs, builds and publishes mobile apps, SaaS platforms and websites. We are the data controller for the personal data described in this policy.
Privacy contact: hello@appitomic.com. We answer privacy requests within 30 days.
What this policy covers
This policy applies to:
- the website appitomic.com, including private demo previews hosted under appitomic.com/demos;
- mobile apps, web apps and SaaS products that Appitomic publishes, including SentSelf (sentself.com) and any app listed on Google Play or the Apple App Store with Appitomic as the developer ("our apps"). Where a product has its own privacy policy on its own website, that policy applies to the product and this policy applies to everything else;
- purchases of our products, which are processed by our reseller and merchant of record, Paddle.
Software that we build for clients and that is published under the client's own name is governed by that client's privacy policy, not this one.
Personal data we collect and why
When you visit appitomic.com
- Contact form: name, email address, company (optional), project type, budget range (optional) and your message. We use these only to reply to your enquiry and to keep a record of our conversation. We also record the IP address and browser type of the submission to detect spam and abuse.
- Private demo access: when you open a demo preview we record the demo name, the time, whether the access code was correct, and the IP address and browser type used. This protects demos against guessing attacks.
- Server logs: our hosting provider, Cloudflare, records standard request logs (IP address, URL, time, browser type) for security and to keep the service running.
When you use our apps
Each app also shows an in-app disclosure and a Google Play Data safety section specific to that app. Across our apps we may collect the following, only where the app needs it to work:
- Account information: name, email address, and a password or sign-in token when you create an account. Used to provide the service, secure your account and contact you about it.
- Content you create: the information you enter or upload while using the app (for example bookings, notes, files or settings). Used to provide the features you asked for.
- Purchase information: what you bought, when, the amount, currency and the last four digits of the payment card, supplied to us by Paddle. We never receive or store full card numbers.
- Device and usage data: device model, operating system version, app version, language, crash reports and which features are used. Used to fix bugs, keep the app secure and improve it.
- Identifiers: a random installation identifier and, where you allow it, a push notification token so we can send notifications you have opted into.
- Permissions: some features need device permissions such as camera, photos, location or contacts. We ask for each permission in the app, at the moment it is needed, with an explanation, and you can refuse or revoke it in your device settings. We do not access these without your permission and we do not use them for advertising.
We do not sell personal data and we do not use it for third-party advertising. We do not knowingly collect data from children under 13 (or the higher age required in your country); if you believe a child has provided us with data, contact us and we will delete it.
Legal bases
Where the GDPR or UK GDPR applies, we process personal data to perform a contract with you (providing the app or service you use or purchase), for our legitimate interests (security, fraud prevention, improving our products, responding to enquiries), to comply with legal obligations (tax and accounting records), and with your consent where we ask for it (for example device permissions or marketing emails). You can withdraw consent at any time.
Who we share data with
We share personal data only with service providers that help us run our website and apps, under contracts that limit what they may do with it:
- Cloudflare, Inc.: hosting, content delivery, security and the database that stores website enquiries and demo access logs.
- Resend, Inc.: delivery of transactional emails, such as our reply to your enquiry or account emails from our apps.
- Paddle.com Market Ltd and Paddle.com Inc. ("Paddle"): our reseller and merchant of record. Paddle processes your payment, collects applicable taxes, issues invoices and handles refunds. Paddle acts as an independent controller of the data it collects at checkout under its own privacy policy.
- Google LLC (Google Play services, Firebase crash reporting and push notifications) and Apple Inc. (App Store, push notifications): app distribution, crash reporting and notification delivery for our mobile apps.
We may also disclose data if required by law, to protect our rights or the safety of others, or as part of a merger or sale of our business, in which case this policy will continue to apply to the data transferred.
International transfers
Our providers store data in data centres that may be outside your country, including the United States and the European Union. Where data leaves the EEA or the UK we rely on the providers' Standard Contractual Clauses or an adequacy decision.
How we protect data
All data is transmitted over HTTPS (TLS) and stored encrypted at rest by our providers. Access to production systems is limited to the people who need it and protected by multi-factor authentication. Passwords in our apps are stored only as salted hashes. Private demo access codes are checked server-side and never included in page code. Payment card data is handled entirely by Paddle and never touches our systems.
How long we keep data
- Website enquiries: up to 24 months after our last exchange with you, then deleted.
- Demo access logs and abuse-prevention records: 12 months, then deleted.
- App account data and your content: for as long as your account exists, then deleted within 30 days of deletion.
- Crash and usage diagnostics: up to 18 months.
- Purchase and invoice records: as long as tax and accounting law requires (typically 6 to 7 years), held by Paddle and in our accounting records.
Your rights
Depending on where you live, you have the right to access the personal data we hold about you, to correct it, to have it deleted, to receive a copy in a portable format, to object to or restrict certain processing, and to complain to your data protection authority. To exercise any of these, email hello@appitomic.com. We will verify your identity and respond within 30 days.
Deleting your account and data
You can delete your account and associated data in any of our apps from the app's settings, or by emailing hello@appitomic.com from the address on the account, which does not require the app to be installed. Deletion removes your account and content within 30 days. We keep only what the law obliges us to keep, such as invoice records, and anonymised diagnostics that can no longer be linked to you.
Cookies
appitomic.com does not use advertising or analytics cookies. The only cookie we set is a session cookie for a private demo that you have unlocked with a code; it is scoped to that demo alone. If you buy a product, Paddle's checkout sets the cookies it needs to process the payment securely, as described in Paddle's privacy policy.
Changes to this policy
When we change this policy we update the date at the top of the page. If a change materially affects how we use your data we will also tell you in the app or by email before it takes effect.
Contact
Appitomic, operated by Hira Muhammad Iqbal, trading as Appitomic
Email: hello@appitomic.com