Start

Appkeepr

Privacy Policy

Effective date: · Version 1.0

About this Policy

This Privacy Policy explains how we handle personal data when you use Appkeepr, its related website, and support services (the “Service”). Receive messages from developer systems in a shared workspace inbox on web and phone, with webhook integrations, uptime checks and domain monitoring.

Tapit Teknoloji Limited Şirketi operates the Tapit Studio brand. Its address is Söğütözü Mahallesi, Söğütözü Caddesi No: 2C, İç Kapı No: 17, Çankaya, Ankara, Türkiye.

Tapit Teknoloji Limited Şirketi is responsible as controller for the personal data processed to operate the Service. Customer-controlled data is described separately below.

The information processed depends on the features you use, the people you interact with, and your device settings. The descriptions below distinguish device-only information from information sent to servers or providers.

Information we process

  • Account and sign-in information: email address, name, profile photo, sign-in sessions, sign-in provider tokens, IP address, and browser, operating system, and device information. Stored on our servers. Used for your access and experience. Used to create and authenticate access to the Service and provide and maintain the Service.
  • Profile information: workspace membership and activity and record times. Stored on our servers. Available to members of the relevant workspace. Used to provide and maintain the Service.
  • Profile information: message read status and activity and record times. Stored on our servers. Used for your access and experience. Used to provide and maintain the Service.
  • App, device, and network information: app, installation, or device identifiers, push notification token, language preference, and time zone. Stored on your device and our servers. Used for your access and experience. Used to deliver messages and notifications.
  • Customer and workspace content: message text, titles, and associated context, identifiers supplied by customers, contact details included in feedback, event identifiers and deduplication information, and activity and record times. Stored on our servers. Available to members of the relevant workspace. Used to provide and maintain the Service and deliver messages and notifications.
  • Integration and API credentials: API token hash and identifying prefix and webhook and integration secrets. Stored on our servers. Used for operation, support, or review by the operator. Used to create and authenticate access to the Service and provide and maintain the Service.
  • Integration processing records: event identifiers and deduplication information, processing and delivery status, and activity and record times. Stored on our servers. Used for operation, support, or review by the operator. Used to provide and maintain the Service and prevent fraud, abuse, and misuse.
  • Integration processing records: message text, titles, and associated context, identifiers supplied by customers, contact details included in feedback, and processing and delivery status. Stored on our servers. Used for operation, support, or review by the operator. Used to deliver messages and notifications.
  • Service usage records: usage counts and activity and record times. Stored on our servers. Available to members of the relevant workspace. Used to provide and maintain the Service and administer accounts and operate the Service.
  • Diagnostic information: app, installation, or device identifiers and app launches, screen views, and feature interactions. Processed or stored by the relevant service provider. Used for operation, support, or review by the operator. Used to understand use of the Service and improve it.
  • Diagnostic information: error details, crash reports, and related technical information, IP address, and browser, operating system, and device information. Processed or stored by the relevant service provider. Used for operation, support, or review by the operator. Used to find and resolve errors and crashes.
  • Diagnostic information: app, installation, or device identifiers and installation and marketing attribution information. Processed or stored by the relevant service provider. Used for operation, support, or review by the operator. Used to measure installations and marketing campaign performance.

How and why we use information

Where a legal basis is required, it depends on the activity and the applicable law. Providing requested functionality relates to our agreement with you; security, support, and improvement relate to our interests in operating the Service; legal obligations may require particular processing. Where processing relies on your consent, you may withdraw that consent without affecting processing that already took place.

  • create and authenticate access to the Service
  • provide and maintain the Service
  • deliver messages and notifications
  • prevent fraud, abuse, and misuse
  • administer accounts and operate the Service
  • understand use of the Service and improve it
  • find and resolve errors and crashes
  • measure installations and marketing campaign performance

Service providers

The providers below support the activities listed for them. The data available to a provider depends on its role and the platforms on which it is used. Their privacy policies provide information about their own processing.

  • Mixpanel: used to understand use of the Service and improve it on iOS and Android.
  • Sentry: used to find and resolve errors and crashes on iOS, Android, the website, and server operations.
  • Tenjin: used to measure installations and marketing campaign performance on iOS and Android.
  • Apple: used to create and authenticate access to the Service on iOS, the website, and server operations.
  • Google: used to create and authenticate access to the Service on iOS, Android, the website, and server operations.
  • Resend: used to create and authenticate access to the Service on server operations.
  • Expo: used to deliver messages and notifications on iOS, Android, and server operations.
  • Sanity: used to provide and maintain the Service on the website.

Sharing and other disclosures

We may disclose relevant information when legally required, to respond to a lawful request, to investigate misuse, or to protect people's safety and rights. Information may also be involved in a business transfer or reorganization, subject to applicable privacy obligations.

Device permissions and choices

If you enable notifications, a notification token and related installation information are used to send them. You can change notification permission in device settings. Your device or lock screen may display notification previews.

Marketing attribution providers process installation and campaign information on the platforms identified above. You can manage available tracking permissions in device settings. A device permission and any consent required by privacy law are separate choices.

Website cookies and storage

The website uses essential cookies or similar storage for functions such as sign-in, session continuity, and security.

The website does not currently use analytics cookies.

Data processed for customers

Customers may send message content, identifiers, feedback contact details, and other information from their own systems into a workspace. For personal data processed on the customer's behalf, the customer determines its purposes and acts as controller, while we provide processing as part of the Service. This is separate from our controller role for our own account, support, and operational data.

Workspace membership determines access to workspace content. Contact the relevant customer or workspace administrator about personal data they have supplied; they are responsible for deciding and communicating their instructions. You may contact us if you need help identifying the relevant route for a request. This notice does not itself create a separate data processing agreement.

Retention and deletion

Retention differs by category. The rules below describe the current lifecycle and the effect of deletion. Closing access, hiding a profile, redacting a record, and physically erasing stored information are different actions.

  • Account and sign-in information (email address, name, profile photo, sign-in sessions, sign-in provider tokens, IP address, and browser, operating system, and device information): Kept as part of the account or access lifecycle. A complete deletion outcome is not specified for this category; contact us about your request.
  • Profile information (workspace membership and activity and record times): No age-based automatic deletion is currently applied. A complete deletion outcome is not specified for this category; contact us about your request.
  • Profile information (message read status and activity and record times): No age-based automatic deletion is currently applied. A complete deletion outcome is not specified for this category; contact us about your request.
  • App, device, and network information (app, installation, or device identifiers, push notification token, language preference, and time zone): Kept as part of the account or access lifecycle. A complete deletion outcome is not specified for this category; contact us about your request.
  • Customer and workspace content (message text, titles, and associated context, identifiers supplied by customers, contact details included in feedback, event identifiers and deduplication information, and activity and record times): No age-based automatic deletion is currently applied. A complete deletion outcome is not specified for this category; contact us about your request.
  • Integration and API credentials (API token hash and identifying prefix and webhook and integration secrets): Kept as part of the account or access lifecycle. A complete deletion outcome is not specified for this category; contact us about your request.
  • Integration processing records (event identifiers and deduplication information, processing and delivery status, and activity and record times): Eligible for cleanup 30 days after acceptance; cleanup may complete later. A complete deletion outcome is not specified for this category; contact us about your request.
  • Integration processing records (message text, titles, and associated context, identifiers supplied by customers, contact details included in feedback, and processing and delivery status): Pending or failed processing records become eligible for cleanup after 7 days; cleanup may complete later. A complete deletion outcome is not specified for this category; contact us about your request.
  • Service usage records (usage counts and activity and record times): No age-based automatic deletion is currently applied. A complete deletion outcome is not specified for this category; contact us about your request.
  • Diagnostic information (app, installation, or device identifiers and app launches, screen views, and feature interactions): The retention period depends on the provider's policies and settings. Deletion and retention are managed by the relevant provider.
  • Diagnostic information (error details, crash reports, and related technical information, IP address, and browser, operating system, and device information): The retention period depends on the provider's policies and settings. Deletion and retention are managed by the relevant provider.
  • Diagnostic information (app, installation, or device identifiers and installation and marketing attribution information): The retention period depends on the provider's policies and settings. Deletion and retention are managed by the relevant provider.

Account deletion

Contact us to request deletion of information held by the Service. We assess the request against the data involved, the category-specific retention rules in the Privacy Policy, and applicable obligations.

You may also email info@appkeepr.com with “Appkeepr deletion request” and information that helps us identify the relevant account or device. We may ask for limited information to verify your request. Do not send passwords, sign-in tokens, or full payment details.

Your privacy rights

Depending on the law that applies, you may have rights to learn about processing, access or receive a copy of your data, correct it, request deletion, restrict processing, or object to particular processing. You may also withdraw consent and complain to the relevant data protection authority. These rights can be subject to legal conditions and exceptions.

Send privacy questions and requests to info@appkeepr.com. Tell us which Service you use and what you would like us to do. We may need information to verify and complete the request.

International processing and security

Providers may process information outside your country of residence. The countries and transfer arrangements depend on the provider and activity. We assess applicable transfer requirements for the relevant processing; contact us for information about an arrangement that affects your data.

Access and security measures depend on the type of information and the systems involved. No internet transmission or storage system can be guaranteed completely secure. Protect your sign-in links, credentials, and devices, and contact us if you believe your access or information has been compromised.

Children's privacy

A parent or legal guardian should supervise children's use of content, device permissions, and purchases. Content suitable for a child does not mean that the device, purchase, or diagnostic information described above is not processed.

If you believe a child's information has been provided inappropriately, contact info@appkeepr.com so the circumstances and any required action can be assessed.

Changes and contact

We may update this Policy as the Service or its data practices change. The version and effective date identify the published revision. We will provide additional notice where required by applicable law.

Send privacy questions and requests to info@appkeepr.com. Tell us which Service you use and what you would like us to do. We may need information to verify and complete the request.

Customer workspace data

Workspace members can read all channels in their workspace and may be eligible for new-message push. Current owner, admin and member roles do not create private-channel or project-specific reading audiences. Message content can include personal information supplied by a customer, such as customer identifiers and feedback names or contact details.

Customers choose what their own systems and connected providers send. For this customer content, Appkeepr processes data to operate the configured workspace service; customers remain responsible for their own notices, permissions and sending instructions. Customer-selected sources such as RevenueCat and Sentry are distinct from the services Appkeepr itself uses to operate the product.

Uptime and domain monitoring store configured endpoint URLs, domain and hostname settings, and the latest observations. The service sends immutable messages for observed state changes; it does not promise a complete probe-history or incident archive.

Messages, receipts and credentials

Published messages and personal read state have no age-based automatic expiry. Receipt metadata has a 30-day retention window; the prepared message draft is cleared when completed, while pending or failed drafts expire after seven days. Monthly message usage is a separate workspace record and is not reset by message or receipt deletion.

API token records contain a hash and display prefix rather than the original token. Reversible webhook secrets are encrypted using the service credential owner. Disabling or removing a connection stops new acceptance; previously accepted work and published messages have separate lifecycles.