Appstack Studio

Your privacy matters. Protect yourself with a secure VPN.
Sponsored

# Privacy Policy

**Effective date: 17 July 2026**  
**Last updated: 17 July 2026**

This Privacy Policy explains how AppStack Studio AB processes personal data when you use our mobile applications, websites, support channels, and related services (together, the **“Services”**).

Not every AppStack Studio app uses every feature or service described below. A particular category of data is processed only when it is relevant to the app or feature you use. Where appropriate, we provide additional information in the app, on its app-store page, or at the point where data is collected. If an app-specific notice conflicts with this Policy, the app-specific notice applies to that app and processing activity.

## 1. Who we are

AppStack Studio AB is the data controller for the processing described in this Policy, unless we state otherwise.

**AppStack Studio AB**  
Organisation number: 559535-4902  
Mariehällsvägen 30B  
168 65 Bromma  
Sweden  
Email: [info@appstackstudio.com](mailto:info@appstackstudio.com)  
Website: [https://appstackstudio.com](https://appstackstudio.com)

We have not appointed a data protection officer because we are not currently required to do so. Privacy questions and requests can be sent to the email address above.

## 2. Data we process

Depending on the Service and how you use it, we may process:

- **Information you provide**, such as your email address, name, support message, feedback, and any attachments you choose to send to us.
- **App content and feature data**, such as information, documents, images, text, recipient details, or other content you choose to enter, import, create, or transmit through a feature. Some apps keep this content only on your device; a feature that sends, synchronises, or processes content online must transmit the data needed to perform that feature.
- **Purchase and subscription data**, such as product purchased, subscription status, purchase dates, expiry date, transaction or receipt information, and an app-user identifier. Apple or another app-store operator processes your payment details. We do not receive your full card or bank details.
- **Technical and diagnostic data**, such as app version, device model, operating-system version, language, approximate region, IP address, timestamps, crash traces, performance information, and diagnostic logs.
- **Usage data**, such as app-instance or installation identifiers, screens or features used, session information, and interactions with the Service. We collect this only in Services where analytics is enabled and, where required, after obtaining consent.
- **Website data**, such as requested page, referrer, browser or user-agent information, approximate country, language or locale, session identifier, and performance measurements.
- **Device-permission data**, such as photos, camera scans, files, contacts, or notifications, when you choose to grant the relevant permission. Access is limited to the purpose shown in the permission prompt and the feature you request.

We ask you not to send us special-category data—such as health, biometric, political, religious, or trade-union information—unless a Service expressly supports that information and explains how it will be handled. Content you choose to transmit may nevertheless contain sensitive information. You are responsible for having the right to provide personal data about other people.

## 3. Why we process data and our legal bases

Under the GDPR, we rely on the following legal bases:

| Purpose | Typical data | Legal basis |
|---|---|---|
| Provide requested app features and deliver the Service | App content, feature data, technical identifiers, device permissions | Performance of a contract or steps taken at your request |
| Process purchases, verify entitlements, restore purchases, and prevent subscription abuse | Purchase and subscription data, app-user identifier, technical data | Performance of a contract; legitimate interests in preventing fraud and protecting the Service |
| Respond to support requests and communicate with you | Contact details, messages, attachments, relevant diagnostics | Performance of a contract or legitimate interests in providing support |
| Maintain security, diagnose faults, and prevent misuse | IP address, logs, crash and diagnostic data, identifiers | Legitimate interests in operating a secure and reliable Service |
| Measure and improve apps and websites | Usage, session, device, and performance data | Consent where required; otherwise legitimate interests where permitted by law |
| Send marketing communications | Email address and communication preferences | Consent, or legitimate interests where applicable law permits existing-customer marketing |
| Keep accounting records and respond to lawful requests | Transaction and business records, communications | Compliance with legal obligations |
| Establish, exercise, or defend legal claims | Relevant account, transaction, technical, and communication data | Legitimate interests in protecting our legal rights |

Where we rely on legitimate interests, we consider whether our interests are necessary and proportionate and balance them against your rights and expectations. Where processing is based on consent, you may withdraw consent at any time without affecting processing already carried out.

We do not use personal data for solely automated decisions that produce legal or similarly significant effects on you.

## 4. Local data and device permissions

Some apps are designed to store drafts, files, preferences, or history locally on your device. Local data remains under your device's security controls unless you choose a feature that transmits it, enable an operating-system backup or synchronisation service, or share it with another service. Deleting an app may delete its local data, subject to your device and backup settings.

You can manage app permissions in your device settings. Refusing or withdrawing a permission may prevent the related feature from working but should not affect unrelated features.

## 5. Service providers and other recipients

We do not sell personal data. We share data only as needed for the purposes in this Policy, including with processors acting on our instructions and with independent controllers where necessary.

Depending on the Service, recipients may include:

- **Apple** for App Store distribution, in-app purchases, subscriptions, StoreKit, and related platform services. Apple independently processes data under its own terms and privacy policy.
- **RevenueCat, Inc.** for purchase and subscription management. RevenueCat may process an anonymous or app-specific user identifier, device and operating-system information, product and entitlement information, transaction dates, store receipt or purchase-token information, and optional attributes we configure. We do not intentionally send RevenueCat documents or other user-created app content. See [RevenueCat's privacy information](https://www.revenuecat.com/privacy/) and [data processing addendum](https://www.revenuecat.com/dpa/).
- **Google Firebase / Google Cloud** in apps that use Firebase. The data depends on the enabled products. For example, Firebase Analytics may process app-instance identifiers and usage events; Crashlytics may process crash traces, installation identifiers, device and app information; Authentication may process login identifiers; and database, storage, functions, messaging, configuration, performance, or security products may process the data required for those features. Google generally acts as our processor for customer data, while some service data is processed by Google for its own purposes. See [Firebase privacy and security information](https://firebase.google.com/support/privacy/) and [Firebase data processing terms](https://firebase.google.com/terms/data-processing-terms/).
- **Website hosting, delivery, and operational analytics providers** for hosting the website, protecting it, measuring page use and performance, and delivering content. Our website currently creates a short-lived session identifier and records page, referrer, browser/user-agent, locale, approximate country, and performance information. We use non-essential storage or analytics only where permitted by law and, where required, after consent.
- **Feature-specific infrastructure and service providers** where an online feature cannot be provided without them—for example cloud hosting, communications, document processing, or delivery providers. The relevant app or feature will identify material providers or processing that goes beyond the general descriptions in this Policy.
- **Professional advisers, authorities, courts, or transaction counterparties** where reasonably necessary to comply with law, protect rights and security, obtain professional advice, or complete a merger, financing, reorganisation, or sale. Any recipient must handle the data lawfully.

Third-party websites and services you choose to access are governed by their own privacy notices.

## 6. Analytics, identifiers, and consent

Where an app uses optional analytics, advertising, or similar tracking, we request consent when required and provide available controls in the app or device settings. Withdrawing consent stops future optional collection but does not invalidate earlier lawful processing.

Our Services do not use personal data for targeted advertising unless an app-specific notice and consent flow expressly say so. We do not combine user-created documents or private app content with advertising profiles.

The website may use session storage, cookies, or similar identifiers. Strictly necessary technologies support security and operation. Analytics or other non-essential technologies are used only where permitted by law and, where required, after consent. Browser settings can delete or block these technologies, although some site functions may be affected.

## 7. International transfers

We are established in Sweden, but some providers process data in countries outside the European Economic Area, including the United States. Where the destination is not covered by an adequacy decision, we use an approved transfer mechanism where required, such as the European Commission's Standard Contractual Clauses, together with supplementary measures when appropriate. A provider may also rely on an applicable adequacy framework, such as the EU–U.S. Data Privacy Framework, where valid and relevant to the transfer.

You may contact us for more information about the safeguards relevant to your data.

## 8. How long we keep data

We keep personal data only for as long as needed for the stated purpose, taking account of legal, accounting, security, dispute-resolution, and technical requirements.

Typical retention periods are:

- **Support correspondence:** normally up to 24 months after the request is resolved, unless longer retention is needed for an ongoing issue or legal claim.
- **User-level analytics data:** no longer than 14 months where we control the setting; aggregated statistics that no longer identify an individual may be kept longer.
- **Crash and diagnostic data:** normally up to 12 months, unless a shorter provider setting applies or specific logs are needed to investigate an ongoing security or reliability issue.
- **Purchase and entitlement records:** for as long as needed to provide and restore the purchase, meet accounting or consumer-law obligations, prevent fraud, and resolve disputes. App-store operators and RevenueCat may apply their own retention duties and schedules.
- **App content held by us:** for the time needed to provide the requested feature, followed by deletion or de-identification according to that feature's operational schedule. Content stored only on your device remains until you delete it, delete the app, or your device or backup service removes it.
- **Security and operational logs:** normally up to 12 months, unless needed longer to investigate abuse, a security incident, or a legal claim.
- **Consent records and legal claims:** for as long as needed to demonstrate compliance or until the relevant limitation period expires.

Backups may retain residual copies for a limited period before scheduled deletion. We may keep irreversible aggregated or anonymised information because it is no longer personal data.

## 9. Your rights

Subject to the conditions and exceptions in applicable law, you may have the right to:

- receive information about our processing and access your personal data;
- correct inaccurate or incomplete data;
- request deletion of your data;
- restrict processing;
- object to processing based on legitimate interests or to direct marketing;
- receive data you provided in a structured, commonly used, machine-readable format and transmit it to another controller;
- withdraw consent at any time

To exercise a right, email [info@appstackstudio.com](mailto:info@appstackstudio.com). Please identify the app or Service, describe your request, and provide any anonymous app-user or purchase identifier shown in the app's settings or support screen. We may request proportionate information to verify your identity. We normally respond within one month, as required by the GDPR.

Deleting data held by us does not automatically cancel an App Store subscription. You can manage or cancel subscriptions through your Apple account settings. Some records may be retained where required by law or where a GDPR exception applies.

## 10. Security

We use reasonable technical and organisational measures designed to protect personal data, such as access controls, encrypted transport, service-provider review, data minimisation, and limiting access to people and systems that need it. No system is completely secure, so we cannot guarantee absolute security.

If you believe personal data has been exposed or an account or device connected to a Service has been compromised, contact us promptly at [info@appstackstudio.com](mailto:info@appstackstudio.com).

## 11. Children

Our general-audience Services are not directed to children under 13, and we do not knowingly collect personal data from a child under 13 without any consent required by law. An app intended for children will provide an app-specific notice and age-appropriate protections. If you believe a child has provided personal data contrary to this section, contact us so we can investigate and delete it where appropriate.

## 12. Changes to this Policy

We may update this Policy when our Services, providers, or legal obligations change. We will publish the revised version with a new “Last updated” date. If a change materially affects how we process data, we will provide additional notice where appropriate and request new consent where required.

## 13. App terms

This Privacy Policy describes data processing and is separate from the licence terms governing an app. Unless an app presents a custom licence, apps distributed through Apple's App Store are governed by [Apple's Standard Licensed Application End User License Agreement](https://www.apple.com/legal/internet-services/itunes/dev/stdeula/).

## 14. Contact

For privacy questions, requests, or complaints:

**AppStack Studio AB**  
Organisation number: 559535-4902  
Mariehällsvägen 30B  
168 65 Bromma, Sweden  
[info@appstackstudio.com](mailto:info@appstackstudio.com)