Legal
Privacy Policy
Last updated: August 11, 2026
Data categories at a glance
Account, email, and support metadata
Account email and verification state, authentication-session metadata, email subscription records, support requests, and communication preferences.
Workspace inputs and output
Submitted store URLs, app identifiers, competitor URLs, search terms, campaign intent, ranking evidence, public-ad comparisons, and generated CPP direction candidates.
Technical and optional usage data
Request logs, security signals, job status, error traces, and consented analytics events.
How AppTide handles data
AppTide collects only the information needed to operate the keyword-ranking and CPP-research workspaces, authenticate free accounts, measure optional product usage, respond to support, and prevent abuse.
We do not sell visitor data. Submitted public-tool inputs and export records are not exposed to other visitors or used to train unrelated external foundation models.
Data you provide
Data you provide may include an account email address, authentication credentials handled by Supabase, support messages, app-store URLs, app identifiers, competitor app URLs, campaign intent text, and keywords you ask AppTide to inspect.
The current release provides free accounts for CPP research. It does not sell a paid workspace or collect payment-card details. This policy will be updated before any paid workflow is opened.
Essential cookies and browser storage
Essential cookies support account sessions, security, and daily limits. Browser localStorage saves your keyword Focus List, previous ranking snapshot, and privacy choice; sessionStorage may temporarily retain CPP inputs while you complete sign in.
When you arrive through a valid referral link and have allowed analytics, AppTide may store the referral code in a first-party cookie for up to 30 days. Rejecting optional analytics removes that referral cookie.
Optional analytics
If you allow optional analytics, AppTide may load Google Analytics and Vercel Analytics. These services can receive page URLs, referrer information, browser and device details, approximate location derived from IP address, event names, timestamps, and identifiers used to measure visits and feature usage.
Google Analytics is configured with IP anonymization. AppTide does not intentionally send email addresses, account IDs, app payloads, or other direct personal identifiers in analytics page paths or event properties.
Advertising and Google AdSense
If AppTide enables Google AdSense, Google and participating third-party vendors may use cookies, web beacons, IP addresses, advertising identifiers, and similar technologies to serve, limit, personalize, measure, and report advertising.
Google may use advertising cookies to show ads based on visits to AppTide and other websites. Depending on your region and consent choice, ads may be personalized or non-personalized. AppTide will use a Google-certified consent management platform for applicable EEA, UK, and Swiss advertising choices before personalized ads are served.
Model-assisted CPP analysis
When model-assisted CPP analysis is configured, AppTide sends a bounded set of public Apple Ad Repository metadata and public creative image URLs to OpenAI to create structured creative observations and experiment briefs. The request uses store=false. AppTide does not send account email addresses or authentication credentials in the model request.
If model analysis is not configured or fails, AppTide returns a clearly labeled rules-based fallback. Public competitor assets remain owned by their respective rights holders and are processed only for the requested contextual analysis.
Service providers and sharing
Data is shared only with service providers needed to run AppTide, such as Vercel for hosting and delivery, Supabase for account authentication and database services, OpenAI for configured model-assisted CPP analysis, email delivery providers, security services, analytics when allowed, and advertising when enabled.
Providers process data under their own terms and privacy notices. We may also disclose information when required by law or necessary to protect users, the service, or legal rights.
Retention and security
Account records are retained while your account remains active or as needed for security and legal obligations. Export subscription records and support messages are retained while needed to provide the requested communication or meet legal obligations. Technical logs and rate-limit records are retained only as long as reasonably needed for security, reliability, and abuse prevention.
No internet service can guarantee absolute security. AppTide uses access controls, secure transport, and limited data collection to reduce risk.
Your choices
You can reject or allow optional analytics and reopen the privacy settings at any time. Advertising choices are managed separately through the Google-certified advertising privacy controls when AdSense is enabled.
You can also manage Google ad personalization through Google Ads Settings and may use industry opt-out tools where available. Browser controls can delete cookies and local storage, but doing so may sign you out or reset ranking history, Focus List selections, or pending CPP inputs.
What we do not do
- Sell customer data to advertisers or data brokers
- Expose submitted audit data or keyword inputs to other visitors
- Train unrelated external AI products on submitted public-tool inputs
- Store full payment-card details on AppTide infrastructure
Data requests
To request access, correction, export, or deletion of your account, email subscription, or support data, email hello@apptide.xyz. We will respond within a commercially reasonable timeframe.
Email hello@apptide.xyz