Privacy Policy for MyApp Studio

Last updated: August 23, 2026

This Privacy Policy explains how MyApp Studio, a product of Clearbrook Software LLC ("the App," "we," "us," or "our"), collects, uses, stores, and shares information when you use our Android and iOS applications, related backend services, and our marketing website (myappstudio.app).

MyApp Studio is an AI-powered app builder. You describe an app you want by voice or text, and the App generates a working mini-application ("a MyApp") that runs inside MyApp Studio and can optionally be installed as a standalone Progressive Web App (PWA) on your device.

1. Information We Collect

1.1 Account Information

We use Google Sign-In and, on iOS, Sign in with Apple (both via Firebase Authentication) as the only ways to sign in. When you sign in, we receive and store:

We do not have or use any other login method, and we never receive your Google or Apple password.

1.2 Content You Create

To build and edit your MyApps, we collect and store:

Voice input: If you use voice mode, your speech is transcribed into text by your device's built-in speech recognition service (on Android, the system speech recognizer, typically provided by Google; on iOS, Apple's speech recognition service). Depending on your device and its settings, that platform service may process the audio on-device or on the platform provider's (Google's or Apple's) servers, according to your device's own configuration and the platform provider's terms. Your raw voice audio is never sent to our backend; only the resulting text transcript is, and from there it is handled exactly like a typed prompt. To speak the assistant's replies aloud, the reply text is sent through our backend to Google's Gemini text-to-speech model, which generates the audio played back to you. We do not record or retain raw audio recordings; the text transcripts and responses are what gets stored as part of your conversation and app data.

Before the microphone is ever activated, the App shows an in-app "Use Microphone" / "Type instead" prompt — your microphone is never opened automatically, and the operating system's microphone permission dialog is never triggered, without you first explicitly choosing "Use Microphone" in this prompt. This in-app confirmation is requested again every time you switch from typing back to voice mode, not just the first time.

The App requests camera access only so that generated MyApps can offer a "take photo" option for image fields, as described above.

1.2.1 AI-Powered Runtime Lookups ("AI Actions")

Some MyApps include an opt-in feature that looks up data from AI — and, for certain lookups, from web search — while you're using the app: for example, a food log that fills in nutrition facts when you type a food name, or a recipe app that generates timer steps for a dish. This feature exists in a MyApp either because you saw and approved it as part of the build plan when creating or modifying that app — it is never added silently to an app you build — or because it came with a MyApp another user shared with you, in which case the AI data-sharing consent you gave when you first signed in (Section 7) is what covers it. Either way, you can see which lookups a MyApp uses, and every use consumes AI credits from your token balance (Section 1.6).

When you trigger one of these lookups:

Data sitting in a MyApp's regular tables is not sent to Gemini or Google Search by this feature unless you separately re-enter it as that lookup's input.

1.3 Application Data Storage

All MyApps you build, including their schema, custom code, and the data you enter into them (table rows, form submissions, etc.), are stored in:

1.4 End-to-End Encryption of Personal Table Data

When a table inside a MyApp is identified as personal — for example a journal, mood log, or health measurement tracker — the row content of that table is end-to-end encrypted on your device before it ever leaves it:

This classification is made automatically by the AI as it designs your MyApp (based on cues like "journal," "log," or "history" versus static reference content such as recipes or presets), not something you manually tag yourself. It's a best-effort classification: the AI can occasionally misclassify a table (marking personal content as non-personal, or vice versa), so we cannot guarantee that every sensitive table you create will be encrypted, or that every encrypted table actually contains sensitive data. If a table is misclassified, you can ask the AI assistant to fix the classification as a follow-up edit, the same way you'd request any other change to your MyApp.

Tables not classified as personal are not end-to-end encrypted and are visible to our backend and AI models in the ordinary course of generating and editing your MyApp, as described elsewhere in this policy.

1.5 Usage and Activity Logs

We maintain two layers of operational logging, both of which are accessible only to us (no third party) and used to run, debug, and manage the cost of the service:

Because personal table rows are end-to-end encrypted before they reach our backend (Section 1.4), this content is never present in any of these logs. A prompt summary, or an AI lookup's logged request/response, could include personal information only if you directly typed or spoke it into a chat prompt or a lookup's input field (as opposed to entering it into an encrypted personal table).

1.6 App Slot and AI Usage Data

The App includes a free usage-tracking system: every account is granted a starting allotment of app creations ("app slots") and a daily allowance of AI-powered features, and we store and update:

We do not collect or process any payment information. There is currently no real purchasing mechanism. If we introduce real payments in the future, we will update this Privacy Policy first and handle any payment data through a dedicated, PCI-compliant payment processor rather than storing it ourselves.

1.7 Sharing Features

If you choose to share a MyApp, the App creates a share link. We store a copy of the shared MyApp's data alongside that link, together with your email address and the display name from your sign-in provider, until the link expires or you replace it. We do not collect recipients' email addresses when you create a link — a link is delivered by you, over whatever channel you choose, and anyone who opens it while signed in receives their own copy of the MyApp into their account inbox.

What recipients see about you. Anyone who opens your link is shown the MyApp's name and your display name — not your email address. Your email address is stored with the copy they receive because blocking works by email address, but it is not displayed to them. The one exception is MyApps shared before we made this change: no display name was recorded for those, so the App still shows the recipient the sender's email address, as it did when they received it.

Personal tables are always excluded from shares. When you share a MyApp, any table the AI has classified as personal (Section 1.4) is left out of the copy sent to the recipient — they receive the table structure but no rows. This is enforced on our servers regardless of what the sending device asks for, and the share dialog shows those tables as locked rather than offering to include them.

Blocking and flagging. You can block another user (from the Sharing Settings screen, or when declining a shared app); this also immediately removes any apps that user has already shared with you from your library. You can also flag any MyApp in your library — your own or one shared with you — for our review; if the flagged app came from another user, flagging it also blocks that user and removes their other apps from your library, the same as blocking them directly. You're shown this consequence in the app before you confirm either action.

1.8 Notifications

If you grant notification permission, the App can:

1.9 Information We Do Not Collect

We do not use any advertising SDKs, analytics/tracking SDKs (e.g., no Firebase Analytics, no Crashlytics, no ad networks), and we do not collect device identifiers, location data, contacts, or browsing history. We do not sell your data.

1.10 Marketing Website Email Signups

If you provide your email address through the "Get updates" signup on our marketing website, we store that address, the fact that it came from the website signup, and your browser's user-agent string, so we can let you know when MyApp Studio is available. We also briefly retain the submitting IP address (for up to one hour) to prevent automated abuse of the signup form. This list is entirely separate from the Account Information described in Section 1.1 — providing your email here does not create an App account, and signing in to the App does not add you to this list.

2. How We Use Your Information

We use the information described above to:

3. How We Share Your Information

We do not sell, rent, or trade your personal information. We share information only as follows. Every service provider listed below is contractually bound to provide the same or equal protection of your information as stated in this Privacy Policy, and we do not share personal data with a provider that has not made that commitment. In particular, we use the paid tier of Google's Gemini API: under Google's terms for paid services, Google does not use your prompts or responses to improve or train its products, processes them in accordance with Google's Data Processing Addendum for Products Where Google is a Data Processor, and logs them only for a limited period, solely to detect abuse and to meet legal or regulatory obligations. (Lookups that use Google Search carry an additional 30-day retention — see the Google Search entry below.)

We do not have any other third-party advertising, analytics, or data-broker integrations.

4. Data Retention and Deletion

5. Data Security

We rely on Firebase's security infrastructure and on-device cryptography, including:

No method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security. Note that end-to-end encryption protects personal table *content* — table/column names and the fact that a personal table exists are not encrypted.

6. Children's Privacy

MyApp Studio is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us so we can delete it.

7. Your Choices and Rights

8. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above. Continued use of the App after changes take effect constitutes acceptance of the revised policy.

9. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:

Email: support@myappstudio.app