This page is a placeholder and must be reviewed by a qualified legal professional before App Buddy launches publicly. Bracketed notes mark items to confirm.
Who we are
App Buddy (“we”, “us”) provides simple online tools. You can contact us through the feedback page. [Add legal entity name, address, and a privacy contact email.]
Information we collect
Account information: your email address, an optional display name, and authentication records managed by our authentication provider. If you sign in with Google, our authentication provider also stores your Google account ID, name, and profile picture link.
Guest use: if you use a tool without an account, our authentication provider creates a temporary guest account with no email address or name, so your allowance works. Guest accounts that go unused for 30 days are deleted. Guest analyses are also counted per network, using a one-way hash of your IP address.
Billing information: payments are processed by Stripe. We store only Stripe customer and subscription identifiers, plan, and subscription status — never your card details.
Usage records: analysis counts, comment counts, timestamps, the YouTube video ID you analyzed, and AI processing usage, so we can enforce plan limits.
Feedback: the message, category, and optional contact email you submit.
Security data: IP addresses are converted to one-way pseudonymous hashes for rate limiting; raw IP addresses are not stored by App Buddy.
YouTube API Services
Question Finder for YouTube uses YouTube API Services to retrieve publicly available comments for the video you choose. Comments are processed temporarily to identify questions and are displayed only in your browser. We do not store comment text or comment author names. Question Finder does not access your YouTube account. Signing in with Google shares only your basic profile (name, email address, and profile picture) with App Buddy.
To classify comments, comment text (without author names) is sent to the Google Gemini API. Results are labeled as App Buddy AI output and may be inaccurate. [Confirm before launch: the Gemini API project uses paid-tier terms, under which Google does not use submitted content to improve its products.]
Service providers
Supabase — authentication and database
Stripe — payments and subscription management
Resend — transactional email
Google — YouTube Data API and Gemini API
Vercel — hosting
Retention
YouTube comment text and author information: never stored
Analysis metadata: 30 days
Usage and cost records: 13 months
Feedback: 12 months
Payment webhook and email delivery records: 90 days
Cookies
We use only essential cookies required to keep you signed in. We do not use advertising or cross-site tracking cookies.
Your choices and rights
You can delete your account at any time from Account settings. Deleting your account cancels any active subscription and deletes or anonymizes your stored data according to the retention schedule above. Minimal pseudonymous records may be kept to prevent free-trial abuse. [Add jurisdiction-specific rights, e.g. GDPR/CCPA.]
Changes
We will update this page when our practices change and revise the date above.