Privacy Policy
Last updated: September 9, 2026
appwin is a platform published by Les Ignobles that helps mobile app studios operate their apps: analytics, support, community, notifications, revenue, acquisition. This policy explains what personal data we process, why, on what legal basis, for how long, and what your rights are. We wrote it to be read - not scrolled past.
Who is responsible?
The data controller for the data described in this policy is Les Ignobles, the company publishing appwin, established in France. For any question about your personal data, write to contact@appwin.io - the single point of contact, including to exercise your rights.
Our services are hosted in the European Union and we apply the General Data Protection Regulation (GDPR) and the French Data Protection Act.
Two roles: who this policy applies to
Data controller: for visitors of this website and for people who create an appwin account (studio teams), we determine the purposes and means of processing. This policy fully applies.
Data processor: studios use appwin to operate their own applications, and data about the end users of those applications flows through our services (usage events, support messages, community content). For that data, the controller is the studio publishing the application; appwin acts exclusively on its instructions, under a data processing agreement. If you use an application that embeds appwin, the applicable privacy policy is that application's - and we forward any request received directly to the studio.
Studio account data
When creating and using an account: email address, name, password (hashed, never stored in clear text), avatar if provided, organization and role within the team.
For billing: company name, address, payment data processed by our payment provider - we never store card numbers. Credentials and keys for the services a studio connects (ad accounts, stores, revenue tools) are stored encrypted and used solely for the features the studio enabled.
Automatically: technical logs (IP address, timestamps, pages visited, errors) required for security and proper operation, and website audience measurement - see our cookie policy for that part.
End-user data from client apps (SDK)
The appwin SDK collects on the studio's behalf: a pseudonymous device identifier generated by the SDK (never a hardware identifier), usage events (launches, screens, actions defined by the studio), device information (model, OS version, app version), and content users submit voluntarily (support messages, community posts).
The analytics event stream is designed without directly identifying data: no email, no phone number, no advertising identifier inside events. The advertising identifier (IDFA on iOS, GAID on Android) is only collected if the studio enabled advertising features AND the user consented - on iOS this additionally requires App Tracking Transparency authorization. It travels through a separate channel and is deleted as soon as consent is withdrawn.
When a studio enables conversion sharing with advertising platforms (Meta, TikTok), only events from consenting users are transmitted, on the studio's instruction. Withdrawing consent stops these transfers.
Purposes and legal bases
Every processing activity has a defined purpose and a legal basis, summarized below for the data we control.
| Purpose | Data | Legal basis |
|---|---|---|
| Create and manage your account | Identity, email, password, organization | Performance of the contract (art. 6.1.b) |
| Provide and improve the service | Account content and settings, technical logs | Performance of the contract; legitimate interest for improvement (art. 6.1.f) |
| Billing and accounting | Company name, address, billing records | Performance of the contract and legal obligation (art. 6.1.c) |
| Keep you informed about the service | Email, preferences | Legitimate interest; consent for marketing (art. 6.1.a) |
| Secure the platform and prevent abuse | Technical logs, IP address | Legitimate interest (art. 6.1.f) |
Hosting and processors
Our services and databases are hosted in the European Union (Scaleway, France). Our main processors: Scaleway (hosting, France), OVHcloud (domains and DNS, France), Stripe (payments, with its own compliance guarantees). Each is bound by a data processing agreement compliant with GDPR article 28.
The platforms a studio chooses to send conversions to (Meta, TikTok) are not our processors: they are recipients, processing that data under their own policies, only on the studio's instruction and for its consenting users.
Retention periods
Studio account: for the lifetime of the account, then deletion within 30 days of closure (subject to legal retention duties, notably accounting records: 10 years for billing documents). Technical logs: 12 months at most.
Data processed on behalf of studios: kept as long as the studio uses it in the service, deleted on its instruction or when its contract ends. Analytics events are pseudonymous from collection.
Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection over your data, as well as the right to set post-mortem directives. To exercise them: contact@appwin.io. We answer within one month.
If you are an end user of a client application, exercise your rights with the studio publishing the application first (the data controller) - it is the fastest path. Any request reaching us directly is forwarded to the studio without delay, and we carry out its instructions.
You may also lodge a complaint with the CNIL (cnil.fr), the French supervisory authority.
Deleting your data
Studio account: from your organization's settings (account deletion), or by email to contact@appwin.io. Deletion is effective within 30 days, backups included within 90 days.
End user of a client application: request deletion from the studio publishing the application, which has the necessary tools in appwin. You can also write to contact@appwin.io naming the application: we forward to the studio and confirm execution.
If you arrived here from a third-party platform (for instance after connecting a service to appwin): disconnecting the service in appwin stops the related collection, and the email above obtains deletion of data already collected.
Security
Encryption in transit (TLS) on all exchanges, encryption at rest for secrets and access keys, strict per-organization data isolation down to the database layer, role-based access control, and logging of sensitive operations.
In the event of a data breach likely to result in a risk to your rights and freedoms, we notify the CNIL within 72 hours and the affected individuals without undue delay, in accordance with GDPR articles 33 and 34.
Transfers outside the European Union
Our hosting providers and databases are located in the European Union, and we do not transfer your data outside it by default.
Some recipients enabled by studios (advertising platforms, providers they connect) may process data outside the EU; such transfers then rely on those recipients' own compliance mechanisms (standard contractual clauses, adequacy decisions) and only happen on the studio's instruction, for consenting users.
Changes to this policy
This policy evolves with the service. Any substantial change is announced to account holders (email or in-product notice) before it takes effect, and the date at the top of this page is authoritative.
Contact us
For any question about this policy or your data: contact@appwin.io. Les Ignobles, France.