Privacy Policy

Last updated: September 9, 2026

appwin is a platform published by Les Ignobles that helps mobile app studios operate their apps: analytics, support, community, notifications, revenue, acquisition. This policy explains what personal data we process, why, on what legal basis, for how long, and what your rights are. We wrote it to be read - not scrolled past.

Who is responsible?

The data controller for the data described in this policy is Les Ignobles, the company publishing appwin, established in France. For any question about your personal data, write to contact@appwin.io - the single point of contact, including to exercise your rights.

Our services are hosted in the European Union and we apply the General Data Protection Regulation (GDPR) and the French Data Protection Act.

Two roles: who this policy applies to

Data controller: for visitors of this website and for people who create an appwin account (studio teams), we determine the purposes and means of processing. This policy fully applies.

Data processor: studios use appwin to operate their own applications, and data about the end users of those applications flows through our services (usage events, support messages, community content). For that data, the controller is the studio publishing the application; appwin acts exclusively on its instructions, under a data processing agreement. If you use an application that embeds appwin, the applicable privacy policy is that application's - and we forward any request received directly to the studio.

Studio account data

When creating and using an account: email address, name, password (hashed, never stored in clear text), avatar if provided, organization and role within the team.

For billing: company name, address, payment data processed by our payment provider - we never store card numbers. Credentials and keys for the services a studio connects (ad accounts, stores, revenue tools) are stored encrypted and used solely for the features the studio enabled.

Automatically: technical logs (IP address, timestamps, pages visited, errors) required for security and proper operation, and website audience measurement - see our cookie policy for that part.

End-user data from client apps (SDK)

The appwin SDK collects on the studio's behalf: a pseudonymous device identifier generated by the SDK (never a hardware identifier), usage events (launches, screens, actions defined by the studio), device information (model, OS version, app version), and content users submit voluntarily (support messages, community posts).

The analytics event stream is designed without directly identifying data: no email, no phone number, no advertising identifier inside events. The advertising identifier (IDFA on iOS, GAID on Android) is only collected if the studio enabled advertising features AND the user consented - on iOS this additionally requires App Tracking Transparency authorization. It travels through a separate channel and is deleted as soon as consent is withdrawn.

When a studio enables conversion sharing with advertising platforms (Meta, TikTok), only events from consenting users are transmitted, on the studio's instruction. Withdrawing consent stops these transfers.

Purposes and legal bases

Every processing activity has a defined purpose and a legal basis, summarized below for the data we control.

PurposeDataLegal basis
Create and manage your accountIdentity, email, password, organizationPerformance of the contract (art. 6.1.b)
Provide and improve the serviceAccount content and settings, technical logsPerformance of the contract; legitimate interest for improvement (art. 6.1.f)
Billing and accountingCompany name, address, billing recordsPerformance of the contract and legal obligation (art. 6.1.c)
Keep you informed about the serviceEmail, preferencesLegitimate interest; consent for marketing (art. 6.1.a)
Secure the platform and prevent abuseTechnical logs, IP addressLegitimate interest (art. 6.1.f)

Hosting and processors

Our services and databases are hosted in the European Union (Scaleway, France). Our main processors: Scaleway (hosting, France), OVHcloud (domains and DNS, France), Stripe (payments, with its own compliance guarantees). Each is bound by a data processing agreement compliant with GDPR article 28.

The platforms a studio chooses to send conversions to (Meta, TikTok) are not our processors: they are recipients, processing that data under their own policies, only on the studio's instruction and for its consenting users.

Retention periods

Studio account: for the lifetime of the account, then deletion within 30 days of closure (subject to legal retention duties, notably accounting records: 10 years for billing documents). Technical logs: 12 months at most.

Data processed on behalf of studios: kept as long as the studio uses it in the service, deleted on its instruction or when its contract ends. Analytics events are pseudonymous from collection.

Your rights

You have the rights of access, rectification, erasure, restriction, portability and objection over your data, as well as the right to set post-mortem directives. To exercise them: contact@appwin.io. We answer within one month.

If you are an end user of a client application, exercise your rights with the studio publishing the application first (the data controller) - it is the fastest path. Any request reaching us directly is forwarded to the studio without delay, and we carry out its instructions.

You may also lodge a complaint with the CNIL (cnil.fr), the French supervisory authority.

Deleting your data

Studio account: from your organization's settings (account deletion), or by email to contact@appwin.io. Deletion is effective within 30 days, backups included within 90 days.

End user of a client application: request deletion from the studio publishing the application, which has the necessary tools in appwin. You can also write to contact@appwin.io naming the application: we forward to the studio and confirm execution.

If you arrived here from a third-party platform (for instance after connecting a service to appwin): disconnecting the service in appwin stops the related collection, and the email above obtains deletion of data already collected.

Security

Encryption in transit (TLS) on all exchanges, encryption at rest for secrets and access keys, strict per-organization data isolation down to the database layer, role-based access control, and logging of sensitive operations.

In the event of a data breach likely to result in a risk to your rights and freedoms, we notify the CNIL within 72 hours and the affected individuals without undue delay, in accordance with GDPR articles 33 and 34.

Transfers outside the European Union

Our hosting providers and databases are located in the European Union, and we do not transfer your data outside it by default.

Some recipients enabled by studios (advertising platforms, providers they connect) may process data outside the EU; such transfers then rely on those recipients' own compliance mechanisms (standard contractual clauses, adequacy decisions) and only happen on the studio's instruction, for consenting users.

Changes to this policy

This policy evolves with the service. Any substantial change is announced to account holders (email or in-product notice) before it takes effect, and the date at the top of this page is authoritative.

Contact us

For any question about this policy or your data: contact@appwin.io. Les Ignobles, France.