Appy

Security and privacy, in plain words

What protects your links, your account and your app users’ data at Appy, and how long that data stays. Everything here describes how the service runs today.

  • HTTPS on every request

    Plain HTTP is redirected to HTTPS, and browsers are told to stay on HTTPS.

  • Data off the internet

    Where your data is stored cannot be reached from the internet. Only Appy’s own services connect to it.

  • Keys you see once

    API secret keys are shown once and stored only as a hash. Revoke them at any time.

  • No advertising IDs

    The Appy SDK reads no IDFA or GAID and never stores an IP address to match installs.

How data moves

From a tap to a stored click

Every request takes the same path. Traffic is encrypted on its way to Appy, and the places where data is stored cannot be reached from the internet.

Encrypted in transitPrivate network

Phone or browser

Someone taps a link, scans a QR code or opens the dashboard.

Protected edge network

The first stop for appy.to, the API and app link domains.

Encrypted gateway

Accepts encrypted connections and redirects any plain HTTP to HTTPS.

Private network

Appy services

Redirects, links, QR codes, statistics, the API and the SDK backend.

Private storage

Accounts, links and statistics, unreachable from the internet.

Payments take a separate path

Checkout and invoices run on Lemon Squeezy, the Merchant of Record. Card details are entered on their page, never on Appy.

Infrastructure

Encrypted in transit, closed by default

Every connection to Appy is encrypted, and the places where your data lives are kept off the public internet.

  • Encrypted connections everywhere

    Every Appy address uses HTTPS. Plain HTTP is permanently redirected, and browsers are told to stay on HTTPS.

  • Protected edge network

    appy.to, the API and every app link domain pass through a protected edge network before they reach Appy’s servers.

  • Data stored on a private network

    Accounts, links and statistics sit on a private network that is not reachable from the internet. Only Appy’s own services connect to it.

  • Strict browser protections

    The website asks browsers to apply strict security rules and refuses to be embedded in other sites.

  • Abuse protection on links and sign-in

    Redirects and sign-in are protected against abuse, and new free links are checked too.

Access control

Who can do what, and with which key

Your account, your API keys and Appy’s own staff each work within clear limits.

  • Passwords stored only in hashed form

    Appy never stores your password itself. You can also sign in with Google.

  • Protected sign-in sessions

    Page scripts cannot read sign-in cookies, and they travel only over encrypted connections.

  • Secret keys shown once

    Appy keeps only a hashed form of each API key. Keys are created from a signed-in session and revoked in one click.

  • App keys do one job

    The key inside your app can only open links and send events. It cannot read or change links or statistics.

  • Limits on every key

    Each API key, session and app has its own request limits, and your plan is checked on every request.

  • Read-only, time-limited support access

    When support looks into an account, the view cannot change anything, is time-limited and is logged.

  • A link domain of your own

    Each app gets its own link domain that serves only your account’s links, so no other app can claim them.

  • AI assistants ask first

    The MCP server uses the same secret keys, and assistants that follow MCP hints ask before changing a link.

Data and retention

What we keep, and for how long

Short-lived data expires on its own. The rest stays until you delete it or your account is deleted.

How far back your reports go depends on your plan. After an account is deleted, the privacy policy allows keeping some records where law, fraud prevention or security require it.

  1. Network key for install matching

    A keyed hash of the network that changes daily. Never the IP address.

    Kept

    2 hours
  2. Click record for deferred deep links

    Link, parameters, platform, OS version and device model. No IP address.

    Kept

    24 hours
  3. Installs and in-app events

    Sent by your app through the SDK, or by your own server.

    Kept

    Until you delete them
  4. Account, links, QR codes and statistics

    Your profile, everything you create and the click statistics behind your reports.

    Kept

    Until the account is deleted
  5. Card details

    Entered on Lemon Squeezy’s checkout. Appy keeps only your plan and subscription status.

    Kept

    Never stored by Appy

Your users’ privacy

An SDK that stays out of advertising

For data your app sends through the Appy SDK, you decide what happens, and Appy processes it on your behalf.

What the SDK sends, in the developer docs
  • No advertising identifiers

    The SDK never reads the IDFA or GAID, shows no tracking prompt and sends nothing to ad networks.

  • No stored IP addresses

    Install matching uses a keyed hash of the network that changes every day and is deleted after two hours.

  • One switch for consent

    With tracking off, the SDK sends no events, skips install matching, and Appy stores nothing for that device.

  • Verified installs only, if you prefer

    Strict attribution counts only installs Appy can confirm from the link itself. Everything else is organic.

  • Privacy manifest included

    The iOS SDK ships Apple’s privacy manifest. Your store privacy details remain yours to fill in.

  • Delete a user in one call

    Your server can permanently erase every install and event tied to one of your user IDs.

Deletion and GDPR

Requests from you, and from your users

Appy supports the rights set out in the GDPR and Turkey’s KVKK, as described in the privacy policy. Appy does not sell personal data.

  • Your Appy account

    Ask for a copy of your data, a correction, or deletion of your account. We may verify your identity first and answer within 30 days.

  • Your app’s users

    For SDK data, you are the controller and Appy processes it for you. Your users’ requests come to you, and you act on them.

Erasing one of your users

  1. 1

    Set a user ID

    Pass your internal user ID to the SDK after sign-in, so Appy can find what belongs to that person.

  2. 2

    Delete from your server

    One API call erases that user’s installs and in-app events.

  3. 3

    Gone for good

    The deletion is permanent and runs in one transaction, so nothing is left half deleted.

Read the privacy policy

Backups and monitoring

Regular backups, continuous monitoring

If something breaks, we want to notice it first and be able to restore what was there.

  • Regular backups

    Appy’s data is backed up regularly, so it can be restored if something goes wrong.

  • Continuous monitoring

    Every service is watched for errors and slowdowns, so problems are noticed early.

  • Automatic recovery

    If a service stops, it starts again on its own.

Responsible disclosure

Found a vulnerability? Tell us first

If you believe you have found a security issue in Appy, email us before sharing it anywhere else. The same address is listed in our security.txt file.

Write to

[email protected]

We read reports in English and Turkish.

Helpful to include

  • The page, app version or request involved
  • Steps to reproduce it, and what you expected instead
  • How we can reach you for questions

Please

  • Test only with your own account and data
  • Avoid anything that slows the service down for others
  • Give us reasonable time to fix it before you disclose it

Security questions

Does Appy sell my data or share it for advertising?

No. Appy does not sell personal data and does not share account data with third parties for advertising or resale.

Is traffic to Appy encrypted?

Yes. Every Appy address uses HTTPS, plain HTTP is redirected to HTTPS, and browsers are told to stay on HTTPS.

Does the Appy SDK use advertising IDs or need the tracking prompt?

No. The SDK does not read the IDFA or GAID and shows no App Tracking Transparency prompt. Your app’s store privacy details are still yours to complete.

Does Appy store my users’ IP addresses to match installs?

No. Install matching uses a keyed hash of the network that changes daily and is deleted after two hours. Regular click statistics are separate and described in the privacy policy.

How do I handle a GDPR erasure request from one of my app users?

Delete that user’s installs and events with one API call from your server, using the user ID you set in the SDK. To delete your own Appy account, email us.

Who processes payments?

Lemon Squeezy, as Merchant of Record. You enter card details on their checkout, and Appy never stores them.

Can Appy staff see my account?

Support can open a read-only view of an account. It cannot change anything, is time-limited and is logged with the staff member’s ID.

Ready when you are

Create a free account, or read the full privacy policy first.