Privacy Policy
Last Updated: February 16, 2026
Thank you for using our platform ("Platform"), which allows users to create, share, and discover apps. Your privacy is important to us. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Platform.
By accessing or using the Platform, you agree to this Privacy Policy and our Terms of Service.
1. Who We Are
Boosterbot AI, LLC ("we," "us," or "our") operates the Anything App platform ("Platform"). Our service enables you to create, publish, share, buy, and sell web applications. If you have any questions or concerns about this Privacy Policy or about how we handle your personal data, please contact us using the information provided in Section 17.
2. Information We Collect
2.1 Personal Information You Provide
- Account Information: When you sign up for an account, we collect your name, username, email address, and password. We may also collect optional profile details such as profile images.
- User-Generated Content (UGC): This includes the prompts, HTML, CSS, JavaScript, and schema data you create or upload when building and deploying apps. Versions of your projects and logs generated by your app development and publication activities are stored indefinitely.
- App Usage Data: When you or others use apps hosted on our Platform, we collect and store any data generated through app interactions (e.g., todo list items, form submissions, user inputs, saved preferences within apps). This data is stored to maintain app functionality and user experience.
- Marketplace and Transaction Data: If you purchase or sell Apps through the Platform, we collect purchase history, transaction amounts, seller payout details, refund and dispute records, and related financial information necessary to facilitate and record transactions. Sellers who onboard to our marketplace may have additional identity and financial information collected by Stripe as part of their KYC (Know Your Customer) verification process (see Section 4.2).
- Communication: If you contact us (e.g., for support or with questions), we may collect the information you provide in your message.
2.2 Automatically Collected Information
- Usage Data: We collect information about your interactions with the Platform, such as IP addresses, device information (e.g., browser type, operating system), and analytics data.
- App Interactions: We track likes, dislikes, and saved apps (favorites). This data is tied to your user identity to offer personalized features and analytics.
- Cookies and Similar Technologies: We use cookies, local storage, and similar tracking technologies to maintain sessions, remember user preferences, and analyze usage of our Platform.
2.3 Sensitive or Special Categories of Data
We do not intentionally collect sensitive or special categories of data (e.g., biometric data). We do not offer multi-factor authentication or WebAuthn/FIDO2 at this time; therefore, we do not collect biometric or device-based authentication data.
3. How We Use Your Information
We may use the information we collect for the following purposes:
- Account Creation and Management: To create and manage your user account, authenticate your login credentials (hashed passwords), and provide customer support.
- Platform Functionality: To allow you to build, deploy, and share your apps, as well as to manage version histories, app visibility settings (public, private, unlisted, draft), and collaboration features.
- Analytics and Improvements: To analyze usage patterns, improve the Platform's features, troubleshoot technical issues, and optimize performance.
- AI Operations and Logs: We use AI operations via external APIs (e.g., OpenAI, Anthropic). We store and process logs to maintain and improve our services.
- Marketing and Communications: To send you newsletters, product updates, or marketing messages, where you have opted in.
- Security and Fraud Prevention: To protect our Platform, users, and data from unauthorized access.
- Legal Compliance: To comply with legal obligations and respond to law enforcement requests.
4. Sharing and Disclosure of Your Information
4.1 Service Providers and Third Parties
- Hosting and Infrastructure Providers
- Analytics Providers
- Email or Communication Service Providers
- AI Service Providers
4.2 Payment Processing & Stripe
All payments on the Platform are processed by Stripe, Inc. ("Stripe"). We do not store your full credit card number or bank account details. We store limited payment references (e.g., Stripe customer IDs, payment intent IDs, and transaction metadata) necessary to manage subscriptions, purchases, and refunds.
Buyers: When you purchase an App, Stripe processes your payment on our behalf. Stripe collects your payment card information directly and is subject to Stripe's Privacy Policy.
Sellers: To sell Apps on the marketplace, you must complete Stripe Connect onboarding. During this process, you are redirected to Stripe where they may collect identity verification documents, tax identification numbers (e.g., SSN or EIN), bank account information, date of birth, and other information required for KYC (Know Your Customer) compliance. Stripe acts as an independent data controller for this information and processes it under their own privacy policy. On our side, we store your Stripe Connect account ID, payout eligibility status, and onboarding completion status to manage your seller experience on the Platform.
4.3 Marketplace Transaction Data Sharing
When a transaction occurs on the marketplace, limited information may be shared between parties:
- Buyers can see the seller's public profile name and username associated with Apps they purchase.
- Sellers can see that a purchase was made but do not receive the buyer's personal information (name, email, or payment details).
- Transaction records (amounts, dates, and status) are maintained for both parties for account management and dispute resolution purposes.
4.4 Legal Requirements and Business Transfers
We may disclose information if required by law or in the event of a merger, acquisition, or sale of assets.
4.5 Third-Party Apps and User Data Exposure
Important: When you interact with apps created by other users, any information you provide to those apps may be accessible to the app creators and could potentially be shared, stored, or transmitted by them in ways outside our control. This includes personal information, form inputs, messages, and any other data you enter into third-party apps.
4.6 No Sale of Personal Information
We do not sell or rent your personal information to third parties under any circumstances.
5. Cookies & Tracking Technologies
We use cookies, local storage, and similar technologies for:
- Authentication
- Preferences
- Analytics
6. International Data Transfers
Our company is based in the United States. All application data is stored in the United States using Neon, a PostgreSQL serverless database provider, with infrastructure located in the US East region.
We comply with applicable data protection laws regarding international transfers. We use mechanisms such as Standard Contractual Clauses (SCCs) when transferring data outside protected regions.
7. Data Retention & Deletion
We retain personal information and user-generated content for as long as your account is active and for a reasonable period thereafter for legal, business, and audit purposes. You can delete your data directly within the Platform at any time.
Transaction records (purchases, sales, refunds, and disputes) are retained for a minimum of seven (7) years as required by tax and financial regulations, even if your account is deleted.
When you request account deletion, we will delete or anonymize your personal information within a reasonable timeframe, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention, legal compliance, dispute resolution).
8. Security Measures
8.1 Platform Security
We implement the following security measures for our Platform:
- Encryption in transit and at rest
- Secure password hashing
- Access controls
- Rate limiting
- App isolation and sandboxing
8.2 Third-Party App Security Limitations
Important Limitation: While we implement security measures to protect our Platform, we cannot guarantee the security of data you share with third-party apps created by other users. These apps may:
- Potentially bypass our security measures
- Collect and transmit your data without encryption
- Store your information in insecure ways
- Share your data with external parties
Your responsibility: Exercise caution when sharing sensitive information with third-party apps and only use apps from trusted sources.
9. User Rights & Control
You have the right to:
- Access your personal information
- Correct or update information
- Delete your information
- Restrict processing
- Data portability
10. Children's Privacy
Our Platform is not intended for individuals under the age of 13 (or 16 in certain jurisdictions) without parental consent.
11. AI and Automated Processing
We use AI and machine learning processes via external APIs for content generation and service improvements.
12. Third-Party Apps and User-Generated Content
Important Security Notice: When you use apps created by other users on our Platform, those apps may be able to access, collect, store, or transmit any information you provide to them.
12.1 Risks of Third-Party Apps
- Data Collection: Apps created by other users may collect any information you input, including personal or sensitive data.
- Security Bypass: While we implement security measures, third-party apps may potentially bypass these protections or be designed to collect your information.
- External Transmission: Third-party apps may send your data to external services or store it in ways we cannot control.
- No Oversight: We cannot review, monitor, or control all user-generated apps for data collection practices.
12.2 Your Responsibility
By using third-party apps, you acknowledge and accept these risks. We strongly recommend:
- Only using apps from trusted creators
- Being cautious about sharing sensitive information
- Reviewing app descriptions and creator profiles
- Understanding that we are not responsible for third-party privacy practices
13. Communication & Marketing
We send:
- Transactional emails
- Marketing messages (opt-in required)
14. GDPR Compliance (European Users)
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) and applicable local data protection laws apply to our processing of your personal data. Boosterbot AI, LLC acts as the data controller for the personal data we collect through the Platform.
14.1 Legal Basis for Processing
Under GDPR Article 6, we process your personal data based on the following legal bases:
| Data Category | Legal Basis |
|---|---|
| Account data (name, email, password) | Contract performance (necessary to provide the Platform) |
| User-generated content (apps, code) | Contract performance |
| Payment and transaction data | Contract performance + legal obligation (tax and financial reporting) |
| Analytics and usage data | Legitimate interest (improving Platform performance and user experience) |
| AI processing (prompts, outputs, logs) | Legitimate interest (providing and improving AI features) + consent where required |
| Marketing and communications | Consent (opt-in required) |
| Security and fraud prevention | Legitimate interest (protecting the Platform and users) |
14.2 Your Rights Under GDPR
In addition to the rights listed in Section 9, European users have the right to:
- Right to erasure ("right to be forgotten"): Request deletion of your personal data, subject to legal retention requirements.
- Right to restrict processing: Request that we limit the processing of your data in certain circumstances.
- Right to object: Object to processing based on legitimate interest at any time. We will cease processing unless we demonstrate compelling legitimate grounds.
- Right to withdraw consent: Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint: You have the right to lodge a complaint with your local data protection authority.
To exercise any of these rights, please contact us at contact@boosterbot.ai. We will respond to your request within 30 days.
14.3 International Data Transfers
As described in Section 6, your data is stored in the United States. For transfers of personal data from the EEA/UK to the US, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other legally recognized transfer mechanisms.
15. CCPA Compliance (California Residents)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with specific rights regarding your personal information.
15.1 Categories of Personal Information Collected
In the preceding 12 months, we have collected the following categories of personal information:
- Identifiers: Name, email address, username, IP address, Stripe customer ID.
- Commercial information: Purchase history, transaction records, products or services purchased.
- Internet or electronic network activity: Browsing history on the Platform, interactions with Apps, device information, analytics data.
- Professional or employment-related information: For sellers, information provided during Stripe Connect onboarding (collected and controlled by Stripe).
- Inferences drawn from the above: User preferences, usage patterns, and content recommendations.
15.2 Sources of Personal Information
- Directly from you: Account registration, app creation, communications, and purchases.
- Automatically: Cookies, analytics tools, and usage tracking as described in Sections 2.2 and 5.
- Third-party service providers: Stripe (payment and seller verification data).
15.3 Business Purposes for Collecting
We collect and use personal information for the business purposes described in Section 3, including: providing and improving the Platform, processing transactions, analytics, security, fraud prevention, legal compliance, and marketing (with consent).
15.4 Your Rights Under CCPA
As a California resident, you have the right to:
- Right to know: Request that we disclose the categories and specific pieces of personal information we have collected about you.
- Right to delete: Request deletion of your personal information, subject to certain exceptions (e.g., legal obligations, transaction records).
- Right to correct: Request correction of inaccurate personal information.
- Right to opt-out of sale or sharing: We do not sell your personal information, nor do we share it for cross-context behavioral advertising purposes.
- Right to non-discrimination: We will not discriminate against you for exercising any of your CCPA rights.
15.5 "Do Not Sell or Share My Personal Information"
We do not sell your personal information as defined by the CCPA. We do not share your personal information for cross-context behavioral advertising purposes. If our practices change in the future, we will update this policy and provide a clear opt-out mechanism.
15.6 Exercising Your Rights
To exercise any of your CCPA rights, you may contact us at contact@boosterbot.ai. We will verify your identity before processing your request. We will respond to verifiable consumer requests within 45 days, as required by the CCPA. You may also designate an authorized agent to submit a request on your behalf.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email, in-app notification, or other reasonable means. Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
17. Contact Us
If you have any questions or concerns about this Privacy Policy, please contact us at:
Boosterbot AI, LLC
Email: contact@boosterbot.ai
BY USING OR CONTINUING TO USE THE PLATFORM, YOU ACKNOWLEDGE THAT YOU HAVE READ AND AGREE TO THIS PRIVACY POLICY.