Skip to content

Legal

Privacy Policy

Last updated:

This policy explains what Nitpick collects, why, where it is stored, who processes it for us and for how long. It covers two groups of people: app builders who have an account, and the users of their apps who send feedback.

Who is responsible

Nitpick is run by [TO FILL IN: legal name of the business], [TO FILL IN: business address], KvK number [TO FILL IN: KvK number].

Questions about privacy, and requests about your data: support@appsko.com.

Data about app builders

What Why Legal basis
Your email address To create your account, send you sign-in links, and email you about your subscription and the monthly limit. Contract
Your account: the apps you add, the names of your tokens, your feedback settings and which token or tool last changed them To run the service for you, in the dashboard and for your agent. Contract
Your subscription: until when you have paid, and the number of reports this month To apply the subscription and the limits. Contract
A sign-in request from the CLI: the name of the tool that asks, for 30 minutes To give the CLI a token after you allow it in the browser. Contract

Payments. You pay in the secure checkout of Paddle, which opens over our payment page; your card or other payment details go straight to Paddle and never reach our servers. Paddle (Paddle.com Market Limited) sells the subscription as merchant of record and processes your payment details under its own privacy policy. We send Paddle only your email address and the id of your account. Paddle tells us when a payment is completed or refunded, and for which period.

Data in a feedback report

A report is sent only after a user opens the feedback form in an app and taps Send. A report contains:

A report never contains the user's name, email address, or an account or device identifier, and never the device name the user chose. The feedback is anonymous. A screenshot does show what was on the screen at that moment, which can include personal data that the app itself displays, unless the builder masked that part.

IP address and User-Agent. Like any internet request, a request from the component carries an IP address and a User-Agent. When the app starts, the component asks for its feedback settings. We use the IP address and User-Agent only to answer that request and do not store them. When a report is sent, we use the IP address to limit the number of reports per minute; it is not stored with the report. Our application does not write IP addresses to its logs. Our hosting provider Vercel keeps request logs; see "How long" below.

We use reports only to deliver them to the builder of the app, in the dashboard and through the API, CLI and MCP.

Visitor statistics on this site

This website counts visits with Vercel Web Analytics, so we can see how many people visit and which pages they open. The count is anonymous and uses no cookies: nothing is stored on your device, and no data that identifies a visitor is kept, such as your IP address or a profile of you. Vercel counts the visits for us. The Nitpick platform and the feedback component do not measure anything. Because no cookies are used, there is no cookie banner.

No AI on our platform

The Nitpick platform does not run AI on reports. The builder's own coding agent fetches the reports through the CLI or MCP, with a token from the builder's account. What the agent and its AI provider then do with a report is up to the builder and falls under the builder's own privacy policy.

Where the data is stored

Your account and all feedback reports, including screenshots, are stored at Supabase on servers located in Frankfurt, Germany (European Union). The platform runs on Vercel in the Frankfurt region. Email is sent via Resend from its EU region. Vercel and Resend are companies based in the United States, but their services for Nitpick run from EU infrastructure. Payments are processed through Paddle, which acts as merchant of record.

Who processes data for us

Service What for What it receives
Supabase Database, file storage for screenshots, and sign-in Account data and reports
Vercel Hosting of the site and the platform, and the anonymous visit count on the site Every request to the site and the platform, including the IP address; for the visit count only the page and an anonymous count
Resend Sending sign-in links and emails about your subscription and the monthly limit Your email address and the text of the email
Paddle Payments as merchant of record: checkout, VAT, invoices and the customer portal Your email address and the id of your account; never reports or data of app users

How long we keep data

Data How long
A screenshot 12 months after the report came in. The report stays, without the screenshot.
Reports, while the subscription runs As long as the subscription runs, with the screenshot rule above.
Locked reports, after the subscription stops Deleted from 46 days after the end of the last paid period.
Other reports, after the subscription stops Deleted from 136 days after the end of the last paid period.
IP address and User-Agent of a request for the settings Not stored.
Request logs at Vercel [TO FILL IN: how long Vercel keeps request logs on the chosen plan]
Your email address and account As long as your account exists. You can ask us to delete it.

Our deletion runs log only numbers per account, not the content of reports. If you pay again before a deletion, nothing is deleted. The timeline after a subscription stops is explained in the Terms of Service.

Your rights

Under the GDPR you can ask us to see the data we have about you, to correct or delete it, to limit its use, to object to its use, and to receive it in a format you can take elsewhere. Write to support@appsko.com. We answer within one month. You can also file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

If you sent feedback from an app: reports are anonymous, so we usually cannot tell which report is yours. Contact the maker of the app, who is responsible for your report. We help the maker to answer your request. If you write to us directly with details that point to your report, such as the app, the time and the text of your comment, we pass your request on to the maker.

Security

Reports and screenshots can only be read with the builder's sign-in session or with a token of the builder's account. Builders can revoke tokens in the dashboard. The platform limits the number of reports per minute per app and per IP address, and limits the size of what it accepts.

Changes

If we change this policy, the date at the top of this page changes with it. If a change matters for builders, we tell them by email.