This policy explains what Nitpick collects, why, where it is stored, who processes it for us and for how long. It covers two groups of people: app builders who have an account, and the users of their apps who send feedback.
Who is responsible
Nitpick is run by [TO FILL IN: legal name of the business], [TO FILL IN: business address], KvK number [TO FILL IN: KvK number].
- For the data of app builders (your account), [TO FILL IN: legal name of the business] is the controller.
- For feedback reports that users send from inside an app, the builder of that app is the controller. We process the reports for the builder, as processor, under our Data Processing Agreement.
Questions about privacy, and requests about your data: support@appsko.com.
Data about app builders
| What | Why | Legal basis |
|---|---|---|
| Your email address | To create your account, send you sign-in links, and email you about your subscription and the monthly limit. | Contract |
| Your account: the apps you add, the names of your tokens, your feedback settings and which token or tool last changed them | To run the service for you, in the dashboard and for your agent. | Contract |
| Your subscription: until when you have paid, and the number of reports this month | To apply the subscription and the limits. | Contract |
| A sign-in request from the CLI: the name of the tool that asks, for 30 minutes | To give the CLI a token after you allow it in the browser. | Contract |
Payments. You pay in the secure checkout of Paddle, which opens over our payment page; your card or other payment details go straight to Paddle and never reach our servers. Paddle (Paddle.com Market Limited) sells the subscription as merchant of record and processes your payment details under its own privacy policy. We send Paddle only your email address and the id of your account. Paddle tells us when a payment is completed or refunded, and for which period.
Data in a feedback report
A report is sent only after a user opens the feedback form in an app and taps Send. A report contains:
- the user's comment;
- if the user points at something: a screenshot of the app screen, the tap position, the size of the screen, and the screen and element names that the builder marked. The user sees a preview of the screenshot first and can remove it. Parts that the builder masked are black;
- the device model identifier (for example "iPhone16,1"), the operating system and its version, the language, the app version and build number, and the version of the component;
- the time on the device and the time we received the report, and whether the builder marked it as resolved.
A report never contains the user's name, email address, or an account or device identifier, and never the device name the user chose. The feedback is anonymous. A screenshot does show what was on the screen at that moment, which can include personal data that the app itself displays, unless the builder masked that part.
IP address and User-Agent. Like any internet request, a request from the component carries an IP address and a User-Agent. When the app starts, the component asks for its feedback settings. We use the IP address and User-Agent only to answer that request and do not store them. When a report is sent, we use the IP address to limit the number of reports per minute; it is not stored with the report. Our application does not write IP addresses to its logs. Our hosting provider Vercel keeps request logs; see "How long" below.
We use reports only to deliver them to the builder of the app, in the dashboard and through the API, CLI and MCP.
Visitor statistics on this site
This website counts visits with Vercel Web Analytics, so we can see how many people visit and which pages they open. The count is anonymous and uses no cookies: nothing is stored on your device, and no data that identifies a visitor is kept, such as your IP address or a profile of you. Vercel counts the visits for us. The Nitpick platform and the feedback component do not measure anything. Because no cookies are used, there is no cookie banner.
No AI on our platform
The Nitpick platform does not run AI on reports. The builder's own coding agent fetches the reports through the CLI or MCP, with a token from the builder's account. What the agent and its AI provider then do with a report is up to the builder and falls under the builder's own privacy policy.
Where the data is stored
Your account and all feedback reports, including screenshots, are stored at Supabase on servers located in Frankfurt, Germany (European Union). The platform runs on Vercel in the Frankfurt region. Email is sent via Resend from its EU region. Vercel and Resend are companies based in the United States, but their services for Nitpick run from EU infrastructure. Payments are processed through Paddle, which acts as merchant of record.
Who processes data for us
| Service | What for | What it receives |
|---|---|---|
| Supabase | Database, file storage for screenshots, and sign-in | Account data and reports |
| Vercel | Hosting of the site and the platform, and the anonymous visit count on the site | Every request to the site and the platform, including the IP address; for the visit count only the page and an anonymous count |
| Resend | Sending sign-in links and emails about your subscription and the monthly limit | Your email address and the text of the email |
| Paddle | Payments as merchant of record: checkout, VAT, invoices and the customer portal | Your email address and the id of your account; never reports or data of app users |
How long we keep data
| Data | How long |
|---|---|
| A screenshot | 12 months after the report came in. The report stays, without the screenshot. |
| Reports, while the subscription runs | As long as the subscription runs, with the screenshot rule above. |
| Locked reports, after the subscription stops | Deleted from 46 days after the end of the last paid period. |
| Other reports, after the subscription stops | Deleted from 136 days after the end of the last paid period. |
| IP address and User-Agent of a request for the settings | Not stored. |
| Request logs at Vercel | [TO FILL IN: how long Vercel keeps request logs on the chosen plan] |
| Your email address and account | As long as your account exists. You can ask us to delete it. |
Our deletion runs log only numbers per account, not the content of reports. If you pay again before a deletion, nothing is deleted. The timeline after a subscription stops is explained in the Terms of Service.
Your rights
Under the GDPR you can ask us to see the data we have about you, to correct or delete it, to limit its use, to object to its use, and to receive it in a format you can take elsewhere. Write to support@appsko.com. We answer within one month. You can also file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
If you sent feedback from an app: reports are anonymous, so we usually cannot tell which report is yours. Contact the maker of the app, who is responsible for your report. We help the maker to answer your request. If you write to us directly with details that point to your report, such as the app, the time and the text of your comment, we pass your request on to the maker.
Security
Reports and screenshots can only be read with the builder's sign-in session or with a token of the builder's account. Builders can revoke tokens in the dashboard. The platform limits the number of reports per minute per app and per IP address, and limits the size of what it accepts.
Changes
If we change this policy, the date at the top of this page changes with it. If a change matters for builders, we tell them by email.