← Preflight

Legal

Privacy

Plain-language summary · Updated August 3, 2026

What we process

Account identity, repository and submission metadata, app artifacts, runtime evidence and payment state strictly to deliver the requested review.

Isolation and retention

Review inputs and artifacts are private, tenant-scoped and excluded from shared-model training. Production retention is configurable; deletion requests remove stored artifacts and associated review data subject to legal payment-record requirements.

Providers

Google provides authentication, Stripe processes payment, Cloudflare hosts application data, and AWS Device Farm executes the physical-device pass. Each receives only the data required for its role.