Legal

Privacy policy

Last updated 4 October 2026

This policy explains what WebToApp collects when you use the service, why, and the choices you have.

What we collect

  • Account data: name, email address and a salted hash of your password.
  • App data: the website URLs, app names, icons, settings and feature configuration you provide, and uploaded site ZIP files.
  • Signing credentials: keystores, certificates, provisioning profiles, service-account and API keys you choose to save. They are encrypted at rest (AES-256-GCM) and decrypted only inside your own build run.
  • Build data: build status, version numbers and logs.
  • Payment data: payments are handled by Razorpay. We store the order and payment identifiers and amounts, never card or UPI details.
  • Devices of your app’s users: if you enable push notifications, a push token and platform for each installed device.

How we use it

To run the service: build and deliver your apps, bill you, send push notifications you request, secure accounts and prevent abuse. We do not sell personal data.

Who we share it with

  • GitHub runs builds; your app configuration and signing material reach a build runner only for the duration of your build.
  • Razorpay processes payments. Google Firebase delivers push notifications if you use them.
  • Hosting providers that store our database and files.

Retention and deletion

You can delete an app, its stored keys, or your whole account from the dashboard at any time; deletion removes the associated data from our systems. Build artifacts are kept by GitHub for up to 30 days.

Cookies

We use one essential, httpOnly session cookie to keep you signed in. We do not use advertising cookies.

Your rights

You can access, correct, export or delete your data. Use the dashboard, or contact us.

Changes

We will update this page when the policy changes and note the date above.