Appilot Privacy Policy
Last updated: 2026-09-13
This privacy policy applies to Appilot.
Data Collection
Appilot is local-first. Project records, repository facts, App Store and ranking snapshots, release drafts, Copilot sessions, scheduled tasks, and execution history are stored on your device in Appilot's local SQLite database and application data directory. Appilot does not use this operational data for advertising or cross-app tracking.
File System Access
Appilot reads repositories and files that you explicitly connect so it can inspect Git history, project metadata, release materials, and other evidence needed by the features you invoke. Generated Keynote presentations, screenshots, and exports are written only as part of an action you start or approve. Repository content is not uploaded to an Appilot-operated cloud service.
API Keys
GitHub, AI-provider, and App Store Connect credentials are kept locally using Electron safeStorage; on macOS, encryption is backed by Keychain. App Store Connect private key files remain in Appilot's local application data directory. Credentials are used only to authenticate requests to the service you configured and are not included in AI prompts.
Network Requests
When you enable the corresponding features, Appilot may contact GitHub, App Store Connect, Apple's public storefront and search services, and the AI endpoint you configure. AI requests can include the prompts and project or release context required to produce the requested result. Appilot includes no third-party advertising or analytics SDKs.
Permissions
Appilot performs remote writes only after an explicit action or approval. Read-only collection and diagnosis remain separate from operations that change drafts, schedules, release materials, or remote services. You control which repositories, credentials, and external integrations are configured.
Third-Party Services
Data sent to GitHub, Apple, or your configured AI provider is governed by that service's privacy policy and your account agreement with it. Appilot does not control those providers' data practices. You can avoid a provider by leaving its integration unconfigured.
Contact
If you have questions about this privacy policy, please contact: xingyu.wang@gmail.com