Privacy Policy
Last updated August 21, 2026
This policy describes exactly what AppClap stores, for how long, and what we never collect. You can browse and search the entire catalog without an account.
1. What you can do without giving us anything
Searching, reading listings, and following links to products all work with no account and no name, email, or payment details. Submitting an app doesn't need one either. An account is only needed to save searches, manage your notification settings, or connect MCP under your own key.
2. What we store when you search
We store the text of your search so we can see what people look for and what we failed to answer — it is the single most useful signal we have for deciding what to add to the catalog. Search text is automatically erased after 90 days. Searches you deliberately save to your account are the exception: those are yours, and we keep them until you delete them or your account. Please treat the search box like a public one: it is a good place to describe a problem, and a bad place to type anything personal about yourself or anyone else.
3. Cookies and how we count visits
We set one cookie, appclap_sid. It is a random identifier with no name or email attached, and it is httpOnly, meaning page scripts cannot read it. We ask before using it to count anything: until you choose, and if you decline, it lasts 24 hours and does one job — stopping a single visitor from exhausting the daily budget for the AI that answers searches. If you allow counting, it lasts a year and also joins your actions into one visit, so that “someone searched, then clicked a result” counts once rather than twice. We remember your choice in a second cookie and ask again after six months. If you sign in, your login session uses additional cookies from our authentication provider. We do not use advertising cookies. If you allow counting, our analytics provider PostHog — hosted in the European Union — sets its own cookies so it can recognise your browser between visits, and records a replay of that visit: the pages you opened and where you clicked. Anything you type is masked inside your browser before it is sent, and the sign-in and account screens are left out of the recording entirely. Until you allow counting, PostHog stores nothing on your device and sends nothing at all. We never send it the text of your searches.
4. What we never collect
We do not store your IP address against your browsing or your searches. If you have not allowed counting, we do not build a picture of your visit: no session identifier, no link between one action and the next, nothing that could be traced back to you. We do still keep plain totals — that a page was opened, that a link to a product was followed, that something went wrong — because a creator needs to know how many people we sent them and we need to know when the site is broken. Those totals carry no identifier of any kind and cannot be tied to a person. We record a two-letter country code supplied by our hosting edge, and nothing more precise. We do not sell personal information, and we do not share it with advertisers or data brokers.
5. How long we keep things
Usage events such as page views and clicks: 180 days. Search text: 90 days, after which the query is erased and only the anonymous outcome remains. The IP address attached to anything you send us through a form — an app submission, a report about a listing, or a thumbs up or down on results: 90 days, kept that long only to limit abuse of forms that are open to everyone.
6. If you sign in or submit an app
We sign you in with a one-time link rather than a password, so there is no password for us to store or leak. If you submit an app we keep what you sent — the link, any details, and your email if you gave one — because we may need to come back to you about the listing. Submitting someone else's product is fine and common; you don't need to be its creator, and you don't need an account. If you happen to be signed in when you submit an app, report a listing, or rate some results, we record which account it came from, so we can credit your contributions and come back to you about them. If you are not signed in, none of it is linked to a person. Deleting your account unlinks what you sent rather than retracting it, since the catalog may already have acted on a correction.
7. Where your data goes
We use a small number of providers to run the Service: Supabase, which hosts our database and signs you in; our web and server hosting providers; PostHog, which counts visits once you allow it; and the AI providers whose models read publicly available product pages and your search text in order to answer it — Anthropic and Voyage AI. They process this data on our instructions and may not use it for anything else. PostHog is on its European Union hosting, so what it holds stays in the EEA. The others are based in the United States, so if you are outside it, the data described in this policy is transferred out of your country — including out of the UK and EEA — in the course of answering you. Result pages load product icons from Google's favicon service, so Google sees that some browser requested an icon for a given site. We send no referrer, so the request can't be tied back to your search. Our own servers also fetch those icons when building the preview image shown for a link shared on social media; that happens without any visitor involved, so nothing about you is in it.
8. Your rights
You can ask us what we hold about you, ask for a copy, ask us to correct it, or ask us to delete it — including your account and anything you submitted. Write to the address below and we will action it and confirm when it is done. If you are in the UK, EU, or another region with statutory data rights, those rights apply and we will respond within the period the law requires.
9. Security, changes, and contact
Data is encrypted in transit, access is limited to the people running AppClap, and we hold as little as we can so that there is less to lose. No system is perfectly secure; where an incident affects you and the law requires it, we will tell you. If this policy changes we will update it here with a new date. Questions, or a request under section 8: legal@app-clap.com.