1. Information We Collect
We collect the following categories of information to deliver, secure, and improve ANDROID-ARCHITECT functionality:
- Account information: name, email address, and authentication identifiers managed through Supabase Auth.
- AI interaction data: prompts and queries you send to the Google Gemini API, as well as generated outputs such as app blueprints, code scaffolding, and consultation responses.
- Usage analytics: if you accept analytics cookies, page views, feature usage patterns, and session data collected via Google Analytics 4 and Datadog Real User Monitoring to help us understand how the platform is used. Nothing is collected by these tools unless you opt in.
- Newsletter: your email address, if you subscribe to updates through a sign-up form on the site.
- Account information: API keys you choose to store are encrypted in your browser and held on our servers against your account until you delete them.
- Browser storage: localStorage is used to persist user preferences and session state on your device.
- Operational data: performance logs and security telemetry used to maintain platform reliability and safety, and — if you accept analytics cookies — crash diagnostics collected via Sentry.
- Error reports: when something breaks in the app, we record the error message, its stack trace, the script position, the page path, the app version and your browser’s user-agent string in our own database. These reports carry no account identifier, and email addresses, tokens and keys are removed from the text before it is sent. They are kept for 30 days. This happens whether or not you accept analytics cookies, because it is how we find faults in the product.
2. How We Use Information
The information we collect is used for the following purposes:
- Provide, secure, and continuously improve platform functionality, including AI-assisted architecture generation, code scaffolding, and real-time consultation.
- AI processing disclosure: prompts you submit are sent to the Google Gemini API for processing, including architecture generation, code scaffolding, design system creation, and consultation responses. Generated outputs are returned to you within the platform.
- Analytics: understand feature adoption, optimize the user experience, measure performance, and diagnose technical issues through aggregated usage data.
- Personalize onboarding flows, tutorials, and product recommendations based on your usage patterns and preferences.
- Detect and prevent abuse, fraud, unauthorized access, and violations of our Terms of Service.
- Support legal obligations, regulatory compliance, and legitimate business operations.
3. Data Sharing and Processing
We share data with trusted subprocessors solely to operate and improve the platform. We require contractual safeguards from each subprocessor and process only the minimum data necessary. Our current subprocessors include:
- Google Gemini API — AI processing for architecture generation, code scaffolding, compliance analysis, and consultation responses.
- Supabase — user authentication, database storage, and backend services.
- Cloudflare — hosting, content delivery network (CDN), and web application firewall (WAF) protection.
- Stripe — payment processing and subscription billing.
- Resend — delivery of account and subscription emails, such as the follow-up after a cancellation.
- Sentry — error tracking, crash diagnostics, and performance monitoring, only with your analytics consent.
- Google Analytics 4 — aggregated usage analytics and feature adoption measurement, only with your analytics consent.
- Datadog — real user monitoring of page performance, only with your analytics consent.
We do not sell, rent, or trade your personal data to third parties. Data is shared with subprocessors only as described above and subject to appropriate data processing agreements.
4. Security
We implement industry-standard technical and organizational measures to protect your data:
- Encryption in transit: all data transmitted between your browser and our services is protected by HTTPS/TLS encryption.
- Application-layer protection: Cloudflare WAF provides web application firewall protection against common attack vectors.
- Credential isolation: API keys you store are encrypted with AES-GCM in your browser before they reach us, and the ciphertext and its initialisation vector are what we hold. Because the encryption key is derived from your account identifier, this protects a stored key if our database is exposed, but it does not prevent ANDROID-ARCHITECT itself from decrypting it. Platform secrets are kept in environment-isolated configuration and never in client code.
- Access controls: role-based access controls and audit mechanisms govern internal access to systems and data.
- Data retention: retention schedules are aligned to legal requirements and operational needs. Data is purged when no longer necessary for the purposes described in this policy.
5. Your Rights and Controls
Depending on your jurisdiction, you may exercise the following rights regarding your personal data:
- Right to access: request a copy of the personal data we hold about you.
- Right to correction: request correction of inaccurate or incomplete personal data.
- Right to data portability: export your blueprints as JSON or PDF from the Blueprint Builder, and request a copy of your account data by emailing [email protected].
- Right to deletion: delete your account and associated personal data yourself from your profile in Settings, or ask us to.
- Right to opt out of analytics: withdraw analytics consent at any time from Cookie preferences — the Cookies link in the site footer, or the cookie control in the app sidebar.
California residents (CCPA): you have the right to know what personal data we collect, request its deletion, and opt out of the sale of personal data. We do not sell personal data.
EU/EEA residents (GDPR): you have all rights listed above, as well as the right to restrict processing, the right to object to processing, and the right to lodge a complaint with your local supervisory authority.
6. Cookies and Local Storage
ANDROID-ARCHITECT uses the following browser storage mechanisms:
- localStorage: used to persist user preferences, interface settings, and session state. This data remains on your device and is not transmitted to our servers.
- No third-party tracking cookies: the platform itself does not set third-party tracking cookies.
- Google Analytics 4: if analytics is enabled, GA4 may use first-party cookies to track session information and distinguish between users. You can opt out of analytics in your settings.
- Clearing stored data: you can clear all locally stored data at any time through your browser settings or by using the in-app data management options.
7. Children's Privacy
ANDROID-ARCHITECT is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected personal data from a child under 13, we will take prompt steps to delete that information from our systems.
If you believe a child under 13 has provided us with personal data, please contact us at [email protected] so we can investigate and take appropriate action.
8. International Data Transfers
Your data may be processed in jurisdictions where our subprocessors operate, including the United States and the European Union. When data is transferred across borders, we rely on Standard Contractual Clauses (SCCs) and adequacy decisions recognized by applicable data protection authorities to ensure appropriate safeguards are in place.
By using ANDROID-ARCHITECT, you acknowledge and consent to the transfer and processing of your data in these jurisdictions as described in this policy.
9. Contact
For privacy requests, data subject rights inquiries, or any concerns regarding this Privacy Policy, please contact us at [email protected].
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will notify registered users via in-product notification and email.
Your continued use of ANDROID-ARCHITECT after any changes to this policy constitutes your acceptance of the updated terms. We encourage you to periodically review this page for the latest information on our privacy practices.