Legal
Privacy Policy
This Privacy Policy explains how Websody AG (“IndieAppScale”, “we”, “us”) collects, uses and protects your personal information when you use indieappscale.com and our services (the “Service”). By using the Service you agree to this policy.
1. Who we are
The data controller is Websody AG, registered at Gerechtigkeitsgasse 25, 8001 Zürich, Switzerland. For any privacy question, contact us at contact@indieappscale.com.
2. Information we collect
- Account information. Your email address, and — if you sign in with Google or Apple — the basic profile information (name, email) those providers share with us.
- Authentication data. Sign-in is passwordless and handled by Amazon Cognito. We do not store passwords. One-time codes are sent to your email solely to verify it's you.
- Content you provide. Your app's store listing, screenshots, uploads and the details you enter, which we send to the AI providers listed below so they can generate slideshow images and copy for you.
- Connected social accounts. If you connect a TikTok account, we receive the basic profile information and permissions you authorize through TikTok's official flow (such as your display name and account identifier), and access tokens used solely to act on your behalf — for example, publishing content you created. You can revoke this access at any time from your settings or from TikTok.
- App Store Connect. If you connect App Store Connect to a project, you provide an App Store Connect team API key: its Issuer ID, Key ID and private key (.p8 file), plus your vendor number. We use it only to read your app's download reports and App Store keywords and, on plans that include it, to write the keywords you edit. We store the daily download counts by date and source, and the keywords we read or write. We never show the private key back to you or anyone else.
- Usage data. On our public website we record each page you open and which call to action you pressed, along with the page it was on, the referring site's domain, any campaign tags in the link, and whether you were on a phone or a desktop. This part is stored by us, identified only by a random number kept in your browser — never your name, email or IP address (we store a salted, rotating hash of the IP purely to rate-limit abuse). It is collected whatever you answer to the cookie banner.
- Analytics, only if you accept. If you accept analytics cookies, the pages you view and the buttons you press on the website and in the app are also sent to PostHog, our product analytics provider. PostHog sets a cookie so that repeat visits, and a visit to the website followed by one to the app, read as one person rather than several — which is what lets us see how people arrive and what they do next. We do not send it your name or email address. Decline, and none of this loads.
3. How we generate content
The images and the first drafts of the copy in your posts are produced by AI models run by third-party providers on our behalf. When you generate or regenerate a post, the app details, prompts and any reference images involved are sent to those providers so they can produce the result. We do not send them your sign-in credentials, the data from your connected social accounts, or your App Store Connect key or the figures synced with it, and we do not use your content to train our own models.
Generated images are marked as AI-generated inside the app. When you publish a post that contains them to TikTok, we declare it to TikTok as AI-generated content wherever TikTok's API accepts that declaration; where it does not — video uploads, and drafts you finish inside the TikTok app — the app tells you to switch the label on yourself. You remain the publisher of what you post.
4. How we use your information
- To create and secure your account and authenticate your sign-ins.
- To provide, operate and improve the Service.
- To communicate with you about your account and service updates.
- To detect, prevent and address fraud, abuse and security incidents.
- To comply with legal obligations.
5. Legal bases
Where the GDPR applies, we process personal data on the bases of performing our contract with you, our legitimate interests in operating and securing the Service, your consent (where requested), and compliance with legal obligations.
6. Authentication, cookies and tokens
Update, 4 September 2026. While we work out why people try IndieAppScale and then stop, PostHog analytics and session recording run by default for everyone, rather than only for people who accept. This overrides the "only if you accept" wording in this section and in section 2 for now. Two things have not changed: everything you type is masked out of the recording — form fields, including sign-in codes, are never recorded — and we never send PostHog your name or email. You can switch it off for your browser with the control below, or under Analytics in the app's settings; either one stops the website and the app together.
We use strictly necessary cookies to keep you signed in. Session tokens are stored in secure, httpOnly cookies that your browser's scripts cannot read, and they expire automatically. We do not use advertising or cross-site tracking cookies, and we load no advertising scripts.
If you accept analytics, we load PostHog's script and it sets a cookie scoped to indieappscale.com. That scope is the point: it covers the website and the app, so one person moving between them is counted once. If you decline, the script is never fetched and no analytics cookie is set. We also keep two things in your browser's local storage: the random number described in section 2, and, in the app, your language and theme. Your cookie-banner answer itself is a cookie, for the same reason — so the website and the app both honour it.
You can turn analytics off at any time, on this browser, from here.
You have not answered yet on this browser.
7. How we share information
We do not sell your personal information. We share it only with the service providers that help us run the Service, under appropriate safeguards:
- Amazon Web Services — hosting, storage and Cognito authentication. Everything you create is stored here.
- Google (Gemini) — image and text generation. Receives your prompts and the app details behind them.
- Runware — image generation infrastructure. Receives your prompts and any reference images.
- OpenAI — text generation, used as a fallback when Gemini is unavailable. Receives the same prompts and app details.
- Pexels — stock photo search. Receives only the search terms, never your app details or account information.
- Stripe — payments. Handles your billing details directly; we never see or store your card number.
- PostHog — product analytics, and only if you accept analytics cookies. Receives the pages you view and the buttons you press, on the website and in the app.
- Amazon SES — transactional email (sign-in codes, project invitations).
- TikTok — only if you connect an account. We send the content you choose to publish, under TikTok's own terms and privacy policy.
- Apple — only if you connect App Store Connect. Receives authenticated API requests signed with your key, including the keywords you choose to save, under Apple's own terms and privacy policy.
- Authorities or third parties where required by law or to protect rights and safety.
We do not use an advertising provider, and we do not sell or share your data for advertising. The page-visit and call-to-action record described in section 2 is collected and stored by us alone; PostHog receives only what section 2 describes, and only with your consent.
8. International transfers
We are established in Switzerland, and several of the providers above (including Google, OpenAI, Stripe, TikTok, Apple and PostHog) process data in the United States and other countries outside Switzerland and the EEA. Where data leaves your region we rely on appropriate transfer mechanisms, such as the European Commission's Standard Contractual Clauses and the relevant adequacy decisions. PostHog is the one you can opt out of: decline analytics cookies and nothing is sent to it at all.
9. Data retention
We keep your information for as long as your account is active and as needed to provide the Service, then delete or anonymize it unless a longer period is required by law. If you disconnect App Store Connect or delete the project it is connected to, we delete the key and every download figure and keyword synced with it.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, export or restrict processing of your personal data, and to object to certain processing. To exercise these rights, email contact@indieappscale.com. You may also delete your account at any time.
11. Security
We use industry-standard measures — encryption in transit (TLS/HTTPS) and encryption at rest, managed authentication with expiring tokens, and least-privilege access — to protect your information. Access tokens for connected accounts (such as TikTok) and App Store Connect private keys are encrypted before they are stored and are never shared with other users or third parties. Each App Store Connect private key is encrypted with a key of its own, which is in turn locked by a master key held in AWS Key Management Service; the master key never leaves that service, only the systems that talk to Apple for you may use it, and each use is logged. No method of transmission or storage is perfectly secure, but we work to protect your data and to notify you of incidents as required.
12. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data.
13. Changes to this policy
We may update this policy from time to time. We will post the new version here and update the "Last updated" date above; material changes will be communicated as appropriate.
14. Contact
Questions? Email contact@indieappscale.com or write to Websody AG, Gerechtigkeitsgasse 25, 8001 Zürich, Switzerland.
