Legal

Privacy Policy

This policy describes what AppRamp (“we”, “us”) collects when you use the AppRamp website, portal, and gateway (together, the “Service”), and how we handle it.

1. What we collect

Account data

Authentication is provided by Supabase. You can sign in with Google, with GitHub, or with an email address and password; passwords are held and hashed by Supabase and are never visible to us. From your sign-in we store your email address, the display name your identity provider shares (used to name your workspace), your workspace identifier, your plan and limits, and timestamps. We do not collect postal addresses, and we do not store payment card details ourselves.

Service data

To operate the gateway we store the API specifications you import, the configuration derived from them, the UI widgets you generate and deploy (their configuration and rendered markup), and per-workspace request counters (a number per day and per month — not the contents of requests).

Widget generation

When you use the Widget Builder, the description you write, the schema of the selected tool, and (if you fetch it) a sample of that tool’s output are sent to the AI model provider (Anthropic or OpenAI) solely to generate the widget. We do not use this content for anything else.

Request handling

Requests to your MCP endpoints pass through our gateway to your configured backend. Request and response bodies are processed in memory to perform validation and transformation and are not persisted. Operational logs may include metadata (timestamps, endpoint paths, status codes, error classes) retained for a limited period for debugging and abuse prevention.

2. What we do not do

3. How we use data

We use the data above to provide the Service: authenticating you, serving your endpoints, enforcing plan limits, showing you your own usage, and communicating essential service information. Aggregated, non-identifying statistics may be used to improve the Service.

4. Storage and security

Service data is stored on Cloudflare’s global infrastructure; authentication data is stored by Supabase. All traffic is encrypted in transit (TLS). Sign-in tokens are cryptographically signed and verified on our servers on every request. Backend credentials you configure are stored as isolated secrets and injected only at request time, server-side. Access to production systems is restricted and audited.

5. Retention and deletion

Account data is retained while your workspace exists. Sessions expire after seven days. Daily usage counters are retained for 90 days and monthly counters for approximately 13 months. To delete your workspace and associated data, contact support@appramp.dev; we complete deletion within 30 days.

6. Your rights

Depending on your jurisdiction (including under the GDPR and CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to or restrict processing. Write to support@appramp.dev and we will respond within 30 days.

7. Subprocessors and identity providers

We use the following subprocessors to provide the Service:

ProviderPurpose
Cloudflare, Inc.Hosting, storage, and content delivery
Supabase, Inc.Authentication and account identity
Anthropic, PBC / OpenAI, LLCAI widget generation (only when you use the Widget Builder)

If you choose to sign in with Google or GitHub, those providers act as your identity provider under their own privacy policies; we receive only your email address and display name from them.

8. Changes

We will post any material changes to this policy on this page with a new effective date, and notify workspace owners by email for significant changes.

9. Contact

Questions about this policy: support@appramp.dev