Legal
Privacy Policy.
Last updated: March 30, 2026
1. Introduction
AppMuse is operated by SaaS Factory Sweden AB ("Company", "we", "us", "our"), a company registered in Sweden. AppMuse is an AI-powered application builder that generates native mobile applications (Flutter, Kotlin/Android, Swift/iOS) and their backends from natural language descriptions. This Privacy Policy explains how we collect, use, and protect your information when you use our service, in accordance with the EU General Data Protection Regulation (GDPR) and applicable Swedish law.
2. Information We Collect
Account Information
When you create an account, we collect:
- Email address
- Name (if provided)
- Password (stored securely hashed)
- GitHub account details (if you connect GitHub integration)
Project Data
When you use AppMuse to build applications, we process:
- Your natural language prompts and messages to the AI
- Generated source code (Flutter/Dart, Kotlin/Android, Swift/iOS, and backend code)
- Project configuration and metadata
- Images you upload as part of your prompts
Technical Data
- IP address and browser information
- Usage patterns (features used, session duration)
- Error logs and performance data
3. How We Use Your Information
- To provide and operate the AppMuse platform
- To process your prompts through our AI system and generate application code
- To run your projects in isolated Docker containers
- To sync your code with GitHub when you enable this feature
- To improve our AI models and platform quality
- To communicate with you about your account and service updates
- To detect and prevent abuse or misuse of the platform
4. AI Processing
Your prompts and project context are sent to third-party AI providers — Anthropic (Claude), OpenAI (GPT), Google (Gemini), and xAI (Grok 4.5) — to generate code and responses. These providers are US-based; see the "International Data Transfers" section below for the safeguards that apply. Your conversation data may be used in anonymized and aggregated form to improve our AI models and service quality. You can request deletion of your data at any time by contacting us at privacy@appmuse.dev or through your account settings. The AI processes your input in real-time to generate responses relevant to your project.
5. Code Ownership & Storage
All source code generated by AppMuse belongs to you. Your project files are stored in isolated Docker containers with dedicated storage volumes. When you delete a project, its container and associated data are permanently removed.
If you connect GitHub, your code is synced to your own GitHub repository under your account. We do not retain copies of code pushed to GitHub beyond the active container.
6. Data Security
We protect your data through:
- Isolated Docker containers per project with memory and CPU limits
- Encrypted connections (HTTPS/TLS) for all data in transit
- Encryption at rest for stored data
- Hashed passwords using industry-standard algorithms
- Scoped database schemas per project preventing cross-project access
- GitHub access tokens stored encrypted and scoped to minimum required permissions
- Third-party API keys stored encrypted in our database
7. Third-Party Services
We use the following third-party services (processors and recipients) to operate AppMuse. This list is kept consistent with the third-party table in our Cookie Policy:
- Anthropic (US) — AI model provider (Claude) for code generation
- OpenAI (US) — AI model provider (GPT) for code generation
- Google (Gemini) (US) — AI model provider for code generation
- xAI (Grok 4.5) (US) — AI model provider for code generation
- Cloudflare — CDN, edge delivery, DDoS protection, and bot mitigation
- Sentry — Error and performance monitoring (consent-gated; see our Cookie Policy)
- Google Fonts — Web font delivery (your IP address is visible to Google when fonts are fetched)
- Stripe — Payment processing and subscription management
- GitHub — Optional code repository integration
- Docker — Container runtime for project isolation
- PostgreSQL — Database for account and project metadata
- Redis — Caching and session management
Additionally, users may optionally connect their own third-party services through the Connectors panel. These user-connected integrations include Firebase, Google Maps, OneSignal, Cloudinary, Resend, RevenueCat, and Sentry. These services are connected at the user's discretion and are governed by their respective privacy policies.
8. Legal Basis for Processing
Under GDPR Article 6, we rely on the following legal bases to process your personal data, depending on the purpose:
- Performance of a contract (Art 6(1)(b)) — delivering the AppMuse service to you: creating and maintaining your account, processing your prompts and generating application code, running and previewing your projects, GitHub syncing you enable, and handling billing and subscriptions.
- Legitimate interests (Art 6(1)(f)) — securing the platform, preventing abuse and fraud, enforcing usage limits, monitoring for errors and performance issues, and improving our AI models and product quality (using anonymized and aggregated data where possible). You may object to processing based on legitimate interests as described in the "Your Rights" section.
- Consent (Art 6(1)(a)) — where applicable, for optional, non-essential processing such as analytics and performance monitoring (Sentry) and any future marketing communications. You can grant or withdraw consent at any time through the Cookie Settings dialog or your account settings.
- Legal obligation (Art 6(1)(c)) — retaining billing and invoice records to comply with Swedish accounting law (see the "Data Retention" section).
9. International Data Transfers
Platform data — your account, project metadata, generated code storage, and databases — is hosted on servers located within the EU. However, AI inference is performed by US-based providers: your prompts and project context (and the resulting generated code) are transferred to Anthropic, OpenAI, Google (Gemini), and xAI (Grok 4.5) in the United States so they can generate responses in real time.
These transfers to third countries are made under appropriate safeguards required by GDPR Chapter V, namely the European Commission's Standard Contractual Clauses (SCCs) or another valid Article 46 transfer mechanism offered by each provider. In other words, EU hosting applies to your stored platform data, while AI processing may occur in the US under SCCs. If you would like a copy of the relevant safeguards, contact us at privacy@appmuse.dev.
10. Credits & Usage Tracking
We track token usage for billing purposes. This includes which AI model was used for each request, the number of input and output tokens consumed, and the corresponding credit consumption. This data is associated with your account to calculate billing, enforce plan limits, and provide usage transparency through your account dashboard. Usage data is retained for the duration of your account; where it forms part of billing or invoice records, it is kept for 7 years to comply with Swedish accounting law, as described in the "Data Retention" section.
11. Companion Desktop App
AppMuse offers an optional companion desktop application that accesses local Android emulators and USB-connected devices on your computer for live preview of your projects. Screen content from the emulator or device is streamed to the browser to provide a real-time preview experience. No personal data from the connected device is collected, stored, or transmitted to our servers. The desktop app only facilitates the connection between your local device and the AppMuse web platform.
12. Third-Party Integrations (Connectors)
When you connect third-party services such as Firebase, Google Maps, OneSignal, Cloudinary, Resend, RevenueCat, or Sentry through the Connectors panel, your API keys and credentials for those services are stored encrypted in our database. These keys are injected into your project containers solely to enable the connected service within your project. We do not access or use these keys for any purpose other than enabling the connected service. You can disconnect any integration and remove the stored credentials at any time.
13. Data Retention
We retain personal data only as long as necessary for the purpose it was collected. In practice:
- Account and project data — retained for the duration of your account. Project data is retained while the project exists; when you delete a project, its data is permanently removed within 24 hours. If you delete your account, all associated account and project data is removed within 30 days of account deletion.
- Billing and invoice records — retained for 7 years to comply with the Swedish Bookkeeping Act (Bokföringslagen). These records are kept even after account deletion for the duration of this statutory period.
- Technical and error logs — retained for a short, defined period (up to 90 days) for security, debugging, and abuse-prevention purposes, then deleted or anonymized.
- Aggregated and anonymized analytics — retained indefinitely, as this data no longer identifies you and is therefore no longer personal data.
14. Your Rights
Under the GDPR and applicable data protection laws, you have the right to:
- Access and export all your project source code at any time
- Delete your projects and their associated data
- Delete your account and all associated information
- Request a copy of your personal data (right of access)
- Right to data portability — export all your data in a structured, commonly used format
- Right to erasure — request deletion of all your personal data
- Right to restriction of processing — request that we limit how we process your data
- Right to rectification — correct inaccurate personal data
- Right to object to processing based on legitimate interests
- Opt out of non-essential communications
- Right to lodge a complaint with a supervisory authority — in Sweden, this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at www.imy.se
To exercise any of these rights, contact us at privacy@appmuse.dev.
15. Cookies
We use essential cookies for authentication and session management. We also store your theme preference (light/dark mode) in your browser's local storage. We do not use third-party tracking cookies.
16. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes by email or through a notice on our platform. Your continued use of AppMuse after changes constitutes acceptance of the updated policy.
17. Contact & Data Controller
The data controller for the purposes of GDPR is:
- SaaS Factory Sweden AB
- Reg. no.: 559162-8168
- Registered address: Skarplöts Allé 31, 137 43 Västerhaninge, Sweden
- Contact: privacy@appmuse.dev
We have not appointed a Data Protection Officer, as we are not required to under GDPR Article 37. Privacy questions go to privacy@appmuse.dev.
If you have questions about this Privacy Policy or wish to exercise your data protection rights, contact us at privacy@appmuse.dev.