Recappel helps app developers turn useful app activity into personalised stories, show them inside their
apps, and measure how customers respond. This Policy explains the information used to provide the
Recappel website, Builder application, embedded SDK and related cloud services.
Recappel is currently a developer preview. Public Production release and paid checkout are not yet
available. Descriptions of purchases and optional native features apply only when those features are
offered and enabled.
Privacy at a glance
- Developers control which permitted values their apps send and when stories appear. Recappel does
not automatically read an app's database, source code or customers' private content.
- Our servers receive pseudonymous customer identifiers, selected aggregate values and limited story
and outcome records. Pseudonymous does not mean anonymous.
- AI prepares reusable story drafts from developer-provided app context and value definitions.
Individual customers' records are not supplied to that AI workflow.
- Uploaded app icons and approved story artwork are public assets. Do not upload private images or
confidential documents as artwork.
- Optional Builder product insights and native crash reporting default off. Essential operation and
customer-story measurement are separate activities.
- We do not sell personal information or share it for cross-context behavioural advertising.
1. Who we are and whose information this covers
ARTIFACTS LLP, LLPIN ACS-5971, Bengaluru (Bangalore), Karnataka, India, provides Recappel.
Privacy, legal and data requests: contact@artifacts.software. Product support:
support@artifacts.software. Company website: artifacts.software.
Builder users and website visitors. We determine how information is used to administer your Recappel
account, provide our website, handle support, secure the service and manage our commercial
relationship. For that processing, we are the controller or data fiduciary where those legal terms apply.
Customers of a developer's app. The app developer normally determines the purpose and lawful basis
for using Recappel in its app. We process permitted customer data on that developer's instructions to
deliver and measure its stories, acting as a processor or service provider where applicable. If that
developer itself acts for another business, the contractual roles may differ. Limited processing needed
for our own security, abuse prevention and legal obligations is described separately in this Policy.
Seeing a Recappel-powered story does not create a Builder account or make you a Recappel subscriber.
Your app developer remains responsible for its app, payments and privacy notice. Contact that
developer first about its customer data; you can also contact us for help routing a request.
This Policy applies to Recappel pages that link to it. Other ARTIFACTS products have separate notices. A
data processing agreement governs processing undertaken for a developer where one is required; this
public notice does not replace it. Third-party services have their own notices for processing they
control.
2. Information provided through Builder
Account and authentication. We process your email address, account identifier, profile name and
settings, sign-in provider, session credentials and account-security records. A sign-in provider may also
supply a profile image. Supabase supports Recappel authentication and account storage. If you choose
Google Sign-In, we receive the basic identity information you authorise, not your Google password.
Password-based authentication, where offered, is handled by our authentication service; passwords
must never be sent to support or entered in story values.
Your apps and stories. We store app names, platform and package identifiers, public project keys,
integration status and timestamps, metric names and meanings, counting rules, app descriptions,
selected fonts and colours, drafts, generated proposals, edits, saved versions, publication settings and
access permissions. Information entered in these fields may reveal your business plans or app design.
Supply only information you are authorised to share.
Files and artwork. When you choose a supported image or context file, Builder reads the selected file to
perform that action. Context imports are reviewed before being saved; they do not authorise us to
inspect your computer or repository. App icons and approved story artwork are uploaded to public cloud
storage so they can be displayed. Anyone who has the asset URL may access it. URLs may contain
technical account or app identifiers. Removing an asset from a draft does not withdraw copies
referenced by saved versions or already downloaded by others.
Public store information. If you request app-icon lookup, the app may contact Apple's or Google's
public listing services using your supplied app identifier. The provider may receive your IP address and
ordinary request information. A match is not proof of app ownership or SDK integration.
Feedback and support. We process messages you deliberately submit, their category, account
association, timestamps, correspondence, attachments you choose to send through a support
channel, and internal resolution notes. In-app feedback does not automatically attach a screenshot or
customer record. Do not include credentials, payment details or customer content in a support
message unless we have arranged a necessary, secure method.
3. Information processed by the embedded SDK
The developer selects and implements the integration. Recappel does not gain unrestricted access to
the host app or its payment provider merely because the SDK is installed.
The integration can send:
- Connection identifiers: app/project key, Sandbox or Production environment, SDK and
supported-format versions, an opaque customer ID supplied by the host app, and request/cache
metadata.
- Selected values: numeric totals, latest values, maxima or approved short category tokens; metric
names, counting method, revision, period identifier and a randomly generated installation identifier.
These are selected summaries, not a recording of every action in the host app.
- Story records: whether an invitation was shown, a story opened, completed or dismissed, a
supported action was used, or an eligible customer belonged to the comparison group. Records can
include event time, story/version and experiment identifiers, group, period and the action's card
category.
- Outcome records: a configured result reported by the app, such as a renewal or another
developer-defined action, associated with the relevant pseudonymous customer and period. Where
the developer connects server reporting, records also contain a random event identifier, occurrence
time, revision and confirmation or revocation status. We do not need a raw payment-provider receipt
to accept that report.
The server receives the supplied customer and installation identifiers and uses hashed forms in
customer-measurement tables. These hashes and IDs can still be personal data. We do not attempt to
identify customers across unrelated developers' apps or build advertising profiles from them.
Billing details have a specific boundary. Full lifecycle inputs and host-provided plan/price display
information are used locally to decide when a story is appropriate and to show the customer's actual
access situation. They are not uploaded as a full billing record. However, period identifiers are
transmitted: the original integration can include an entitlement expiry timestamp, and other identifiers
can reveal a calendar month, lifecycle profile, purchase/period reference or anniversary year. It would
therefore be inaccurate to say that no billing-related information ever reaches our servers.
The intended SDK inputs exclude names, emails, phone numbers, advertising IDs, precise location,
contacts, private notes, messages, photographs, passwords, card numbers and bank credentials.
Developers must not hide such information in an otherwise valid identifier, value name or category
token. Even a number can disclose sensitive information in context; developers must assess their
selected metrics.
4. Personalisation, experiments and previews
The SDK applies the published story rules to the customer's supplied local values and billing/access
context. It may show, shorten or suppress a story when data, timing or safety conditions differ. A
configured comparison experiment assigns eligible customers to a story or comparison group and
measures the declared outcome. This is personalisation and service measurement, not an independent
determination of payment, credit, eligibility for essential services or another legally significant right.
An app-reported or developer-server-confirmed outcome is not independent verification by a bank or
app store. Group-level Results are made available to the relevant developer; they are not sold to
unrelated businesses. The app's own notice should explain its use of personalisation and experiments
and the lawful basis or choices that apply.
Sandbox testing associates a test identity with the selected app using a pairing code. Testers should
use synthetic data wherever possible. Real data in Sandbox remains subject to the same privacy
obligations; the word Sandbox does not make it anonymous.
Shared previews disclose the selected story design to people holding the preview link. Our server
stores a token hash, validity and redemption limits, and use counts, rather than the reusable secret
token itself. Recappel's preview-redemption payload does not send the recipient's customer ID or localexample values. The device renders with its local facts, and the preview does not create ordinary story
Results or activate its purchase actions. Normal network metadata may still be processed. Links can be
forwarded; expiry or revocation cannot erase a screenshot or previously downloaded copy. Any
separate poster sharing is initiated in the host app and is subject to that app's controls.
5. AI-assisted story authoring
When a developer starts story preparation or generation, our server sends bounded authoring
information to OpenAI's API. It can include the approved app description/category, metric definitions
and meanings, counting periods and units, confirmed relationships between values, answers to
clarification questions, palette choices, registered font identifiers, and artwork roles or descriptions.
The authoring workflow does not send individual customer IDs, customer-level numbers, raw
subscription records, private customer content, source code, account credentials, or uploaded image
files and their public URLs to the model. Artwork is represented by permitted registry tokens and
descriptions. Filters help enforce this boundary but cannot recognise every inappropriate statement;
developers must review their inputs and keep personal or confidential customer information out of
them.
We store the approved context, structured job/proposal information and saved drafts needed to
resume, review and use the result, plus bounded operational status, usage and cost records. We do not
deliberately persist raw provider reasoning or arbitrary raw responses as an application feature. AI is
used when authoring reusable designs, not for a separate model request every time a customer views a
story.
We do not use your submitted content to train our own general-purpose AI models. OpenAI states that
API input and output are not used for model training by default unless the API customer opts in.
Recappel requests response storage to be disabled. This is not a zero-retention guarantee: provider
abuse-monitoring logs may normally be kept for up to 30 days, with legal exceptions, and some models
may retain temporary prompt-cache state for up to 24 hours. See OpenAI's API data controls. A
separately approved zero-data-retention arrangement is not assumed.
6. Optional insights, diagnostics and notifications
Builder product insights default off. If you enable them, we collect bounded daily action counts, such as
draft saves, meaningful edits, layout selections and colour/font category changes. These records are
associated with the relevant Builder account/app but do not contain story copy, customer values,
actual colour values, font names or session replay. Disabling the option stops future optional collection;
it does not by itself erase previous records.
Essential operational records support authentication, quotas, generation jobs and costs, delivery,
security, support and fraud prevention regardless of the optional insights setting. The customer-story
receipts in Section 3 provide the developer's requested Results and are not controlled by a Builder
user's optional product-insights switch. Where the host app needs customer consent for SDK activity, it
must obtain and respect that consent separately.
Native crash reports, in builds that offer them, require a separate opt-in and default off. Firebase
Crashlytics can receive native crash traces, crash/installation identifiers, app version, crash time,
device and operating-system details. Recappel does not intentionally attach your account ID, email,
story data, credentials or custom customer content. This reporting applies to Builder, not automaticallyto developers' host apps. Opt-out disables future collection and requests removal of pending unsent
reports; it cannot recall reports already uploaded.
SDK technical diagnostics are separately enabled by the integrating developer. They send only allowed
error/stage codes, bounded counts, version and a random batch identifier for duplicate prevention, not
customer, cycle or installation IDs, raw exceptions or customer content in that payload. Network
infrastructure can still receive technical connection information.
Phone notifications require an explicit choice and operating-system permission. We register a random
device reference, notification token, platform and relevant preferences. Firebase Cloud Messaging, and
Apple's push service where applicable, deliver generic update notices. Recappel then opens the
authenticated in-app inbox to display the actual notice. Generic notices may still reveal that Recappel is
installed. You can disable phone notifications in Builder or device settings; service and security
communications may still be sent where necessary.
7. Website activity and ordinary network data
Our website is hosted using Framer. Loading a page, cloud asset, sign-in endpoint or SDK endpoint
exposes ordinary connection information to the provider serving that request, which may include an IP
address, user agent, request time, referring page, response status and security information. We use
information available to us to operate, secure and troubleshoot the service.
Website forms collect the fields and messages you choose to submit. Authentication and preferences
may use cookies, secure device storage or browser storage when those functions are used. Optional
website analytics or third-party embeds, if enabled, are governed by the choices and disclosures on the
relevant page; non-essential tracking requires consent where applicable. Framer's built-in analytics use
a cookie-free approach, but that does not establish that every ARTIFACTS page or third-party embed is
Recappel's Builder and embedded SDK do not include a third-party advertising SDK or intentionally
request an advertising identifier. Your host app or a linked external service may use other technologies
under its own policy.
8. Why we use information and the legal basis
For processing we control, the applicable legal basis depends on your location and the purpose:
- Providing the service and managing an account: performing our agreement, or taking requested
steps before it, where that basis applies. For an employee or representative of a business customer,
our legitimate interests in administering that relationship may apply instead.
- Optional insights, crash reporting, permissions and marketing: consent where required.
Withdrawing consent affects future processing and does not invalidate processing lawfully
undertaken before withdrawal. Required account notices are not marketing subscriptions.
- Security, abuse prevention, limited operational analysis and support: our legitimate interests in
providing a reliable, secure service, balanced against affected people's rights, or another permitted
basis where local law requires one.
- Legal, accounting, tax and regulatory requirements, and legal claims: compliance with applicable
obligations or the applicable basis for establishing or defending legal rights.
Where consent is the required basis, another basis in this list is not a substitute for obtaining it. You may
decline optional information or processing, but a feature cannot operate without information genuinely
needed for that feature.
For customer-app data processed on instructions, the developer is responsible for identifying and
explaining its lawful basis. Its SDK configuration or payment status is not evidence that a customer
consented.
9. Who receives information
We limit disclosures to the purpose and relevant feature:
- Supabase and its infrastructure suppliers: authentication, databases, functions, storage, story
delivery and operational services, including the permitted SDK data described above.
- OpenAI: only the authoring inputs described in Section 5 when a developer invokes that workflow.
- Google: chosen Google sign-in, requested public app-listing lookup, Firebase notification delivery
and opted-in native crash reporting. Recappel does not use Firebase Analytics for Builder product
insights.
- Apple: distribution, requested public listing lookup, platform services and push transport where
applicable.
- Framer: website delivery and the website functions described above.
- Payment providers, when paid checkout launches: Apple or Google for store purchases and
RevenueCat for Recappel Builder entitlement validation, restoration and subscription administration.
They may process store, product, transaction reference, purchase/renewal/expiry/refund status and
a Builder account reference. We do not receive full payment-card details. RevenueCat is not required
in developers' own apps, and their customer billing records are not automatically shared with it
through Recappel.
- The relevant developer and authorised personnel: app-scoped settings, reports and service
information needed for their own apps. Personnel and service providers may access information for
necessary operation or support under appropriate restrictions.
- Professional advisers, competent authorities or a business successor: where necessary for advice,
a valid legal requirement, protection from harm or abuse, a dispute, or a genuine corporate
transaction, subject to applicable safeguards and notice duties.
We do not sell personal information, share it for cross-context behavioural advertising, or authorise
processors to use customer data for their own unrelated advertising. Public artwork and intentionally
shared stories have the separate visibility described above.
10. Retention
We keep information for its stated purpose, then delete it or irreversibly de-identify it where
appropriate. Pseudonymous records do not become anonymous merely because a name is absent. The
current application retention rules are:
- Account, app context, drafts, approved versions and referenced artwork: while the account/app
and relevant feature remain in use, until deletion or the end of the applicable retention need. Saved
versions may retain artwork no longer selected in a current draft.
- Authoring job state and operational cost records: job records are marked to expire after 30 days and
are cleaned when later authoring work starts for that app or on app/account deletion. Expiry is not a
promise of physical deletion on day 30. Account-level quota/cost records currently remain until
account deletion, subject to necessary legal records.
- Customer aggregate rows and story/outcome receipts: normally 90 days from the applicable server
receipt. A newly received higher aggregate revision refreshes that aggregate row's receipt time.
Server-confirmed outcome retention uses its first receipt, not a later correction. Earlier
customer/app/account deletion also applies.
- Experiment assignments and test-identity authorisations: until the relevant customer or
app/account is deleted, or test access is revoked. These are separate from the 90-day event window.
- Deletion-suppression records: a minimal hashed customer marker remains until app/account
deletion to reject late writes and avoid restoring erased customer data.
- In-app feedback: up to 365 days from submission, or earlier account deletion. Separate email support
correspondence is retained while needed to resolve the matter and for a proportionate follow-up,
dispute or legal period.
- In-app notifications: up to 90 days. Optional daily product-insight counts use 365 daily buckets. SDK
diagnostic counters use 30 daily buckets.
- Push delivery jobs: up to seven days, with unsent jobs expiring after 24 hours. Inactive Recappel
device registrations are removed after 60 days. Provider-held installation data follows separate
provider rules.
- Shared links: until expiry, revocation or app/account deletion; a no-expiry link remains valid until
revoked or its use limit is reached. Link metadata may remain while needed to enforce limits and
ownership.
- Live-app capacity: a limited hashed grant/cooldown record can survive deletion until the existing
30-day reassignment restriction ends, without retaining the deleted story or profile.
Scheduled cleanup runs after the cutoff rather than at an exact per-record second. Backups,
hosting/security logs, legal holds and independently held provider records can follow different retention
schedules. Retained exceptions must remain restricted to their necessary purpose.
Firebase states that deletion of Crashlytics traces and associated identifiers begins after 90 days. Its
messaging installation identifiers follow a separate deletion lifecycle, which can take up to 180 days
after a provider deletion request. Disabling notifications or deleting our registration row is not the same
as deleting all Firebase-held information. See Firebase privacy and retention. OpenAI retention is
addressed in Section 5. Store purchase and required tax/accounting records may be retained for
statutory periods.
11. Deletion and your controls
Builder accounts. Use the account-deletion control or email contact@artifacts.software. We verify
authority, then remove the account and associated active app, authoring and customer records and
arrange cloud-asset deletion. Storage or network failures may require a retry; we do not treat a failed
request as completed deletion. Keep independent copies of anything you need first. Deletion is not a
guarantee that a full self-service export tool exists.
Deleting Recappel, an app project or a Builder account does not cancel a separately billed store
subscription. When paid plans are available, cancel through the store or billing provider as well. We
cannot erase independent store, sign-in-provider or host-app accounts on your behalf.
Customers of integrated apps. Ask your app developer to delete your Recappel-related data using the
same opaque identity and environment used in the integration. The SDK has a local deletion operation
and a best-effort server request; developers must handle failures and retries. A server-side deletion by
itself cannot erase an offline device. A minimal suppression record prevents later requests from
recreating erased server data.
Offline and public copies. Local state may remain until the device receives deletion, the host removes
it, or its storage is cleared. Pausing publication does not immediately erase cached content. Third-party
caches, screenshots, already shared posters and downloaded public artwork cannot reliably be
recalled. Backup removal may take longer than active-system deletion. A retention exception does not
authorise ordinary reuse of data that must remain erased or restricted.
12. Privacy rights and requests
Depending on the law that applies, you may request access to and a copy of your information,
correction, deletion, portability, restriction, or an objection to particular processing. You can withdraw
optional consent and raise a complaint. Some laws also provide authorised-agent, appeal or nomination
rights. Rights have lawful exceptions and do not grant access to another person's data or protected
trade secrets.
Email contact@artifacts.software with the subject Recappel privacy and enough detail to identify the
account or app concerned. Do not send a password, full card number or an identity document
unsolicited. We may request proportionate verification or evidence of an agent's authority. If we act only
for an app developer, we will refer the request to it and assist as required rather than disclose its
customer data to an unverified requester.
We respond within the applicable legal deadline and explain any permitted extension or refusal. Where
the GDPR or UK GDPR applies, the usual response period is one month, subject to lawful extensions and
applicable verification rules. If a US state privacy law applies to you and to our processing, its applicable
access, correction, deletion, opt-out, appeal and non-discrimination protections also apply. We do not
sell or share data for targeted advertising, so there is no such activity to opt out of in Recappel. We
honour legally applicable opt-out signals where relevant.
You may complain to the authority competent for your location, including an EEA supervisory authority,
the UK Information Commissioner's Office or an Indian authority where the relevant regime and
complaint route are in force. India-specific statutory rights apply as their provisions commence; this
Policy does not claim all provisions of the DPDP framework are already effective. An internal request
does not remove a right to seek a lawful external remedy.
13. International processing and security
ARTIFACTS is based in India. Recappel's current primary Supabase project is in the United States, and
providers or authorised support personnel can process information in other countries where they
operate. This is not a promise of India-only, EEA-only or single-country processing.
Where a transfer requires a legal safeguard, the applicable arrangement must use a permitted
mechanism, such as approved contractual clauses, a valid adequacy decision or another mechanismallowed by law. We do not claim Recappel is certified under a data privacy framework or that a provider's
certification covers us automatically. Contact us for information about the safeguards applicable to
your data. Required customer processing/transfer agreements must be settled before a restricted
transfer begins; clicking a general acceptance button is not a substitute.
We use safeguards appropriate to the service, including encrypted network transport,
account/app-scoped access controls, restricted server credentials, input validation, controlled
operator access and deletion protections. Authorised service personnel may access data when needed
for support, security or lawful operations. No network, local storage method or cloud system is perfectly
secure, and Recappel is not an end-to-end encrypted vault. Host-app storage protection also depends
on the developer's integration and device. Report a suspected breach to contact@artifacts.software.
We will investigate and make legally required notifications to affected developers, individuals or
authorities.
14. Children and sensitive information
Builder accounts are for adults aged 18 or older who are authorised to act for themselves or a business.
We do not knowingly invite children to create Builder accounts. Notify us if a child has supplied account
data so we can investigate and take appropriate action.
A host app may have a different audience. Its developer must apply the age restrictions, parental
permissions and other protections required for its customers. Do not send children's data or sensitive
regulated data through Recappel without a separately agreed, legally supported arrangement.
Recappel's standard offering does not supply a parental-consent service or a health-record compliance
agreement. The use of an opaque ID alone does not satisfy those obligations.
15. Changes and contact
We will publish a dated update if our handling of data materially changes. Where required, we will notify
affected people or developers and obtain consent before a new use. Updating this notice does not turn
optional consent into mandatory consent or authorise unrelated use of existing customer data.