Recappel

Privacy Policy

Privacy Policy

Effective Date: September 15, 2026

Effective Date: September 15, 2026

Last Updated: September 15, 2026

Last Updated: September 15, 2026

Recappel helps app developers turn useful app activity into personalised stories, show them inside their

apps, and measure how customers respond. This Policy explains the information used to provide the

Recappel website, Builder application, embedded SDK and related cloud services.


Recappel is currently a developer preview. Public Production release and paid checkout are not yet

available. Descriptions of purchases and optional native features apply only when those features are

offered and enabled.


Privacy at a glance


- Developers control which permitted values their apps send and when stories appear. Recappel does

not automatically read an app's database, source code or customers' private content.


- Our servers receive pseudonymous customer identifiers, selected aggregate values and limited story

and outcome records. Pseudonymous does not mean anonymous.


- AI prepares reusable story drafts from developer-provided app context and value definitions.

Individual customers' records are not supplied to that AI workflow.


- Uploaded app icons and approved story artwork are public assets. Do not upload private images or

confidential documents as artwork.


- Optional Builder product insights and native crash reporting default off. Essential operation and

customer-story measurement are separate activities.


- We do not sell personal information or share it for cross-context behavioural advertising.


1. Who we are and whose information this covers


ARTIFACTS LLP, LLPIN ACS-5971, Bengaluru (Bangalore), Karnataka, India, provides Recappel.


Privacy, legal and data requests: contact@artifacts.software. Product support:

support@artifacts.software. Company website: artifacts.software.


Builder users and website visitors. We determine how information is used to administer your Recappel

account, provide our website, handle support, secure the service and manage our commercial

relationship. For that processing, we are the controller or data fiduciary where those legal terms apply.


Customers of a developer's app. The app developer normally determines the purpose and lawful basis

for using Recappel in its app. We process permitted customer data on that developer's instructions to

deliver and measure its stories, acting as a processor or service provider where applicable. If that

developer itself acts for another business, the contractual roles may differ. Limited processing needed

for our own security, abuse prevention and legal obligations is described separately in this Policy.


Seeing a Recappel-powered story does not create a Builder account or make you a Recappel subscriber.

Your app developer remains responsible for its app, payments and privacy notice. Contact that

developer first about its customer data; you can also contact us for help routing a request.


This Policy applies to Recappel pages that link to it. Other ARTIFACTS products have separate notices. A

data processing agreement governs processing undertaken for a developer where one is required; this

public notice does not replace it. Third-party services have their own notices for processing they

control.


2. Information provided through Builder


Account and authentication. We process your email address, account identifier, profile name and

settings, sign-in provider, session credentials and account-security records. A sign-in provider may also

supply a profile image. Supabase supports Recappel authentication and account storage. If you choose

Google Sign-In, we receive the basic identity information you authorise, not your Google password.

Password-based authentication, where offered, is handled by our authentication service; passwords

must never be sent to support or entered in story values.


Your apps and stories. We store app names, platform and package identifiers, public project keys,

integration status and timestamps, metric names and meanings, counting rules, app descriptions,

selected fonts and colours, drafts, generated proposals, edits, saved versions, publication settings and

access permissions. Information entered in these fields may reveal your business plans or app design.

Supply only information you are authorised to share.


Files and artwork. When you choose a supported image or context file, Builder reads the selected file to

perform that action. Context imports are reviewed before being saved; they do not authorise us to

inspect your computer or repository. App icons and approved story artwork are uploaded to public cloud

storage so they can be displayed. Anyone who has the asset URL may access it. URLs may contain

technical account or app identifiers. Removing an asset from a draft does not withdraw copies

referenced by saved versions or already downloaded by others.


Public store information. If you request app-icon lookup, the app may contact Apple's or Google's

public listing services using your supplied app identifier. The provider may receive your IP address and

ordinary request information. A match is not proof of app ownership or SDK integration.


Feedback and support. We process messages you deliberately submit, their category, account

association, timestamps, correspondence, attachments you choose to send through a support

channel, and internal resolution notes. In-app feedback does not automatically attach a screenshot or

customer record. Do not include credentials, payment details or customer content in a support

message unless we have arranged a necessary, secure method.


3. Information processed by the embedded SDK

The developer selects and implements the integration. Recappel does not gain unrestricted access to

the host app or its payment provider merely because the SDK is installed.

The integration can send:

- Connection identifiers: app/project key, Sandbox or Production environment, SDK and

supported-format versions, an opaque customer ID supplied by the host app, and request/cache

metadata.

- Selected values: numeric totals, latest values, maxima or approved short category tokens; metric

names, counting method, revision, period identifier and a randomly generated installation identifier.

These are selected summaries, not a recording of every action in the host app.

- Story records: whether an invitation was shown, a story opened, completed or dismissed, a

supported action was used, or an eligible customer belonged to the comparison group. Records can

include event time, story/version and experiment identifiers, group, period and the action's card

category.

- Outcome records: a configured result reported by the app, such as a renewal or another

developer-defined action, associated with the relevant pseudonymous customer and period. Where

the developer connects server reporting, records also contain a random event identifier, occurrence

time, revision and confirmation or revocation status. We do not need a raw payment-provider receipt

to accept that report.

The server receives the supplied customer and installation identifiers and uses hashed forms in

customer-measurement tables. These hashes and IDs can still be personal data. We do not attempt to

identify customers across unrelated developers' apps or build advertising profiles from them.

Billing details have a specific boundary. Full lifecycle inputs and host-provided plan/price display

information are used locally to decide when a story is appropriate and to show the customer's actual

access situation. They are not uploaded as a full billing record. However, period identifiers are

transmitted: the original integration can include an entitlement expiry timestamp, and other identifiers

can reveal a calendar month, lifecycle profile, purchase/period reference or anniversary year. It would

therefore be inaccurate to say that no billing-related information ever reaches our servers.

The intended SDK inputs exclude names, emails, phone numbers, advertising IDs, precise location,

contacts, private notes, messages, photographs, passwords, card numbers and bank credentials.

Developers must not hide such information in an otherwise valid identifier, value name or category

token. Even a number can disclose sensitive information in context; developers must assess their

selected metrics.

4. Personalisation, experiments and previews

The SDK applies the published story rules to the customer's supplied local values and billing/access

context. It may show, shorten or suppress a story when data, timing or safety conditions differ. A

configured comparison experiment assigns eligible customers to a story or comparison group and

measures the declared outcome. This is personalisation and service measurement, not an independent

determination of payment, credit, eligibility for essential services or another legally significant right.

An app-reported or developer-server-confirmed outcome is not independent verification by a bank or

app store. Group-level Results are made available to the relevant developer; they are not sold to

unrelated businesses. The app's own notice should explain its use of personalisation and experiments

and the lawful basis or choices that apply.

Sandbox testing associates a test identity with the selected app using a pairing code. Testers should

use synthetic data wherever possible. Real data in Sandbox remains subject to the same privacy

obligations; the word Sandbox does not make it anonymous.

Shared previews disclose the selected story design to people holding the preview link. Our server

stores a token hash, validity and redemption limits, and use counts, rather than the reusable secret

token itself. Recappel's preview-redemption payload does not send the recipient's customer ID or localexample values. The device renders with its local facts, and the preview does not create ordinary story

Results or activate its purchase actions. Normal network metadata may still be processed. Links can be

forwarded; expiry or revocation cannot erase a screenshot or previously downloaded copy. Any

separate poster sharing is initiated in the host app and is subject to that app's controls.

5. AI-assisted story authoring

When a developer starts story preparation or generation, our server sends bounded authoring

information to OpenAI's API. It can include the approved app description/category, metric definitions

and meanings, counting periods and units, confirmed relationships between values, answers to

clarification questions, palette choices, registered font identifiers, and artwork roles or descriptions.

The authoring workflow does not send individual customer IDs, customer-level numbers, raw

subscription records, private customer content, source code, account credentials, or uploaded image

files and their public URLs to the model. Artwork is represented by permitted registry tokens and

descriptions. Filters help enforce this boundary but cannot recognise every inappropriate statement;

developers must review their inputs and keep personal or confidential customer information out of

them.

We store the approved context, structured job/proposal information and saved drafts needed to

resume, review and use the result, plus bounded operational status, usage and cost records. We do not

deliberately persist raw provider reasoning or arbitrary raw responses as an application feature. AI is

used when authoring reusable designs, not for a separate model request every time a customer views a

story.

We do not use your submitted content to train our own general-purpose AI models. OpenAI states that

API input and output are not used for model training by default unless the API customer opts in.

Recappel requests response storage to be disabled. This is not a zero-retention guarantee: provider

abuse-monitoring logs may normally be kept for up to 30 days, with legal exceptions, and some models

may retain temporary prompt-cache state for up to 24 hours. See OpenAI's API data controls. A

separately approved zero-data-retention arrangement is not assumed.

6. Optional insights, diagnostics and notifications

Builder product insights default off. If you enable them, we collect bounded daily action counts, such as

draft saves, meaningful edits, layout selections and colour/font category changes. These records are

associated with the relevant Builder account/app but do not contain story copy, customer values,

actual colour values, font names or session replay. Disabling the option stops future optional collection;

it does not by itself erase previous records.

Essential operational records support authentication, quotas, generation jobs and costs, delivery,

security, support and fraud prevention regardless of the optional insights setting. The customer-story

receipts in Section 3 provide the developer's requested Results and are not controlled by a Builder

user's optional product-insights switch. Where the host app needs customer consent for SDK activity, it

must obtain and respect that consent separately.

Native crash reports, in builds that offer them, require a separate opt-in and default off. Firebase

Crashlytics can receive native crash traces, crash/installation identifiers, app version, crash time,

device and operating-system details. Recappel does not intentionally attach your account ID, email,

story data, credentials or custom customer content. This reporting applies to Builder, not automaticallyto developers' host apps. Opt-out disables future collection and requests removal of pending unsent

reports; it cannot recall reports already uploaded.

SDK technical diagnostics are separately enabled by the integrating developer. They send only allowed

error/stage codes, bounded counts, version and a random batch identifier for duplicate prevention, not

customer, cycle or installation IDs, raw exceptions or customer content in that payload. Network

infrastructure can still receive technical connection information.

Phone notifications require an explicit choice and operating-system permission. We register a random

device reference, notification token, platform and relevant preferences. Firebase Cloud Messaging, and

Apple's push service where applicable, deliver generic update notices. Recappel then opens the

authenticated in-app inbox to display the actual notice. Generic notices may still reveal that Recappel is

installed. You can disable phone notifications in Builder or device settings; service and security

communications may still be sent where necessary.

7. Website activity and ordinary network data

Our website is hosted using Framer. Loading a page, cloud asset, sign-in endpoint or SDK endpoint

exposes ordinary connection information to the provider serving that request, which may include an IP

address, user agent, request time, referring page, response status and security information. We use

information available to us to operate, secure and troubleshoot the service.

Website forms collect the fields and messages you choose to submit. Authentication and preferences

may use cookies, secure device storage or browser storage when those functions are used. Optional

website analytics or third-party embeds, if enabled, are governed by the choices and disclosures on the

relevant page; non-essential tracking requires consent where applicable. Framer's built-in analytics use

a cookie-free approach, but that does not establish that every ARTIFACTS page or third-party embed is

cookie-free. See Framer's privacy information.

Recappel's Builder and embedded SDK do not include a third-party advertising SDK or intentionally

request an advertising identifier. Your host app or a linked external service may use other technologies

under its own policy.

8. Why we use information and the legal basis

For processing we control, the applicable legal basis depends on your location and the purpose:

- Providing the service and managing an account: performing our agreement, or taking requested

steps before it, where that basis applies. For an employee or representative of a business customer,

our legitimate interests in administering that relationship may apply instead.

- Optional insights, crash reporting, permissions and marketing: consent where required.

Withdrawing consent affects future processing and does not invalidate processing lawfully

undertaken before withdrawal. Required account notices are not marketing subscriptions.

- Security, abuse prevention, limited operational analysis and support: our legitimate interests in

providing a reliable, secure service, balanced against affected people's rights, or another permitted

basis where local law requires one.

- Legal, accounting, tax and regulatory requirements, and legal claims: compliance with applicable

obligations or the applicable basis for establishing or defending legal rights.

Where consent is the required basis, another basis in this list is not a substitute for obtaining it. You may

decline optional information or processing, but a feature cannot operate without information genuinely

needed for that feature.

For customer-app data processed on instructions, the developer is responsible for identifying and

explaining its lawful basis. Its SDK configuration or payment status is not evidence that a customer

consented.

9. Who receives information

We limit disclosures to the purpose and relevant feature:

- Supabase and its infrastructure suppliers: authentication, databases, functions, storage, story

delivery and operational services, including the permitted SDK data described above.

- OpenAI: only the authoring inputs described in Section 5 when a developer invokes that workflow.

- Google: chosen Google sign-in, requested public app-listing lookup, Firebase notification delivery

and opted-in native crash reporting. Recappel does not use Firebase Analytics for Builder product

insights.

- Apple: distribution, requested public listing lookup, platform services and push transport where

applicable.

- Framer: website delivery and the website functions described above.

- Payment providers, when paid checkout launches: Apple or Google for store purchases and

RevenueCat for Recappel Builder entitlement validation, restoration and subscription administration.

They may process store, product, transaction reference, purchase/renewal/expiry/refund status and

a Builder account reference. We do not receive full payment-card details. RevenueCat is not required

in developers' own apps, and their customer billing records are not automatically shared with it

through Recappel.

- The relevant developer and authorised personnel: app-scoped settings, reports and service

information needed for their own apps. Personnel and service providers may access information for

necessary operation or support under appropriate restrictions.

- Professional advisers, competent authorities or a business successor: where necessary for advice,

a valid legal requirement, protection from harm or abuse, a dispute, or a genuine corporate

transaction, subject to applicable safeguards and notice duties.

We do not sell personal information, share it for cross-context behavioural advertising, or authorise

processors to use customer data for their own unrelated advertising. Public artwork and intentionally

shared stories have the separate visibility described above.

10. Retention

We keep information for its stated purpose, then delete it or irreversibly de-identify it where

appropriate. Pseudonymous records do not become anonymous merely because a name is absent. The

current application retention rules are:

- Account, app context, drafts, approved versions and referenced artwork: while the account/app

and relevant feature remain in use, until deletion or the end of the applicable retention need. Saved

versions may retain artwork no longer selected in a current draft.

- Authoring job state and operational cost records: job records are marked to expire after 30 days and

are cleaned when later authoring work starts for that app or on app/account deletion. Expiry is not a

promise of physical deletion on day 30. Account-level quota/cost records currently remain until

account deletion, subject to necessary legal records.

- Customer aggregate rows and story/outcome receipts: normally 90 days from the applicable server

receipt. A newly received higher aggregate revision refreshes that aggregate row's receipt time.

Server-confirmed outcome retention uses its first receipt, not a later correction. Earlier

customer/app/account deletion also applies.

- Experiment assignments and test-identity authorisations: until the relevant customer or

app/account is deleted, or test access is revoked. These are separate from the 90-day event window.

- Deletion-suppression records: a minimal hashed customer marker remains until app/account

deletion to reject late writes and avoid restoring erased customer data.

- In-app feedback: up to 365 days from submission, or earlier account deletion. Separate email support

correspondence is retained while needed to resolve the matter and for a proportionate follow-up,

dispute or legal period.

- In-app notifications: up to 90 days. Optional daily product-insight counts use 365 daily buckets. SDK

diagnostic counters use 30 daily buckets.

- Push delivery jobs: up to seven days, with unsent jobs expiring after 24 hours. Inactive Recappel

device registrations are removed after 60 days. Provider-held installation data follows separate

provider rules.

- Shared links: until expiry, revocation or app/account deletion; a no-expiry link remains valid until

revoked or its use limit is reached. Link metadata may remain while needed to enforce limits and

ownership.

- Live-app capacity: a limited hashed grant/cooldown record can survive deletion until the existing

30-day reassignment restriction ends, without retaining the deleted story or profile.

Scheduled cleanup runs after the cutoff rather than at an exact per-record second. Backups,

hosting/security logs, legal holds and independently held provider records can follow different retention

schedules. Retained exceptions must remain restricted to their necessary purpose.

Firebase states that deletion of Crashlytics traces and associated identifiers begins after 90 days. Its

messaging installation identifiers follow a separate deletion lifecycle, which can take up to 180 days

after a provider deletion request. Disabling notifications or deleting our registration row is not the same

as deleting all Firebase-held information. See Firebase privacy and retention. OpenAI retention is

addressed in Section 5. Store purchase and required tax/accounting records may be retained for

statutory periods.

11. Deletion and your controls

Builder accounts. Use the account-deletion control or email contact@artifacts.software. We verify

authority, then remove the account and associated active app, authoring and customer records and

arrange cloud-asset deletion. Storage or network failures may require a retry; we do not treat a failed

request as completed deletion. Keep independent copies of anything you need first. Deletion is not a

guarantee that a full self-service export tool exists.

Deleting Recappel, an app project or a Builder account does not cancel a separately billed store

subscription. When paid plans are available, cancel through the store or billing provider as well. We

cannot erase independent store, sign-in-provider or host-app accounts on your behalf.

Customers of integrated apps. Ask your app developer to delete your Recappel-related data using the

same opaque identity and environment used in the integration. The SDK has a local deletion operation

and a best-effort server request; developers must handle failures and retries. A server-side deletion by

itself cannot erase an offline device. A minimal suppression record prevents later requests from

recreating erased server data.

Offline and public copies. Local state may remain until the device receives deletion, the host removes

it, or its storage is cleared. Pausing publication does not immediately erase cached content. Third-party

caches, screenshots, already shared posters and downloaded public artwork cannot reliably be

recalled. Backup removal may take longer than active-system deletion. A retention exception does not

authorise ordinary reuse of data that must remain erased or restricted.

12. Privacy rights and requests

Depending on the law that applies, you may request access to and a copy of your information,

correction, deletion, portability, restriction, or an objection to particular processing. You can withdraw

optional consent and raise a complaint. Some laws also provide authorised-agent, appeal or nomination

rights. Rights have lawful exceptions and do not grant access to another person's data or protected

trade secrets.

Email contact@artifacts.software with the subject Recappel privacy and enough detail to identify the

account or app concerned. Do not send a password, full card number or an identity document

unsolicited. We may request proportionate verification or evidence of an agent's authority. If we act only

for an app developer, we will refer the request to it and assist as required rather than disclose its

customer data to an unverified requester.

We respond within the applicable legal deadline and explain any permitted extension or refusal. Where

the GDPR or UK GDPR applies, the usual response period is one month, subject to lawful extensions and

applicable verification rules. If a US state privacy law applies to you and to our processing, its applicable

access, correction, deletion, opt-out, appeal and non-discrimination protections also apply. We do not

sell or share data for targeted advertising, so there is no such activity to opt out of in Recappel. We

honour legally applicable opt-out signals where relevant.

You may complain to the authority competent for your location, including an EEA supervisory authority,

the UK Information Commissioner's Office or an Indian authority where the relevant regime and

complaint route are in force. India-specific statutory rights apply as their provisions commence; this

Policy does not claim all provisions of the DPDP framework are already effective. An internal request

does not remove a right to seek a lawful external remedy.

13. International processing and security

ARTIFACTS is based in India. Recappel's current primary Supabase project is in the United States, and

providers or authorised support personnel can process information in other countries where they

operate. This is not a promise of India-only, EEA-only or single-country processing.

Where a transfer requires a legal safeguard, the applicable arrangement must use a permitted

mechanism, such as approved contractual clauses, a valid adequacy decision or another mechanismallowed by law. We do not claim Recappel is certified under a data privacy framework or that a provider's

certification covers us automatically. Contact us for information about the safeguards applicable to

your data. Required customer processing/transfer agreements must be settled before a restricted

transfer begins; clicking a general acceptance button is not a substitute.

We use safeguards appropriate to the service, including encrypted network transport,

account/app-scoped access controls, restricted server credentials, input validation, controlled

operator access and deletion protections. Authorised service personnel may access data when needed

for support, security or lawful operations. No network, local storage method or cloud system is perfectly

secure, and Recappel is not an end-to-end encrypted vault. Host-app storage protection also depends

on the developer's integration and device. Report a suspected breach to contact@artifacts.software.

We will investigate and make legally required notifications to affected developers, individuals or

authorities.

14. Children and sensitive information

Builder accounts are for adults aged 18 or older who are authorised to act for themselves or a business.

We do not knowingly invite children to create Builder accounts. Notify us if a child has supplied account

data so we can investigate and take appropriate action.

A host app may have a different audience. Its developer must apply the age restrictions, parental

permissions and other protections required for its customers. Do not send children's data or sensitive

regulated data through Recappel without a separately agreed, legally supported arrangement.

Recappel's standard offering does not supply a parental-consent service or a health-record compliance

agreement. The use of an opaque ID alone does not satisfy those obligations.

15. Changes and contact

We will publish a dated update if our handling of data materially changes. Where required, we will notify

affected people or developers and obtain consent before a new use. Updating this notice does not turn

optional consent into mandatory consent or authorise unrelated use of existing customer data.

ARTIFACTS LLP

ARTIFACTS LLP

Email: support@artifacts.software

Email: support@artifacts.software