Privacy Policy
What we collect, why we collect it, who else sees it, and how long we keep it.
Last updated September 9, 2026
Operator: AppReady, contactable at support@appready.tech. Full registration details are available on request.
The short version
We store your email address, the sites you ask us to scan, and the reports we produce. You sign in with Google, so we hold no password of yours at all. We do not run advertising or analytics trackers. We never store the passwords, tokens, cookies or authorisation headers belonging to the sites we scan. You can have everything deleted by asking.
Who is responsible
AppReady is the controller of the personal data described here. Write to support@appready.tech about anything on this page.
What we collect
When you sign in
Signing in is done through Google, and it is the only way in. We ask Google for three things and nothing else: your email address, your first name, and the account identifier Google uses for you. We never see your Google password, and we have no access to your Gmail, Drive, contacts or anything else in your Google account.
There is no password on our side to store, to leak, or to reset. What we keep is:
- Your email address, and the first name Google gave us.
- Google’s account identifier for you, so that we recognise you next time even if you later change the address on your Google account.
- Sign-in sessions: an identifier per device, the browser’s user agent, an approximate location derived from the IP address, and the time it was last used — so that you can see and revoke your own sessions in settings.
- Whether you want an email when a scan finishes.
When you run a scan
- The address you asked us to scan and the address it finally resolved to.
- The findings: what was measured, the evidence for each issue, and the scores. Evidence comes from what the site returns publicly — response headers, HTML, script files, console errors.
- A screenshot of the scanned page.
- How long the scan took and whether it failed.
Before anything is stored, sensitive values are removed at the point they are read: authorization and cookie headers and other credential-shaped headers are dropped entirely, credential-shaped query parameters are replaced, and any secret we detect is reduced to a masked fragment such as sk_l…8f2a. The full value never leaves the process that found it, so it is never written to the database, to a log, or into an AI prompt.
When you scan without an account
The public scanner on the home page does not need an account. For it we store the address scanned, the report, and a one-way hash of your IP address — used only to stop one visitor from consuming the service for everyone. We do not keep the IP address itself.
When you pay
We never see your card. Payment is handled by Paddle, which acts as merchant of record. From Paddle we receive your subscription status, plan, renewal date and the identifiers needed to keep your account in sync — not your payment details.
Server logs
Our servers keep short-lived operational logs: request paths, status codes and timings. Passwords, tokens, authorisation headers, cookies and API keys are excluded from logs by design.
Why we are allowed to hold it
- To provide the service you asked for
- Account data and scan results — performance of our contract with you. Without them the product does not work.
- To keep the service standing up
- Rate limits, hashed IPs for anonymous scans, and abuse prevention — our legitimate interest in a service that is not overwhelmed or misused.
- To bill you
- Subscription records — performance of the contract, and our legal obligations.
- To email you
- Service email — scan-finished alerts you switched on, and anything we must tell you about your account or your subscription. We do not send marketing email.
Who else sees it
- DeepSeek — when you open a finding’s details, or ask for an AI fix prompt, the text of that finding is sent to the DeepSeek API to be written up in plain language. What is sent is the finding itself: its title, its description, the technical evidence already shown to you on screen, and the technologies detected on the site. Your email address is not sent, and neither is any secret we detected — that is already reduced to a masked fragment before this point. The result is cached, so reopening the same finding does not send it again.
- Paddle — payment processing and merchant of record, as above.
- Hosting — the application and its database run on a virtual server we rent from Hostinger, in Frankfurt, Germany.
- Google — sign-in. Google learns that you signed in to AppReady, in the same way it does for any site you use it on. We receive an identity from Google; we send it nothing about you.
- Email delivery — the provider that delivers our service email receives the recipient address and the message.
We do not sell personal data, we do not share it for advertising, and we do not use it to train models.
Sending data outside Europe
Your account and your reports are stored in Germany. Two things leave it: the finding text sent to DeepSeek, whose service is operated from China, and payment data handled by Paddle. Nothing about your site reaches an AI provider unless you open a finding’s details or ask for a fix prompt; the scan itself, the scores and the report do not.
Cookies
We set two cookies, both strictly necessary and both httpOnly, meaning JavaScript cannot read them: a short-lived session cookie that keeps you signed in, and a longer-lived one that renews it. There is no analytics cookie, no advertising cookie and no third-party tracker, which is why you are not asked to consent to any.
On billing pages we load Paddle’s checkout script, which may set its own cookies for the payment. That is governed by Paddle’s privacy policy.
How long we keep things
- Scan history — for as long as your plan provides: 30 days on Free, 6 months on Pro, 12 months on Pro+. Older scans are deleted nightly. The most recent completed scan of a project you still have is always kept, whatever its age.
- Screenshots — deleted after 30 days on every plan.
- Anonymous scans — deleted after 7 days, together with the hashed IP.
- Account data — until you ask us to delete the account.
- Billing records — retained as long as tax and accounting law requires, even after the account is closed.
Your rights
You can ask for a copy of your data, correct it, have it deleted, object to processing based on legitimate interest, or ask us to hand it over in a portable form. Email support@appready.tech and we will answer within 30 days.
Deleting your account is not yet self-service. Ask us and we will remove your account, your projects, your scans and your reports within one working day, and confirm when it is done. If you are in the UK, EU or a country with a data protection authority, you may also complain to it.
Security
Traffic is served over HTTPS. Because sign-in goes through Google, there is no password here to be stolen. Session tokens are stored hashed, rotate on every use, and a reused token invalidates the whole family of sessions it belongs to. The scanner refuses to reach private networks, loopback addresses and cloud metadata endpoints, re-checking after every redirect. No system is perfect; if you find a problem in ours, please tell us at support@appready.tech and we will treat it seriously.
Children
The service is not intended for children, and we do not knowingly collect their data.
Changes
If this policy changes materially we will tell registered users by email. The date at the top always shows the current version. See also our terms of service.