Legal

Privacy Policy

Last updated 2026-09-11

A short policy for a product that collects little. The only measurement is a page count on our own server, with no cookie and no identifier; there is no advertising and no tracking of any kind, and your rendered screenshots never reach us at all — they are drawn on your machine and written straight to your disk.

Who is responsible for your data

The controller is the operator of Easy App Screens — one developer, established in Argentina, working under that name. Under the GDPR that is who decides what is described on this page and who answers for it.

The operator is an individual, so their legal name is a personal detail rather than a company registration, and it is not printed across a public site — it is given on request instead. You are entitled to know who holds your data: ask at support@easyappscreens.com and you get the full legal identity and address, without having to say why you want them.

Every question, request or complaint about your data goes to that same address, and we aim to answer within 3 business days. The product is small enough that a data protection officer is not required, and honest enough not to invent one.

What we collect, and why

Seven things, and nothing beyond them:

WhatThe detailWhy we have it
Your accountYour name, your email address, whether the address has been confirmed, and your password stored only as a salted hash we cannot reverse.To have an account at all, to let you sign in, and to send you the notices we owe you.
Your sessionsA session token, the IP address and browser user agent the session was opened from, and when it was created and expires.To keep you signed in, to let you end a session, and to detect password guessing against your account.
Your projectsThe project document — your layout, your copy, your languages, your variants — plus the captures and font files you upload.To store the work you asked us to store, so you can open the same app on another machine.
Your planThe Paddle customer, subscription and transaction identifiers, the price identifier, the plan, the status and the dates that decide access, and a count of the files you have exported. We also keep, for a while, the billing notification Paddle sends us about your account, as it arrived.To know what your account is allowed to do, to keep it correct when a payment, a cancellation or a refund happens, and to be able to explain a charge that did not do what it should have.
Server logsOrdinary web server records: request paths, status codes, timestamps, and the IP address making the request.To keep the service running and to investigate abuse or a security problem.
Error reportsWhen a page or the server fails: the error message, where in our code it happened, the page path without its query, the browser version, the time, the version of the app, and your account id if you were signed in. Never the copy you write, your captures or your exports. They stay on our own servers; no error-tracking company receives them.To find out that something broke, and fix it, before you have to write to us about it.
Page viewsA count of pages viewed, with the page, the referring site, the country, and the kind of browser and device. No cookie, no identifier stored in your browser, no IP address kept: the numbers are aggregates and none of them points back at a person or an account.To know which pages are read and which are ignored, which is the only way a one-person product decides what to write next.

When you write to us, we also have your email and whatever you told us, for as long as it takes to resolve it and to remember what we agreed.

What we do not collect

This list is short and we intend to keep it that way.

  • No third-party analytics. No Google Analytics, no session recording, no heatmaps, no A/B testing platform, and nothing that follows you to another site. The page counts described above run on Plausible on a server we operate, they set nothing in your browser, and no company receives them.
  • No advertising, no advertising identifiers, no tracking pixels, no remarketing tags, no data sold or shared with a broker.
  • No fingerprinting, and no cookie that is not needed to keep you signed in. The cookie policy lists what is set, by name.
  • No card numbers. The payment form belongs to Paddle and runs inside their frame; nothing you type into it reaches our code.
  • No exported screenshots. The rendering, the encoding and the ZIP happen in your browser, so the finished files exist on your machine and nowhere else.
  • No use of your content to train machine-learning models, ours or anyone else’s.

Who else touches it

A short list of companies, each doing one job, every one of them named on our sub-processors page with what they handle and where they are.

Beyond them, we disclose data only when the law requires it. If we ever receive a legally binding demand for your data, we will tell you unless we are prohibited from doing so.

We do not sell your data, and there is no scenario in which we would: nothing about this product’s revenue depends on it.

Where your data lives, and crossing borders

The application, the database and your uploaded files are hosted with DigitalOcean. Encrypted backups of the database and of those files are kept with Cloudflare R2 in the European Union, so that losing the server does not lose your work; they are encrypted before they leave our server, with a key Cloudflare never receives. Billing runs through Paddle in the United Kingdom and the European Union. Transactional email is delivered by Resend in the United States. The page counts run on a server the same operator rents and administers, so they reach no other company at all. We operate from Argentina, so your data is accessed from there.

For transfers out of the European Economic Area: Argentina holds an adequacy decision from the European Commission, which is the recognised basis for that particular hop. For our sub-processors in the United States we rely on the European Commission’s standard contractual clauses, which are part of their data processing terms.

How long we keep it

Long enough to do the job, and not by default forever.

WhatHow long
Your account and your projectsWhile the account exists. Deleted when you close it.
A capture or font the project stopped usingRemoved from the database and from disk about 60 minutes after the save that dropped it. The delay is deliberate: deleting the instant a file leaves the document would destroy the capture behind an undo.
SessionsUntil they expire or you sign out, whichever comes first. A password reset ends every session on the account.
Your plan recordWhile the account exists, and afterwards only where a tax or dispute obligation requires it. Paddle keeps its own record independently, as the seller.
A billing notification from PaddleDeleted 90 days after it arrives. It is what lets us explain a charge that went wrong; past that window it explains nothing that is still worth asking about.
BackupsEach backup copy of the database and of the uploaded files is deleted 30 days after it is made. A copy is never edited afterwards: it holds what existed on the day it was taken, until it expires.
Server logsOnly as long as the platform that holds them keeps them — days to weeks, long enough to investigate an incident and no longer.
Error reportsDeleted 30 days after the error happened. That is long enough to see whether a fix held.
Page viewsThe aggregate counts are kept while the product exists. There is nothing in them to delete for one person: no request is stored, only totals.
Support emailWhile the conversation is useful, and then it goes.

When you ask us to delete your account, everything above that is not held by a legal obligation is gone within 30 days. Backup copies made before the deletion still hold the account until they expire, at most 30 days later, and a backup is never restored to bring a deleted account back. Export what you want to keep before you ask.

Your rights, and how to use them

Wherever you live, you can ask us to:

  • Tell you what we hold about you, and give you a copy.
  • Correct anything that is wrong. There is no self-service edit for your name or your email address today, so write to us and we will change it — sending you to look for a button that does not exist would be worse than saying so.
  • Delete your account and everything in it.
  • Give you your content in a portable form. The studio exports the project document as JSON on its own, which is the whole design in a format you can read and re-import; the captures you uploaded are files you already have, and if you want our copies of them back, ask and we will send them.
  • Object to, or restrict, a use of your data that rests on our legitimate interests.

Write to support@easyappscreens.com from the address on the account, or from another one if you have lost access and can show the account is yours. We answer within 3 business days and complete the request within a month. If you think we have handled your data badly, tell us first — and if that does not settle it, you can complain to the Agencia de Acceso a la Información Pública in Argentina, or to the data protection authority of the country you live in.

If you are in the United States

The rights above are not limited to Europe: whatever state you are in, you can ask us what we hold, ask for a copy, ask us to correct it and ask us to delete it, and nothing you get from the product changes because you asked.

For the specific question California asks: we do not sell personal information and we do not share it for cross-context behavioural advertising. There is no advertising here to share it with, and the page counts we keep build no profile — they are totals on our own server, not a record of what you in particular read.

Nothing here decides anything about you automatically

There is no profiling, no scoring and no automated decision that produces a legal or similarly significant effect on you. The only automatic decisions in the product are what your plan allows and whether a file passes pre-flight, and both are arithmetic on numbers published in these documents.

Children

This is a tool for publishing software to app stores, and it is not directed at children. Do not create an account if you are under 16. If we learn that an account belongs to a child, we delete it.

How your data is protected

The specifics — transport encryption, how passwords are stored, how accounts are isolated from one another in every query, what uploads are checked for, and what we do if something goes wrong — are on the security page rather than summarised into vagueness here.

Changes to this policy

If this policy changes, the new text is published on this page with a new date. If a change means we start doing something materially different with data we already hold, we email account holders before it takes effect rather than relying on you to re-read the page.

Questions about any of this

Write to support@easyappscreens.com. Ask before you buy rather than after: it is a shorter conversation and nobody has to ask for a refund at the end of it.

The other documents