AppUnblock

Trust & security Guarantee & refunds Terms of service Right of withdrawal Privacy & GDPR Data processing (DPA) Legal notice Disclaimers

Your code & your idea — how we protect both

You're trusting us with the thing you've been building. Here's exactly how we handle it — and the commitments you can hold us to.

You own everything

Your app, your code, your store assets, and your idea remain 100% yours. We claim no ownership of any of it. On full payment, the specific fixes and written deliverables we produce for you are licensed to you to keep and use forever. See §6 of the Terms.

We keep it confidential, and we never reuse it

We treat your repository, build, rejection details and anything non-public about your app or business as confidential. We use them only to do the job you hired us for. We do not sell or publish them, and we do not reuse your code or build a clone of your product from your confidential materials. Everyone on our side with access is bound by confidentiality. See §6A of the Terms.

We'll sign your NDA

If you'd like a signed non-disclosure agreement before you share anything, just ask — we'll sign a reasonable one. Either yours or ours.

We take the least access possible

  • Read-only. When you connect a GitHub repo, our service account gets read access to that one repo — nothing else. It cannot push, change, merge or delete anything.
  • You stay in control. You can remove our access in one click, any time, from your own GitHub settings.
  • No passwords, ever. We never ask for your GitHub, Apple, or Google password. You invite our account; you keep yours.
  • Time-boxed. Access exists only for the duration of your job, and we remove ourselves when it closes.

If you choose "fix-by-PR" (optional)

By default, everything is read-only. If you opt in and grant write access, we may open a pull request with the fix — on its own branch, for you to review and merge. We never push to your default branch and never merge it for you; you stay in control and can close the PR or revoke access at any time.

We delete it

Any copy of your code or files we hold is deleted within 7 days of closing your engagement — sooner on request. We store encrypted at rest and persist none of your secrets. See the Privacy policy and Data Processing terms.

We never send your code to the AI

When we generate an automated fix, the AI sees only your store-rejection message and our playbook — never your source code. That text goes through our AI gateway (a route to Anthropic's Claude) as a disclosed sub-processor; it is not stored as full content (only a short, encrypted extract for up to 7 days, for routing and abuse-prevention), and Anthropic does not train its models on API traffic by default. Your repository is read only for our own inspection and is never sent to any AI. Full detail in the Privacy policy.

We log our access

What we access is logged, so there's a clear record that we only looked at what your fix actually required — protection for you, and for us.

What stays ours, and our independence

Our generic templates, playbooks, tools and methods are ours and contain none of your confidential material. Like any service provider, we may keep our general know-how and may independently build other products — but never by using your confidential code or materials. See §6B of the Terms. This is what lets us serve many founders without anyone's work touching anyone else's.


Questions about any of this before you connect a repo? Email [email protected] — we're happy to put it in writing.