legal

Privacy Policy

last-updated: May 31, 2026

This policy describes how AppMeta (the desktop application) handles information when you use it. It applies to the AppMeta app itself — not to privacy policies you generate for your own apps using AppMeta.

Summary

  • AppMeta scans project files locally on your device.
  • Your full codebase is not uploaded to AppMeta servers — we do not operate cloud storage for your projects.
  • When you generate content, confirmed facts from your project truth file are sent to your chosen AI provider using your API key.
  • We do not currently collect analytics or telemetry in the app.

Information processed locally

When you connect a project folder, AppMeta reads files on your machine to extract facts, such as:

  • Package manifests (e.g. pubspec.yaml, package.json)
  • Platform config (e.g. Info.plist, AndroidManifest.xml)
  • Source file names and paths for feature detection
  • Documentation files you choose to import (README, CHANGELOG, spec)

This processing happens on your computer. AppMeta does not transmit your project files to Masked Syntax or any third party as part of the scanning step.

Data stored on your device

AppMeta stores the following locally in your app data directory:

  • Settings — AI provider, model preferences, and API keys
  • Project profiles — truth files and generated metadata per submission project
  • Export history — when you save submission packs to a folder you choose

In the current MVP, API keys are stored in local JSON settings. macOS Keychain integration is planned for a future release. You are responsible for securing access to your machine and app data directory.

AI provider requests

When you explicitly trigger generation, AppMeta sends a prompt to your configured AI provider (e.g. OpenAI or OpenRouter) using your API key. The prompt includes:

  • Confirmed and verified facts from your project truth file
  • Instructions for the specific field being generated
  • Character limits and formatting requirements

Your relationship with the AI provider is governed by that provider's terms and privacy policy. Review their policies before entering an API key.

What we do not collect

  • No account system or login in the current version
  • No analytics, crash reporting, or usage telemetry (as of this policy date)
  • No automatic upload of project source code

If we add optional telemetry or crash reporting in the future, this policy will be updated and the app will disclose it clearly before collection.

Website

This marketing website is a static site hosted on GitHub Pages. It does not use cookies or tracking scripts in the current version. GitHub may collect standard web server logs as described in GitHub's privacy statement.

Contact

Questions about this policy? Open an issue on GitHub.

Changes

We may update this policy as AppMeta evolves. The "Last updated" date at the top will reflect the most recent revision.

next step

Privacy-first by design

Local scan. BYOK. Confirmed facts only.

download