This Privacy Policy explains how Native Made ("Native Made", "we", "us", "our") processes personal data in connection with our websites, apps, and related services (the "Service"). It should be read together with our Terms of Use.
Privacy contact: privacy@nativemade.app.
1. Who is the controller
Native Made is the controller of personal data processed for operating the Service, unless stated otherwise (for example, where we act as a processor for enterprise customers under a separate agreement).
2. Data we collect
2.1 Account and profile
- Email address and password (passwords are hashed by our auth provider).
- Display name or similar profile fields you choose to provide.
- Authentication session identifiers and security logs.
2.2 Project and generation data
- App ideas, briefs, prompts, reference links, and project metadata you submit.
- Generated specifications, design artifacts, SwiftUI source, build/repair logs, Simulator screenshots, and downloadable project packages associated with your jobs.
- Job status, timestamps, and pipeline event history.
2.3 Credentials you choose to store
- Optional LLM API keys (for example Anthropic) if you bring your own key instead of using platform-provided capacity.
- Optional Apple Developer / App Store Connect credentials when you enable TestFlight or related release features.
Secrets are encrypted at rest using application-level encryption where implemented, and access is restricted to performing the actions you request. You can remove stored credentials from account or project settings when available.
2.4 Technical and usage data
- IP address, device/browser type, approximate location derived from IP, pages viewed, referring URLs, and diagnostic logs.
- Cookies or local storage required for authentication and security (see Cookies below).
2.5 Communications
- Messages you send to support or legal contacts, and related correspondence.
3. Why we process data (purposes and legal bases)
Where the GDPR / UK GDPR applies, we rely on the following bases:
- Contract — to create and manage your account, run generation jobs, compile on hosted Macs, deliver artifacts, and provide customer support you request.
- Legitimate interests — to secure the Service, prevent abuse, improve reliability and quality (including debugging failed builds), and understand aggregate product usage. You may object where applicable.
- Consent — where we ask for it (for example optional marketing emails, or non-essential cookies if introduced). You may withdraw consent at any time.
- Legal obligation — to comply with law, respond to lawful requests, or establish/exercise legal claims.
4. How we use AI providers
To generate plans, design guidance, and code, we send relevant Inputs and job context to model providers (including Anthropic or other providers we configure). Those providers process data as independent controllers or processors under their terms. Do not submit data you are not allowed to share with such providers. We do not use your private Inputs to publicly train open models; however, providers may process prompts under their own policies—review their documentation if you require stricter contractual controls.
5. Hosted Mac builds and artifacts
When you start a build, project source and related job data may be transferred to isolated macOS build workers (for example via CI runners or a dedicated Mac pool) to run Xcode, Simulator, tests, and screenshot capture. Build logs and artifacts may be stored in object storage so you can download them. Workers are intended to process job data for your request and not to retain it longer than needed for delivery, debugging, and security.
6. Who we share data with
We share personal data with:
- Infrastructure processors — hosting, database, auth, and storage providers (including Supabase and Vercel or successors) that process data on our instructions.
- Model and tooling providers — as needed to run agents and generation.
- Build infrastructure providers — macOS CI / Mac hosting used to compile and test.
- Apple — only when you connect Apple credentials and request App Store Connect / TestFlight actions.
- Professional advisors and authorities — where required by law or to protect rights, safety, and security.
- Successors — in a merger, acquisition, or asset transfer, subject to appropriate protections.
We do not sell your personal data. We do not share it for cross-context behavioral advertising as defined under California law.
7. International transfers
We and our processors may process data in the European Economic Area, the United Kingdom, the United States, and other countries. Where required, we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.
8. Retention
We keep account data for as long as your account remains active. Project, job, log, and artifact data is retained while needed to provide the Service and for a reasonable period afterward for security, dispute resolution, and backups, unless you delete it earlier or law requires longer retention. You may request deletion of your account and associated personal data; some residual copies may remain in encrypted backups for a limited time.
9. Security
We use technical and organizational measures appropriate to the risk, including encryption in transit (HTTPS), access controls, hashed passwords via our auth provider, and encryption of certain stored secrets. No method of transmission or storage is completely secure.
10. Cookies and similar technologies
We use strictly necessary cookies / local storage to keep you signed in and to protect sessions. We do not currently use non-essential advertising cookies. If we add analytics or marketing cookies, we will update this Policy and, where required, request consent.
11. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing; to receive a copy of data you provided in a portable format; and to withdraw consent. California residents may have rights to know, delete, and correct personal information, and to not be discriminated against for exercising those rights.
To exercise rights, email privacy@nativemade.app from your account email. We may need to verify your identity. You may also lodge a complaint with your local supervisory authority.
12. Children
The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided data, contact us and we will take appropriate steps to delete it.
13. Automated decision-making
We use automated systems to generate code and run builds. These systems do not produce legal or similarly significant decisions about you without human involvement in the sense of GDPR Article 22; they produce software artifacts you choose to use.
14. Changes
We may update this Privacy Policy. The "Last updated" date will change when we do. Material changes will be posted on this page and, where required, notified to you.
15. Contact
Privacy requests and questions: privacy@nativemade.app. Legal notices: legal@nativemade.app.