Legal
Privacy Policy
Last updated: August 4, 2026. This policy describes how WebsiteTo.app (“we”, “us”) handles information when you use our website and services.
1. Who we are
WebsiteTo.app converts websites into native Android and iOS app shells and provides a dashboard, build pipeline, billing, and support around that product. Contact: contact@websiteto.app.
2. Information we collect
- Account data: name, email address, password (hashed), and optional Google account identifiers if you sign in with Google.
- App configuration: website URLs, branding assets, package/bundle IDs, signing materials you upload, integration keys (for example OneSignal or AdMob), and related settings needed to build your apps.
- Billing: subscription status and Stripe customer/subscription identifiers. Card details are processed by Stripe; we do not store full card numbers.
- Support: messages you send via contact forms or the support chat, including guest email when used.
- Usage & logs: approximate IP address, user agent, and server logs for security, abuse prevention, and reliability. Article view analytics may use a first-party cookie.
- Analytics: if Google Analytics is enabled, aggregate traffic data per Google’s terms.
3. How we use information
We use personal data to:
- Provide, secure, and improve the service (accounts, builds, storage, support)
- Process subscriptions, trials, invoices, and entitlement checks
- Send transactional email (password reset, build status, billing notices)
- Send optional product/marketing email if you have not opted out
- Detect fraud, abuse, and technical issues
- Comply with legal obligations
4. Legal bases (EEA/UK)
Where GDPR/UK GDPR applies, we rely on contract performance, legitimate interests (security, product improvement, limited marketing to existing users with opt-out), consent where required, and legal obligation.
5. Sharing and processors
We share data with service providers who process it on our behalf, including:
- Stripe (payments)
- Object storage (Contabo S3-compatible) for builds and media
- Email delivery (fortuly.cloud)
- Hosting / VPS infrastructure
- Google (OAuth and Analytics, when configured)
We do not sell personal data.
6. Retention
Account and app data are retained while your account is active. Demo binaries are retained about 7 days after success; production binaries about 15 days after success, then removed from object storage. Support threads and logs are retained as needed for operations and dispute resolution, then deleted or anonymized.
7. Security
We use HTTPS, hashed passwords, access controls, and least-privilege secrets on the server. No method of transmission or storage is 100% secure; please use a strong unique password.
8. Your rights
Depending on your location, you may have rights to access, correct, delete, export, or restrict processing of your personal data, and to object to certain processing or withdraw consent. You can update account settings in the dashboard, cancel subscriptions via Billing / Stripe Customer Portal, or email contact@websiteto.app. You may also lodge a complaint with a supervisory authority.
9. International transfers
We may process data in the EU/EEA and other countries where our providers operate. Where required, we use appropriate transfer safeguards.
10. Children
The service is not directed to children under 16. We do not knowingly collect personal data from children.
11. Changes
We may update this policy from time to time. The “Last updated” date at the top will change; continued use after changes constitutes acceptance where permitted by law.
12. Contact
Privacy questions: contact@websiteto.app.