Legal

Privacy Policy

Effective date: September 21, 2026

This is the current Privacy Policy of Broctic Inc. It applies to broctic.com, the Broctic console and Studio, the Broctic API and SDK, and any other service that links to it.

1. Who we are

Broctic Inc. (“Broctic,” “we,” “us”) provides a platform for building mobile apps with AI, publishing them to the App Store, marketing them and earning revenue from them. For the personal information described in this policy about our own customers and website visitors, Broctic is the controller. You can reach us about privacy at irennie@broctic.com.

Where our customers use Broctic to run their own apps, we also process information about the people who use those apps. For that information we act as a processor (or “service provider”) on our customer’s behalf — see section 3.

2. Information we collect

  • Account information. Your name and email address, and either a password (stored only as a salted hash) or, if you sign in with GitHub or Google, the basic profile and email address that provider shares with us.
  • Organization information. Organizations you create or join, their members and roles, invitations, and settings.
  • App content. What you create in the Studio: prompts and instructions, generated and uploaded source code, assets, app metadata, screenshots and artwork, store listings, marketing posts, and build and submission records.
  • Credentials for services you connect. API keys and tokens you give us — for example an App Store Connect API key, an Apple In-App Purchase key, a PostHog key, an OpenRouter key, or social-account connections. We encrypt these with AES-256-GCM before storing them, and use them only to perform the actions you ask for.
  • Usage and log data. When you use the service we record request logs that include IP address, request identifiers, timestamps and the routes accessed. We use these to operate, debug and secure the service.
  • Information you give us directly. Support emails, feedback, and optional answers such as “how did you hear about us.”

3. Data about your app's users

If you add the Broctic SDK or connect PostHog or Apple, your app and those services send us data about your end users — for example product events with an anonymous or customer-assigned user ID, session ID, app and OS version, locale and country. Apple sends us App Store Server Notifications for your app: the purchase and subscription events behind them, including a transaction identifier, the amount charged with its currency, and the identifier your app attached at purchase where it did. We process this data only to provide the service to you (analytics, funnels, revenue reporting and recommendations), following your instructions.

You are the controller of that data and are responsible for having a lawful basis to collect it and for telling your users about it in your own app’s privacy policy. End users who want to exercise their rights should contact the app’s publisher; we will assist our customers in responding. If you need a data processing agreement, email irennie@broctic.com.

4. How we use information

  • To provide the service: generate and preview apps, run builds, submit to the App Store, publish marketing posts and show analytics.
  • To secure the service: authenticate you, rate-limit requests, and detect and prevent abuse.
  • To support you and send service messages, such as password resets and invitations.
  • To understand and improve the product, using aggregated or de-identified information.
  • To comply with law and enforce our Terms of Service.

We do not use your app content or your end users’ data to train AI models, and we do not use it for advertising.

5. Legal bases (EEA, UK and Switzerland)

  • Contract — to provide the service you signed up for.
  • Legitimate interests — to keep the service secure and reliable, prevent abuse, and improve the product, balanced against your rights.
  • Consent — for optional analytics on our website, which you can withdraw at any time (see our Cookie Policy).
  • Legal obligation — where the law requires us to keep or disclose information.

6. How we share information

We share personal information only with service providers that help us run Broctic (our subprocessors), with the third-party services you choose to connect, and when required by law. Our current subprocessors are listed on the Subprocessors page. For example, prompts and code you write in the Studio are sent to AI models through OpenRouter to generate code, and native builds run on Expo (EAS) and GitHub Actions.

When you connect a service such as Apple, PostHog, OpenRouter, Instagram or TikTok, we send it the data needed to do what you asked, and its own terms and privacy policy apply to what it does with that data.

If Broctic is involved in a merger, acquisition or sale of assets, information may be transferred as part of that transaction, subject to this policy.

7. International transfers

Broctic is based in Canada and our infrastructure is in the United States (AWS in US East, N. Virginia, and a Hetzner server in Ashburn, Virginia). Some providers process data in other countries. When we transfer personal data from the EEA, UK or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses offered by our providers.

8. Retention

We keep account, organization and app data for as long as your account is active. Operational logs are kept for a limited period (typically up to 90 days) unless needed longer to investigate a security issue. When you delete your account, or ask us to, we delete or de-identify your personal information within a reasonable period, except where we must keep it to comply with law or resolve disputes.

9. Security

We use TLS for data in transit, hash passwords, encrypt third-party credentials with AES-256-GCM before storing them, scope access to organization members, and rate-limit authentication endpoints. No system is perfectly secure; if we learn of a breach affecting your personal information, we will notify you as required by law. Report security issues to irennie@broctic.com.

10. Your rights

Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal information; to object to or restrict certain processing; to withdraw consent; and to complain to your local data protection authority. Email irennie@broctic.com to make a request. We will verify your identity and respond within the time the law requires (generally 30 days under GDPR and 45 days under California law).

California residents (CCPA/CPRA). In the past 12 months we have collected the categories described in section 2 (identifiers, account and commercial information, internet activity such as logs, and content you provide) for the purposes in section 4. You have the right to know, delete and correct your information, and to not be discriminated against for exercising these rights. We do not sell or share personal information (as those terms are defined in California law), and we do not use sensitive personal information to infer characteristics about you.

Canada. You may request access to and correction of your personal information under PIPEDA by emailing irennie@broctic.com.

11. Children

Broctic is a tool for businesses and developers and is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has given us personal information, contact us and we will delete it.

12. Cookies

We use cookies and similar storage to keep you signed in and remember preferences. Optional analytics are off unless you accept them. Details are in our Cookie Policy.

13. Changes to this policy

We may update this policy as Broctic changes. We will post the new version here with a new effective date and, for material changes, notify account holders by email or in the product before they take effect.

14. Contact

Broctic Inc., Toronto, Ontario, Canada. Email irennie@broctic.com.