Privacy Policy
Last updated: 12 August 2026
1. Introduction
AppMecca is operated by UNOMENA ("we", "us", "our"). This policy explains how we collect, use, store, and protect your personal information when you use our platform and website.
We respect your privacy and are committed to protecting it. We collect only what we need to provide the Service, and we never sell your data.
2. Information we collect
Information you provide
- Account information: name, email address, and password when you register
- Communications: messages you send us via email, contact forms, or support channels
- Your Content: application code, configuration, and data you deploy on the Service
Information collected automatically
- Usage data: deployment activity, CLI commands, API calls, and feature usage
- Log data: IP address, browser type, operating system, and access times
- Device information: device type and identifiers
Information from third parties
- OAuth providers: when you sign in with GitHub, Google, or GitLab, we receive your name, email, and profile identifier as authorized by you
3. How we use your information
We use your information to:
- Provide, maintain, and improve the Service
- Send transactional emails (account verification, password resets, team invitations)
- Respond to support requests and communications
- Detect, prevent, and address abuse, fraud, and security issues
- Generate anonymized, aggregated analytics to improve the Service
We do not use your information for advertising or sell it to third parties.
4. Data storage and security
Your data is stored on infrastructure hosted by Amazon Web Services (AWS). Each AppMecca environment runs in a single AWS region — currently us-east-2 (Ohio, United States) — across multiple availability zones. We will publish additional regions as they become available. We implement industry-standard security measures including:
- Encryption in transit (TLS) for every connection; object storage, file storage and cache encrypted at rest with AES-256
- Private networking — application hosts have no public IP address and are not directly reachable from the internet
- Access controls and authentication for all internal systems, with an audit log of administrative actions
- Automatic backups before every deployment, plus on-demand backups you control
5. Data sharing
We share your information only in these circumstances:
- Service providers: email delivery and infrastructure providers who process data on our behalf under strict agreements
- This marketing website: Google receives your IP address and user-agent when your browser loads our web fonts, and analytics data as described in section 7. This does not apply to the Service itself
- Legal requirements: when required by law, regulation, or legal process
- Safety: to protect the rights, safety, and property of our users and the public
- Business transfers: in connection with a merger, acquisition, or sale of assets, with prior notice
We do not share Your Content (application code and data) with anyone. Your deployments are private to your account.
6. Your rights
You have the right to:
- Access your personal information held by us
- Correct inaccurate or incomplete information
- Delete your account and associated data
- Export your data in a portable format
- Object to processing of your data in certain circumstances
- Withdraw consent where processing is based on consent
To exercise any of these rights, contact us at info@appmecca.com.
7. Cookies and analytics
In the Service (the dashboard and API), we use only essential cookies required for it to function — authentication and session management. No tracking cookies, no advertising cookies.
On this marketing website, we use Google Tag Manager and Google Analytics to understand which pages people find useful. These set cookies and are operated by Google, which may correlate them with activity on other sites. We do not use them for advertising, and we do not sell or share this data. You can block them with any standard content blocker. We are working on a consent control; until it ships, a content blocker is the reliable way to opt out.
8. Data retention
- Account data: retained while your account is active, deleted within 30 days of account closure
- Your Content: deleted within 30 days of account closure or upon your request
- Billing records: once paid plans begin, retained for 7 years as required by tax and accounting regulations
- Platform and application logs: retained for 365 days for security and debugging purposes
- Request and deployment records held in our database: retained for 7 days
9. International transfers
Your data may be processed in countries other than your own, including the United States (where AWS infrastructure is located). We ensure appropriate safeguards are in place for international transfers in compliance with applicable data protection laws.
10. Children's privacy
The Service is not directed to individuals under 18. We do not knowingly collect information from children. If you believe we have inadvertently collected such information, contact us and we will promptly delete it.
11. Changes to this policy
We may update this policy from time to time. We will notify you of material changes via email or through the Service at least 14 days before they take effect.
12. Contact
For privacy-related questions or requests, contact us at:
- Email: info@appmecca.com
- General enquiries: contact page
13. Data Protection Officer
UNOMENA's Data Protection Officer can be reached at info@appmecca.com.