This policy explains how Yibi AI LLC, which provides this service under the AppTelepath brand (“we”, “us”), handles information related to the Service.
1. What we collect
Account information
When you sign in with GitHub or Google, we receive only basic profile data: account identifier, name, email address and avatar (the GitHub scope is read:user user:email, and Google's is openid email profile). We do not request, and cannot access, your repositories or contacts.
Debugging session data
This is the main body of data the Service handles: debugging information reported by the devices where you integrated the SDK, including logs, network request records, screenshots, interface structure, performance metrics, file and database query results, session recordings and so on.
- What gets reported and when depends on how you integrate the SDK and which commands you call — we never collect anything from your devices behind the SDK's back.
- The SDK targets development and test builds: it refuses to start when it detects a production App Store build, and TestFlight requires you to opt in explicitly. In normal use, therefore, what flows through the Service is your development and test data, not your app end users' production data.
- If your debugging data contains end users' personal information, you are the controller of that data and we process it only on your instructions — namely, to provide the Service.
Usage and security auditing
- For billing and quota enforcement, we record workspace-level usage (such as traffic and recording counts).
- For security auditing, we record when an access token was last used and the broad class of client (browser, CLI and so on); we do not keep the full User-Agent.
- Access tokens themselves are stored only as SHA-256 hashes; the plaintext is shown once, at creation.
- To improve the free beta, we use standard website analytics (page views and sessions, referrers, campaign parameters, device and browser characteristics, performance, and interactions on marketing pages) alongside product milestones. PostHog assigns a persistent anonymous browser identifier; after sign-in, we link it only to AppTelepath's internal user ID, without sending your email address, name or avatar.
Payment information
Payments are handled directly by Stripe; your card details neither pass through nor are stored in our systems. We keep only the billing records we need, such as subscription status and plan.
2. How we use data
- To provide and operate the Service: forwarding what your devices report to you and to the agents you authorize, and storing and replaying recordings.
- For billing, quotas and abuse prevention.
- To understand the sign-up, integration and first-debug funnel, and to see where people get stuck.
- To communicate with you about the Service (subscription and security notices, for example).
We do not sell your data, do not use it for advertising, and do not use it for anything unrelated to providing the Service.
3. How long we keep data
- Session recordings are retained according to your plan (14 days for Trial and Solo, 30 days for Team, as listed on the pricing page) and are deleted automatically when that period ends.
- The live event stream persists no messages: real-time data that is not being recorded is no longer stored once it has been forwarded.
- After a subscription expires or is downgraded, existing data is not deleted immediately — we provide an export window for the previous plan's retention period, then clean up according to the current plan's retention period.
- Sign-in sessions are valid for 30 days and are cleared automatically when they expire.
- Account and billing records are retained for the life of the account, to perform the contract and meet legal obligations.
4. How to delete data
- Recordings: delete any single recording at any time in the console or through the API; deletion removes it from storage.
- Tokens: revoke at any time; revocation takes effect immediately.
- Account and workspace: email hello@apptelepath.com to request deletion, and we will delete the related account information and workspace data within a reasonable period (except billing records we are legally required to keep).
5. Third-party processors
We rely on the following third parties, each of which touches data only within its own function:
- Cloudflare — infrastructure and storage: the service runs on Cloudflare Workers, with data stored in its KV, R2 and Durable Objects.
- Stripe — payment processing and subscription management.
- GitHub / Google — OAuth identity providers for sign-in.
- PostHog Cloud (United States) — website and product usage analytics. Its standard web SDK receives page URLs, referrers, campaign parameters, approximate location derived from IP, device and browser characteristics, performance and marketing-page interactions; PostHog also receives IP address and User-Agent at the network layer. It uses a persistent anonymous browser identifier and, after sign-in, AppTelepath's internal user ID. Session Replay and automatic interaction capture in the debugging console are disabled, and credential-like URL parameters are removed. We do not deliberately attach account-profile email addresses, names, provider account IDs, device names, app identifiers, command arguments or results, logs, screenshots, debugging payloads or access tokens to analytics events; page URLs and referrers can still contain information placed there by a visitor or referring site.
Apart from the processors above and cases where the law requires it, we do not provide your data to any third party.
6. Data security
- All traffic is encrypted with TLS (HTTPS / WSS).
- Access tokens are stored as SHA-256 hashes; workspaces are fully isolated, and devices and data in one workspace are invisible to another.
- Sensitive operations in the console require the signed-in user to hold the corresponding workspace role.
7. Your rights
You can access, export, correct or delete your data at any time (see section 4). If your jurisdiction grants you additional data rights — such as access, portability or erasure — you can exercise them through the contact below, and we will respond in line with applicable law.
8. Changes to this policy
We may update this policy. We will give advance notice of material changes on the site or by email, and update the date at the top of this page.
9. Contact us
For any question about this policy or your data, contact hello@apptelepath.com.