// legal

Privacy Policy

Last updated: May 2026

1. Who We Are

WebAppDev.co is operated by WebAppDev.co ("we", "us", "our"). We build custom web applications for businesses and individuals. You can reach us at tech@webappdev.co.

2. Your Idea Is Protected — NDA

Everything you share with us is covered by a mutual Non-Disclosure Agreement (NDA). This applies from the moment you submit your first voice or text description.

  • We will never share, sell, license, or disclose your application concept, business idea, or requirements to any third party.
  • Your idea will not be used to build products for any other client, for internal use, or for any purpose other than delivering your project.
  • All team members who access your project scope are individually bound by confidentiality obligations.
  • This NDA is mutual — we expect you to keep any proprietary processes, tooling, or internal details you learn about us confidential as well.

If you require a signed standalone NDA document before proceeding, contact us at tech@webappdev.co.

3. Information We Collect

We collect the following categories of information:

  • Account data: your name, email address, and password (hashed — we never store plaintext passwords).
  • Project data: voice recordings (transcribed and then discarded), written descriptions, and your answers to our discovery questions.
  • Payment data: processed entirely by Stripe. We never see or store your card number, CVV, or banking details.
  • Usage data: pages visited, actions taken within your dashboard, and basic browser/device metadata for debugging.

4. How We Use Your Information

  • To build and deliver your application as described during the discovery process.
  • To communicate with you about your project status, delivery, and support.
  • To process payments and manage your subscription or one-time purchase.
  • To improve the platform (using aggregated, anonymised analytics only).

We do not use your data for advertising, profiling, or selling to data brokers.

5. Data Storage & Security

Your data is stored in Supabase (PostgreSQL), hosted on AWS infrastructure with encryption at rest and in transit. Access to production data is restricted to authorised team members only, each bound by confidentiality agreements.

Voice recordings submitted through our platform are transcribed immediately and the audio file is discarded. Only the text transcript is retained.

6. Third-Party Services

We use the following services to operate the platform:

  • Supabase — database and authentication
  • Stripe — payment processing
  • Deepgram — voice-to-text transcription
  • Anthropic — AI-powered discovery questions
  • Resend — transactional emails
  • Vercel — hosting and deployment

Each provider is subject to their own privacy policy and security practices.

7. Your Rights

You have the right to:

  • Access all personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and all associated data
  • Export your project data in a portable format

To exercise any of these rights, email us at tech@webappdev.co. We will respond within 30 days.

8. Data Retention

We retain your account and project data for as long as your account is active, or as required to provide support and comply with legal obligations. You may request deletion at any time. After deletion, data is purged from our systems within 30 days.

9. Changes to This Policy

We may update this policy as the product evolves. We will notify you by email of any material changes at least 14 days before they take effect. Continued use of the platform after that date constitutes acceptance.

10. Contact

Questions? Email tech@webappdev.co or visit our Contact page.