Privacy Policy
Effective date: August 28, 2026 · Applies to the Michelangelo iOS app and michelangelo.land
Michelangelo ("we", "the app") is an AI-powered app builder: you describe an idea in natural language, and the app generates a real native project you can preview, edit and optionally publish to the Explore feed. This policy explains what data we process, why, and the choices you have.
1. Data we collect
- Account data — email address, authentication identifier (Sign in with Apple, Google, GitHub, or email one-time code), username and optional profile avatar.
- User content — the prompts you write, the projects you generate (source files, names, icons), and any project you publish to the Explore feed. Published projects are public until you unpublish or delete them.
- Images you attach — photos you explicitly pick to include in a generation request. We never access your photo library without your action.
- Device & push identifiers — Expo push notification tokens and APNs Live Activity tokens, used only to deliver generation updates you start.
- Subscription data — App Store transaction and entitlement status for the optional supporter tiers. Payment details are handled entirely by Apple; we never see your card data.
- Crash & diagnostics data — stack traces, device model and OS version collected via Sentry to fix bugs. No advertising identifiers, no tracking.
- Usage data — generation counts and feature usage tied to your account, used to enforce fair-use limits and show your usage statistics.
We do not collect: your contacts, precise location, health data, microphone recordings, or data for advertising purposes.
2. On-device AI
App suggestions are generated locally on your device using Apple Intelligence (where available) or the optional "Land 1.0" open model. The Land model (~400 MB) is downloaded from Hugging Face only after we show you the size and you explicitly confirm. On-device inference never leaves your iPhone.
3. Server-side AI generation
When you generate or modify a project, your prompt (and any images you attach) is sent to our servers and routed through Cloudflare AI Gateway to third-party AI model providers — currently Moonshot AI (Kimi models) and Anthropic (Claude). These providers process the prompt solely to return generated code. Do not include sensitive personal information in prompts.
4. Third-party processors
| Provider | Purpose | Data |
|---|---|---|
| Supabase (EU, eu-central-1) | Authentication, database, file storage | Account data, projects, avatars |
| Cloudflare (AI Gateway, CDN/API) | AI request routing, public API hosting | Prompts, attached images, IP address |
| Moonshot AI / Anthropic | AI code generation models | Prompts, attached images |
| Sentry | Crash reporting & diagnostics | Stack traces, device/OS metadata |
| Apple | Sign in with Apple, In-App Purchase, push (APNs) | Auth token, transactions, push tokens |
| Google / GitHub | Optional OAuth sign-in; GitHub project sync | OAuth profile basics; repos you connect |
| Expo (Expo Push API) | Push notification delivery | Push token, notification payload |
| Hugging Face | Download of the optional Land 1.0 model | IP address (download request only) |
5. How we use data
- Provide the service: authentication, project generation, storage, sync and publishing.
- Deliver notifications you initiated (generation progress, social activity on your published projects).
- Enforce content rules on published projects (reporting, blocking, moderation).
- Diagnose crashes and improve reliability.
We do not sell your data, do not use it for advertising, and do not track you across other apps or websites.
6. Retention
Account and project data is kept until you delete it or delete your account. Crash diagnostics are retained per Sentry's default retention (90 days). Server logs are rotated routinely.
7. Account deletion
You can permanently delete your account and all associated data directly in the app: Settings → Edit Profile → Delete account. This removes your authentication identity, profile, projects, files, subscriptions records, reports, blocks, notifications, GitHub links and stored avatars. You can also request deletion by emailing us.
8. Your rights (EEA/UK users)
You have the right to access, rectify, export, restrict or erase your personal data, and to object to processing. Most of these actions are available in-app; otherwise email us. Our infrastructure is hosted in the EU (Supabase eu-central-1).
9. Children
The app is not directed at children under 13 and is not listed in the Kids category. We do not knowingly collect data from children under 13.
10. Security
All traffic uses HTTPS/TLS. Sensitive AI processing runs server-side with scoped credentials; on-device inference stays on your device. No method is 100% secure, but we apply industry-standard safeguards.
11. Changes
If we materially change this policy we will update the effective date above and note the change in the app's release notes.
12. Contact
Questions, requests or deletion support: sardo@michelangelo.land.