AppemUp

Data handling

How data moves through AppemUp.

The service minimizes collection, keeps product data role-scoped and treats testing evidence as private.

Account and profile data

Supabase Auth stores identity and session data. AppemUp stores role-specific profile fields used for workspace ownership or campaign eligibility.

Workspace and campaign data

Launch requirements, documents, milestones, risks, campaigns and feedback are stored in Supabase Postgres and protected by Row Level Security.

Evidence files

Files use randomized assignment-scoped paths in private Supabase Storage. The product creates short-lived signed URLs only after participant authorization.

Operational records

Rate limiting stores SHA-256 identifiers rather than raw IP addresses. Security audit events record action type, actor when known, target and bounded metadata—not passwords, tokens or feedback contents.

Future providers

Payments, AI, analytics and live provider synchronization are disabled. Their data will not be collected unless the capability receives a separate privacy and security review.

Last updated July 2, 2026Contact AppemUp
Data handling | AppemUp