Privacy Policy
Last updated:
This policy explains what personal data Cockpitify collects when you use the Cockpitify mobile app, our backend services and the cockpitify.app website (together, the “Service”), why we collect it, who we share it with and what rights you have. It also explains how we handle the data of your own app’s users when Cockpitify works with it on your behalf.
Who we are
The Service is operated by Cockpitify (“Cockpitify”, “we”, “us”). For anything about privacy, including requests to exercise your rights, write to support@cockpitify.app.
Two kinds of data, two roles
- Your account data. The data about you as a Cockpitify user: your email address, your workspace, your devices and so on. For this data, Cockpitify is the controller (data controller under the GDPR, veri sorumlusu under Turkey’s Law No. 6698 on the Protection of Personal Data, “KVKK”).
- Your end users’ data. The data about the people who use the app you connect to Cockpitify. It lives in your own Supabase project, and you decide what happens to it. You are its controller; when Cockpitify handles it for you, we act as your processor and only on your instructions, which are the settings you choose in the Service.
Data we collect about you
| Category | What it includes | Where it comes from |
|---|---|---|
| Account | Email address; if you sign in with Google, the basic profile Google shares (name and profile picture) and your Google account identifier | You, Google |
| Workspace and team | Workspace name, members and their roles and permissions, invitations including the invitee’s email address | You and your team |
| Connected apps | App name, the Supabase project reference and the address of the ops layer, its version, health status, last signal and the number of users in the project | You, your Supabase project |
| Setup records | Install, repair, update and removal jobs: project reference, steps and errors | The Service |
| Devices and notifications | Push notification token, platform, language, when the device was last seen, your notification preferences and daily limits, and a log of notifications sent (event identifier, type and how many devices received it, not the text) | Your device, you |
| Webhooks | The Slack, Discord or server addresses you add and their signing secrets, stored encrypted; the last delivery error | You |
| Google Ads and AdMob link | The Google account email, an encrypted refresh token, the Ads and AdMob account, campaign and app identifiers you choose, and the last aggregated result (days, amounts, currency) | You, Google |
| Purchases | Your plan, product, store, trial and expiry dates, and purchase events (identifier and type). We never receive your card or bank details | Apple, Google, RevenueCat |
| Product interest | Which upcoming backend you asked to be notified about | You |
| Security and audit records | Actions taken in your account, such as connecting or removing an app or changing a webhook, with technical details such as the project reference | The Service |
| Support | The messages you send us and our replies | You |
| Technical logs | Error messages and request details in our server logs | The Service |
| Crash and error reports | When the app crashes or hits an error: the error and where in the code it happened, the screen, recent app actions such as screen changes and request addresses (without their parameters), device model, operating system and app version, and a screen recording of the moments before the error with all text and images hidden. No email address, name or IP address | The app on your device |
We do not use analytics, advertising or tracking SDKs in the Cockpitify app, and we do not access your location, contacts, camera or photos.
Your end users’ data
Cockpitify is built so that your end users’ data stays in your own Supabase project:
- The dashboard data you see (users, revenue, AI cost, analytics and so on) is read by the Cockpitify app directly from your project, through the ops layer installed there. It does not pass through or get stored on our servers.
- API keys you enter for RevenueCat, Sentry and the services you track are stored in your project’s Supabase Vault, not with us.
- Usage analytics are written to your project. An end user’s country comes from the request; their IP address is not kept.
There are three narrow exceptions, all needed to deliver features you turn on:
- Notifications. When something happens in your app, your project sends an event to our backend so we can deliver the push notification. The event can include the end user’s identifier, a display label (their name, or a masked email such as
ab***@example.com) and event details such as the plan bought, a price or the AI spend. We use it only to compose and send the notification through Expo’s push service to Apple or Google, and we don’t store it; we keep only the event identifier, its type and delivery counts. - Webhooks. If you add a webhook, the same event is sent to the address you chose. Display labels are removed unless you turn on Show user names; the JSON format includes the end user’s identifier.
- Inbox. The text of your in-app notification inbox is built on request from your project and is not stored on our servers.
During setup, repair, update and removal, we hold a short-lived Supabase access token for your project, encrypted, for at most 15 minutes. It is deleted when the job ends, and we never store a refresh token.
As the controller of your end users’ data, you are responsible for having a lawful basis for it and for telling your users about it, for example in your own privacy policy.
How and why we use your data
| Purpose | Legal basis (GDPR / KVKK) |
|---|---|
| Creating your account, signing you in and providing the Service, including notifications, webhooks, teams and the Google link | Performance of a contract (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)) |
| Managing subscriptions, trials and plan limits | Performance of a contract; compliance with legal obligations, such as tax and accounting (GDPR Art. 6(1)(c); KVKK Art. 5(2)(ç)) |
| Security, preventing abuse, troubleshooting and keeping audit records | Legitimate interests in running a secure service (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)) |
| Service messages: sign-in codes, invitations, setup and billing notices | Performance of a contract |
| Telling you when an upcoming backend is ready, after you tap Notify me | Your request; you can withdraw it at any time |
| Answering support requests | Performance of a contract; legitimate interests |
We do not sell your personal data, we do not use it for advertising, and we do not make decisions about you based solely on automated processing.
Who we share data with
We use the following service providers. Each processes data only to provide its service to us.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Hosting our database, authentication and server functions; the Supabase Management API when you connect a project | Singapore (our backend); United States (company) |
| Expo | Push notification delivery | United States |
| Apple and Google | Delivering push notifications (APNs, Firebase Cloud Messaging), app distribution and in-app payments | United States and worldwide |
| Sign in with Google; the Google Ads and AdMob APIs when you link them | United States and worldwide | |
| RevenueCat | Managing your subscription status | United States |
| Resend | Sending sign-in codes and team invitations | European Union |
| Sentry | Crash and error reports from the app, and app performance measurements | European Union (Germany) |
| Cloudflare | Hosting and protecting the cockpitify.app website | Worldwide |
When you configure them, data also goes to destinations you choose: Slack, Discord or your own server for webhooks, and your own Supabase project.
We may disclose data if required by law or a valid request from an authority, to protect the rights and safety of our users or the Service, or as part of a merger or acquisition, in which case this policy continues to apply.
International transfers
Our backend is hosted in Singapore, and some providers above are based in the United States or elsewhere. When personal data is transferred outside Turkey, the European Economic Area or the United Kingdom, we rely on the safeguards the law provides, such as standard contractual clauses and the providers’ data processing terms, and, under KVKK Article 9, on the transfer mechanisms permitted there.
How long we keep data
- Account data is kept while your account exists and deleted when you delete it.
- Setup access tokens are deleted when the job ends, at the latest after 15 minutes.
- Push delivery receipts are deleted after they are checked, at the latest after 24 hours.
- Notification logs, webhooks and Google links are deleted with the app they belong to, or when you disconnect them. Disconnecting Google also revokes our access at Google.
- Invitations may be kept after they expire or are used, as a record of who was invited.
- Audit and purchase records are kept for security, accounting and legal purposes. When you delete your account, the link to your account is removed from them.
- Server logs are kept by our hosting provider for a limited period.
Deleting your account
You can delete your account in the app under Settings → Account → Delete my account. This deletes your account, your workspace and its apps, your team members’ access to them, your memberships, devices and settings, and the copy of your purchase history held by RevenueCat. See Delete your account for the details and for what we can’t delete for you, such as a store subscription you need to cancel in the store, or the ops layer in your own projects.
Security
We protect data with encryption in transit (TLS); encryption of stored secrets such as webhook addresses and Google refresh tokens; short-lived access tokens; access controls on our database; and the app’s optional biometric lock. The app’s local data is excluded from Android backups. No system is perfectly secure, so we can’t guarantee absolute security, but we work to protect your data and will notify you and the authorities of a breach where the law requires.
Data stored on your device
The app stores your sign-in session, your push token and preferences such as language, the selected app and the biometric lock setting in the app’s private storage on your device. Signing out removes the session; uninstalling the app removes everything.
The website
cockpitify.app does not use cookies, analytics or tracking. Cloudflare, which hosts the site, processes your IP address and request details to deliver the pages and protect them from abuse.
Your rights
Depending on where you live, including under the GDPR and Article 11 of KVKK, you have the right to:
- learn whether we process your personal data and get a copy of it
- have inaccurate data corrected
- have your data deleted
- object to or restrict certain processing
- receive your data in a portable format
- withdraw consent where processing is based on it
- learn who your data has been shared with, inside or outside the country
- object to a result against you that arises solely from automated analysis
- claim compensation for damage caused by unlawful processing
To exercise a right, email support@cockpitify.app from the address of your account. We respond within 30 days. You also have the right to complain to a supervisory authority, such as the Turkish Personal Data Protection Authority (KVKK) or the data protection authority where you live in the EU or UK.
If you are an end user of an app that uses Cockpitify, please contact that app’s developer, who controls your data. We will help them answer your request.
Children
The Service is meant for app developers and businesses. It is not directed at children, and we don’t knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
We may update this policy as the Service changes. We’ll post the new version here with a new date, and if the changes are significant, we’ll tell you in the app or by email before they take effect.
Contact
Cockpitify, support@cockpitify.app