1. Who is responsible for your information
Lightbulb Moment Labs, Inc., a Texas corporation, operates AppBully. This Privacy Policy describes how we collect, use, disclose and retain personal information through our website, accounts, public checks, connected reviews and integrations.
We determine how account, website and operational information is used to run AppBully. When we review material on behalf of a customer, that customer may separately be responsible for personal information in its websites, repositories or projects. This Policy does not replace a customer’s own privacy notice or any data processing agreement that applies to that relationship.
For privacy questions or requests, contact Lightbulb Moment Labs, Inc. through the contact form. Do not include passwords, access tokens, full source repositories or sensitive personal records in a request.
2. Information we collect
Account information: identifiers such as your user ID, name, email address, profile image, sign-in provider, account status and selected Bully style. Our authentication provider handles sign-in credentials and session management; AppBully does not need your external account password to connect an integration.
App and connection information: app names, public URLs, avatars, descriptions, repository and project identifiers, provider account information, authorization permissions and integration credentials. Connection tokens are sensitive information and are stored with application-level encryption where implemented.
Review material and results: submitted URLs, selected source files, dependency names and versions, database configuration and policy information, public page text, screenshots, evidence excerpts, findings, prompts, check settings and status/history. This material can contain personal information about you or other people, even when it is available on a public page.
Usage and technical information: IP addresses and related network data, request times, browser and device information supplied with requests, session and cookie identifiers, security events, errors, usage counts and actions taken within the Service. Infrastructure and authentication providers may collect technical logs when serving requests.
Communications: the information you provide when asking for help, submitting a privacy request or otherwise contacting us, together with records needed to respond. If a paid purchase is offered, we may receive billing and transaction information necessary to administer it; the payment disclosures at checkout identify the relevant arrangements.
3. Where information comes from
We receive information directly from you, automatically when you interact with the Service, from sign-in and integration providers you authorize, and from websites or files fetched as part of a requested check. An authorized colleague or organization may provide information in material it asks us to review.
A public check can reveal information that was published unintentionally. We treat a possible exposure as a finding to review, not permission to exploit it. Do not use AppBully to collect information about people or systems you are not authorized to review.
4. How we use information
We use information to authenticate users; create and manage accounts; connect authorized providers; fetch and analyze review material; generate, save and display findings; provide fix prompts; operate assistant integrations; remember preferences; and respond to support and privacy requests.
We also use information to understand product usage, diagnose problems, manage usage limits and capacity, prevent fraud and abuse, investigate security incidents, enforce our agreements, meet legal obligations and improve the reliability and usefulness of the Service.
Public showcase information is used for public display only when you choose to participate. A request to run a private review is not permission to publish the repository, screenshots or report.
5. Cookies, local storage and tracking
AppBully uses cookies and similar storage for sign-in, session security, beta access and preferences. For example, the appbully-style cookie remembers your selected tone for up to one year unless you clear it or replace the selection. Public preview requests and results use browser session storage; the preview interface treats them as expired after one hour. Closing the tab or clearing browser storage may remove them sooner.
Technical logging and usage measurement help us understand whether requests succeed, investigate abuse and manage the Service. These activities may associate activity with an account, session, browser or network identifier.
We plan to add tracking to understand how visitors find and use AppBully and how product features perform. This Policy does not mean that every type of tracker is currently active. Before adding new optional analytics, advertising pixels, retargeting or session replay, we will disclose the actual purposes and providers and implement the consent or opt-out controls required for that use.
Optional tracking that requires consent must not begin merely because you visit the site or accept the Terms. Where consent is required, declining or withdrawing it must be available without losing access to features that do not depend on that tracking. Advertising or cross-site measurement may be treated as a sale, sharing or targeted advertising under some laws even if no money changes hands.
You can manage or delete cookies through your browser and clear local or session storage. Blocking essential cookies may prevent sign-in or other functionality. Browser controls do not necessarily remove information already received by us or a provider. Use the contact form for privacy choices or questions about tracking.
Do Not Track is a browser signal without a uniform implementation standard; AppBully does not currently change its essential processing in response to that signal. Legally recognized opt-out preference signals, such as Global Privacy Control, are distinct. Any future processing subject to those signals must honor them where required by applicable law.
6. Source code, screenshots and AI processing
Selected review features send relevant evidence to an AI inference provider to generate explanations or design suggestions. This can include redacted source excerpts, findings, page context and screenshots. Screenshots can contain anything visible on the captured public page. Redaction reduces exposure but cannot guarantee that all personal or confidential information is removed.
Our current implementation uses Inference for configured AI-assisted features. We do not operate a process that trains an AppBully model on your submitted source code or review evidence. This is not a promise of zero retention by every infrastructure or model provider; their applicable service arrangements also govern their processing.
A public URL check does not require a GitHub or Supabase connection. Connected checks process the material available under the permissions you grant. Dependency advisory lookups send supported public package names and exact versions to the Open Source Vulnerabilities service; that lookup does not require sending the entire repository.
Only submit material you are authorized to share for this processing. Do not submit sensitive personal records, regulated health records, payment card data or other highly sensitive information that is unnecessary for a review.
7. Who receives information
Service providers: we use Clerk for authentication, Supabase for application storage, DigitalOcean for hosting and worker infrastructure, and Inference for configured AI processing. Providers receive the information relevant to their functions. Their own notices may also apply when they act independently, such as when you maintain your own account with them.
Connected services: GitHub and customer-connected Supabase services exchange account, authorization, repository/project and related request information with AppBully when you connect and use them. If you connect a coding assistant through MCP, the authorized assistant can receive the reports and other information within the access you grant. Its provider has its own data practices.
Authorized support: designated administrators can access account and app information as needed to provide support and operate the Service. Support impersonation is restricted to a read-only view and is recorded for accountability. This is not public access to your account.
Public recipients: if you opt into the Honor Roll or otherwise share a report or image, other people may see the information you choose to publish. They may copy, index or retain it independently.
Legal and business recipients: we may disclose information when reasonably necessary to comply with law or lawful process, protect rights or safety, investigate abuse, or handle a merger, acquisition, financing, reorganization or transfer of the relevant business. Any new use remains subject to applicable law and required notice.
We do not sell customer source code, integration credentials or private review reports to data brokers. Optional advertising or tracking disclosures must be evaluated separately before those features are enabled; calling an activity “analytics” does not determine its legal classification.
8. Retention and deletion
We keep information for as long as reasonably necessary for the purposes described here, considering account activity, the feature used, support needs, security, applicable legal duties and dispute resolution. Different categories have different operational lifecycles; there is no single retention period for every record.
Account records, app profiles, saved reports and connection settings may remain while your account is active or until they are deleted. Disconnecting a provider removes the connection used for future access but does not automatically delete previous findings. Archiving an app preserves data and is not a deletion request.
Design reports older than 30 days are excluded from normal report reads, with deletion performed by the worker’s cleanup process. Legal report cleanup uses a 90-day age threshold and is triggered by checks. These operational thresholds are not guaranteed deadlines for physical deletion from every system or backup.
You can request account deletion through the contact form. Our deletion process removes the AppBully account and associated app data and connections; it does not delete your GitHub repositories or external Supabase projects. Limited deletion audit records, security records, records subject to legal obligations and backup copies may remain as needed for their purposes and applicable retention cycles.
Full source files fetched for analysis are processed as input; saved reports may retain selected evidence and metadata. A statement that we do not retain a complete repository does not mean no source excerpt is stored. Public copies you or others downloaded or shared cannot be recalled by deleting your AppBully account.
9. Security
We use technical and organizational safeguards designed to limit unauthorized access, including account authentication, access restrictions and protection of stored integration credentials. No system, transmission or security check is guaranteed to be secure.
Protect your accounts and assistant credentials, grant only necessary permissions and revoke integrations you no longer use. If you believe information or access has been compromised, use the contact form. Never send the exposed credential itself unless we provide a secure and necessary method for doing so.
10. Your choices and privacy rights
You can update available profile information, change your Bully style, revoke integrations and turn off showcase participation through the Service. You may also make a privacy request through the contact form.
Depending on where you live and which laws apply to our processing, you may have rights to obtain confirmation and access, correct inaccurate information, request deletion, receive a portable copy, object to or restrict certain processing, withdraw consent, and opt out of a sale, sharing, targeted advertising or qualifying profiling. Some laws also provide a right to limit certain uses of sensitive information.
Tell us what you are requesting and enough information to locate your account. We may need proportionate verification before disclosing or deleting information. An authorized agent may submit a request where permitted, subject to proof of authority and any required verification. We will respond within the time required by applicable law and explain a denial or lawful exception when required.
Where you have an appeal right, you may appeal a decision through the contact form and identify it as a privacy appeal. You may also complain to your state attorney general or applicable data protection authority. We will not unlawfully discriminate against you for exercising privacy rights.
Privacy rights have exceptions and are not identical everywhere. For example, the Texas Data Privacy and Security Act and California Consumer Privacy Act apply only when their respective coverage requirements are met. These references do not represent that every provision of every privacy law applies to AppBully.
11. International users and legal bases
AppBully is operated by a US corporation and uses service providers whose systems may process information in the United States and other countries. Privacy protections may differ from those in your location. Where applicable law restricts a transfer, the required lawful transfer mechanism and safeguards must be in place. We do not claim that all providers use the same mechanism or that AppBully holds a particular transfer certification.
Where European or UK data protection law applies, our purposes may rely on performing a contract or taking steps at your request, legitimate interests such as operating and securing the Service, compliance with legal duties, or consent for processing that requires it. The appropriate basis depends on the activity; consent to optional tracking is separate from a contract for the Service.
You may object to processing based on legitimate interests and withdraw consent where applicable. Withdrawal does not affect the lawfulness of processing before withdrawal. Contact us for information about a particular activity or transfer.
12. Children
AppBully is intended for adults aged 18 and over. We do not knowingly solicit accounts or personal information from children under 18. If you believe a child has provided personal information to us, use the contact form so we can investigate and take appropriate action.
A customer whose website can be used by children is still responsible for what it submits for review. Do not include children’s personal information in screenshots, source files or support requests.
13. Updates and contact
We may revise this Policy as the Service and our practices change. We will update the date above and provide additional notice or obtain consent where required for a material change. A new policy does not authorize retroactive uses that require separate consent.
Direct privacy questions, rights requests and concerns to Lightbulb Moment Labs, Inc. through the contact form.