Privacy.
Last updated 3 September 2026
appstills turns a screen recording into App Store screenshots. This page says exactly what that means for your data. It describes the system we actually run.
Your recording never leaves your machine
The video you drop into the studio is not uploaded. Frames are pulled out of it by code running in your own browser. Only the frames you tick in the review step are sent to our server, and only as still images. Close the tab before that step and nothing has left your machine.
What we hold
- Your email address
- So you can sign in and so credits belong to someone. Signing in with Google or GitHub passes us your email address, and nothing else from that account.
- A device cookie
- A random identifier with a signature, set as an HttpOnly cookie. It counts free runs so that one browser cannot take an unlimited number of them. It says nothing about you.
- A daily hash of your IP address
- Your IP address is never stored. It is combined with a secret and the current date, hashed, and only the hash is kept. The same address produces a different hash tomorrow. It counts free runs per address and cannot be turned back into an address.
- The frames you approve
- With the app name and the one-line description, if you typed them. These go to Anthropic’s API, which scores the frames and writes the headlines. Anthropic does not train its models on data sent through the API.
- The screenshots we render
- Held in private storage so you can come back to a set. Seven days for a free run, ninety days for a set you spent a credit on, then deleted. You can delete any set yourself at any time.
- Your credit balance
- As a list of purchases and spends, with amounts and dates. It never contains card details.
Payment
Stripe takes the payment. Card numbers go to Stripe and never reach us. We receive confirmation that a payment succeeded, its Stripe identifier, and which pack was bought.
Who else processes it
These companies handle parts of the service on our behalf.
- Supabase
- Sign-in, the credit ledger, and storage for rendered screenshots.
- Vercel
- Hosting and the servers that render your screenshots.
- Anthropic
- The models that choose the screens and write the copy.
- Stripe
- Payments.
- Google and GitHub
- Only if you choose to sign in with one of them.
Some of them process data outside the European Economic Area. Where that happens it is covered by the European Commission’s standard contractual clauses. We do not sell your data, and we do not share it for advertising.
Cookies
Only the ones the site cannot work without: the sign-in session, the device cookie described above, and a short-lived cookie that remembers which page you were on when you started signing in. There is no analytics, no advertising and no third-party tracking on this site, which is why there is no cookie banner asking you to accept any.
Why we are allowed to hold it
- To give you the service you asked for. Your email address, your frames, your screenshots and your credit balance.
- Our legitimate interest in keeping the free tier usable. The device cookie and the IP hash, both built to count without identifying.
- A legal obligation. Records of what was sold, kept as long as tax law requires.
Your rights
If you are in the UK or the European Economic Area you can ask for a copy of what we hold, ask us to correct or delete it, ask for it in a portable form, or object to a particular use. Most of it you can do yourself: sets are deletable from Your sets, and asking us to close your account removes the rest.
Write to vik.ceb.dev@gmail.com and we will answer within one month. If you are not satisfied you can complain to your national data protection authority.
Children
appstills is a tool for people who publish apps. It is not intended for anyone under 16.
Changes
If this notice changes in a way that affects you, the date at the top changes and we say so in the studio before your next run.
Contact us
appstills is built and run by one person. Write to vik.ceb.dev@gmail.com about anything on this page: a copy of what we hold, a correction, a deletion, or a complaint. It is read by the person who wrote the code.