Docs
Privacy & data
This page is the practical map of your data in Apple — what exists, where it lives, and who can touch it. The legally binding version is the Privacy Policy; this page just says the same things the way an engineer would over coffee.
The core promise: your projects stay yours, and are never used to train models. Not your scripts, not your chats, not your checkpoints. There is no fine-print exception.
What Apple stores, and why
- Your email + password hash — so you can sign in. This is the only personal information signup asks for.
- Projects — names, descriptions, and the connected place's name and id, so the workspace can show what belongs where.
- Chat history — your conversations with Apple plus the tool trace of what it did. This is your project's memory; deleting a project deletes it.
- Checkpoints — compressed snapshots of the parts of your place Apple works on, kept so rollback works across sessions.
- Usage ledger — when you spent Credits and on which mode, so quotas reset fairly.
- A request log — which route, when, how long, and whether it failed. Routes are logged as routes, never as raw paths, so no project id is in it. It carries your account id for 30 days unless you turn that off in Settings → Privacy; the request is still counted either way, with nobody's name on it.
- Billing state — if you subscribe or buy Credits, the subscription and invoice references Stripe sends back. Your card stays with Stripe.
- Your Roblox Open Cloud key, if you gave one — encrypted at rest and never returned to anybody, including you: the settings page shows a fingerprint and the last four characters, which is what a key looks like when the only thing that can use it is the uploader.
- A Discord account id, if you linked one — so a build started in Discord reaches the right account.
Where it lives
- Cloudflare runs the application and stores project session data — chat and checkpoints — isolated per project, and runs the model inference.
- Supabase runs authentication and the account registry (your email, your project list). Every row is protected so that only requests carrying your verified credentials can read it — our own servers hold no master key that bypasses this.
- Stripe takes the payments. It gets your email and billing identifiers and holds the payment method; we get back the subscription state. No card number reaches us.
- Discord gets whatever Apple posts back to the channel you started a build from — only if you linked an account.
- Roblox gets the assets you ask Apple to upload, to your own account, under your own key — only if you gave one.
What the Studio plugin sees
The plugin only ever acts on the place you explicitly paired, and only sends what a request needs: relevant scripts, tree structure, properties, output logs. It cannot read files on your computer, other places, or anything about your Roblox account beyond the open place — the exact boundary is listed on Install the plugin. And it does none of it until Studio's own per-plugin network permission prompt is accepted, which you can revoke at any time from Studio's plugin management window.
What inference sees
When you send a request, the model receives your message and the project context needed to answer it. That context serves the request and is not retained by the inference layer afterwards. Model routing happens on our infrastructure — your code is not shipped to third-party AI companies' training pipelines.
Who can read your data
- You.
- Apple's systems, mechanically, to serve your requests.
- Authorized operators can access production systems for debugging under access controls. No data sales, no ad networks, no cross-site tracking.
How long things stay
- Checkpoints: the newest 25 per project. The twenty-sixth pushes the oldest out in the same write.
- The request log: 30 days, or 5,000 entries, whichever comes first.
- Notifications: 30 days once read, 90 if never read.
- Automation runs: 90 days.
- Credits ledger: 35 days of daily detail, plus monthly totals.
- New generated images: saved privately with the project until you delete it. Download a copy from the image result. Existing expired images cannot be recovered.
- Temporary image previews and generated sound: one hour in cache.
- Deletion during a running preview: an in-flight temporary image can remain in cache for up to an hour, but deleted-project images cannot be opened through Apple.
- Deleted-image protection: a deleted project identifier is retained without its images or account details, to stop late-running generation from recreating erased images.
- Deleted workspace files: 30 days in the trash.
A nightly sweep is what enforces the ones with a date on them, not a promise that somebody will remember.
Taking it with you
Settings → Privacy → Download my data gathers it into one file in one click. Your account database records and API-key metadata — never a secret key — and then every route the service holds about you, followed for you rather than listed at you: the full transcript of every project, your checkpoints, your Credit spend, your inbox, what Apple was asked to remember, your comments, reviews, share links and Studio pairings. The server's own signed export sits inside it untouched, sha256 and all.
Two kinds of thing stay out, and the file names each one at the top with the route that serves it: bytes — generated images, generated audio, your workspace files and checkpoint snapshots, none of which can be lines of JSON — and a live Studio pairing code, which would be a working key to your project sitting in a downloaded file. If a route does not answer, the file says which one instead of quietly dropping it. Read that list before you delete anything.
Deleting things
- A checkpoint: delete it in the workspace sidebar.
- A project: deleting a project deletes its conversation, checkpoints, memory, notifications, automations, workspace files, generated media and any share links that opened it.
- Your account: Settings → Danger zone → delete account. It erases every store we can reach and hands you a receipt of what it cleared.
Two things outlive that, and the receipt names them rather than leaving you to find out: your sign-in identity (the empty account can still log in until an operator removes it — ask and we will) and your usage ledger and support messages, which are accounting and correspondence records. Backup copies expire within 30 days. Anything else the UI cannot delete for you, a human will: apple.labs.app@gmail.com.
Beta honesty
Apple is a beta run by a small team on a deliberately simple architecture — simple enough to audit, simple enough to explain on one page. If you find a hole in any of the above, please tell us before you tell the internet; we fix fast.