Skip to content
Apple
  • Product
  • Engine
  • Showcase
  • Pricing
  • Docs
Sign in Create an account

Legal

Privacy Policy

Last updated: August 2026

Apple is built and operated by Apple Labs ("we", "us"). This policy describes what data we collect when you use Apple, why we collect it, where it lives, and what we will never do with it. It is written to be read, not skimmed past.

The short version: we store your account email, your projects, your chat history and your checkpoints — because the product cannot work without them. We never sell your data and never use your project content to train AI models. Settings provides data export and deletion tools, with exclusions and separate downloads explained below. Deleting account data does not automatically remove your sign-in identity, usage ledger or support messages.

What we collect

  • Account data. Your email address and a hashed password, used to sign you in and to contact you about your account. That's the entire signup form.
  • Projects. Project names, descriptions, and metadata about the Roblox place you connect (place name and id, as reported by the Studio plugin).
  • Chat history. The messages you exchange with Apple, including attachments you add, and the record of tool actions Apple took (which scripts it edited, which instances it created). This is what lets a project remember its own past.
  • Checkpoints. Compressed snapshots of the parts of your place Apple works on, so you can roll back changes. Apple processes them to provide rollback; authorized operators can access production systems for debugging under access controls.
  • Usage data. A ledger of your Credits usage (which mode, when, how many), used to enforce daily quotas fairly and to keep the free tier viable. We also keep coarse, aggregated counters (e.g. total requests per day service-wide) that contain no content.
  • A request log. Which API route was called, when, how long it took and whether it failed — so a broken feature can be told from a slow one. Routes are recorded as routes, never as the raw path, so a project id is never in the log. Each entry carries your account id for 30 days unless you switch that off in Settings → Privacy, in which case the request is still counted with nobody's name on it.
  • Billing identifiers. If you subscribe or buy Credits, Stripe handles the payment and we keep the subscription state and invoice references it sends back. We never see or store your card.
  • A Roblox Open Cloud key, if you give us one. Only so Apple can upload assets to your own Roblox account when you ask it to. It is encrypted at rest with a key the database does not hold, it is never returned to anyone — including you; the settings page shows a fingerprint and the last four characters — and deleting it from Settings removes it outright.
  • A Discord account id, if you link one. Only so builds you start from Discord reach the right account.

What we deliberately do not collect

  • No card numbers. Payments go to Stripe and card details never touch our servers.
  • No advertising identifiers, no third-party tracking pixels, no analytics that follow you across the web.
  • No contents of your Roblox account beyond what the plugin sends for the place you explicitly connect, and — if you gave us an Open Cloud key — what you asked Apple to upload with it.

Training — the promise

Your private project data is never used to train AI models. Not your scripts, not your chats, not your checkpoints, not "anonymized" derivatives of them. If we ever build an opt-in program for contributing examples, it will be a separate, explicit, off-by-default choice — and this policy will be updated before it exists.

Who processes your data

Everyone who receives any of it because of something Apple does, and what each one gets:

  • Cloudflare — hosts the application, the API, and project session storage (including chat history and checkpoints). Requests to Apple pass through Cloudflare's network, and AI inference runs on Cloudflare's infrastructure.
  • Supabase — hosts authentication and the account registry (your email, your project list). Access is scoped so that every query runs with your own credentials; our servers hold no master key to your rows.
  • Stripe — subscriptions and Credit purchases. Stripe receives your email and billing identifiers and holds your payment method; we receive back only the subscription state and invoice references. We never hold card details.
  • Discord — only if you link a Discord account. It receives the replies Apple sends to the channel you started a build from, and we store the link between the two accounts until you unlink it.
  • Roblox — only if you give Apple an Open Cloud key, and only for the uploads you ask for. What is sent is the asset being uploaded, to your own account, under your own key.

AI inference runs on infrastructure we operate through these providers. Your prompts and relevant project context are sent to the model to answer your request and are not retained by the inference layer beyond serving that request.

How long we keep it

Your projects, conversations and memory are kept while your account exists. The things with a fixed window have one because the product needs a bound, not because the date is arbitrary:

  • Checkpoints — the newest 25 per project. Taking the twenty-sixth deletes the oldest, in the same write.
  • The request log — 30 days, or 5,000 entries, whichever comes first.
  • Notifications — 30 days once read, 90 days if never read.
  • Automation run history — 90 days, so "what did this cost me last month" is still answerable.
  • Your Credits ledger — 35 days of daily detail, plus monthly totals.
  • New generated images — saved privately with the project until deletion. Existing expired images cannot be recovered.
  • Temporary image previews and generated sound — one hour in cache. A running preview can remain cached for up to an hour after deletion, but deleted-project images cannot be opened through Apple.
  • Deleted-image protection — a deleted project identifier, without images or account details, remains to prevent late-running generation from recreating erased images.
  • Deleted workspace files — 30 days in the trash, recoverable until then.

When you delete a project, its conversation, checkpoints, memory, notifications, automations, workspace files, generated media and any share links go with it.

Taking your data with you

Settings → Privacy → Download my data gathers it into one file in one click. Your account database records and API-key metadata — never a secret key — and then every route the service holds about you, followed for you rather than listed at you: the full transcript of every project, your checkpoints, your Credit spend, your inbox, what Apple was asked to remember, your comments, reviews, share links and Studio pairings. The server's own signed export sits inside it untouched, sha256 and all.

Two kinds of thing stay out, and the file names each one at the top with the route that serves it: bytes — generated images, generated audio, your workspace files and checkpoint snapshots, none of which can be lines of JSON — and a live Studio pairing code, which would be a working key to your project sitting in a downloaded file. If a route does not answer, the file says which one instead of quietly dropping it. Read that list before you delete anything.

Deleting your data

Settings → Danger zone → Delete my account erases your projects, conversations, checkpoints, workspace files, memory, notifications, automations, API keys and your stored Roblox key from every store we can reach. It cannot be undone, and you get a receipt listing what was cleared.

Two things survive it, and we would rather say so than let you find out: your sign-in identity — the empty account can still log in until an operator removes it, which we do on request — and your usage ledger and support messages, which are accounting and correspondence records rather than profile data. The receipt names both, and anything else it could not reach, with the reason. Residual copies in backups expire on the backup rotation schedule (at most 30 days). If anything ever seems left behind, email us.

Your rights

Wherever you live, we honor the substance of modern privacy law: you can access the data we hold about you, correct it, export it, and delete it. For anything the app's settings do not cover, email apple.labs.app@gmail.com and a human will handle it.

Children

Apple is a tool for building on Roblox, and Roblox's community includes young creators. Apple requires an email address to create an account, and we do not knowingly collect data from children below the age at which they can consent to online services in their country. If you believe a child has created an account in violation of this, contact us and we will delete it.

Security

All traffic to Apple is encrypted in transit (TLS). Authentication uses industry-standard signed tokens; the Studio plugin authenticates with short-lived scoped session tokens, never your password. No system is unbreakable — Apple is a beta — but we designed the architecture so that the blast radius of any single failure is small.

Changes to this policy

If this policy changes in any way that matters, we will note it in the changelog and, for significant changes, email account holders before the change takes effect.

Governing law & contact

This policy is governed by the laws of the State of Israel. Questions, requests, worries: apple.labs.app@gmail.com.

Apple

It works inside the place you already have open.

Apple Labs

Product

  • How it works
  • Proof
  • Changelog
  • Pricing
  • Status & known issues
  • Discord community

Docs

  • Getting started
  • Studio plugin
  • Credits & limits
  • FAQ

Legal

  • Privacy
  • Terms
  • Your data
  • Contact

© 2026 Apple. Apple is a beta service, provided as-is.

Not affiliated with or endorsed by Roblox Corporation.