Privacy Policy
Last updated: October 11, 2026
This Privacy Policy explains how Beomseok Seo, doing business as [BUSINESS NAME] ("Totipo," "we," "us") collects, uses, shares and protects personal information when you use the Totipo mobile app, the website at totipo.app, and the related services (the "Service"), and the choices and rights you have. Terms like "Your Apps," "Market Apps," "credits" and "Toti" have the meanings given in our Terms of Service.
The short version
- The apps you make, the data you save in them, and your chats with the AI builder stay on your device. They reach our servers only if you back up or publish an app.
- When you use AI features, what's needed to answer your request passes through our servers to OpenAI, only after you agree. We don't store it, and OpenAI doesn't use it to train its models.
- For your account we keep only what the Service needs to run: who you are when you sign in, your credits and their history, your backups, and your App Market activity.
- We don't sell your personal information, share it for targeted advertising, or use ad or analytics trackers.
- You can delete your account, and what we keep for it, at any time in the app.
1. What stays on your device
Totipo is built so that most of what you create never leaves your device. The following are stored only inside the Totipo app on your device, and we don't collect them:
- Your Apps, including their screens and code;
- the data you save in Your Apps (for example, the entries in a habit tracker);
- your chat history with the AI builder; and
- saved earlier versions of Your Apps.
They leave your device only (a) when you back up or publish an app (Section 2.5 and 2.6), and (b) while you use AI features or live data, when the part needed for that request passes through our servers to the provider that answers it, without being stored by us (Sections 2.7, 2.8 and 3). If you delete Totipo, this information is deleted from your device, and we can't recover it.
2. Information we collect
2.1 Account information
When you sign in with Apple or Google, we receive from them, through our authentication provider: a unique account identifier, your email address (with Apple, this may be a private relay address), the name and profile photo address your provider shares (if any), which provider you used, and sign-in records such as dates, times and IP addresses. We use your name as the default publisher name on the App Market, which you can change before publishing. We don't receive your Apple or Google password.
If you signed in with Apple, the app keeps a token from Apple in your device's secure storage. It's sent to our servers only when you delete your account, so we can ask Apple to revoke Totipo's access, and we don't store it.
2.2 Device identifier for the free trial
So the free trial can be offered once per device, the app creates an identifier for your device: on iOS, a random value kept in your device's Keychain; on Android, the Android ID assigned to the Totipo app. The app sends it to our servers when you use the Service without signing in. We store only a one-way hash of it, together with how much of the free trial was used (messages, whether an app was created, and usage). We don't link it to your account.
2.3 Credits, purchases and Toti
For your account we keep your credit balance and a history of every change to it: welcome credits, credits you add, App Market purchases, Toti used as credits, and usage, which records the feature or API used (for example, "AI builder" or "weather"), the operation, the amount, and the time, but not what you asked or what came back. We also keep whether and when your account first bought credits. When purchases are available, they're processed by Apple or Google, which send us confirmation of the purchase; we don't receive your card or bank details.
For the App Market, we keep the apps you got and when, and, if you publish, each sale of your apps (the app, price, time, and the Toti it earned) and each time you used Toti. Publishers see each sale of their apps, including whether it earned Toti (which depends on whether the buyer has bought credits), but not who the buyer is.
2.4 Consent records
When you agree to the Terms and to sending data to OpenAI, the app records which version you agreed to and when, on your device and, once you're signed in, on your account.
2.5 Backups (only if you back up an app)
When you back up an app, we store a copy of it in your account: its name, icon, description, screens and code, all the data saved in it, and its AI chat history (preview screenshots are removed), along with the backup's size and time. Backups may contain any information you put in the app, so they may contain personal information about you or others. Only you can access your backups, through your signed-in account.
2.6 App Market listings (only if you publish)
When you publish an app, we store its screens and code, name, icon, description, price, the APIs and permissions it uses and the names and shapes of the data collections it uses, together with your publisher name, its version, size and download count. A publish never includes the data saved in the app or its chat. Every app and update is reviewed before it's listed: automatic checks look at its code, and its name, description, publisher name and on-screen text are sent to OpenAI's moderation service; our reviewers then see the app, its code, the results of those checks and your account's email address. Your publisher name and listing are shown publicly in the App Market, and people who get your app receive its screens and code. To detect copies, we also keep fingerprints (hashes) of each version's code.
2.6a Reports and blocks
If you report an App Market app, we keep your report (the reason, what you wrote, the app and version, whether you got the app, and when) linked to your account, and our reviewers see it. Publishers aren't told who reported their app. If you block a publisher, we keep that on your account so their apps stay out of your App Market. We keep a record of the actions our reviewers take on apps and accounts.
2.7 Live data requests
When an app uses live data from the API Market, the app sends our servers the API and operation it's calling, the app's name, and the parameters it passes (for example, a city name, coordinates, a search term, a product barcode or a vehicle identification number). Our servers forward the request to the provider and return the response. Providers receive the request from our servers, not from your device, so they don't receive your IP address from us. We don't store the parameters or the responses; we record only the usage described in Section 2.3.
2.8 AI requests
See Section 3.
2.9 Technical information
When your device connects to our servers, our hosting, database and authentication providers automatically record technical information such as IP address, date and time, the address requested, response status, and app and device type. We use it to run, secure and debug the Service. The app also checks for app updates with Expo (our app update service), which receives information such as your device's platform, the app's version and a random installation identifier. We don't use advertising identifiers, and we don't collect your precise location, contacts, photos, camera, microphone, biometric information, or browsing history. The Totipo app doesn't contain advertising or third-party analytics software, and we don't track you across other companies' apps or websites.
2.10 Communications
If you contact us, we keep your message, your email address, and the information you include, and our replies.
3. AI processing
Totipo uses AI models from OpenAI, L.L.C. ("OpenAI"). Before anything is sent to OpenAI, the app explains what will be sent and asks for your permission. If you don't give it, AI features stay off. When you use AI features, the following passes through our servers to OpenAI:
- The AI builder: your messages, the AI's earlier replies in that app's chat, the app's code and settings that the AI reads or writes, screenshots, visible text and error messages of the app taken while the AI checks its work, and information about your other apps the AI looks at to reuse their code (their names, descriptions and code, but never the code of Market Apps or any app's saved data).
- AI features in apps: what the app sends (for example, text you type into an AI feature) and the app's name, for text, image and speech generation.
- Web searches by the AI builder: the search terms the AI writes are sent to our web search providers (Brave Search, and Tavily as a backup), not to OpenAI.
We don't store these requests on our servers, and for text requests we tell OpenAI not to store them for later retrieval. OpenAI doesn't use data sent through its API to train its models. Under its policies, OpenAI may keep requests and responses for up to 30 days to identify abuse, unless the law requires longer. OpenAI's handling is described in its privacy policy and its API data commitments. Please don't include sensitive information, such as passwords, government ID numbers, or health or financial details, in what you send to AI features unless you're comfortable with it being processed this way.
4. How we use information
We use personal information to:
- provide, operate and maintain the Service, including signing you in, building and running apps, AI features, live data, backups and the App Market;
- keep track of credits and Toti, charge usage, process App Market purchases and record earnings;
- run the free trial and prevent abuse, such as fake accounts, repeated trials, self-dealing and fraud;
- protect the security and integrity of the Service, our users and others, including detecting, investigating and preventing security incidents and violations of our Terms;
- detect copies of App Market apps;
- communicate with you, including responding to requests and sending notices about the Service, your account and changes to our terms (we don't send marketing email unless you agree to receive it);
- debug, measure and improve the Service using operational information such as usage records and logs (we don't use the content of your apps, data or chats for this, and we don't use it to train AI models);
- comply with law, legal process and requests from authorities, and establish, exercise or defend legal claims; and
- for any other purpose we describe when we collect the information, or with your consent.
We may also create de-identified or aggregated information that can't reasonably be linked to you, and use it for any lawful purpose. We'll keep de-identified information in that form and won't try to re-identify it, except to test our de-identification.
5. How we share information
We don't sell personal information, and we don't share it for cross-context behavioral (targeted) advertising. We disclose personal information only as follows:
- Service providers that process it on our behalf and under contracts that limit their use of it, including: Supabase (authentication, database and file storage), Railway (server hosting), OpenAI (AI processing and content moderation), Brave Search and Tavily (web search for the AI builder), Expo (app updates), Cloudflare (our website and review tools), and the messaging service that alerts our reviewers to new submissions and reports (which receives the app's name and any text written in a report).
- Data providers in the API Market, which receive the parameters your apps send, from our servers, to answer the request. They currently include Open-Meteo, the National Weather Service, Sunrise-Sunset.org, the U.S. Geological Survey, ExchangeRate-API, CoinGecko, Finnhub, Wikipedia (Wikimedia Foundation), Free Dictionary API, Datamuse, Open Library, Open Trivia Database, JokeAPI, Hacker News Search (Algolia), Spaceflight News API, NASA, the Art Institute of Chicago, TheMealDB, TheCocktailDB, Open Food Facts, USDA FoodData Central, openFDA, Apple (iTunes Search), TVmaze, TMDB, PokéAPI, Nager.Date, the National Highway Traffic Safety Administration and Brave Search. The current list is in the API Market in the app.
- Apple and Google, when you sign in with them, buy through their app stores, or delete your account (to revoke Sign in with Apple).
- Other users, as you direct: your publisher name and App Market listings are public, and people who get your apps receive their screens and code.
- For legal and safety reasons: when we believe in good faith it's necessary to comply with law, legal process or a lawful government request; to enforce our Terms; to protect the rights, property or safety of Totipo, our users or the public; or to report child sexual exploitation to the National Center for Missing & Exploited Children.
- In a business transfer, such as a merger, acquisition, financing, reorganization, bankruptcy or sale of assets, in which case personal information may be transferred as part of that transaction subject to this policy or one at least as protective.
- With your consent or at your direction.
6. Content your apps load
Your Apps and Market Apps run inside Totipo on your device. They can't make network requests of their own; live data and AI go through Totipo as described above. However, your own apps can load content from the internet, such as fonts from Google Fonts, code libraries from jsDelivr, and images from other websites. When they do, your device connects directly to those websites, which receive your IP address and technical information under their own privacy policies. Market Apps are made by other users and run with stricter limits: they can't load code from the internet, they can show images only from the image servers of our API Market providers and fonts only from Google Fonts, and Totipo asks you before opening a link from them. These limits make it much harder for a Market App to send what you enter into it elsewhere, but we can't rule it out completely, so only enter sensitive information into apps you trust.
7. How long we keep it
| Information | How long |
|---|---|
| Account information, credit balance and history, consent records | Until you delete your account or we terminate it |
| Backups | Until you delete the backup or your account |
| App Market listings and published code | Until you delete your account. Removing a listing hides it from the App Market but keeps it, so people who got the app can still update or download it again |
| App Market purchases, sales and Toti | Until the account that made them is deleted |
| Reports you made and publishers you blocked | Until you delete your account |
| Records of reviewers' actions on apps and accounts | As long as needed to enforce our Terms and handle repeat violations; after an account is deleted, they're no longer linked to it |
| Free-trial records (hashed device identifier) | As long as needed to offer the trial once per device, which may be indefinitely; they aren't linked to accounts |
| AI requests and live-data parameters | Not stored by us. OpenAI may keep AI requests for up to 30 days (Section 3) |
| Technical logs | A limited period set by our providers' log retention, generally no more than 90 days |
| Messages to us | As long as needed to answer and to keep a record of the request |
After deletion, copies may remain in our providers' backup systems for a limited period, generally no more than 30 days, until they're overwritten. We may keep information longer when the law requires it, to resolve disputes, to enforce our agreements, or to prevent fraud and abuse, and records of purchases for as long as tax and accounting laws require.
8. Your choices and account deletion
- AI features. You can choose not to allow sending data to OpenAI. AI features then stay off, and you can still open and use your apps.
- No account. You can use the free trial and run your apps without signing in.
- Backups and listings. You can delete a backup at any time (My Apps → Backups), and remove your listings from the App Market.
- Delete your account. In the app, open Account (tap your credit balance) and tap Delete Account. This immediately and permanently deletes your account and everything we keep for it: your account information, credits and their history, Toti, consent records, backups, App Market listings and published code, purchases and sales, and revokes Sign in with Apple. Remaining credits and Toti are forfeited and aren't refunded, as described in the Terms. People who got your apps keep their copies but won't receive updates. Apps on your device aren't affected. If you can't use the app, see how to request deletion.
- Device data. To delete what's stored on your device, delete the app or the data in it.
9. Security
We use reasonable administrative, technical and physical safeguards designed to protect personal information, including encryption in transit, access controls that let each account reach only its own records and files, keeping provider keys only on our servers, and storing device identifiers only as one-way hashes. No method of transmission or storage is completely secure, and we can't guarantee absolute security. If we learn of a security breach affecting your personal information, we'll notify you as the law requires. You can report security issues to totipotentapp@gmail.com.
10. Children and teens
The Service isn't directed to children under 13, and we don't knowingly collect personal information from children under 13. If we learn we've collected personal information from a child under 13 without the verifiable parental consent required by the Children's Online Privacy Protection Act, we'll delete it. If you believe a child under 13 has given us personal information, contact totipotentapp@gmail.com. Users aged 13 to 17 may use the Service only with a parent's or guardian's consent, as described in the Terms. We don't sell the personal information of anyone, including teens, or use it for targeted advertising.
11. Your U.S. state privacy rights
Depending on where you live, including California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia, you may have some or all of the following rights, subject to exceptions in the law:
- Access / know: to confirm whether we process your personal information and to get a copy of it, in a portable format where required, and information about how we collect, use and disclose it;
- Correction: to correct inaccurate personal information;
- Deletion: to delete personal information we collected from or about you;
- Opt out: of the sale of personal information, its sharing or processing for targeted advertising, and profiling in furtherance of decisions with legal or similarly significant effects (we don't do any of these);
- Sensitive information: to limit, or to give or withdraw consent for, the processing of sensitive personal information (we process it only as described in Section 13, with your consent, and don't use it to infer characteristics about you);
- List of third parties: in some states, to get a list of the specific third parties to which we've disclosed personal information (see Section 5); and
- Non-discrimination: not to be discriminated against for exercising these rights.
We honor these requests from all U.S. users, whether or not their state's law requires it.
How to make a request. You can delete your account yourself in the app. For other requests, email totipotentapp@gmail.com from the email address on your account, with "Privacy request" in the subject and what you'd like us to do. Because Totipo operates only online and has a direct relationship with its users, email is our designated method for requests. We'll verify your request by confirming it came from, or by contacting, the email address on your account, and we may ask for more information if needed. We may decline requests we can't verify. If you don't have an account, the only personal information we have about you is likely the hashed device identifier and technical logs, which we can't link to you.
Authorized agents. You may use an authorized agent to make a request. We'll require the agent to provide your signed permission, and we may ask you to verify your identity with us directly, unless the agent has a valid power of attorney.
Timing. We'll respond within 45 days, or within the time your state's law requires. If we need more time, we may extend this as the law permits and will tell you why.
Appeals. If we decline your request, you can appeal by replying to our decision with "Appeal" in the subject line. We'll respond to your appeal in writing within the time required by law (generally 45 to 60 days). If we deny your appeal, you may contact your state's Attorney General.
Nevada. We don't sell covered information as defined by Nevada law. You may still submit a request to opt out of sale to totipotentapp@gmail.com.
12. California notice
This section applies to California residents and supplements the rest of this policy, as required by the California Consumer Privacy Act, as amended ("CCPA"). In the past 12 months, we've collected the following categories of personal information:
| Category (CCPA) | Examples | Sources | Disclosed for a business purpose to |
|---|---|---|---|
| Identifiers | Account identifier, email address, name, hashed device identifier, IP address | You, Apple or Google, your device | Service providers (Supabase, Railway) |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Name, email address | You, Apple or Google | Service providers |
| Commercial information | Credit balance and history, App Market purchases and sales, Toti | You, your use of the Service | Service providers; publishers see anonymous sale records |
| Internet or other electronic network activity | Usage records (feature, API, time, amount), technical logs | Your device, our systems | Service providers |
| Audio, electronic, visual or similar information | Screenshots of your apps taken by the AI builder (not stored by us) | Your device | OpenAI, as a service provider |
| Other information you provide | Messages to the AI builder, what your apps send to AI features and APIs, backups, published apps | You | Service providers (Supabase, OpenAI, Brave, Tavily) and API Market data providers; the public, for published apps |
We collect and use these categories for the business purposes described in Section 4, and keep them as described in Section 7. We don't collect sensitive personal information as defined by the CCPA, except to the extent you choose to include it in content you send to AI features or save in backups, which we process only to provide the Service you requested and not to infer characteristics about you. We don't sell or share personal information, as those terms are defined in the CCPA, and haven't in the past 12 months, including of consumers under 16. You have the rights described in Section 11, including the rights to know, delete and correct, and the right to non-discrimination.
Notice of financial incentive. New accounts receive 1,000 free welcome credits. Creating an account involves providing the account information in Section 2.1, so this may be considered a financial incentive. You opt in by creating an account, and you can withdraw at any time by deleting your account, which forfeits remaining credits. We estimate the value of the personal information involved as roughly equal to the value of the welcome credits (about US $1 at their list value), based on our reasonable estimate of the expenses related to providing the Service to an account.
Shine the Light. We don't disclose personal information to third parties for their own direct marketing purposes.
13. Consumer health data
This section is our Consumer Health Data Privacy Policy under the Washington My Health My Data Act, Nevada's consumer health data law (SB 370) and similar laws, such as Connecticut's.
Totipo isn't designed to collect health information, and we don't ask for it. But you might choose to build apps about health, such as a water, medication or workout tracker, or to mention health information in a message to the AI builder. Information like that, when it identifies you and relates to your past, present or future physical or mental health, may be "consumer health data."
- What we may collect: only health information you choose to include in messages to the AI builder, in what your apps send to AI features or APIs, or in backups you make. Data you save in your apps stays on your device unless you back the app up.
- Sources: you, directly.
- Why: only to provide the feature you asked for: answering your AI request, returning live data, or storing your backup.
- Who receives it: our service providers that process it to provide that feature (OpenAI for AI requests, API Market providers for live data requests, and Supabase for backups), as described in Sections 3 and 5. We don't sell consumer health data, and we don't use it for advertising.
- Consent: we ask for your consent in the app before anything is sent to OpenAI, and you give it again each time you choose to back up an app.
- Your rights: you can confirm whether we collect or share your consumer health data and get a list of the third parties and affiliates we share it with, get a copy of it, delete it (by deleting backups or your account, or by emailing us), and withdraw your consent (by not using AI features, deleting backups, or deleting your account). To exercise these rights or appeal a decision, follow Section 11 or email totipotentapp@gmail.com. If we deny your appeal, you may contact the Washington State Attorney General (or your state's Attorney General).
14. Do Not Track and Global Privacy Control
We don't track you across other companies' websites or apps, and we don't sell or share personal information for targeted advertising, so there's nothing for these signals to opt you out of. Where the law requires it, we treat a Global Privacy Control signal from your browser as a request to opt out of sale and sharing for that browser. Our website doesn't use tracking cookies.
15. Users outside the U.S.
The Service is intended for users in the United States. If you use it from elsewhere, your information is transferred to, stored in and processed in the United States and other countries where our service providers operate, whose data protection laws may differ from those where you live.
16. Changes to this policy
We may update this policy from time to time. We'll post the updated version here and change the "Last updated" date. If we make a material change, such as sending your information to a new kind of recipient or using it for a new purpose, we'll notify you in advance in the app or by email and, where the law requires it or the change affects what's sent to AI providers, ask for your consent again.
17. Contact us
Beomseok Seo, doing business as [BUSINESS NAME]
[MAILING ADDRESS]
Email: totipotentapp@gmail.com (for privacy requests, put "Privacy request" in the subject line)