Legal

Privacy Policy

How AppMetricsKit minimizes and protects personal data while providing mobile app analytics.

Last updated: July 29, 2026

AppMetricsKit is a mobile analytics service operated by AppSurge in Belgium ("AppMetricsKit," "we," "us," or "our"). This policy explains how we handle data about developers, companies, and agencies that use the service ("Customers"), as well as analytics data processed for those Customers.

Our roles

We act as a controller for Customer account, support, security, and billing data used to operate AppMetricsKit. For mobile analytics data submitted by a Customer, the Customer is the controller and AppMetricsKit acts as its processor. Customers are responsible for providing notices and choosing a lawful basis for analytics in their own apps.

Data we handle

  • Account and organization data: name, email address, authentication identity, organization membership, role, settings, audit activity, and support communications.
  • Billing data: plan, subscription, customer, and invoice metadata. Stripe processes payment card details, and AppMetricsKit does not store full card numbers.
  • Mobile analytics data: event name, event and session identifiers, event time, platform, app version, operating system version, device model, locale, timezone, permitted payload values, test-mode status, diagnostic events, and purchase or subscription events. If a Customer calls the SDK identify method, the supplied account identifier is hashed on device before transmission.
  • Request and security data: network address, request headers, timestamps, and diagnostic logs may be processed by AppMetricsKit and its infrastructure providers to deliver and secure the service. Request IP addresses are not added to stored analytics event rows.

How we use data and our legal bases

We use Customer data to provide accounts, authentication, billing, support, security, fraud prevention, and service communications. We rely on performance of our contract where processing is needed to provide the service, legitimate interests for service security and improvement, and legal obligations for records we must retain. Analytics data is processed only to provide the service according to the Customer's instructions.

Data minimization and privacy guardrails

AppMetricsKit does not require advertising identifiers or raw account identifiers. Hashing an account identifier makes it pseudonymous, not anonymous, because the Customer may still be able to associate the hash with an account. The SDKs drop configured payload keys and common email, phone, and payment card patterns on device. The ingest pipeline also checks for risky keys and values. When ingest detects a risky payload key, it removes that key before storing the event and records a privacy finding with a short redacted sample. Automated checks reduce risk but cannot guarantee that every possible personal value will be detected.

Cookies and local storage

The website uses cookies and browser storage needed for authentication, session security, and interface preferences. We do not use advertising cookies or build cross-site advertising profiles.

Retention and deletion

Mobile analytics retention is controlled per app within the Customer's plan limit. Current maximums are 7 days for Free, 90 days for Indie, 395 days for Growth, and 730 days for Scale. Enterprise retention is set by agreement. Customers can start app or organization telemetry deletion in the product. Retention and deletion jobs run in batches, so removal may not be immediate. Account data is kept while an account is active and for a reasonable period afterward. Billing, fraud prevention, and legal records may be kept longer where required by law or needed to establish or defend legal claims.

Sharing and subprocessors

We do not sell personal data. We disclose data only to providers needed for hosting, database services, authentication, payments, email delivery, monitoring, and support. Revenue integration providers receive data only when a Customer configures the relevant integration. Review the current subprocessor list for provider names, purposes, and the data involved.

International transfers

Some providers may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision, Standard Contractual Clauses, or another lawful safeguard. Information about safeguards relevant to a Customer is available on request.

Security

AppMetricsKit uses transport encryption, role-based access controls, tenant-scoped authorization, hashed ingest and API keys, and audited administrative actions. No internet service can guarantee absolute security.

Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, or portability of your personal data, or object to certain processing. Customer app users should normally submit requests to the developer of the app, which can then instruct AppMetricsKit. We may ask for information needed to verify a request.

Children's privacy

AppMetricsKit is a developer service and is not directed to children. Customers are responsible for determining whether their apps are directed to children and for meeting any additional consent and notice requirements.

Changes

We may update this policy as the service or applicable law changes. Material changes will be communicated by email or an in-app notice when appropriate.

Contact and complaints

Send privacy questions or requests to support@appmetricskit.com. You also have the right to lodge a complaint with the Belgian Data Protection Authority or the supervisory authority in your country.