Privacy Policy
Last updated: September 12, 2026
1. Introduction
At Huxly, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered mobile app development platform. Please read this policy carefully to understand our practices regarding your personal data.
2. Information We Collect
We collect information that you provide directly and information collected automatically:
Information You Provide
- Account information (email, name, password)
- Project data and code you create using our platform
- Chat messages and prompts sent to AI models
- Payment information—card payments are processed by our third-party payment processor; we do not collect or store your full card details
- Integration credentials for third-party services you choose to connect
Information Collected Automatically
- Usage data and analytics
- Device information and browser type
- IP address and location data
- Cookies and similar tracking technologies
3. How We Use Your Information
We use the collected information to:
- Provide, maintain, and improve our services
- Process your AI requests and generate code
- Authenticate your identity and manage your account
- Process payments and manage subscriptions
- Send important service notifications
- Provide customer support
- Analyze usage patterns to improve user experience
- Detect and prevent fraud or abuse
4. AI Data Processing and Code Execution
When you use our AI features, your prompts and project context are sent to third-party AI providers (such as OpenAI, Google, and Anthropic) for processing. We do not use your code or prompts to train our own AI models, and our agreements with these providers do not permit them to use your content to train their models. Your data is transmitted over encrypted connections and processed according to each provider's data-handling policies.
Code execution. When you build or preview a project, your project files run in isolated, sandboxed environments that we operate as part of our own infrastructure, used solely to build, run, and preview your project.
5. AI Connector (MCP)
Huxly offers an optional AI Connector that lets an external AI tool you choose — such as Claude, ChatGPT, Cursor, or Windsurf — work directly with your Huxly projects. This is the reverse of the processing described in Section 4: rather than Huxly sending prompts to an AI provider, the AI client you connect reads data from Huxly on your behalf.
What a connected client can access. While connected, the tool can read and modify your project source files, read build and runtime logs from your preview sandbox, capture screenshots of your running app, read the browser console output your app produces, and read the names of your environment variables. Environment variable values are never returned. Anything your app prints to its console, and anything visible on screen in a screenshot, is included in what the connected client receives.
Authorisation. Connecting requires either an API key you generate in Huxly or an OAuth authorisation you grant. We store these credentials, and OAuth access and refresh tokens, to authenticate the connection. You can revoke a key or an authorisation at any time in Huxly settings, which immediately ends the connected tool's access. Once data has been sent to an external AI client, its handling is governed by that provider's own privacy policy, not this one.
6. Backends, Repositories and Deployment
If you generate an API backend for a project, its source code is pushed to a Git repository in your own GitHub account and deployed to a third-party hosting provider you connect, such as Netlify, Railway, or Render. Code and configuration sent to those services are held under your accounts with them and subject to their terms and privacy policies.
To perform these actions on your behalf we store deployment credentials and backend environment secrets, encrypted at rest. We use them solely to push code and trigger deployments you request, and never return their values to an AI client or display them after they are saved.
7. App Testing and Disposable Email Addresses
Automated testing of a project can generate a disposable email address on a Huxly-operated domain so a sign-up or verification flow can be tested end to end. Messages sent to these addresses are received and stored by Huxly, and their contents — including verification links and one-time codes — are returned to the connected AI client or shown to you. Do not send personal correspondence to these addresses. Received messages are deleted automatically after 24 hours, and the addresses themselves after 7 days.
8. Data Sharing and Disclosure
We may share your information with:
- Service Providers: Third-party vendors who assist in operating our platform (cloud hosting, payment processing, analytics)
- AI Providers: To process your AI requests (such as OpenAI, Google, and Anthropic)
- Integration Partners: When you connect third-party services to your projects — for example Supabase, Firebase, or Cloudflare for databases; GitHub and hosting providers such as Netlify, Railway, or Render for backend deployment; and RevenueCat, App Store Connect, or Google Play for subscriptions and store listings. We read from and write to these services only as needed to carry out actions you request, and store-catalogue or pricing changes are made only after you approve the specific plan in Huxly.
- AI Tools You Connect: When you enable the AI Connector, the external AI client you choose receives the project data described in Section 5
- Legal Requirements: When required by law or to protect our rights
- Business Transfers: In connection with mergers, acquisitions, or asset sales
We do not sell your personal information to third parties.
9. Data Security
We implement industry-standard security measures to protect your data, including encryption in transit (TLS) and at rest, secure authentication, and regular security audits. However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security but are committed to protecting your information.
10. Data Retention
We retain your personal information for as long as your account is active or as needed to provide services. Project data is retained until you delete it or close your account. After account deletion, we may retain certain data for legal compliance, dispute resolution, or legitimate business purposes for up to 90 days.
Some data has a shorter, fixed lifetime: messages received at a disposable testing address are deleted after 24 hours and the addresses after 7 days (Section 7), and preview sandboxes and their logs are transient and discarded when the sandbox is recycled.
11. Your Rights and Legal Bases
Depending on your location, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Opt out of marketing communications
- Withdraw consent for data processing
Legal Bases (EEA/UK)
If you are in the European Economic Area or United Kingdom, we process your personal data on the following legal bases: performance of our contract with you (to provide the Service); our legitimate interests (to secure, maintain, and improve the Service and prevent fraud); compliance with legal obligations; and your consent (for example, for non-essential cookies), which you may withdraw at any time.
California (CCPA/CPRA)
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. California residents may exercise the access, deletion, and correction rights described above without discrimination.
To exercise these rights, please contact us at info@huxly.app
12. Cookies and Analytics
We use cookies and similar technologies to operate the platform, remember your preferences, and analyze usage. Essential cookies are required for the platform to function (for example, authentication). We also use third-party analytics tools, which may set cookies to help us understand how the Service is used. You can manage or block cookies through your browser settings, though disabling some may affect features. If you are in a region that requires consent for non-essential cookies, you may withdraw consent or block these cookies through your browser.
13. International Data Transfers
Your information may be transferred to and processed in countries other than your own, including the United States and other countries where we or our service providers operate. We rely on appropriate safeguards for these transfers, such as Standard Contractual Clauses and our providers' compliance with applicable data-protection laws.
14. Children's Privacy
Our Service is not intended for users under 16 years of age (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If we become aware of such collection, we will take steps to delete the information promptly.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the “Last updated” date. We encourage you to review this policy periodically.
16. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at:
Huxly LLC
63 N. Burritt Ave, Room 100 East
Buffalo, WY 82834
United States
Email: info@huxly.app