Scope and data controller
This Privacy Policy explains how GetAppBuilt collects, uses, discloses, and protects personal data when you use its website, APIs, GitHub App, command-line tools, bounty and review workflows, and configured smart-contract interfaces (the "Service").
WEB3 FZCO is the controller of personal data processed for the Service's own purposes. A connected repository owner, GitHub, a payment provider, or a blockchain participant may separately control data for its own purposes.
This Policy does not govern third-party websites, repositories, wallets, networks, or services that have their own privacy notices.
Personal data we collect
- Account and identity data: name, display name, email address, verified-email status, account identifiers, roles, public-profile slug, and connected social identities.
- GitHub and repository data: GitHub user ID, login, avatar, authorized scopes, App installation and repository permissions, organization or repository metadata, issues, comments, pull requests, commit or branch references, webhook events, and private-repository content you authorize the Service to access.
- Wallet and public-chain data: wallet addresses, chain IDs, token choices, signatures, transaction hashes, contract events, funding, stake, payout, and refund evidence. Public-chain data is already visible to others and may be combined with your Service account when you connect or use a wallet.
- Requests and work data: build requests, bounty terms, pledges, claims, Submissions, patches, artifact metadata and files, test or preflight output, review evidence, disputes, ratings, reputation events, publication handoffs, and audit logs.
- Payment and compliance data: payment or payout provider account IDs, checkout and transfer status, amounts, country or eligibility status, chargebacks, refunds, invoice records and privately stored invoice documents, risk results, and KYC status when those features are enabled. Hosted providers, not GetAppBuilt, collect raw card and bank-account credentials.
- Technical and security data: IP address and user agent or their hashes, session and OAuth security cookies, authentication challenge records, timestamps, request and error logs, device or browser state needed for a requested feature, and fraud, abuse, availability, or security signals.
- Communications: support, privacy, dispute, safety, and other messages you send to us, plus in-app and GitHub lifecycle notifications. Email is currently used for authentication links, not marketing or bounty-status campaigns.
Please do not include secrets, unnecessary personal data, raw payment credentials, health data, government identifiers, or other sensitive information in requests, issues, Submissions, or support messages.
Where data comes from
We receive data directly from you when you create an account, submit a request, fund or claim work, connect a wallet, provide a Submission, review work, open a dispute, or contact us. We also receive data from GitHub and repository installations you authorize, public blockchain networks and RPC providers, payment and payout providers, email providers, other bounty participants, and normal browser or API requests.
Public repository, profile, issue, pull-request, and blockchain data may be collected from public sources when needed to display or verify relevant work. Private repository data is accessed only through an authorized GitHub identity or App installation and is subject to stricter visibility checks.
Why we use data and our legal bases
We process personal data to:
- create and secure accounts and authenticate users;
- operate requests, funding, claims, Submissions, reviews, disputes, payouts, refunds, reputation, and publication handoffs;
- verify crypto funding and bounty state, GitHub authorization, repository events, payment-provider status, and contract evidence;
- protect private repositories and artifacts, prevent fraud and abuse, enforce policies, investigate incidents, and preserve audit records;
- provide support and service messages, maintain reliability, debug errors, and improve accessible product flows;
- comply with accounting, tax, sanctions, legal-process, and regulatory obligations; and
- establish, exercise, or defend legal claims.
Depending on the context and law, we rely on performance of a contract or steps you request before a contract, compliance with legal obligations, consent, and legitimate interests such as securing and improving the Service, preventing abuse, and maintaining reliable transaction and audit records. Where we rely on consent, you may withdraw it, but withdrawal does not affect earlier lawful processing and may prevent the requested feature from working.
How we disclose data
We disclose personal data only as reasonably necessary:
- To users and the public: public profiles, repository references, requests, bounty terms, wallet addresses, transaction evidence, ratings, and public Submission metadata are visible according to the relevant visibility settings and public source.
- To authorized participants: sponsors, workers, maintainers, reviewers, repository users, and operators receive the private context needed for their role. Unauthorized and missing private records receive the same generic response.
- To service providers: hosting, database, storage, security, observability, email, GitHub, blockchain/RPC, wallet, payment, payout, identity, support, and professional-service providers process data to supply their functions. Providers may act as our processors or as independent controllers for their own legal, fraud, security, and compliance purposes.
- For legal and safety reasons: we may disclose data to courts, regulators, law enforcement, affected parties, or advisers when required by law or reasonably necessary to protect rights, safety, security, and the integrity of the Service.
- For a business transaction: data may transfer as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and notice where required.
We do not sell personal data, and we do not use it for third-party behavioral advertising. If that changes, we will update this Policy and provide any consent or opt-out required by law.
Public chains, GitHub, and private artifacts
Transactions on Ethereum Sepolia are public. Wallet addresses, token transfers, transaction hashes, timestamps, and contract events can be copied and analyzed by anyone and generally cannot be erased by GetAppBuilt. Avoid using a wallet that reveals activity you do not want associated with your GetAppBuilt account.
GitHub data follows the visibility and permissions of the connected repository. GetAppBuilt requests the minimum practical GitHub access for enabled features. Revoking the App or user authorization stops new access but does not automatically delete records already needed for completed work, security, disputes, or legal compliance.
Private repository rows and artifact contents are limited to authorized users. Downloads may be short-lived and audited. Public viewers receive safe metadata or a generic unavailable response, not private content or confirmation that a hidden record exists.
Risk signals and automated processing
The Service may generate similarity, scope, safety, quality, fraud, reputation, and related-account signals from GitHub, wallet, payment, work, and audit data. AI-assisted and rules-based results are advisory evidence unless a disclosed policy requires a temporary hold.
GetAppBuilt does not use these signals to make a solely automated decision with legal or similarly significant effects. An authorized person reviews payout, refund, dispute, suspension, and other significant outcomes. You may request human review and provide additional evidence through the contact method published in this Policy.
Privacy-sensitive device or IP fingerprinting beyond disclosed security hashes is not enabled as a general related-account signal unless this Policy is updated to disclose and authorize it.
Retention
We keep personal data only as long as reasonably needed for the purposes described here, including to provide the Service, complete payment and bounty obligations, secure accounts, resolve disputes, enforce agreements, maintain financial and audit records, and comply with law. Retention depends on record type, sensitivity, contract and limitation periods, provider requirements, and whether a dispute or security hold exists.
- Session cookies expire under the configured session period; OAuth state cookies expire after about 10 minutes.
- Email sign-in links normally expire after 15 minutes. We retain challenge and security metadata longer when needed to prevent replay and investigate abuse.
- Temporary uploads are retained for 24 hours by default.
- Rejected or withdrawn Submission payloads are retained for 14 days after closure. Normal Submission payloads are retained for at least 30 days from submission and extended from recorded acceptance, dispute, or chargeback lifecycle events.
- Accepted evidence is retained for 30 days after the last recorded applicable event. A legal hold pauses deletion until it is released.
- Transaction hashes, contract versions, payment status, audit logs, dispute evidence, reputation events, and artifact hashes may be kept longer because they protect users and explain money or review outcomes. Compliance metadata is retained for seven years by default.
- Invoice records and their private PDFs are retained for seven years by default for accounting, tax, dispute, and compliance purposes. A legal hold prevents scheduled PDF deletion.
- Backups and provider copies may persist for a limited period after deletion before being overwritten under normal cycles.
Where law requires a fixed retention schedule, we will publish it. Where deletion is not possible, we may restrict use or anonymize data when appropriate.
International transfers and security
GetAppBuilt and its providers may process data outside your country, including outside the United Arab Emirates. Where required, we use lawful transfer mechanisms, contractual protections, provider due diligence, and technical safeguards appropriate to the data and destination. Public blockchain and GitHub data may be globally available by design.
We use measures designed to protect personal data, including access controls, encryption of stored GitHub credentials, short-lived or scoped access, hashed security signals, private artifact controls, audit logging, provider restrictions, and separation of public and operator-only data. No method of storage or transmission is perfectly secure, so we cannot guarantee absolute security.
If a breach creates a legally reportable risk, we will notify the UAE Data Office, affected people, or other authorities as required by applicable law and provide available information about protective steps.
Your privacy rights
Subject to applicable law and exceptions, you may request information about processing; access or a portable copy; correction; deletion; restriction; objection or cessation of certain processing; withdrawal of consent; and review of an automated decision. You may also complain to the UAE Data Office or another competent data-protection authority.
We may verify your identity and authority before responding. Some data cannot be deleted from a public blockchain, GitHub, another user's records, or records we must keep for payment, accounting, safety, disputes, legal claims, or compliance. We will explain an applicable limitation when required.
Submit these requests through the support contact published by GetAppBuilt. We will respond within the period required by applicable law and will not discriminate against you for exercising a privacy right.
Children, changes, and contact
The Service is not directed to anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided personal data, contact GetAppBuilt support so we can investigate and take appropriate action.
We may update this Policy to reflect product, provider, legal, or security changes. We will post the new date and provide reasonable notice of material changes where required. A change will not retroactively make private repository content public.
Privacy questions and data-rights requests may be directed to WEB3 FZCO at support@web3.consulting.
GitHub and payment providers process data under their own notices. You can review the official GitHub Privacy Statement and Stripe Privacy Center before connecting or using those services.