Privacy Policy
How Applora collects, uses, and protects your data.
Last updated: July 25, 2026
This Privacy Policy explains how Applora ("we", "us", "our") handles information when you use our dashboard, our public app/category/keyword/developer/store directory, and our MCP server.
1. Information We Collect
Account information. You sign in via Google OAuth, so we receive your name, email address, and profile image from Google. We don't collect or store passwords.
Billing information. Subscriptions are handled by Stripe. We store your Stripe customer/subscription IDs and plan status — we never see or store your full card number; Stripe handles that directly.
Usage data. Your watchlist entries, and — if enabled for this deployment — basic analytics (pages visited, general usage patterns) via Google Analytics, Mixpanel, or Umami, and chat interactions via Crisp if you use our support chat.
MCP / AI tool connections. If you connect Applora's MCP server to a third-party AI tool (e.g. Claude, Cursor), we issue an OAuth token scoped to your account so that tool can query market data on your behalf. We log which client is connected and when, so you (and we) can see what's authorized.
2. Shopify App Store Data (Not About You)
Separately from the account data above, Applora's dashboard and public directory display data about the Shopify App Store itself — apps, developers, stores, and reviews — gathered from publicly available Shopify App Store listings and reviews via our own daily crawl. This data is about third parties (app developers, stores, reviewers on the Shopify App Store), not collected from them directly, and isn't linked to your Applora account. If you appear in this dataset and have a concern about it, contact us using the details below.
3. How We Use Your Information
We use account and usage information to:
- Provide the dashboard, directory, and MCP server, and keep you signed in.
- Process payments and manage your subscription through Stripe.
- Send transactional email (welcome email, payment confirmations, and reports) via Cloudflare Email Service, and newsletter email if you've subscribed to it — you can unsubscribe from the newsletter at any time via the link in those emails.
- Understand aggregate usage patterns to improve the product.
- Comply with legal obligations.
We do not sell your personal data.
4. Cookies
We use a small number of cookies:
- Session — keeps you signed in (set by our auth provider).
- Theme and locale — remembers your light/dark mode and language preference.
- Analytics (only if enabled for this deployment) — Google Analytics, Mixpanel, and/or Umami may set cookies or use similar techniques to measure usage. Crisp may set a cookie to maintain a support chat session if you use it.
5. Third-Party Service Providers
We share limited data with the following providers, solely to operate the Service:
| Provider | Purpose |
|---|---|
| Sign-in (OAuth) | |
| Stripe | Payment processing and subscription billing |
| Cloudflare Email Service | Transactional and newsletter email delivery |
| Cloudflare | Hosting, database (D1), and caching (KV) — where your account data and application data physically live |
| Google Analytics, Mixpanel, Umami | Optional product analytics |
| Crisp | Optional support chat |
Each of these providers has its own privacy policy governing how they handle data on our behalf.
6. Data Retention
We retain your account data for as long as your account is active. If you delete your account (available any time from Settings → Profile), we remove your account record and associated per-user data (watchlist, preferences). Billing records may be retained longer where required for tax, accounting, or legal purposes.
7. Data Security
We rely on Cloudflare's infrastructure (D1, KV, Workers) to store and serve data, and use industry-standard practices (encrypted transport, scoped API tokens, OAuth rather than passwords) to protect your account. No method of transmission or storage is 100% secure, and we can't guarantee absolute security.
8. Your Rights
Depending on your location, you may have rights to access, correct, export, or delete your personal data. You can:
- Update your name from Settings → Profile.
- Delete your account and associated data at any time from the same page.
- Contact us at the email below for any other request (e.g. a full data export, or a question about data we hold about you).
9. International Data Transfers
Applora runs on Cloudflare's global network, which means your data may be processed in data centers outside your own country. We rely on Cloudflare's own compliance safeguards for these transfers.
10. Children's Privacy
Applora is a business tool intended for professional use and isn't directed at children. We don't knowingly collect personal data from anyone under 16.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we'll notify you by email or an in-app notice before they take effect.
12. Contact
Questions about this policy, or a request regarding your data? Email support@applora.ai.