Privacy
Last updated 28 September 2026. This is a product disclosure, not legal advice.
AppHole inspects public pages of apps you submit. We store the URL, timestamps, HTTP metadata, extracted text needed for findings, and the resulting report. We do not ask for passwords in the Free check.
Do not submit an app you are not authorized to test. Do not paste secrets into the URL field.
If you create an account, we store your email and a password hash. If you upgrade, Stripe stores payment details. AppHole stores Stripe customer and subscription ids so Pro entitlements can sync.
If you request a plug quote, we store the email and hole description you submit, plus optional report context (scan id, app URL, and the finding you picked) so we can reply with a price. We use that only to quote and follow up on the job, not as a marketing list.
Optional AI plug wording: if an operator enables an LLM key, finding titles and evidence may be sent to that provider to rewrite recommended plugs. The model is not allowed to invent extra failures. You can run AppHole without that key.
Scan data is kept so you can reopen a report and, on Pro, retest. You can email hello@apphole.pro to request deletion of stored scans, plug-quote leads, and account data.
We keep first-party usage events (pages viewed, checks started, signup and checkout steps) so we can see where the product is confusing. We also run a Meta Pixel (Facebook) that records page views and those same conversion steps. Meta may set cookies and receive a hashed view of the visit so ads can be measured. We do not send your scan targets, emails, or passwords to Meta.
We do not sell your scan targets as a marketing list.

