What AppNest does
AppNest lets you connect an AI assistant such as Claude or ChatGPT, ask it to build a small app, and deploy that app to a public AppNest URL with persistent shared state.
AppNest is currently operated by Charles Squeri as an early sole-proprietor project.
AppNest's role
AppNest is the data controller for the account and operational data described below. When you build an app that collects personal data from its own visitors — for example form entries, RSVPs, or poll votes — you decide what to collect and why, so for that data you are the controller and are responsible for having a lawful basis and giving the people who use your app appropriate notice. AppNest stores and serves that data for you as part of operating the service and does not use it for its own purposes.
AppNest is an early sole-proprietor project. It does not currently offer signed data processing agreements, SOC 2 reports, or formal compliance certifications. This policy describes a good-faith privacy process, not an audited or certified compliance program.
Information AppNest collects
- Account information from Google sign-in, such as your name, email address, profile image, and Google account identifier.
- Generated app metadata, such as app name, description, slug, status, deployment history, and capability schema.
- Uploaded deployment files, such as HTML, CSS, JavaScript, and other assets your AI assistant asks AppNest to deploy.
- Data stored inside generated apps, such as RSVP responses, poll votes, score entries, list items, or form submissions.
- Operational data, such as OAuth session records, audit events, request IDs, timestamps, status codes, and error details.
- Basic technical data your browser or AI client sends with requests, such as IP address, user agent, and request headers.
- Billing data for paid plans, such as your subscription status, plan, and the customer and subscription identifiers from our payment processor. AppNest does not receive or store your full payment card number.
How AppNest uses information
AppNest uses this information to authenticate you, create and deploy apps, keep app data available, show your apps in the dashboard, process payments and manage subscriptions for paid plans, prevent abuse, troubleshoot errors, and maintain service security.
Legal bases for processing
Where data protection laws such as the GDPR apply, AppNest relies on the following legal bases to process your personal data:
- Performance of the service you request — signing you in and operating, creating, deploying, and serving your apps and keeping their data available.
- Legitimate interests — keeping AppNest and its users secure, preventing abuse, troubleshooting problems, and improving the service, weighed against your rights and freedoms.
- Consent — where AppNest specifically asks for it. Where processing relies on consent, you can withdraw it at any time without affecting processing already carried out.
App visibility
Generated apps are public by link by default — anyone with a generated app URL can open the app and may be able to read or write data depending on how it was built. You can also make an app private, shared only with people you invite, who sign in with a magic link. AppNest is still an early product, so do not put regulated, confidential, or highly sensitive information into generated apps.
Vendors and subprocessors
AppNest relies on a small number of vendors to operate, and shares only the data each one needs:
- Google — sign-in and identity (your Google profile and account identifier).
- Cloudflare — hosting, compute, storage, networking, and abuse-prevention tooling for AppNest and the apps you deploy.
- Stripe — payment processing and subscription billing for paid plans (your billing email, subscription details, and the card details you enter with Stripe). AppNest does not receive or store your full card number; see Stripe's Privacy Policy.
When you use AppNest from an AI client such as Claude or ChatGPT, that client also processes your conversation and tool calls according to its own terms and privacy policy. AppNest relies on Google's and Cloudflare's own data protection terms as their customer.
International data transfers
AppNest runs on Google's and Cloudflare's global infrastructure, so your data may be processed in countries other than the one you live in. Those providers offer their own safeguards for international transfers, such as standard contractual clauses, which AppNest relies on as their customer.
Retention
AppNest keeps personal data only as long as it is needed for the purposes above:
- Account and identity data — while your account is active; removed when your account is deleted.
- App, deployment, and app collection data — until you delete the app, or until your account is deleted.
- Short-lived operational records, such as sign-in, upload, and idempotency tokens — automatically expire within minutes to 24 hours.
- Audit and security logs — kept for a limited period for security, abuse prevention, and legal compliance.
- Billing records for paid plans — kept as long as needed to provide the paid service and to meet financial, tax, and legal obligations.
- Deployment files and snapshots — kept while needed to serve or manage the app, and removed when the app is deleted except for limited records retained for security, abuse prevention, or legal compliance.
Deleting an app removes the live app resources AppNest controls, including its stored data. AppNest may keep limited records where needed for security, reliability, abuse prevention, or legal compliance.
Your privacy rights
Depending on where you live, you may have rights over your personal data, including the right to:
- access the personal data AppNest holds about you and receive a copy;
- export your data (data portability);
- correct inaccurate data;
- delete your data (erasure);
- object to or restrict certain processing;
- withdraw consent where processing is based on consent; and
- complain to your local data protection authority.
You can delete individual apps you own at any time from the AppNest dashboard. AppNest does not currently offer self-serve account deletion: to delete your whole account, or to access or export your data, email Charles Squeri at [email protected] and AppNest will respond within 30 days. On such a request, AppNest will delete or anonymize your account data and delete the apps and data it controls, except limited records it must retain for security, abuse prevention, or legal compliance.
You can also disconnect AppNest from the AI client where you enabled it, and choose not to include sensitive information in public generated apps. AppNest will not treat you differently for exercising these rights.
Security
AppNest uses OAuth for account connection, HTTPS for public endpoints, per-app storage isolation for backed apps, and an AppNest-authored generation engine for server-side behavior. No internet service can guarantee perfect security, but AppNest is designed to keep generated frontend code separate from AppNest's backend infrastructure.
Children
AppNest is not directed to children. You must be old enough to consent to use an online service in your country — generally at least 16 in the EU and EEA — to use AppNest.
Contact
For privacy questions or to make a data request, contact Charles Squeri at [email protected].