Privacy Policy
Last updated 31 August 2026
Wapper.ai turns a sentence into a working app. This page says what we collect while doing that, who else sees it, and how long we keep it. It is written to be read, not to be impressive.
Wapper.ai is in early testing. Things described here may change, and when they do this page changes with them. If a change matters to you, we will say so rather than quietly updating the date.
What we collect
Your account
Your email address, and either a password or a Google account identifier, depending on
how you log in. Passwords are never stored — we keep only a one-way hash
(argon2id), which cannot be turned back into your password.
Your sessions
When you log in we record the time, and may record your IP address and browser identification string, so you can see where your account has been used and so we can tell a normal login from an attack. Login tokens are stored only as a one-way hash, which means a copy of our database would not let anyone log in as you.
What you type
The descriptions you write to build an app, and the app that comes back. We also keep a record of what was sent to the AI model and what it returned, so that when a build goes wrong we can see why. These records are tied to your account.
What we do not collect
No analytics, no advertising identifiers, no tracking pixels, and no cookies for tracking. We do not buy or sell data about you. We do not build a profile of you across other websites.
Data inside the apps you build
Right now, whatever an app you build stores stays in the browser of the person using it. A counter's count, a calculator's history, a list someone types in — that data lives on their own device and is never sent to us. We cannot read it, and we could not hand it over if asked.
This will change when apps can share data between people, which is something we intend to add. When it does, this page will say exactly what is stored and where, before the feature is available to use.
Apps you build are reachable by anyone with the link
Every app gets a public web address, like
your-app-name.wapper.app. That address is not secret, is not
password-protected, and is not hidden from search engines by default. Anyone who has
the link, or guesses it, can open the app.
A visitor can also read the code of an app built with Wapper.ai by using their browser's view-source. We are changing that, but today it is true. Do not put anything private inside an app you build.
Who else sees your data
We use a small number of companies to run the service. Each sees only what it needs to.
- Google — the descriptions you write are sent to Google's Gemini model to build your app. Google processes them under its own terms.
- Cloudflare — serves this website and your apps, and stores the app files. Sees the network traffic that reaches us.
- Fly.io — runs our server, in Singapore.
- SurrealDB — stores your account and the list of apps you have made, on servers in Mumbai, India.
- Resend — sends account emails, such as verifying your address or resetting your password. Sees your email address.
- Google Fonts — this website loads its typefaces from Google, which means Google sees the IP address of anyone visiting this page.
- esm.sh — apps you build load part of their machinery from this public service, so it sees the IP address of anyone opening one of your apps.
We do not give your data to anyone else. If we are ever legally required to, and are permitted to tell you, we will.
Where your data is
Mainly India and Singapore, with some traffic passing through Cloudflare's network worldwide. The AI model runs on Google's infrastructure.
How long we keep it
- Your account — until you ask us to delete it.
- Your apps — until you delete them, or ask us to delete your account.
- Build records — the AI request and response logs, kept while they are useful for fixing problems, and intended to be deleted automatically after 30 days.
- Login sessions — 30 days from last use, or immediately when you log out.
- Email verification and password reset links — a short time, and single-use.
What you can ask for
Email hello@wapper.ai and you can ask us to show you what we hold about you, correct it, delete it, or delete your account entirely. We will do it, and we will not make it difficult. Under India's Digital Personal Data Protection Act, 2023, you may also withdraw consent and raise a grievance; the same address reaches us for both.
Security, honestly stated
Passwords and login tokens are stored as one-way hashes. Traffic is encrypted in transit. Only our own server can reach the database.
We are a very small operation in early testing. We do not have a security team, and we would rather tell you that than imply otherwise. Treat Wapper.ai as somewhere to build things, not as somewhere to keep anything sensitive.
Children
Wapper.ai is not intended for children under 18, and we do not knowingly create accounts for them.
Getting in touch
hello@wapper.ai — for anything on this page, including a complaint.