Privacy Policy — pleaseopen.me

Last updated: 10.09.2026

This Privacy Policy explains how Eighteen1 Studios ("we," "us," "our") collects, uses, and protects information when you use pleaseopen.me (the "Service"), whether as a visitor clicking a redirect link or opening a hosted privacy policy, or as a creator with an account.

Because we are based in Germany, this policy is written to comply with the EU General Data Protection Regulation (GDPR). If you are located outside the EU/EEA, additional local rights may apply to you; nothing here limits rights you have under your local law.

We are not lawyers speaking on your behalf when you read this — if you need this policy reviewed for a specific jurisdiction or edge case, we recommend consulting a qualified privacy lawyer before relying on it for compliance purposes.


1. Who is responsible for your data (Data Controller)

Eighteen1 Studios Owned by Raphael Pappalardo Website: eighteen1.com Contact: contact@pleaseopen.me

For any privacy-related questions, requests, or complaints, please contact us at the email address above.


2. What data we collect

2.1 Visitors clicking a redirect link or opening a hosted privacy policy

We collect limited, aggregated analytics so that creators can see how their public pages are performing. Specifically:

  • Button/action click counts on redirect / bio-link pages — e.g. how many times the "Open in browser" step or the final store redirect was triggered.
  • Visits to a hosted privacy policy URL — counted separately from redirect-page visits.
  • Country of the visitor — derived from the visitor's IP address at the moment of the request (via hosting edge geo headers). We do not store the IP address itself; it is used momentarily to look up the country and is then discarded.
  • Anonymous visit id — a random id kept in the browser's sessionStorage for the duration of a tab session so we can count unique visits and funnel steps without identifying a person.

If a creator turns on email collection on a coming-soon / unmatched-store landing page, we also store the email address the visitor types, together with the time of signup and which landing it belongs to. We do this only to show and export that list to the creator. We do not email those visitors. The creator is the controller of that list and is responsible for how they use it. Visitors can ask us or the creator to delete an address.

We do not otherwise collect or store names, email addresses, device identifiers, precise location, or any other information that could identify an individual visitor. Analytics shown to creators is aggregated (e.g. "42 clicks from Germany"), not tied to any individual person, except for the optional waitlist emails described above.

We do not collect this visitor analytics for ads.txt / app-ads.txt files (those are plain text files for ad networks, not pages we measure).

If this changes in the future (e.g. we begin storing IP addresses, or add more granular tracking), we will update this policy and, where legally required, request consent before doing so.

2.2 Creators with a pleaseopen.me account

When you create an account and use our dashboard, we collect:

  • Account/authentication data: your email address, and — if you choose to sign in via Google or Apple — the basic profile information those providers share with us (typically name and email address) to create and manage your account.
  • Content you provide: the slugs, App Store / Google Play URLs, template choices, custom copy or branding, and — if you use listing tools — app name, developer/contact details, questionnaire answers about how your app handles data, ads.txt lines, and any privacy policy text you paste or generate so we can host it at your listing URL.
  • AI privacy-policy drafts (Premium, optional): only if you choose "write with AI." We then send the information you entered for that draft (see Section 2.3) to a language model so it can produce a policy. We do not run this unless you request it.
  • Payment information: if you purchase a premium upgrade, payment is processed by Stripe. We do not receive or store your full card details — Stripe handles this directly. We retain records of your purchase (e.g. transaction status, plan purchased) for accounting and support purposes.

We do not knowingly collect any special categories of personal data (e.g. health, religious, or political information) — please do not include such information in any custom copy or content you submit through the Service.

2.3 What we send to the AI when you generate a privacy policy

This happens only when you are signed in, on Premium, and you tap to write or rewrite a policy with AI. The request includes:

  • App name, developer/company name, contact email, platforms, category, and region you entered
  • Your questionnaire answers (data types, sign-in, SDKs, ads, payments, security claims, children/retention, and similar)
  • Optional app description and, if you fetched it, a short summary of your public App Store or Play Store listing
  • Any follow-up answers you typed in the AI flow

We send this so the model can draft a policy that matches what you told us. We do not send visitor analytics, payment card data, or your login password. The generated markdown is stored in your account like other listing content so we can show and host it.


3. Why we process your data (Legal basis)

PurposeData usedLegal basis (GDPR)
Creating and securing your accountEmail, auth provider dataContract (Art. 6(1)(b))
Operating your redirect links and hosted listing pages (privacy policy, ads.txt)Slug, store URLs, custom content, listing answers, published policy textContract (Art. 6(1)(b))
Generating an AI-written privacy policy draft when you request itQuestionnaire and app details listed in Section 2.3Contract (Art. 6(1)(b))
Processing paymentsPurchase/transaction recordsContract (Art. 6(1)(b))
Responding to support requestsEmail, message contentLegitimate interest (Art. 6(1)(f))
Providing creators with link and privacy-page performance statsClick/visit counts, country (derived from IP, not stored)Legitimate interest (Art. 6(1)(f))
Complying with legal obligations (e.g. tax records)Payment/transaction recordsLegal obligation (Art. 6(1)(c))

4. Who we share data with (Processors & recipients)

We use the following third-party service providers to operate pleaseopen.me. Each acts as a data processor on our behalf under a data processing agreement, or as an independent controller for their own purposes (e.g. fraud prevention), as noted below.

  • Supabase — database hosting and authentication (email, Google, Apple sign-in). Supabase may store data on servers located outside the EU/EEA depending on project configuration; where this applies, transfers are safeguarded via Standard Contractual Clauses (SCCs) or equivalent mechanisms.
  • Vercel — application hosting and content delivery. May process data on infrastructure located outside the EU/EEA, safeguarded via SCCs or equivalent mechanisms where applicable.
  • Microsoft Azure — hosts the language model we use for optional Premium privacy-policy drafts. The model is DeepSeek, deployed in West Europe. Prompts and completions are processed in that region to return a draft to us. We do not use those prompts to train our own models. Azure processes this as our processor for this feature.
  • Stripe — payment processing. Stripe acts as an independent controller for fraud prevention and regulatory compliance purposes in addition to processing payments on our behalf. Stripe may set its own cookies during checkout (see Section 5).
  • Google / Apple — only if you choose to sign in using these providers, in which case they act as independent controllers for the authentication data they share with us.

We do not sell your personal data, and we do not share it with third parties for advertising purposes.


5. Cookies and similar technologies

We do not use advertising or cross-site tracking cookies. Our visitor analytics (click/visit counts and country, see Section 2.1) do not use advertising cookies. To group events from the same browser tab session we store an anonymous visit id in sessionStorage on your device; it is not a cross-site tracker and clears when the tab session ends.

We do use cookies/tokens that are strictly necessary for the Service to function, including:

  • Authentication session cookies (via Supabase Auth) — to keep you logged in.
  • Payment security cookies (via Stripe) — set automatically during checkout for fraud prevention (e.g. __stripe_mid, __stripe_sid).

Because these cookies are strictly necessary for the Service to work, and because our visitor analytics do not use advertising cookies or retain personal identifiers beyond an anonymous session visit id, none of this requires a cookie consent banner under GDPR/ePrivacy rules. If we introduce non-essential cookies or start retaining personal identifiers in the future (e.g. storing IP addresses, advertising), we will update this policy and implement a consent mechanism as required by law.


6. How long we keep your data

  • Account data: retained for as long as your account is active. If you delete your account, we will delete your account data within a reasonable period, except where we are required to retain certain records (e.g. transaction records) for legal or tax purposes.
  • Listing content (including hosted privacy policies and the answers used to generate them): retained with your account until you delete the page or the account.
  • AI generation requests: we do not keep a separate prompt log beyond the listing content and the resulting draft stored in your account. Azure processes the request to produce the draft and does not receive it for our own model training.
  • Analytics events (click/redirect counts and privacy-policy visits for creators): retained for 7 days on Free plans and 1 year on Premium plans, then automatically deleted. Upgrading does not restore already-purged history.
  • Payment/transaction records: retained as required by applicable tax and accounting law (typically up to 10 years in Germany for financial records), even after account deletion.
  • Support correspondence: retained only as long as reasonably necessary to resolve your inquiry and for a limited period afterward for quality/reference purposes.

7. Your rights (GDPR)

If you are located in the EU/EEA (or otherwise protected by GDPR), you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data ("right to be forgotten"), subject to legal retention obligations
  • Restrict processing in certain circumstances
  • Data portability — receive your data in a structured, machine-readable format
  • Object to processing based on legitimate interest
  • Withdraw consent at any time, where processing is based on consent
  • Lodge a complaint with a supervisory authority — in Germany, the relevant authority depends on your state, or you may contact the authority local to you

To exercise any of these rights, contact us at contact@pleaseopen.me. We will respond within the timeframe required by GDPR (generally one month).


8. Children's privacy

pleaseopen.me is not directed at children, and we do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.


9. Data security

We rely on the security measures provided by our infrastructure providers (Supabase, Vercel, Stripe, Microsoft Azure), including encryption in transit. No system is completely secure, and we cannot guarantee absolute security, but we take reasonable steps to protect your data against unauthorized access, loss, or misuse.


10. Changes to this policy

We may update this Privacy Policy from time to time, for example if we add new features or change service providers. We will update the "Last updated" date at the top of this page, and for material changes, we will make reasonable efforts to notify account holders (e.g. via email).


11. Contact us

If you have questions about this Privacy Policy or how we handle your data, contact:

Eighteen1 Studios Raphael Pappalardo contact@pleaseopen.me eighteen1.com