Privacy Policy

The information Appabl collects, the purposes for which it is used, the service providers that process it, and the rights available to you. Appabl is a product of Bulam Labs LLC.

Effective September 25, 2026. Last updated September 28, 2026.

1. Introduction

Appabl is a product of Bulam Labs LLC (“Appabl”, “we”, “us”). This policy applies to this website, appabl.ai, and to the Appabl platform.

In this policy, Customer means the organization or individual holding an Appabl account, and End User means a person who uses an application that a Customer has published.

Questions concerning this policy, and requests concerning personal information, should be addressed to privacy@appabl.ai. Reports of security vulnerabilities should be addressed to security@appabl.ai; see reporting a vulnerability.

2. Responsibility for information

Appabl holds two categories of personal information. Responsibility for each is allocated as follows.

Customer and account information. We determine what is collected and the purposes for which it is used, and we are responsible for it. This policy describes our handling of it.

Information held in a Customer's application. The Customer determines what the application collects and the purposes for which that information is used. We hold it on the Customer's behalf, act only on the Customer's instructions, and make no use of it for our own purposes. The Customer is responsible for it.

This allocation determines to whom a request must be directed. A request concerning information held in a Customer's application is properly made to that Customer, who determines how it is answered. We will act on that Customer's instructions and assist in responding, and we will not grant, refuse or alter access to that information on the request of an End User alone. Where an End User is unable to identify or contact the Customer concerned, we will forward the request to that Customer.

3. Information we collect

  • Account and identity. Name and email address, passkey credentials, the identity supplied by an organization's provider where single sign-on is used, and records of sessions and trusted devices.
  • Organization. Organization name, member roles and grants, groups, and invitations issued and claimed.
  • Customer content. Application source and published versions, uploaded files, and collection documents, including information submitted by the End Users of a published application.
  • Billing. Plan, seat and subscription state, and invoice references. Purchases are made through Stripe as merchant of record, which holds the payment relationship. Card details are not received or stored by us.
  • Email. Service email sent to account holders, such as sign-in codes, invitations and billing notices, and email sent by a Customer's application to its own recipients.
  • Usage. Usage counters and storage totals measured against the allowances of the applicable plan and, for a published application, the type of website from which a visitor arrived.
  • Activity log. A record of actions taken within an organization, such as access grants, invitations, member changes, publications, backups and plan changes.
  • Support. Support tickets submitted by Customers and our replies to them.
  • This website. Visits are counted in aggregate through Cloudflare Web Analytics. The waitlist form collects an email address, and records the plan selected, if any, the page it was submitted from, and the sender's IP address and country.

4. Use of information

Personal information is used to operate the service: to authenticate users and maintain their sessions; to store and serve the applications and information our Customers create; to apply the limits of a Customer's plan; to invoice and collect payment; to send service email; to tell those on the waitlist when they can join; to respond to support requests; to detect and prevent abuse; to diagnose and correct faults; and to meet our legal, tax and accounting obligations.

We do not sell personal information. We do not use a Customer's content for advertising. We do not use a Customer's content to train any AI model, and Appabl does not transmit it to any AI provider on its own initiative. The circumstances in which a Customer's content reaches an AI provider are set out in AI assistants.

5. Cookies

This website sets no cookies. It uses Cloudflare Web Analytics, which sets no cookies, to count visits in aggregate. It contains no advertising and nothing that follows visitors across other websites.

Cloudflare Turnstile, an automated abuse-prevention check, is loaded when a visitor opens the waitlist form, and not on page load.

The Appabl platform sets cookies that are necessary for its operation: to maintain a signed-in session, to record a device the user has marked as trusted, to keep the sessions of separate published applications isolated, and to carry short-lived state through sign-in and connector processes. None of these cookies is used for profiling or advertising, and the service cannot operate without them.

6. Disclosure of information

We disclose personal information to the service providers required to operate Appabl, and to no other party. We do not sell or otherwise trade personal information. Those providers supply hosting and network infrastructure, storage for uploaded files and backups, outbound email, payment processing and, where an organization uses single sign-on, the identity provider it has selected. Each handles the information only as required to provide its service to us.

Purchases are an exception to that arrangement. They are made through Stripe, which acts as merchant of record: Stripe sells the subscription in its own right, collects payment and billing details directly from the purchaser, and handles that information under its own terms and privacy policy rather than on our instructions.

We may also disclose personal information where required by law, or where necessary to establish or defend a legal claim, and will notify the affected Customer where permitted to do so.

7. AI assistants

Appabl is designed to be operated through an AI assistant selected by the Customer, such as Claude or ChatGPT, or any other client supporting the Model Context Protocol.

Where a Customer connects an assistant, that assistant reads and writes the Customer's information held in Appabl at the Customer's direction. We are not the provider of that assistant and are not party to the Customer's agreement with it. What that provider retains, for how long, and whether it uses submitted information to train models are governed by that provider's terms and privacy policy rather than by this one. Appabl makes no requests to any AI provider.

Information that a Customer directs an assistant to read from Appabl is accordingly disclosed by that Customer to the assistant's provider.

8. Availability

Appabl is offered only in the United States. This website is reachable from other countries, and its availability elsewhere is not an offer to provide the service in those countries.

9. Retention

  • Activity log. 90 days, after which entries are deleted automatically.
  • Backups. Retained on a rotating schedule determined by the plan, the oldest removed as a new one is taken. The number retained is set out on the pricing page.
  • A deleted application. Its versions, files, collections and documents are deleted with it. A snapshot is taken automatically immediately before deletion, and the files it holds remain restorable for 30 days.
  • Collection documents. Until deleted by the Customer, or automatically on a rolling window where the Customer has configured one.
  • Sign-in state. Sessions expire according to the policy set by the organization, and in any event within 14 days.
  • Support tickets. Retained for as long as the record of the request and our response may be required.
  • Waitlist entries. Up to 24 months from the date of joining.
  • Account and organization records. For the life of the account, and thereafter only as required for tax, accounting and legal purposes.

Deletion takes effect immediately in the live system. Information contained in a backup taken before deletion remains in that backup until it is removed on the schedule stated above.

10. Your rights

Subject to verification, you may request a copy of the personal information we hold concerning you, the correction of anything inaccurate, an export of it, or its deletion. Several of these may be exercised directly within the service: export and backup tools are provided, and the deletion of an application or a document takes effect immediately.

These rights are extended to all users regardless of location.

Requests should be addressed to privacy@appabl.ai. We will verify that the requester controls the account concerned before acting on a request, and will respond within 30 days. No charge is made for a request, and the making of a request will not affect the account concerned or the service provided under it.

Where the information concerned was submitted to an application published by a Customer, that Customer determines how the request is handled and the request should be directed to them, as stated in Responsibility for information.

Residents of certain states have additional rights under applicable state law. Nothing in this policy limits those rights.

11. Security

Our handling of access, authority and storage is described on the security page, including passkeys, roles and grants, encryption in transit and at rest, tenancy, and the process for reporting a vulnerability.

In the event of a breach affecting personal information for which we are responsible, we will notify the affected users, and any authority we are required to notify, without unreasonable delay. In the event of a breach affecting information held on a Customer's behalf, we will notify that Customer.

12. Children

Appabl is not intended for children. Account holders must be 18 or over. We do not knowingly collect personal information from any person under that age, and will delete such information on becoming aware of it. Any person who believes that a child's information has been provided to us should contact privacy@appabl.ai.

Where a Customer's application collects information from children, that Customer is responsible for it and for the obligations arising from it.

13. Amendments

Where this policy is amended, the date stated at the top is updated accordingly. Where an amendment materially affects the handling of personal information, we will give notice by email or within the product before it takes effect.

14. Contact

Bulam Labs LLC operates the Appabl service. Correspondence may be addressed as follows.

Early access

Join the waitlist.

appabl isn't open to everyone yet. Leave your email and we'll let you know when there's a spot for you.

We use this to tell you when you can get in, and nothing else. What we keep, and for how long, is in our Privacy Policy.