Playbix

Privacy Policy

Last updated 11 August 2026

Short version: we collect as little as we can. We never store your IP address in readable form, we do not sell data, and we run no advertising or analytics trackers on this site.

Draft — needs completion before launch

Details shown in square brackets are placeholders. Fill them in at src/lib/legal.ts, then have this document reviewed by a lawyer in your jurisdiction. Hosting third-party app files carries more liability than an ordinary website.

1. Who is responsible

Playbix of [Your business address] is the data controller for playbix.store. For any privacy question or request, email privacy@playbix.store.

2. What we collect

If you just browse or download

  • Install and download events. When you download an app we record which app and version, the time, your approximate country, and a hashed form of your IP address. The hash is one-way and salted — we cannot recover your IP address from it. We use it only to avoid counting the same download repeatedly.
  • Standard server logs. Our hosting and CDN providers log requests, including IP address, for security and abuse prevention. These are retained by them for a short period and we do not combine them with your account.

We do not use advertising cookies, third-party analytics, tracking pixels, or fingerprinting on this site.

If you create an account

  • Email address and a securely hashed password (we never see your password itself).
  • The display name you choose.
  • Reviews and ratings you post, which are public alongside your display name.
  • A session cookie so you stay signed in. This is strictly necessary and cannot be disabled while you are logged in.

If you apply as a developer

  • Your legal or business name, contact email, phone number, and country.
  • A government identity document — passport, driver's licence, or national ID card. This is required before your application can be reviewed.
  • Payment records if a registration fee applies in future. Card details are handled entirely by our payment processor — we never receive or store them.

We need this to decide whether to approve you, to meet legal obligations, and to be able to identify who published an app if it later harms users. That accountability is the point of manual approval — an anonymous publisher of executable code is not something we are willing to vouch for.

How we handle your identity document specifically

This is the most sensitive thing we ask for, so we are precise about what happens to it:

  • It is stored in private object storage. It has no public URL and is not served by the same system that serves app icons and screenshots.
  • Only a Playbix reviewer can open it, and every single viewing is recorded in our audit log with who viewed it and when. If you ask us who has looked at your document, we can tell you.
  • It is never sent to VirusTotal or any other third-party scanning service. That applies to uploaded app files only.
  • It is deleted once your application is decided, and always within 90 days. We keep the record that verification happened, and who performed it, but not the document itself.
  • Replacing a document deletes the previous one immediately.

Our lawful basis is our legitimate interest in knowing who publishes software through us, balanced against your privacy by collecting one document, showing it to as few people as possible, logging every access, and deleting it as soon as it has served its purpose.

If you use the Playbix Android app

  • Which apps you have installed from us, so we can offer you updates. This is determined on your device; we receive only the package names and versions needed to check for updates.
  • Your device's Android version and CPU type, so we can serve a compatible build.

The app does not read your contacts, messages, location, files, or the list of apps you installed from anywhere else.

3. Why we are allowed to process it (GDPR)

  • Contract — running your account, publishing your apps, delivering downloads.
  • Legitimate interests — security, fraud and abuse prevention, malware scanning, aggregate install counts. We have weighed these against your privacy and minimised the data accordingly, which is why IPs are hashed rather than stored.
  • Legal obligation — responding to lawful requests, keeping records required of us.
  • Consent — optional emails, which you can withdraw at any time.

4. Who we share it with

We do not sell your data and we do not share it for advertising. We use the following processors to run the service:

ProviderPurposeDataLocation
SupabaseDatabase, account authentication and email sign-inEmail address, password hash, profile name, activity recordsJapan (Tokyo)
CloudflareStorage and delivery of app files, images and site trafficRequested files, IP address, approximate locationGlobal edge network
VercelWebsite hostingIP address, request logsGlobal edge network
VirusTotal (Google)Malware scanning of every uploaded app fileUploaded app files and their hashes. No end-user personal data.United States
ResendSending account and review-status emailsEmail address, message contentUnited States

We may also disclose data where legally required, or where necessary to investigate a credible security threat to our users.

A note on malware scanning

Every uploaded app file is submitted to VirusTotal for scanning. Files sent to VirusTotal may be shared with its antivirus partners. Developers should be aware of this: do not upload builds containing secrets or unreleased content you would not want analysed by third-party security vendors.

5. International transfers

Our database is hosted in Japan; our storage, hosting, and email providers operate globally and in the United States. Where data leaves the UK or EEA we rely on the safeguards our providers offer, including the European Commission's standard contractual clauses.

6. How long we keep things

  • Account data — until you delete your account.
  • Reviews — deleted with your account.
  • Install events — 24 months, then deleted. Aggregate counts remain.
  • Developer records and published app files — retained while the app is published, and for up to 24 months afterwards. We need to be able to answer questions about who published software that reached users' devices.
  • Identity documents — deleted as soon as an application is decided, and in every case within 90 days. The fact that verification took place is kept; the document is not.
  • Moderation and audit records — up to 24 months, to enforce bans and handle disputes.

7. Your rights

Depending on where you live you may have the right to access, correct, delete, restrict, or object to our processing of your data, to receive a copy in a portable format, and to withdraw consent. Email privacy@playbix.store and we will respond within one month.

We may need to keep a minimal record of a banned account, or of who published a given app, in order to enforce our policies and meet legal obligations. We will tell you if that applies to your request.

If you are in the UK or EEA and unhappy with our response, you may complain to your national data protection authority.

8. Children

Accounts are for people aged 13 and over. We do not knowingly collect personal data from children under 13. If you believe a child has given us data, email privacy@playbix.store and we will delete it.

Games and apps in our catalogue carry content ratings, but we are not a substitute for parental supervision. Developers publishing apps directed at children must comply with children's privacy law, including COPPA and the UK Age Appropriate Design Code, as required by our Developer and Content Policy.

9. Security

Everything is served over HTTPS. Passwords are hashed by our authentication provider. App files are stored privately and delivered through short-lived signed links. Database access is enforced row by row, so one account cannot read another's data. Every app's signing certificate is pinned on first publication, so an update signed with a different key is rejected automatically.

No system is perfectly secure. If you find a vulnerability, please report it to abuse@playbix.store rather than disclosing it publicly, and we will work with you.

10. Changes

We will post any changes here and update the date above. For material changes affecting how we use your data, we will notify account holders by email.

11. Contact

Playbix
[Your business address]
privacy@playbix.store