native codeLas Vegas, NV · available for work

App Store Disclosures

Answers to what Apple, Google and Shopify each ask at review, in one place, with links into the detail.

Version
1.0
Effective
20 August 2026
Applies to
Native Code LLC

If you are reviewing one of our appsThis page exists for you. Each section below answers one platform’s questions in that platform’s own terms and links to the exact section of the policy that backs it up. If something you need is missing, tell us through the contact form and we will add it rather than make you ask twice.

Section 1The company behind the apps

Section 2For Apple App Review

Privacy policy, Guideline 5.1.1(i)

Our Privacy Policy identifies the data each app collects, how it is collected, and all uses of it. It names every third party that receives data on the Subprocessors page, states retention periods per category, and explains how to revoke consent and request deletion.

Account deletion, Guideline 5.1.1(v)

Every app that supports account creation offers account deletion inside the app, under Settings, then Account, then Delete account. It deletes the account and the personal data attached to it rather than deactivating it. The same route exists on the web for people who have removed the app. Where an app offers Sign in with Apple, we call the Apple REST API to revoke the user token as part of deletion.

Data minimisation, Guideline 5.1.1(iii)

Our apps do not require registration to use features that do not need an account, and we do not ask for data unrelated to the app’s function. Each app’s supplement lists the permissions it requests and the feature each one is for. Nothing is requested "for later".

Data use and sharing, Guideline 5.1.2

We do not sell personal information, we do not share it for advertising, we use no advertising SDKs, and we do not use data to build a profile of a person. This is stated as a commitment in what we never do.

Subscriptions, Guideline 3.1.2

Where an app sells a subscription, the title, the length, the price per period and what is included appear in the app before purchase and in the App Store Connect metadata. The binary contains functional links to both the End User License Agreement and the Privacy Policy. Renewal and cancellation are explained on the Billing and Refunds page, which directs App Store purchasers to Apple for refunds.

License terms, Schedule 1

We use a custom End User License Agreement rather than Apple’s standard one. It contains every minimum term Apple requires, including the acknowledgement that the agreement is with us and not with Apple, the scope of license tied to the Usage Rules, maintenance and support being solely ours, the warranty and refund provision, product claims, intellectual property claims, legal compliance and export representations, our name and contact information, and Apple as a third party beneficiary entitled to enforce it.

Age rating and children

Our apps are business tools built for adults. They are not directed at children, we do not knowingly collect data from anyone under 13, and they carry an age rating consistent with that. See Children.

Section 3For Google Play

Privacy policy

The Privacy Policy is linked in the Play Console listing and from inside each app. It covers every app we publish, and it discloses how each accesses, collects, uses and shares user and device data.

Data safety section

Each app’s Data safety declaration is completed from the same source as its supplement, so the label and the policy cannot drift apart. Across our apps the declaration is consistently: data is encrypted in transit, users can request deletion, no data is sold, and no data is shared for advertising or marketing.

Account deletion URL

The Delete Account URL we submit is nativecodeapps.com/legal/delete-account/. It is reachable on the open web without installing or reinstalling the app, it lets a person start a deletion request directly, and it states what gets deleted, what is retained and for how long, and how long the process takes.

Permissions and sensitive APIs

We request the minimum permissions an app needs, we request them at the point the feature is used rather than at launch, and we show a plain explanation first. No app of ours requests a permission it does not use. We do not request the advertising identifier, and we do not use accessibility services, SMS or call log permissions.

Target audience

Our apps declare an adults only target audience and are not part of the Designed for Families program.

Payments

Where an app sells a subscription on Android, it is billed through Google Play Billing. Cancellation and refunds run through Google, which is stated plainly on the Billing and Refunds page.

Section 4For Shopify App Review

Protected customer data

We request the minimum data scopes an app needs, declare the purpose for each, and do not request protected customer data an app does not use. Protected customer data is encrypted in transit and at rest, access is restricted to the people delivering the service, and it is retained only as long as the app’s function requires.

Mandatory compliance webhooks

Every app we publish implements the three mandatory compliance webhooks over HTTPS, with HMAC verification on each request:

  • customers/data_request, which returns the data we hold for that customer to the merchant;
  • customers/redact, which deletes that customer’s data;
  • shop/redact, which deletes the store’s data after uninstall.

Requests are queued and retried, so a delivery that arrives during a deploy is not dropped.

Merchant data requests and the DPA

We respond to a merchant or customer data request within 30 days. Our full processor obligations, including subprocessors, breach notice, audit rights and the transfer mechanism, are in the Data Processing Addendum, which binds us automatically without a merchant having to ask for a signature. Shopify specific commitments are in Section 15 of it.

Uninstall behavior

Uninstalling an app stops its subscription and starts deletion of the store’s data on the schedule in the DPA. We do not keep a store’s data as leverage to win it back.

Section 5True of every app we publish

  • No advertising, no advertising SDKs, no advertising identifiers.
  • No selling of personal information, and no sharing for cross context behavioral advertising.
  • No session recording, no cross app tracking, no data brokers.
  • No data used to train machine learning models for us or for anybody else.
  • Account deletion available inside the app and on the web.
  • All traffic over TLS, all data encrypted at rest.
  • Breach notification without undue delay, and within 72 hours where European law applies.
  • A working support route, answered within one business day.

Section 6Per app documents

Each app has its own privacy supplement and support page, giving the exact data types, permissions and retention for that app. The URL is submitted with the app and appears in its store listing and inside the app itself. Those pages are deliberately not linked from the site navigation, because they exist for the store listing rather than for browsing.

If you are reviewing an app and cannot find its supplement, ask through the contact form and we will send the direct link.