Privacy Policy
Effective: 7 October 2026
This policy explains what Appservices stores about you when you use our website, your account, our APIs, our Telegram bot, our browser extensions and our desktop products; why; how long we keep it; who processes it for us; and what you can ask us to do with it.
1.Who we are
This service is operated by Appservices, which is responsible for the data described here.
Privacy and legal requests: appservices@appservices.dev. You can also write to us through the support chat of your account or through the Contact Admin link on www.appservices.dev.
2.What this policy covers
- The website www.appservices.dev, including the remote-selfie landing pages your customers open.
- Your account and its web app (www.appservices.dev/account): sign-in, API keys, notifications, support chat, purchases and downloads.
- Our APIs: the remote-selfie (Appservices Liveness - Remote Selfie) API and the CAPTCHA API (www.appservices.dev/captcha).
- Our Telegram bot, once you link it to your account.
- Our browser extensions: the Appservices Admin extension (its own section closes this policy) and the Captcha extension, which has its own policy at www.appservices.dev/captcha/privacy.
- Our desktop products (Sython): a licence is bound to a device identifier (a one-way hash of the hardware, the HWID) and each licence check opens a validation session, kept 7 days after it expires. The statistics a desktop installation sends for its own Statistics dashboard are shown only to that licence and kept until the licence holder asks us to delete them.
3.What we store about your account
- Your profile: username, a hash of your password (never the password itself), your email address if you add one and whether it is confirmed, your language, the network address (IP) and country you signed up from, and the address of your last sign-in.
- Your sessions: for each signed-in browser, its IP address, country, and the browser and operating system it reports, so you can see and end your sessions; a keyed hash of a device cookie, so a new device can be told apart.
- Security events: sign-ins, failed sign-ins, password, email, key and two-step verification changes, with the same network and browser details.
- Two-step verification: its secret and hashes of your recovery codes, if you turn it on.
- Telegram: your Telegram user id, chat id, username and language, once you link our bot.
- API keys: a keyed hash of each key and an encrypted copy of it, so that you can show the key again in your account after confirming your password (a key created before this was available is shown once only), its last use and a masked network address of that use.
- Support chat: your messages and the images you send. Images are re-encoded on our server and their metadata (such as location and camera details) is removed before anyone sees them.
- Purchases: your purchase requests, the payment references you give us (for example a transaction hash) and the payment screenshots you upload, and the resulting subscription.
- Downloads: which file you downloaded from your account, when, from which country, through which source and with which browser.
- Your choices about news and offers: when and how you switched them on or off.
- Subscriptions: your plan, its limits and usage (remote-selfie links, CAPTCHA solves per day) and its devices.
4.What we measure
To run the service we count how it is used. We do this on our own server, without analytics cookies and without third-party analytics:
- whether a signed-in session was active in the last few minutes (kept no longer than 15 minutes);
- per-day activity counters, by account, that tell how many different accounts were active on a day (kept 40 days);
- which versions of our extensions and apps call our APIs, as counts per version (kept 35 days);
- downloads, with country, source and browser, as described above (kept 400 days).
Daily totals built from these figures contain no personal data and are kept.
5.Records about other people
When you use the remote-selfie service, we store a transaction for each link you create: the name and email you give for your customer, the network address, browser (user agent) and device identifier of the device that opens the link, the page it runs on, and the result returned by the liveness provider. These transactions are kept 180 days after their last update. Your customers are not our users: you are responsible for informing them that their data is processed this way and for having a lawful reason to do so.
6.What we never store
We never store card numbers, wallet private keys or seed phrases, or your password in readable form. We do not store your customers' face images: the liveness check runs between their device and the liveness provider.
7.Who processes data for us
- Our hosting provider: hosting of our servers and their data.
- Cloudflare: content delivery, DNS and protection of the website, and the Turnstile check on the sign-up and sign-in forms.
- Resend: sending our emails.
- Brevo (France): sending the news, release-note, announcement and offer emails that you
switched on, from
updates@news.appservices.dev. Brevo receives your email address, the message and its language, and tells us whether it was delivered, bounced or reported as spam. Their opens and clicks are counted anonymously, without being linked to you. Your security, sign-in and account emails never go through Brevo. - Zoho (Zoho Mail): hosts the mailbox of our contact address, so the emails you send us are kept there; it may also send our emails as a fallback provider.
- Telegram: delivering the bot's messages, once you link it.
- YouTube (youtube-nocookie.com): the demo video and the videos in our news, each loaded only after you click it.
- GitHub: our server fetches release files from it; no visitor data is sent there.
We do not sell data, share it with data brokers, or use it for advertising. We may disclose information if the law requires it.
8.How long we keep it
| Data | Kept |
|---|---|
| Your account and profile | Until the account is erased (section 11) |
| Security events | 180 days |
| Account sessions | While they last, then 30 days after they end |
| Notification events | 30 days after they are sent |
| Delivery records of our emails and Telegram messages | 180 days |
| Delivery records of our news, release notes, announcements and offers (the channel, when it was sent, whether it arrived) | 180 days after the item ends (its end date, or the day we took it down); while an item without an end date stays published, its records are kept |
| Your choices to receive or stop them (the category, the channel, when, and where you chose: your account, the bot, an email link or our email provider) | For the life of the account |
| Download records (linked to your account) | 400 days |
| Audit log of administrative actions. It keeps copies of the account rows an action changed, including the email address and sign-up network address | 730 days |
| Remote-selfie transactions | 180 days after their last update |
| Support chat messages | For the life of the account; deleted 30 days after the account is erased |
| Chat images | 365 days after they were sent |
| Payment evidence (screenshots and references) | 365 days after the account's last purchase request closes |
| Purchase records | Kept, as records of the sale |
| Email-suppression list (addresses that bounced, complained or unsubscribed) | Kept, so that we never write to them again |
| Desktop licence validation sessions | 7 days after they expire |
Backups. Our server keeps the daily copies of the last 14 days and one weekly copy for 8 weeks of the database, with a copy of the cache's snapshot beside each daily copy, and a mirror of uploaded files in which a deleted file stays 14 days. So data we prune or erase can survive in these copies for up to about 8 weeks, until they rotate. Copies may also be kept in our hosting provider's server backups. Should we add a copy kept elsewhere, this section will name its provider first.
9.Messages we send and how to stop them
- Security emails (for example a changed password, email address or API key) are always sent to your confirmed email address; they cannot be switched off.
- Sign-in emails: in Account → Notifications you choose every sign-in, automatic (every sign-in while Telegram cannot reach you, otherwise new devices only, the default) or new devices only. A sign-in from a new device is always mailed.
- Account, reminder and support emails are set to automatic by default (sent when Telegram cannot reach you); switch each on or off in Account → Notifications.
- Telegram messages start only after you link our bot. Security, sign-in, account, reminder
and support messages are on there by default; turn them off in Account → Notifications, or end
them all with
/stop(or/unlink) in the bot or by unlinking it in your account. Lowering security or sign-in messages asks for your password again. - News, release notes, announcements and offers are off by default on every channel. We send
them only if you switch them on in Account → Notifications, for email and for Telegram
separately, per category: Releases (new versions and their release notes),
Announcements (news about Appservices and its services) and Offers (offers and
discounts on the plans). These emails are sent for us by Brevo (section 7). You can stop them at any time:
- with the unsubscribe link at the bottom of every such email, without signing in (your mail app's own Unsubscribe button does the same);
- in Account → Notifications;
- with the Stop button under every such message from our Telegram bot
(
/stopends all of the bot's messages).
10.Cookies and browser storage
__Host-as_session: keeps you signed in (essential).__Host-as_device: recognises a browser you used before, so a new device can be reported to you; kept 365 days (essential).as_hint: tells our pages that you may be signed in; it holds no identifier (essential).- Your choice of language (and, in the account app, of theme) is kept in your browser's local storage.
- Which news items and offers you closed on our website or in your account, so that they stay closed (local storage; it holds no identifier).
We use only the essential cookies above and no analytics or advertising cookies, so we show no cookie banner.
11.Your rights, age and changes
You can see and correct most of your data in your account. You can ask us for a copy of your data, for a correction, or for erasure of your account through support or the contact above; we answer within 30 days. Self-service deletion and export will follow later.
Erasure signs out every session, revokes your API keys, unlinks Telegram, and removes your email address, network addresses and two-step verification at once; your username stays reserved. What erasure keeps: purchase records, payment evidence until its date (section 8), copies in the audit log until it is pruned, and backups until they rotate. Your support chat is deleted 30 days after the erasure.
Our services are for professionals and are not directed to anyone under 18; they should not use them.
We may update this policy. The effective date above changes with each version, and for a material change we show a notice on the website or in your account first.
Translations of this policy may be offered for convenience; the English text governs.
The Appservices Admin browser extension
This section applies only to the browser extension published in the Chrome Web Store as Appservices Admin (Appservices Liveness); the sections above govern account, payment and retention data.
1.What the extension is
Appservices Liveness is an operator console. An authorized agent uses it to start a liveness-verification session for an end user (the "consumer"). The end user then completes a genuine liveness check on their own device using the third-party liveness SDK. When the consumer's own check succeeds, the extension records the resulting session reference against the appointment form the agent is working on.
2.Information we handle
| Data | Why | Where it goes | Stored |
|---|---|---|---|
| Agent's Appservices API key | Sign the agent in, verify the subscription and authorize each request | Sent to appservices.dev with each request (never to the appointment site) | On the device, in the extension's own storage, which web pages and the extension's page scripts cannot read; our backend keeps a keyed hash of each key and an encrypted copy of it, so that you can show the key again in your account after confirming your password (a key created before this was available is shown once only) |
| Agent's account name, plan and remaining credits | Show them in the popup | Received from appservices.dev | On the device |
| Device identifier (one-way hardware fingerprint hash) | Bind a subscription to a device; prevent credential sharing | Sent to appservices.dev | On the device and in our backend account record |
| Saved consumer names | Label/route a session ("Select consumer") | Optionally sent as a session label when chosen | On the device only, unless attached to a session |
| Public IP address of the agent's browser on the appointment page | Recorded on the verification session as its network address. The consumer's app reads it back for that same session, so the consumer's check runs with network details consistent with the agent's appointment session | Looked up from the appointment page through api.ipify.org (a public IP-lookup service), then sent to appservices.dev | In our backend, with the session record (not stored on the device) |
| Verification session details (the liveness user and transaction IDs the appointment page issues, which supported site the session runs on, the session code, status and result token, and whether the agent's form submission succeeded) | Create a session, track progress, record the result on the form, and confirm the outcome | Exchanged with appservices.dev | On the device; session records retained in our backend |
We do not collect: passwords, payment details, browsing history, page content beyond the specific appointment-page identifiers and form fields required to run and record a verification, precise location (such as GPS), or any biometric/health data. The public IP address above is the only location-related information the extension handles.
3.How we use the information
- Authorize the agent — verify the API key + device on sign-in and periodically thereafter. (Versions before 2.2.0 signed in with the subscription email; that sign-in is retired.)
- Run a verification session — create a session (attaching the public IP address of the agent's appointment page), generate the consumer link or route it to a saved consumer name, and poll its status.
- Record the result — once the consumer's own liveness check passes, place the resulting session reference into the appointment form and submit it.
- Operational notifications — tell the agent when a session was generated, succeeded, or failed.
We do not sell data, share it with data brokers, or use it for advertising or any purpose unrelated to the single function above. This is consistent with the Chrome Web Store Limited Use requirements.
4.Permissions — why each is requested
- storage — save the agent's sign-in status (account name, masked key, plan) and saved consumer names on the device. The API key itself is kept in the extension's own IndexedDB storage.
- scripting — place the completed verification result into the appointment form the agent is working on and submit it.
- webRequest — on the supported appointment sites only: notice when the liveness page has loaded its session and whether the agent's form submission succeeded, so the agent doesn't have to refresh manually.
- declarativeNetRequest — present one consistent browser identity to the liveness SDK on the supported appointment sites.
- notifications — tell the agent when the consumer has finished their check, and when the account needs to sign in again.
- alarms — periodically re-check that the subscription is still valid.
- host access — limited to the supported appointment domains and appservices.dev.
5.Data sharing
Information is sent only to appservices.dev, our own backend, for the purposes in Section 3, with two narrow exceptions:
- To read the public IP address, the panel on the appointment page makes one request to api.ipify.org, a public IP-lookup service. Like any website, it sees the address the request comes from; nothing else is sent to it.
- The details of a verification session, including its public IP address, are made available to the consumer's app for that same session, so the consumer can complete it.
We use no third-party analytics, advertising, or tracking SDKs. We may disclose information if required by law.
6.Retention
- On the device: stored in the browser's extension storage until you log out (which deletes the key), remove the extension, or clear its data.
- On our backend: account and session records are retained while the account is active and for a reasonable period afterward for support and abuse-prevention, then deleted. To request deletion, contact appservices@appservices.dev.
7.Security
Data in transit is protected with HTTPS/TLS. The API key is sent only by the extension's background process, never from the appointment page or the extension's page scripts. Device-binding limits a device-limited plan to authorized hardware. We restrict internal access to account and session records. If an API key may have been exposed, ask us for a new one: the old key then stops working.
8.Children
The extension is a professional tool and is not directed to children under 13, who should not use it.
9.Changes
We may update this policy; the "Last updated" date will change and, for material changes, we will surface a notice in the extension or on our website.