This Privacy Policy describes how Flowing Code LLC ("AppJars") collects, uses, and shares personal information about visitors, customers, and prospects of the AppJars website and licensed software.
Version 1.0 — last updated 2026-09-30
This Privacy Policy describes how Flowing Code LLC (“AppJars”, “we”, “us”) collects, uses, and shares personal information about visitors, customers, and prospects of the AppJars website and licensed software (“you”).
1. Who is the controller of your personal information?
Flowing Code LLC is the data controller for personal information collected through https://appjars.com, the Customer Portal at https://portal.appjars.com, support communications, and the licensing transactions described in the Software License Agreement and the Subscription & Service Terms.
Flowing Code LLC 710 W. Hallandale Beach Blvd Suite 103 Hallandale Beach, FL 33009 United States
Flowing Code LLC is the data controller responsible for personal data collected through this service. Technical support services are provided by Flowing Code S.A. (Argentina), which acts as a data processor on behalf of Flowing Code LLC and may access personal data solely for the purpose of providing technical support. Flowing Code S.A. processes such data under Flowing Code LLC’s instructions and is bound by equivalent confidentiality and data protection obligations.
Contact for privacy matters: see https://appjars.com/contact.
2. What we collect, why, and how long we keep it
2.1 From website visitors
Visiting the website involves three kinds of processing: audience measurement (2.1.1), delivering and protecting the website (2.1.2), and the external services you can choose to use from it (2.1.3). For what is stored in your browser, see Section 6.
2.1.1 Analytics (Umami)
We measure how the website is used with Umami, an open-source analytics tool that we host ourselves. Flowing Code LLC operates the instance, on a server in Atlanta, United States, and no third party receives the data.
- What is collected. The pages you view, the referring page, your browser, operating system and device type, your browser language, your screen resolution, your approximate location (country, region and city, derived from your IP address when the page view is received), and clicks on a few buttons and links (for example “Buy Now” or “Schedule a meeting”), recorded only with the product and plan they refer to. Query strings and URL fragments are never sent, and nothing typed into a form is recorded.
- How visits are counted. Umami groups page views into visits with a pseudonymous visitor ID, a one-way hash of your IP address and user agent combined with a secret salt that changes every month. Your IP address is used to compute that hash and your approximate location, and is not stored. Because the salt changes, the same visitor cannot be recognized from one month to the next. Umami sets no cookies and stores nothing in your browser.
- Purpose. Aggregate audience measurement, to understand which pages and products interest visitors and to improve the website. The data is for our own use only. It is not used for advertising or profiling, it is not combined with other data we hold about you, and we do not try to identify individual visitors.
- Legal basis. Our legitimate interest in understanding, in aggregate, how our website is used and in improving it (Article 6(1)(f) GDPR). The measurement is limited to what that purpose needs.
- Retention. Analytics data is kept for 25 months and then deleted.
- How to object. You can opt out at any time in Section 6.1. We also honour your browser’s Do Not Track setting: if it is on, no analytics data is sent. With JavaScript disabled, or with a content blocker that blocks the analytics script, nothing is measured either.
2.1.2 Website delivery and security (Cloudflare)
The website is served through Cloudflare, Inc., which we use as our content delivery network, reverse proxy and security provider, and which acts as our data processor.
- What is processed. Your IP address and the technical data of each request (such as the requested URL, the user agent, the date and time, and request headers).
- Purpose. Delivering the website to you, protecting it against attacks, abuse and malicious bots, and producing aggregate traffic statistics.
- Cookies. Cloudflare sets no cookies on this website today. If we
enable one of its security features that needs one (such as bot
protection, which uses
__cf_bm), it will be strictly necessary and listed in Section 6. - Legal basis. Our legitimate interest in keeping the website secure and available (Article 6(1)(f) GDPR).
- International transfers. Cloudflare operates a global network, so your request may be processed outside your country, including in the United States. These transfers are covered by Cloudflare’s certification under the EU-U.S. Data Privacy Framework (including the UK Extension and the Swiss-U.S. Data Privacy Framework) and, where it does not apply, the European Commission’s Standard Contractual Clauses, as set out in Cloudflare’s Data Processing Addendum. See Cloudflare’s privacy policy at https://www.cloudflare.com/privacypolicy/.
The website does not load fonts, scripts or other assets from third-party content delivery networks.
2.1.3 External services used from the website
- Contact form and license details form (Google Forms). The contact form on the Contact page, and the form buyers complete after a purchase to receive their license keys, are Google Forms. They are not loaded until you click “Load the form”: until then your browser does not connect to Google. Once you load one, Google receives your IP address and technical browser data, sets its own cookies (see Section 6), and processes whatever you submit, which it makes available to us. You can also open the form directly on Google Forms. See Google’s privacy policy at https://policies.google.com/privacy.
- Meeting booking (Google Calendar). The “Schedule a meeting” link opens Google’s appointment booking page. Nothing is sent to Google unless you follow the link. See Google’s privacy policy at https://policies.google.com/privacy.
- Checkout (Stripe). The “Buy” buttons take you to a checkout page hosted by Stripe on its own domain. See Section 2.2 and Stripe’s privacy policy at https://stripe.com/privacy.
2.2 From customers (purchase and subscription)
- Name, email address, company name, billing address. Used to issue the License Key, send the license-delivery email, populate invoices, and communicate about the subscription. Retained for the duration of the subscription plus seven (7) years for tax and recordkeeping purposes.
- Tax ID (where applicable). Used solely for tax reporting. Retained as required by applicable tax law.
- Payment information (card, bank details). Handled exclusively by Stripe, our payment processor. AppJars does not store and does not have access to full payment credentials.
2.3 From Customer Portal users
- Account credentials. Email address (login) and a password hash. Stored using industry-standard hashing.
- Support tickets and Portal activity logs. Ticket content, attachments, timestamps, and metadata. Retained for the duration of the subscription plus three (3) years for support history.
- AI documentation assistant interactions. Prompts and responses are temporarily logged to monitor and improve the assistant. Anonymized after thirty (30) days. We do not use these conversations to train any general-purpose model.
2.4 From the AppJars software (the licensed product)
The AppJars software does not transmit any data back to AppJars or any third party. License Key validation is performed locally on the customer’s machine. See Section 18 of the License Agreement.
The customer’s own application may emit local log lines for each licensed Component identifying the Customer name, Component name, Permitted Application name, and license expiration date. These logs go to the customer’s own log infrastructure, not to AppJars. AppJars has no visibility into them.
3. How we use your information
We use the personal information described above to:
- issue and deliver License Keys,
- provide support and operate the Customer Portal,
- bill, collect, and reconcile subscription fees,
- comply with tax, accounting, and other legal obligations,
- communicate about the subscription (renewal notices, security and service updates),
- diagnose and improve the website and Customer Portal,
- detect and prevent fraud, abuse, and security incidents.
We do not use your personal information for advertising or ad-targeting and we do not sell your personal information.
4. Who we share it with
We share personal information only with the third parties needed to operate the service:
- Stripe, for payment processing, fraud detection, and tax calculation. Stripe acts as an independent data controller for payment data and as a processor for billing data we provide. See Stripe’s privacy policy at https://stripe.com/privacy.
- Email service provider, for transactional emails (license delivery, renewal notices, support replies).
- Cloudflare, for delivering and protecting the website (see Section 2.1.2). Cloudflare acts as a processor.
- Google, for the forms embedded in the website (see Section 2.1.3).
- Cloud hosting provider, for hosting the website and the Customer Portal. The provider acts as a processor.
- Support tools, for managing tickets and AI documentation assistant interactions.
- Flowing Code S.A. (Argentina), the developer of the AppJars software, which provides technical support as a processor on behalf of Flowing Code LLC and may access personal data solely for that purpose, under Flowing Code LLC’s instructions and equivalent confidentiality and data protection obligations.
We may also disclose personal information when required by law, when responding to lawful requests by public authorities, or to protect the rights, property, or safety of AppJars, our customers, or others.
We do not sell or rent personal information to third parties for their own marketing purposes.
5. International transfers
Personal information is stored and processed in the United States. If you access AppJars from outside the United States, your data will be transferred to the United States. For transfers from the European Economic Area, the United Kingdom, or Switzerland to the United States, we rely on Standard Contractual Clauses where applicable. Customers in those jurisdictions may request a copy of the relevant clauses by contacting us at the address above.
6. Cookies and browser storage
The AppJars website sets no cookies of its own, and nothing from a third party is stored in your browser unless you choose to load one of the embedded Google Forms. This is everything that can be stored in your browser when you visit it:
| Name | Set by | Type | Purpose | Duration |
|---|---|---|---|---|
| Service worker and its cache (Cache Storage) | AppJars | Strictly necessary | Stores a copy of the home page, the web app manifest and the app icons so the site can be installed as an app and open when you are offline. It holds only our own public files, no identifier. | Until the next site update or until you clear site data |
umami.disabled (localStorage) | AppJars | Strictly necessary | Remembers that you opted out of analytics. Set only if you opt out. | Until you opt back in or clear site data |
NID, COMPASS, S (cookies on Google’s domains) | Third-party, only after you choose to load a form | Set by Google when you load an embedded Google Form. Google decides their purpose and duration; see https://policies.google.com/technologies/cookies. | Set by Google |
Analytics (Umami, Section 2.1.1) use neither cookies nor browser storage, and run without prior consent on the basis of our legitimate interest, with the opt-out below. Stripe sets its own cookies on its checkout pages, on Stripe’s domain, not on this website.
6.1 Opting out of analytics
Checking your analytics preference…
Your choice is stored in this browser only. Opting out in one browser or device does not affect others, and clearing this site’s data resets it.
7. Your rights
Depending on your jurisdiction, you may have the following rights:
- Access. Request a copy of the personal information we hold about you.
- Correction. Request correction of inaccurate information.
- Deletion. Request deletion of personal information for which we no longer have a lawful basis to retain. Note that we cannot delete records required by law (such as billing and tax records during the statutory retention period).
- Portability. Request a machine-readable copy of personal information you provided.
- Objection / restriction. Object to or restrict certain processing. To object to analytics, use the opt-out in Section 6.1.
- Withdraw consent. Where processing is based on consent, withdraw it at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
- Complaint. Lodge a complaint with your local data-protection authority.
To exercise any of these rights, contact us at the email address published at https://appjars.com/contact. We will respond within thirty (30) days, or sooner if required by applicable law.
8. Data security
We use commercially reasonable technical and organizational measures to protect personal information, including encryption in transit (TLS), encryption at rest where applicable, access controls, and regular security reviews. No method of transmission or storage is one hundred percent secure; in the event of a security incident affecting personal information, we will notify affected individuals as required by applicable law.
9. Children’s privacy
AppJars is a developer tool intended for use by professionals. We do not knowingly collect personal information from children under the age of sixteen (16). If we become aware that a child under sixteen has provided us with personal information, we will delete it.
10. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be announced through the Customer Portal and by email to the address associated with active subscriptions at least thirty (30) days before they take effect. The current version of this Privacy Policy and a historical archive are available at https://appjars.com/legal/privacy.
11. Contact
Questions about this Privacy Policy can be sent to the email address published at https://appjars.com/contact.
Copyright © Flowing Code S.A. All rights reserved.
