Privacy Policy

Last updated: July 2026

This Privacy Policy explains how Pixel Perfect Labs Ltd., a private company limited by shares incorporated in Israel, company registration number 517324067(“Pixel Perfect Labs”, “we”, “us”, “our”), collects, uses, and shares information when you use the AI App Builder Architect website and app-blueprint builder (the “Service”). We are the data controller for that information. This policy forms part of, and should be read together with, our Terms of Service. We process personal data in accordance with the Israeli Protection of Privacy Law, 5741-1981, as amended (including Amendment No. 13), and its regulations (the “Privacy Law”), and, where it applies to you, the EU and UK General Data Protection Regulation (“GDPR”) and the California Consumer Privacy Act as amended (“CCPA/CPRA”). By using the Service you acknowledge this policy.

Providing information is voluntary

This section is our notice under section 11 of the Privacy Law. You are under no legal duty to provide us with any information; any information you provide is provided voluntarily and with your consent. The consequences of choosing not to provide information are practical only: if you do not enter your app idea and funnel choices, we cannot generate a blueprint for you, and if you decline analytics (see “Consent model” below), your usage is simply not measured — the Service itself remains available either way. Information you do provide is processed for the purposes, and shared with the recipients, described in this policy, and you have the rights of access and correction described under “Your rights” below.

Information we collect

We are designed to be data-minimising: using the Service does not require an account, and we do not ask for your name, email, or other directly identifying information. We collect:
  • Anonymous device identifier.When analytics is permitted in your region (see “Consent model” below), we set a random anonymous identifier (typically a UUID) named aiab_didin a first-party, httpOnly cookie. It is created on your first qualifying request — immediately on your first visit in opt-out regions, or after you accept the consent banner in opt-in regions — persists for 365 days (one year), and does not contain your name, email, or any directly identifying information.
  • Your inputs (funnel choices and idea description).The choices you make while building your blueprint — app type, target audience, your free-text app idea, visual style, screen selections, and Yes/No answers. These are held in your browser's local storage on your device. To generate your blueprint, your inputs are transmitted to our third-party AI provider (see “How we share information”). We do not retain your inputs on our own servers after your session, other than the anonymous analytics events described below.
  • Analytics events. We record anonymous events about your progress through the flow (for example, which step you reached and which options you selected), associated with the anonymous aiab_did— never with your name or email.
  • Marketing parameters & click IDs. If you arrive via a marketing link and analytics is permitted, we capture standard UTM parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content), an optional specialId, and advertising click IDs (gclid, gbraid, wbraid, fbclid, msclkid) onto the anonymous profile to measure advertising effectiveness. Separately, only a Google Ads click ID (gclid, gbraid, or wbraid) is stored in a first-party cookie (aiab_attr, 90 days) and forwarded to our affiliate-launch redirect so we can attribute sign-ups and purchases; fbclid and msclkid are not stored in that cookie or sent to the affiliate.
  • Approximate location.To understand where our users come from, your IP address is transmitted to our analytics provider (Mixpanel) solely so it can derive an approximate location (city, region, and country); it is not retained as an analytics event property. The country used to choose the correct privacy regime for your region is read from our hosting provider's edge geolocation header. We do not store your full IP address.
  • Technical data. Standard server logs (IP address, browser type, referrer URL, timestamp) processed to detect abuse and keep the Service reliable. We do not build individual profiles from these logs.

How we use information

  • Deliver the Service. Your inputs are transmitted to our third-party AI provider to generate your app blueprint and a suggested app name.
  • Analytics. We use Mixpanel (via a first-party, server-side proxy) to count funnel events, measure completion rates, derive approximate location, and improve the product. Events carry only the anonymous aiab_did— no personal identifiers.
  • Advertising measurement. We use Google Ads conversion tracking to understand which ads lead to sign-ups and purchases. Specifically:
    • When you arrive from a Google ad, your gclid (Google Click Identifier) is captured and, where analytics is permitted, stored in the aiab_attr first-party cookie.
    • Where analytics is permitted, the gclidis included as a sub-id on our affiliate redirect link so the resulting sign-up or purchase can be attributed to the originating Google ad. We do not call Google's conversion API directly from this website.
    • No gclid is shared if you have denied consent or if a Global Privacy Control (GPC) signal is detected in your browser.
  • Security & abuse prevention. We process IP addresses and request logs for a short period to detect and block malicious activity and to enforce rate limits. This security processing relies on our legitimate interests and is not affected by your analytics consent choice.

Legal bases for processing (EEA / UK)

Where the GDPR applies to you, we rely on the following legal bases:
  • Your consent(Art. 6(1)(a)) — for analytics, approximate-location measurement, and advertising/conversion measurement. You may withdraw consent at any time (see “Your privacy choices”); withdrawal does not affect processing carried out before withdrawal.
  • Performance of your request(Art. 6(1)(b)) — to provide the blueprint you ask us to generate, including transmitting your inputs to our AI provider.
  • Our legitimate interests(Art. 6(1)(f)) — to keep the Service secure, prevent abuse, and maintain reliability, balanced against your rights.

Consent model (region-specific)

We apply a geo-aware consent model using your country-level IP geolocation (read only to set a consent-regime cookie and approximate location):
  • EEA & UK (opt-in).If you are located in the European Economic Area (the EU‑27 plus Iceland, Liechtenstein, and Norway) or the United Kingdom, analytics and ad measurement are off by default. A consent banner asks for your permission before any tracking begins.
  • All other regions, including Israel and the United States (opt-out). Analytics and ad measurement are on by default, and you may opt out at any time (see “Your privacy choices”).
  • Unknown country. If your country cannot be determined, we apply the opt-in (more protective) regime by default.
Your consent preference is remembered in first-party cookies (aiab_consent and aiab_regime, 180 days). We also honour Global Privacy Control (GPC) signals sent by your browser: if GPC is active and you have not explicitly granted consent, tracking is treated as denied, regardless of region. An explicit prior choice to accept takes precedence over a later GPC signal.

Your rights

Depending on where you live, you have rights over your personal data. Because the data we hold is keyed only to an anonymous identifier, we may need the value of your aiab_did cookie (visible in your browser's developer tools under Storage → Cookies) to locate it.
  • Under Israeli law (the Privacy Law).You have the right to review information held about you (section 13) and to request that we correct, amend, or delete it if it is incorrect, incomplete, unclear, or out of date (section 14). You may also lodge a complaint with the Israeli Privacy Protection Authority (PPA).
  • Under the GDPR (EEA/UK). You have the right to access, rectify, erase, restrict, or object to processing, the right to data portability, and the right to withdraw consent at any time. You may also lodge a complaint with your local supervisory authority.
  • Under the CCPA/CPRA (California).You have the right to know, delete, and correct personal information, and to opt out of its “sale” or “sharing”. We do notsell personal information and have not sold or shared personal information for cross-context behavioural advertising in the preceding 12 months. We treat a Global Privacy Control signal as a valid request to opt out of sale or sharing.
To exercise any right, email us at contact@pixelperfectlabs.site. For requests under the GDPR we respond within one month, which we may extend by up to two further months for complex requests (we will tell you if we do). Because we hold only anonymous, cookie-keyed data and no account, if you cannot provide your aiab_did value we may be unable to identify your data and therefore unable to action an access or deletion request for it (GDPR Articles 11 and 12); we will not collect additional identifying information solely to re-identify you.

Your privacy choices (global opt-out)

You may opt out of analytics and ad measurement at any time:
  • Consent controls.In EEA/UK regions, choosing “Reject” in the consent banner stops all tracking. Elsewhere, you can withdraw consent at any time through the “Your Privacy Choices” control on the Service.
  • GPC signal.Enable Global Privacy Control in a supporting browser (for example, Brave or DuckDuckGo) to have us automatically treat your session as opted‑out.
  • Cookie deletion. Deleting your browser cookies clears the aiab_did, aiab_consent, aiab_regime, and aiab_attr cookies. Your anonymous identifier is regenerated on your next visit where analytics is permitted (in opt-in regions, after you accept again); no data is linked across sessions.
  • Email request. You may request deletion of event data associated with your anonymous identifier by emailing contact@pixelperfectlabs.site with the value of your aiab_did cookie.

How we share information

We do not sell your personal information. We share limited data with the following service providers and partners, solely for the purposes described above. These providers are primarily located in the United States:
  • OpenRouter— our AI gateway, which routes your inputs to an underlying large-language model to generate your blueprint. Your free-text idea and selections are transmitted to OpenRouter and the model provider it routes to. Please do not enter personal or sensitive information in the free-text idea field. openrouter.ai/privacy.
  • Mixpanel— analytics events (anonymous IDs, funnel choices, and approximate location) forwarded server-side. mixpanel.com/legal/privacy-policy.
  • Google (Google Ads) — your gclid passed through our affiliate redirect (/go/base44) when analytics is permitted, as a service provider for conversion measurement only.
  • Impact.com & Base44— when you choose to launch on Base44, you are redirected through our affiliate network (Impact.com) to the Base44 platform. The redirect always includes a source tag and your anonymous identifier (as subId1/sharedid) for attribution; when analytics is not permitted, that identifier is replaced with the value “unknown” and no click ID is included. Your generated blueprint may also be passed to Base44 to pre-fill the builder. Base44 and Impact.com handle your information under their own privacy policies.
  • Vercel— our hosting and infrastructure provider, which processes standard server logs under its data-processing agreement.
We may also disclose information where required by law, to enforce our Terms, or to protect the rights, safety, or property of our users or others.

International data transfers

We are based in Israel, which benefits from a partial adequacy decision from the European Commission for certain automated data transfers. Some of our service providers (such as Mixpanel, Google, OpenRouter, and Vercel) are located in the United States. Where we transfer personal data outside Israel, the EEA, or the UK, we rely on an appropriate safeguard — such as an adequacy decision or the European Commission's Standard Contractual Clauses (or the UK equivalent), and, for transfers from Israel, the conditions of the Israeli Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 5761-2001 (under which the recipient is bound to data-protection conditions no less protective than Israeli law).

Data retention

  • aiab_did cookie— 365 days (one year); set the first time analytics is permitted (see the Consent model).
  • aiab_consent & aiab_regime cookies— 180 days.
  • aiab_attr cookie(click ID) — 90 days.
  • Mixpanel event data— retained per Mixpanel's default retention for our plan; we do not extend those defaults.
  • Server logs— retained for up to 30 days for security purposes, then deleted.

How we protect your information

We apply reasonable technical and organisational measures appropriate to the limited, anonymous nature of the data we hold. The anonymous device identifier (aiab_did) is stored in an httpOnly cookie that JavaScript cannot read; the consent, regime, and attribution cookies are conventional first-party cookies used only as described. Analytics is forwarded through our own server-side proxy rather than via third-party scripts in your browser, and our connections use encryption in transit. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Children

Our Terms of Service require users to be 18 or older (or to have a parent or guardian's consent). In any case, the Service is not directed at children, and we do not knowingly collect personal data from children under the applicable age of digital consent (13 in the United States and the UK; between 13 and 16 in the EEA, depending on the country). If you believe a child has provided us with information, contact us and we will delete it.

Changes to this policy

We may update this policy from time to time. When we do, we will update the “Last updated” date above. Material changes will be communicated via a notice on the Service. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

Contact

Pixel Perfect Labs Ltd. (company no. 517324067), Israel.
Questions about this policy or requests related to your data? Email us at contact@pixelperfectlabs.site. We aim to respond within 30 days.