This policy explains what information publik collects, why we collect it, who we share it with, how long we keep it, and what you can do about it. By using publik, you agree to this policy. If you do not agree, do not use publik.
The short version
We collect what you give us, what your use of publik shows us, and what our desktop app, Iris, sends when you use it.
We use it to run publik, keep it safe, bill you, and make it better.
We do not sell your personal information. We do not show ads. We do not use your content to train AI models.
When you ask Iris for help, it sends your message and screenshots of your screen to an AI provider. Close anything private first.
Iris sends us anonymous counts of which catalog apps you open and which AI option you pick. They carry no content and no identity. You can turn them off in Iris.
Most apps on publik are made by other people. Their developers, not publik, control what those apps do with your data.
To delete your account, use Delete your account at the bottom of your profile settings. To see or correct your data, or if you cannot sign in, email privacy@publikhq.com.
Who we are and what this covers
publik (“publik”, “we”, “us”) runs publikhq.com, where you can find, download, and publish free and open-source apps. This policy covers:
the publikhq.com website;
Iris, our desktop app for Mac and Windows;
publik API, including when an app made by someone else uses it;
the emails we send; and
chatmany, when publik hosts it for a creator (see the last section).
It does not cover apps made by other developers that you find or install through publik, or services such as GitHub, Google, and Stripe that you sign in with or that we link to. Their own policies apply. See Apps made by other people.
Information you give us
Your account. Your email address. If you sign up with email, you also set a password. Our sign-in provider stores the password only in hashed form, and we never see it. If you sign in with Google or GitHub, we get your name, email address, and profile photo from that account. If you sign in with GitHub, we also store your GitHub username and user ID, so we can connect apps that are listed under your GitHub account.
Onboarding answers. What you want to get done, which paid apps you use, about how much you spend on software each month, which devices you use, how comfortable you are with technology, and how you found publik. Every question is optional. Earlier versions of onboarding also asked for your role, age range, and household income band. If you answered those questions, we still have your answers.
Your public profile. If you claim a handle: your handle, display name, photo, bio, links to your social accounts, and website. This information is public.
Apps you publish. The repository, descriptions, screenshots, install guides, and your answers about the app. This information is public.
Bug reports. What you write, up to three screenshots, your email address if you give it, and your browser and device type. See What other people can see for what the app’s developer gets.
Surveys. Your answers. We link them to your account so we can compare them with how you use publik.
Payments. Stripe collects your card details. We get a Stripe customer ID, what you bought, the status of your plan, and the dates. We do not get or store your full card number.
Messages. When you email us or reply to one of our emails, we keep the message and your address.
Waitlists. If you ask us to tell you when an app is ready, we keep your email address for that.
Information we collect when you use publik
Usage analytics. We use PostHog to record the pages you visit, what you click and search for, how long you stay, and how fast pages load. PostHog also records your browser, your device type, and your approximate location, which it works out from your IP address. When you are signed in, this is linked to your account. We also send PostHog your onboarding answers and your account ID, but not your email address. Session recording is off: we do not record video of what you do on the site.
Downloads. When you download an app, we record the app, the file, the time, your platform, your browser’s user agent, the page you came from, and a hashed form of your IP address. When you are signed in, we link the download to your account.
What you see. We record which apps we show you, to count views and to decide what to show next. If you are not signed in, a cookie with a random ID does this. When you sign in, those records move to your account and the cookie is deleted.
Votes. Which apps you vote for, and a hashed form of your IP address to stop repeat votes.
IP addresses and logs. We use your IP address to stop abuse and to limit how many requests one person can make. Our rate limiter keeps IP addresses for up to 30 days. Our hosting and database providers keep request logs, which include IP addresses, under their own retention rules.
Iris, the desktop app
Iris is our assistant for Mac and Windows. It helps you install, fix, and change apps. To do that, it looks at your screen and runs commands on your computer.
When you send Iris a message, it sends to an AI model: your message; screenshots of your screens; the name and window title of the app in front; the guide step you are on and the output of its commands; basic facts about your computer, such as its OS version, its chip type, and which developer tools and publik apps it has; and your last few messages. A screenshot shows everything on your screen. Close anything private before you ask.
While a guide is open, Iris takes screenshots to check your progress and to point at the right place, and it sends some of them to the AI model. On a Mac, it stops while you type in a password field or use a password manager.
Commands. Iris runs commands on your computer to install and set up apps. It asks you before it runs riskier commands, unless you turn on “Let Iris take control”. It sends the output to the AI model after it removes common secrets, such as API keys and tokens.
Where your messages go. You choose in Iris’s settings. With publik API, they go through our servers to the providers in AI providers. With your own Anthropic key, they go straight from your computer to Anthropic. With your ChatGPT account, they go straight from your computer to OpenAI, through OpenAI’s Codex app. We do not store the content of your chats on our servers.
On your computer. On a Mac, Iris keeps your chat history in a file on your computer: up to your last 300 messages, with no screenshots. On Windows, Iris keeps only the current chat, in memory. Keys and sign-in tokens are kept in the Mac Keychain, or encrypted with Windows DPAPI.
Crashes and freezes. Iris watches for crashes and freezes of publik apps on your computer. When it finds one, it may look up known fixes for that kind of crash, and then it asks you what happened. If you say something is broken, Iris sends us a crash report: the app, its version, and the shape of the crash, which is function and file names from the crash, not full file paths. The report has no account ID or install ID. We use it to fix the same bug for everyone. This sharing is part of using Iris.
Feature requests. On a Mac, when you ask Iris for a new feature while a publik app is in front, Iris sends us that request automatically. It sends up to 300 characters, in lowercase, with numbers, file paths, and IDs removed, and a random install ID. We count how many installs ask for the same thing. A request becomes public only when at least five installs ask for it.
Changes Iris makes. When Iris fixes or changes a publik app for you, it sends us a short, cleaned-up title of the change and whether it worked. Iris asks you before it posts anything to an app’s public page.
Install IDs and device details. Iris makes random install IDs. They are not tied to your hardware. The one for publik API and the one for anonymous usage counts stay the same. The one used for crash and feature reports changes every 90 days. When Iris sets up publik API, it sends your OS, OS version, chip type, and Iris version. On Windows, it also sends your computer’s name, which can include your name.
Updates. On a Mac, Iris checks publikhq.com for updates. On Windows, it checks GitHub. Updates download from GitHub.
Anonymous usage counts. Iris counts a few things and sends the counts to us: when you open a publik catalog app, when you start and finish an app’s install guide, when you ask Iris a question, and when you pick how Iris answers. Each count carries only these facts: the catalog app’s name as publik lists it (for a question, the catalog app that was in front, on a Mac), the AI option (publik API, your own Anthropic key, or your ChatGPT account) and its tier (fast, balanced, or smart), your OS (Mac or Windows), the Iris version, the hour it happened, how many times it happened in that hour, and a random install ID. A count never carries your account, your name, your messages, Iris’s answers, screenshots, window titles, file paths, or keys. We accept only app names that publik lists, so a count cannot carry the name of a private project.
Your choice about usage counts. Iris shows you what it counts the first time you open it, with the switch on. It counts nothing before that. You can turn the switch off then, or at any time in Iris’s settings. When you turn it off, Iris stops counting, throws away counts it has not sent, and asks us to delete the counts your install sent. Iris sends counts at most once a minute, and if a send fails it drops them. Nothing in Iris waits for a send. We use the counts to learn which apps and AI options people use, so that we can make better recommendations. We keep them for 90 days.
Usage patterns. Onboarding has a separate switch to share usage patterns that are linked to your account. It is off unless you turn it on. Iris does not collect usage patterns linked to your account. The anonymous usage counts above are not linked to your account.
publik API
publik API lets apps, including Iris and apps made by other developers, use AI models. When an app sends a request:
Content. The text, images, or audio pass through our servers to an AI provider. We do not store the content of requests or responses. When a provider returns an error, we log the first few hundred characters of that error.
Usage records. For each request, we store which key, app, and install sent it, the model, the token counts, the cost, how long it took, and whether it worked. We use these records for billing, for your dashboard, and to stop abuse.
Installs. A random install ID, the OS, OS version, chip type, app version, and the device name if the app sends one.
Keys. We store API keys only in hashed form.
Other developers’ apps. The developer of an app decides what the app sends to publik API. That developer is responsible for telling you, and for their own privacy practices.
AI providers
Iris, publik API, and our tool that fills in a listing from a public repository send content to AI providers:
OpenRouter, which sends each request to a company that runs the model we chose. The models we use today include models made by OpenAI, Google, Z.ai (GLM), DeepSeek, and Xiaomi (MiMo). We tell OpenRouter to use only providers that do not store your data or train on it.
OpenAI, directly, for speech, images, and text embeddings, and as a backup for chat.
Google (Gemini API), as a backup.
Anthropic. Older versions of Iris sent chat to Anthropic through publik. If you give Iris your own Anthropic key, Iris sends your messages straight to Anthropic.
We do not use your content to train AI models. AI output can be wrong. Check it before you rely on it, and read a command before you let it run. Do not send passwords, health information, or other sensitive information to Iris or publik API.
How we use information
To run publik: accounts, downloads, guides, Iris, and publik API.
To recommend apps, based on your onboarding answers and what you do on publik.
To bill you, process payments and credits, and prevent fraud.
To keep publik safe: to stop abuse, spam, and malware, and to enforce our rules.
To find and fix bugs in publik and in the apps we list.
To understand how people use publik and to make it better, with analytics and surveys.
To obey the law, answer legal requests, and protect our rights and yours.
We do not sell, rent, or trade your personal information. We do not show ads. We do not make decisions about you by automated means that have legal or similarly significant effects on you.
Who we share it with
Service providers process data for us, under their terms with us:
Supabase: database, sign-in, and file storage.
Vercel: website hosting.
PostHog: product analytics.
Resend: sending email.
Stripe: payments.
Upstash: rate limiting.
OpenRouter, OpenAI, Google, and Anthropic: AI models (see AI providers).
GitHub: sign-in, app downloads, repositories, and automated app scans.
Cloudflare: hosting for chatmany.
Calendly: booking a demo from our enterprise page.
Meta: the Instagram connection for chatmany.
We also share information:
With app developers. When you report a bug in an app, its developer gets your description, screenshots, the app version, and your platform. The developer does not get your email address or your account.
For legal reasons. When the law, a subpoena, or a court order requires it, or when we believe in good faith that it is necessary to protect the rights, property, or safety of publik, our users, or others, or to investigate fraud or abuse.
If publik changes hands. If publik is part of a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information can transfer as part of it. This policy continues to apply to it unless we tell you otherwise.
With your permission, or when you tell us to.
In aggregate. We can share totals and other data that cannot reasonably identify you.
What other people can see
Your public profile, if you claim a handle: name, handle, photo, bio, links, the date you joined, and the apps you published.
Apps you publish, with your name, handle, or GitHub username.
If someone lists your public GitHub repository, the listing shows your GitHub username and photo. You can claim the listing, or ask us to remove it.
Vote counts, download counts, and the log of fixes. Crash counts and feature requests show only when at least five installs report them.
How donations to builders are split between app owners.
A bug report’s status page and a stats verification page. Anyone who has the link can see them.
Emails
Account emails, such as the email that confirms your address.
Notifications about your apps, reviews, and bug reports. You choose which ones you get in Settings.
Free Apps Friday, a weekly email with new and popular free apps. Every account gets it, and one click unsubscribes you.
Occasional emails about publik, such as news about the service or a survey about how you use it.
Every email has an unsubscribe link. One click stops all email from us to that address. We record whether each email was delivered, bounced, or marked as spam. Payment receipts come from Stripe.
Cookies and browser storage
Sign-in cookies keep you signed in. publik does not work without them.
A view cookie (publik_viewer) holds a signed random ID for visitors who are not signed in, so we know which apps we already showed. It lasts one year.
A donor cookie (publik_donor) is set after you donate, so we stop asking. It lasts 90 days.
Install markers (publik_installed, one year; publik_survey_nudge, one day) are set after you download an app. They name no app and no account. This browser reads them to time the short survey and the donation ask so neither shows before you have installed something.
PostHog keeps a random ID in a cookie and in local storage.
Local and session storage keep small preferences, such as banners you closed, drafts, and your email choice until it is saved.
Calendly sets its own cookies on our enterprise page.
You can block or delete cookies in your browser, but you cannot sign in without them. We do not sell your information or use it for targeted ads, so browser signals such as Global Privacy Control and Do Not Track have nothing to opt you out of. We do not change what we do when we receive them.
How long we keep it
Your account, profile, onboarding answers, survey answers, and activity: until you delete your account. After that, we delete them, or we remove everything that links them to you.
Bug reports: until you ask us to delete them, or the app leaves publik.
Crash reports and feature requests: as long as they help fix bugs. They carry no account ID.
Iris guide sessions: 30 days.
Iris anonymous usage counts: 90 days, or less if you turn the switch off, which deletes them.
Email send records: 180 days.
Unsubscribe and bounce records: as long as we need them to keep our promise not to email you.
IP addresses in our rate limiter: up to 30 days.
Billing and publik API usage records: as long as tax and accounting law requires, which can be up to seven years.
Analytics: until you delete your account, when we also ask PostHog to delete your data.
We can keep information longer when the law requires it, or when we need it to resolve a dispute, stop fraud or abuse, or enforce our rules. Copies in backups are deleted on our providers’ backup schedules.
Security
We use HTTPS for all traffic. Our database lets each account read only its own private rows. We store passwords and API keys only in hashed form. We limit access to our systems to the people who need it to run publik.
No method of storage or transfer is completely secure. We cannot promise that your information will never be accessed, disclosed, changed, or destroyed without permission. You are responsible for keeping your password and your API keys secret. If a breach affects your personal information, we will tell you as the law requires.
Your choices and rights
Wherever you live, you can ask us to:
tell you what personal information we hold about you, and give you a copy;
correct information that is wrong;
delete your account and your personal information;
stop sending you emails;
stop using your information for a purpose, or take back consent you gave.
To ask, email privacy@publikhq.com from the address on your account. We may ask you to confirm that the account is yours. We answer within 30 days, or within 45 days where the law allows. It is free. Someone can ask for you if you give them written permission. If we say no, we tell you why. You can appeal by replying to our answer with the word “appeal”, and we answer the appeal within 45 days. We will not treat you differently because you used these rights.
Deleting your account. Email us and we delete it within 30 days. We can keep some records after that: billing records the law requires, records we need to stop fraud and abuse, the record that you unsubscribed, and data that no longer identifies you. Apps you published can stay listed without your name, unless you ask us to remove them.
Things you can do yourself. Edit your profile and remove your photo in Settings. Choose your notifications in Settings. Unsubscribe from any email. Block analytics with your browser or an ad blocker. Turn off Iris’s anonymous usage counts in Iris’s settings.
California and other US states
Depending on your state, such as California, Colorado, Connecticut, Oregon, Texas, Utah, or Virginia, the law may give you the rights listed above. In the last 12 months, we collected these categories of personal information:
Identifiers: name, email address, account ID, IP address, and install ID.
Commercial information: what you bought, your plan, and your credits.
Internet activity: pages, clicks, searches, downloads, the apps we showed you, and Iris’s anonymous counts of which apps and AI options you use.
Approximate location: worked out from your IP address.
Audio and visual information: screenshots in bug reports, and screenshots Iris sends to AI providers.
Characteristics and professional information: age range and role, from an earlier version of onboarding.
Inferences: the apps we think you may want, from your answers and activity.
Sensitive information: your account login. We use it only to sign you in.
The sources, purposes, and recipients are described above. We do not sell personal information or share it for cross-context behavioral advertising, and we did not do so in the last 12 months. We have no actual knowledge of selling or sharing the personal information of anyone under 16.
People in the EEA, UK and Switzerland
publik is the controller of your personal information. We rely on these legal bases:
Contract: to run your account, Iris, and publik API, and to bill you.
Legitimate interests: to keep publik safe, to understand and improve it (including through Iris’s anonymous usage counts, which you can turn off), to fix bugs from crash reports, and to send Free Apps Friday, surveys and news about publik to people who use it.
Consent: for optional usage patterns. You can take consent back at any time.
Legal obligation: to keep billing records and to answer lawful requests.
You have the right to access, correct, delete, restrict, and move your data, and to object to how we use it. You can also complain to your local data protection authority.
Children
publik is not for children under 13. We do not knowingly collect personal information from children under 13. If the law where you live sets a higher age for consent to process personal data, you must be that age or have a parent’s consent. If we learn that we collected information from a child under that age, we delete it. Parents can email privacy@publikhq.com.
Where your data is processed
publik is based in the United States. We and our providers process data in the United States and in other countries, where the law can be different from the law where you live. When we move personal data out of the EEA, the UK, or Switzerland, we rely on safeguards such as the Standard Contractual Clauses in our providers’ data terms.
Apps made by other people
Most apps on publik are made by independent developers, not by publik. When you download, install, or use one of them:
its developer, not publik, controls what it collects and what it does;
its developer’s privacy policy applies, not this one;
we scan apps for known risks, but we cannot check everything, and we do not promise that any app is safe, private, or works.
We are not responsible for the privacy practices of these apps, or of sites we link to.
Changes to this policy
We may change this policy. We post the new version on this page with a new date. If a change materially affects you, we tell you before it takes effect, by email or with a notice on publik. If you keep using publik after a change takes effect, the new policy applies.
Contact
For questions, requests, or complaints about privacy, email privacy@publikhq.com.
chatmany, when publik hosts it for a creator
A creator can have publik run chatmany for them: publik holds their Instagram connection, watches the posts they choose, and sends the DM they wrote to people who comment a keyword. Two different people’s data is involved, so both are listed. Nothing here is sold, shared with another creator, pooled across creators, or used to train anything.
For the creator who connected the account
The Instagram access token Meta issues when you press Allow, and the app ID and app secret of the Meta app it belongs to. Encrypted at rest with a key that lives only in publik’s server environment, decrypted only at the moment a request is made on your behalf, never shown back to you and never written to a log. Kept until you disconnect, then deleted.
Your Instagram user ID, username and account type, so the dashboard can say which account is connected. Kept until you disconnect.
Your automations — which post, which keyword, what the DM says, what link it carries. Kept until you delete them or delete your tenant.
Counts of what publik ran for you: comments processed, messages attempted, checks made. These are what hosting is billed on and they appear on your dashboard. Kept for 24 months as part of your billing history, like any other line on your publik bill.
For a person who commented or sent a message
Your Instagram-scoped user ID (the opaque id Meta gives the creator’s app for you — not your handle, not your email, not your profile), the comment or message ID, which automation matched, and whether the reply was delivered or refused. This is what stops the same person being DMed twice for the same comment.
The text of your comment is not stored. Only whether it matched, and the IDs above.
90 days, then deleted. Every per-exchange record expires 90 days after it is written, whether or not anyone asks. The 7-day window Instagram allows for a private reply, and the 30-day range the creator’s dashboard shows, are both well inside that.
The creator sees what Instagram already shows them — your comment on their post and your message in their inbox. publik adds nothing to that.
Everything above is deleted on request, at once and for every creator publik hosts: how to ask, and how to check the status. Removing the app from Instagram does it automatically.