App Opener (https://appopener.recut.in) website and the App Opener Android app on Google Play (in.recut.appopener) are tools by App Opener.. This policy explains how we handle data for both the App Opener website and the App Opener Android app (together, the “Service”).
Who we are (what “we/our/us” means)
“We,” “our,” and “us” mean App Opener by App Opener and the team that runs it. “Service” means the App Opener website, the App Opener Android app, our API, and related tools. “You” means the person using the Service. “Link” or “short link” means a link created by App Opener. “Owner” means a person who controls a link through an App Opener account.
What App Opener does
App Opener helps you turn a long link into an “open in app” short link using our own custom URL shortening engine. You can use the website or the Android app to:
- Paste a long link from a supported platform and tap Shorten.
- Get a short “open in app” link.
- Manage your links and view analytics via our dashboard.
App Opener offers a free tier as well as paid plans, and provides an API. The Android app has the same core URL shortening and “open in app” behaviour as the website.
Age requirement
You must be 13+ to use App Opener. If your local law requires a higher age, follow that law.
What we collect (website & app)
App Opener collects the following data to provide and secure our Service:
Account Information:
To use the App Opener dashboard, you must create an account. We collect your email address and a secure password. If you choose to sign up or log in using a third-party service like Google, we will receive basic profile information provided by that service, such as your email address and name.
Billing & Address Information:
For paid plans and account management, we collect your address details (including name, account type, street, city, state, postal code, and country) specifically to process payments and generate your billing invoices. To complete your transactions, this necessary information is shared securely with our authorized payment processors. We do not sell your billing or address data to any third parties.
Account Security & Activity:
To protect your account and provide you with login activity notifications (such as password changes or new logins), we log technical details when you access your account. This includes logging the exact IP address, device type, operating system, and browser you use to log in. We also store the creation and expiration times of your active login sessions.
The mobile app and website do not ask you to submit any health or medical information, and they are not designed to collect any sensitive categories of personal data.
Link Analytics & Visitor Data
When you use our Service to create short links, we provide analytics on how those links are performing. When a visitor clicks a short link, we collect specific information about their visit to display in your dashboard:
Location Data:
We temporarily process the visitor's IP address and use the MaxMind library to determine their approximate location, including their country, region, and city.
Privacy Protection:
To protect visitor privacy, we do not store the raw IP address for link analytics; instead, we convert it into a secure cryptographic hash before saving it.
Device & Usage Data:
Alongside the hashed IP, we collect and display the visitor's referring website, language preference, device type, operating system, and browser information to help link owners understand their audience.
Session Management & Authentication
When you log into the App Opener dashboard, we use secure session tokens to keep you authenticated.
Persistent Sessions:
If you check the "Remember Me" box during login, or if you authenticate using a third-party provider like Google, your login session will remain active for 7 days before automatically expiring.
Temporary Sessions:
If you log in using an email and password but do not check "Remember Me," your session is strictly temporary. You will be logged out and your session data will be cleared instantly as soon as you close your web browser.
Service & Safety Communications
Because we now manage user accounts, we use your registered email address to send essential communications. By creating an account, you agree to receive important, non-promotional emails necessary for the operation and security of the Service. These include password resets, login alerts, account deletion notices, billing receipts, and critical policy updates. These are sent without requiring explicit marketing consent because they are essential for your safety and to provide the Service.
Analytics, push notifications, and Firebase
To understand how the Service is used and to send optional notifications, we use a few third-party tools. These tools receive necessary technical and usage data from your browser or device to function. We use them only to operate, secure, and improve the Service.
Google Analytics:
We use Google Analytics on the website (and may use Google Analytics / Google Analytics for Firebase in the app) to measure basic usage. Google Analytics collects online identifiers (such as IP address or advertising identifiers), device information, and approximate location. We use these reports in aggregated form only.
Firebase:
The App Opener app may use Firebase services to keep the app stable and reliable. Firebase can receive technical information such as app version, device model, operating system, language, and crash or error details.
OneSignal (push notifications):
The app may use OneSignal to send optional push notifications. OneSignal may collect device identifiers, language, time zone, and basic device information so that notifications can be delivered. You can control or disable push notifications at any time in your Android device settings.
These third-party providers handle data under their own privacy policies. We do not sell your data to them.
API Use
We provide an API that allows users to interact with App Opener programmatically. When you make requests to our API, we collect and log only your IP address. We use this exclusively to monitor rate limits, prevent abuse, and protect the stability of the Service. As noted in our retention policy, these IP logs are automatically deleted after 30 days.
Bot Protection (Google reCAPTCHA & hCaptcha)
We use Google reCAPTCHA and hCaptcha on the website to stop bots, spam, and abuse. When these tools load, they receive technical information (like your IP address, browser details, and interaction patterns) to determine if a request is coming from a human. This data is handled under their own respective terms of service and privacy policies.
Payments & Paid Plans
We offer paid subscriptions and accept donations via payment processors like Razorpay and PayPal. We share your billing information securely with these providers to facilitate the transaction. We do not see or store your raw credit card or bank details on our servers. Any data processed during the payment is governed by the respective provider’s terms and privacy policies.
Reporting Abuse & Safety
If a link is harmful, suspicious, phishing, or abusive, we may disable or delete it automatically and permanently. You can appeal at [email protected].
Report a link:
Found a malicious, spammy, or harmful link? Let us know and we’ll investigate and take action promptly. We will review your request details. If we need more information, we may contact you. Please note: You must use your official email address for copyright reports. Submitting a report does not guarantee immediate removal — after verification, if the link is verified to be non-genuine or in violation, we will remove it.
Analytics visibility
Your link analytics are strictly private. Only you (and App Opener for service operation) can view the stats associated with your links through your dashboard.
Tip: do not put personal data in your long URLs or custom slugs.
Ads, affiliate links, third-party content (and disclaimer)
App Opener (website and Android app) offers a free tier that may be monetized by ads, affiliate links, and other third-party content. Ad and affiliate providers may receive basic information from your browser or device when their content loads (for example: IP address, user agent, advertising ID, and approximate location) under their own policies.
We are not responsible for any damage caused by third-party content or actions.
3rd-party blog posts
Some blog posts may be written by third parties. We may tag these posts to show they are third-party content.
Data sharing
We do not sell your personal data. We only share specific, necessary data with trusted third-party service providers to operate and secure our Service. This includes:
Authentication:
If you log in via Google, authentication data is shared securely with Google to verify your identity.
Service Providers:
We transfer necessary technical, email, and billing information to our authorized partners—including Google Analytics, Firebase, OneSignal, reCAPTCHA, hCaptcha, Razorpay, and PayPal—strictly so they can provide their services to us (such as payment processing, analytics, and bot protection).
Data Hosting and Media Storage
App Opener prioritizes the security and localization of your data.
Primary Hosting:
Our core databases and application servers are securely hosted on Google Cloud in India.
Media Storage:
Any media files associated with your account are stored using Cloudflare R2. To ensure strict access control and security, these media files are generated only upon request and are delivered via securely signed, temporary links.
International Transfers:
Depending on your location and the location of our global edge networks (like Cloudflare), some technical data may be transferred to or processed in a country different from your own. We ensure that appropriate safeguards are in place to protect your data in accordance with this Privacy Policy.
Do Not Track (DNT) Signals
Some web browsers have a “Do Not Track” feature that lets you tell websites you visit that you do not want to have your online activity tracked. At this time, our Service does not currently recognize or respond to Do Not Track browser signals.
Security
We work to keep the Service reliable and safe, including using technical and organisational measures to reduce misuse and abuse. No online service is 100% secure, but we aim to prevent unauthorised access or misuse of the systems we control.
Data Retention
We believe in data minimization and only keep your information for as long as it is necessary to operate our Service securely. Our specific data retention periods are as follows:
Sensitive Account Logs:
Logs related to your account security, such as login activity, password changes, and active session data, are retained for 90 days.
API Logs:
To monitor API usage and prevent abuse, we log only the IP address associated with API requests. These logs are automatically and permanently deleted after 30 days.
General System Logs:
Standard technical and usage logs generated by interacting with our website or app are retained for 15 days.
Account Deletion and Inactivity
We give you full control over your data, including the right to securely erase your account. We also proactively remove abandoned accounts to minimize the data we store.
User-Initiated Deletion:
You can delete your account at any time directly from your dashboard. When you trigger this, your account undergoes an immediate "soft delete," which instantly hides your profile and makes your account inaccessible. 7 days after this request, your account and all associated data will undergo a permanent "hard delete." We may send you an email notification 24 hours before the permanent deletion takes effect.
Inactive Accounts:
To maintain system hygiene and protect privacy, accounts that remain entirely inactive for 90 days will be automatically deleted. "Inactivity" is defined as not logging in and not performing any core actions (such as shortening a link) within that timeframe.
Your Privacy Rights
Depending on your location, you may have specific rights regarding your personal data. You have the right to:
Access and Export:
Request a copy of the personal data we hold about you (Data Portability).
Update and Correct:
Edit your account details and billing information directly through your dashboard.
Erase:
Delete your account and associated data (as detailed in the "Account Deletion and Inactivity" section).
To exercise any of these rights that are not directly available in your dashboard, please contact us at [email protected]. We will respond to your request within the timeframes required by applicable law.
Legal Basis for Processing (EEA/UK Users)
If you are an individual located in the European Economic Area (EEA) or the United Kingdom (UK), our legal basis for collecting and using the personal data described in this policy depends on the data concerned and the context in which we collect it. We normally collect and process your data where:
- We need it to perform a contract with you (i.e., to provide the App Opener Service and maintain your account).
- The processing is in our legitimate business interests, provided these are not overridden by your data protection interests or fundamental rights (i.e., to secure the platform, prevent abuse, and deliver critical service communications).
- We have your explicit consent to do so.
Changes to this policy
We may update this page at any time. If we make material changes to how we process user data, we may notify registered users via their provided email address. However, please check this page for the latest version before using the website or app.




