Ghapp Privacy Policy
Effective date: 30 September 2026
Ghapp is operated by Bold Technology and AI. This policy explains how Ghapp handles information when you browse app listings, create an account, participate in testing, or submit feedback.
For privacy questions or account and data deletion requests, email support@boldtechai.com. This policy is intended for publication at https://boldtechai.com/ghappstore/privacy.
Information we process
Account information. When you register, we process your display name, Ghanaian (+233) phone number, Firebase account identifier, and account creation information. Your account record also holds participation credits and saved app identifiers. Credits are participation points, not money.
App listings. Developers provide an app name, package identifier, description, category, icon emoji, and testing or store links. Listings include the developer's display name and account identifier, creation date, testing status, tester count, and progress.
Testing participation. We store which apps you join, assignment identifiers, start dates, daily check-in dates, assignment status, and completion information. The backend maintains private records of the tester group used to calculate a listing's progress. Check-ins are your reports of testing; Ghapp does not inspect your installed apps or measure usage inside the apps you test.
Feedback. When you submit a bug report, idea, or experience note, we store its text, type, date, your display name and account identifier, and the associated listing and testing assignment. Avoid including passwords, verification codes, or other sensitive information in feedback.
Notifications. If you allow notifications, we process a push notification token associated with your account so we can send testing reminders. Firebase Cloud Messaging also processes installation identifiers and technical delivery information.
Security and service operation. Firebase and Google Cloud process technical information needed to authenticate users, check app integrity, deliver requests, and operate the service. Depending on the service, this can include IP addresses, app and device information, identifiers, and diagnostic or security logs. Ghapp also keeps an account-based request counter to limit excessive API requests and records needed to process account deletion.
Optional crash diagnostics. Crash reporting is disabled by default. If you turn on “Share crash diagnostics” in Profile, Firebase Crashlytics can receive error reports, stack traces, app version, operating system and device information, and installation-related identifiers. Ghapp does not intentionally attach your phone number, account identifier, or feedback text to crash reports. Error details can nevertheless contain information relevant to the failure.
How we use information
We use this information to:
- Create and authenticate accounts and restore signed-in sessions.
- Display app listings and save your chosen apps.
- Manage testing commitments, daily check-ins, credits, and listing progress.
- Deliver feedback to the relevant developer and show you your submitted notes.
- Send testing reminders when notifications are enabled.
- Prevent unauthorized changes and excessive requests, investigate failures, and operate the service.
- Respond to support requests and process account deletion.
Firebase SDKs can retain authentication state and cached service data on your device. Clearing the app's storage or uninstalling it removes local app storage; doing so does not itself delete your server account.
Search and filter operations run within the app; Ghapp does not maintain a separate search-history record. The current app does not include advertising, Google Analytics, or payment processing. Express is a preview feature, and the app does not collect payment-card or mobile-money payment details.
Who can see information
Public listings: Published listings can be read without signing in. Their developer name and account identifier, app details, links, and progress information are part of the listing. Signed-in users with active accounts can also read listings that are still preparing for or undergoing testing. Do not put confidential information in a listing.
Private account information: Other users cannot read your account profile, phone number, saved collection, or notification token through the app's database access rules. Testing assignments are readable by the assigned tester. The backend uses these records to calculate aggregate listing progress.
Feedback: A feedback note is readable by its author and the owner of the associated listing. Authorized service administration also has access to information needed to operate and support Ghapp.
Service providers: Ghapp uses Google Firebase Authentication, Cloud Firestore, Cloud Functions, Firebase Cloud Messaging, Firebase App Check with Google Play Integrity, and optional Firebase Crashlytics, together with underlying Google Cloud infrastructure. These providers process information to deliver their services. Their processing and service-specific retention are described in Firebase's privacy and security information.
For phone verification, Google receives and stores phone numbers for spam and abuse prevention across Google services, as described in the Firebase phone authentication documentation. Ghapp asks for your consent before sending a verification code. Verification codes are handled by the authentication flow and are not stored in Ghapp's profile database.
Google's processing can take place outside your country. The backend functions in this release are configured for Google's US Central region; this does not establish the storage location of every Firebase service.
Device permissions and external links
The Android app uses internet access and permissions needed for network status, push delivery, and notifications. Notifications are optional. The app does not request access to your contacts, location, camera, microphone, SMS inbox, or general file storage. Phone verification may use Google's automatic verification features without reading your SMS inbox through a general SMS permission.
Testing links, store links, and other external links open services outside Ghapp. Those services and the apps you choose to test have their own privacy practices. Copying an app link writes that link to your clipboard; Ghapp does not read clipboard contents.
Your choices
You can browse published listings without an account. Registration and testing participation require phone verification. You can remove saved apps, sign out, manage notification permission in Android settings, and turn optional crash reporting on or off in Profile.
Turning off crash reporting stops future optional collection and asks the SDK to delete unsent reports. It does not recall reports already sent. Signing out attempts to remove the stored notification token and delete the device's messaging token. Network failures can delay that cleanup, and a delivery already in progress may still arrive. You can also disable notifications in Android settings.
For access, correction, deletion, or other privacy requests concerning your information, contact support@boldtechai.com. We may need to verify that the account belongs to you before acting on a request. Do not email your password or SMS verification code.
Account deletion and retention
Use Profile → Delete account to request deletion in the app. This action requires a recent sign-in. Once accepted, the request is queued for backend processing and the app signs you out. Processing is asynchronous and failed jobs are retried.
The deletion process removes your Firebase authentication account, Ghapp profile, saved collection, stored notification token, testing assignments, and feedback you authored. It also removes listings you own and their associated feedback, testing assignments, and private testing-progress records. Progress for other listings may be adjusted when your participation is removed. Copies other people have independently made, and information held by external apps or websites, are outside this process.
A minimal technical deletion record is scheduled for removal seven days after processing completes. This helps prevent interrupted or repeated deletion requests from recreating account data. Records needed while deletion is still pending remain until processing completes.
Account, listing, and participation records do not currently have an automatic inactivity-expiry period. Removing a bookmark deletes the saved association from your account. Account deletion removes the application records described above; it does not mean every provider security log, already-submitted crash report, or provider-held copy is erased at the same moment. Google applies its service-specific retention practices, described in Firebase's privacy information. We do not specify a separate fixed retention period for backend logs or backups in this policy because those operational settings have not been established for this release.
You can also request account deletion by emailing support@boldtechai.com. Include enough information to identify your Ghapp account; we will arrange any ownership verification needed.
Policy updates
We may update this policy as Ghapp's features or data practices change. The effective date above identifies this version. For questions about this policy, contact Bold Technology and AI at support@boldtechai.com.