Revolutionary Designs

Plain-language privacy notice

How AppShield handles information

AppShield is a service of Revolutionary Designs, operated by Revo Lue Shin. This notice covers the AppShield website, policy-update signup, review requests, payments, and materials supplied for an accepted human review.

Effective: September 1, 2026

The short version: the free code checker runs locally in your browser and does not upload the files you select. A review request is built locally and opened in your email app. AppShield asks for review materials only after scope and payment are confirmed, and it does not need store-console passwords, signing keys, production accounts, or real customer data.

Website use and the free checker

GitHub Pages hostingThe public site is delivered by GitHub Pages. Like most web hosts, GitHub may process request information such as IP address, browser or device information, requested URL, and request time to deliver, secure, and operate the service.
Memory-only PostHog analyticsMost public pages load PostHog to measure page views, referrers, page interactions, browser and device type, and approximate geographic information. AppShield configures PostHog with memory-only persistence and session recording disabled. It does not intentionally persist a PostHog identifier in cookies or local storage across page loads. The checker and signup area is marked to prevent automatic interaction capture; a checker run sends only the check-status categories and number of files scanned, not filenames, file contents, pasted text, or findings. PostHog and its delivery network still receive ordinary network information needed to serve and process requests. The review request and payment-return pages do not load PostHog.
Free checker filesThe Android source checker runs in the browser. Selected or pasted source text is analyzed on the device and is not sent to AppShield. Normal website and analytics requests still occur separately from that local analysis.

Optional policy-update signup

If you choose the policy-update signup on the checker page, the form sends your email address, a consent flag, list and signup-source identifiers, and a hidden anti-spam field to an AppShield Cloudflare Worker. Cloudflare also receives ordinary request information such as IP address, browser user-agent, and request time while delivering and securing the endpoint. The Worker stores the subscription record in a D1 database so AppShield can manage the requested updates and prevent abuse.

The signup is optional and separate from purchasing a review. To unsubscribe or ask for removal, email the address below from the subscribed address. The active subscription record is retained until you withdraw consent, request deletion, or the list is discontinued, subject to the provider's normal backup and recovery cycle.

Review requests and correspondence

The request page uses browser JavaScript to assemble the details you enter into request text. It does not post those field values to AppShield or a form provider. The primary action copies the text to your clipboard and asks your browser to open an addressed email; a manual-copy fallback remains on the page. Nothing reaches AppShield until you paste the request, review it, and send it through your own email service.

A request can include your name, reply email, app name, target store, build-access type, approximate flow count, primary locale and role, intended submission date, rejection status, and high-level notes. Gmail processes messages sent to the published AppShield contact address. AppShield uses them to assess fit and availability, answer questions, document the agreed scope, and provide the service.

Payments

Payment is requested only after AppShield accepts a review scope in writing. Stripe processes the hosted checkout and payment credentials. AppShield does not receive or store a full card number, bank login, or wallet credential. Stripe also receives the non-sensitive checkout fields you provide: app name or working title, target store, and approved scope ID. AppShield can receive those fields plus the payer name and email, transaction amount, time, status, payment-provider identifiers, and limited payment-method details made available for receipts, refunds, accounting, fraud prevention, and dispute handling.

Payment-method availability and Stripe's own use of information are governed by the checkout shown to you and Stripe's privacy notice. Do not send payment credentials by email or through a review-materials folder.

Accepted review materials and test access

After scope and payment are confirmed, AppShield may receive a TestFlight invitation, APK or internal-test link, draft listing and screenshots, draft privacy or Data Safety answers, age-rating answers, policies, an SDK and data inventory, prior rejection text, and reviewer notes. If login is required, use one disposable, least-privilege test account populated only with invented test data.

Materials are shared through the restricted folder or platform invitation agreed in the acceptance email. The customer generally controls that storage account and grants access directly to the reviewer. A disposable password must be shared separately through the agreed one-time-secret or password-manager method, never in an email body, folder name, or URL query string.

Do not provide: App Store Connect or Play Console passwords, signing keys or certificates, two-factor or recovery codes, API secrets, payment credentials, production accounts or databases, real customer records, or regulated personal data such as health, financial, children's, government-ID, or precise-location data. If a secret is sent accidentally, revoke or rotate it immediately and notify AppShield.

AppShield uses accepted materials only to perform, document, clarify, and recheck the agreed review. Reports and client materials are not published or used as a public testimonial without separate written permission.

Who processes information

Depending on the action you take, information may be processed by GitHub (site hosting), PostHog (memory-only website analytics), Cloudflare (email-signup endpoint and database), Google Fonts (web-font delivery), Google/Gmail (correspondence), Stripe (payments), and the restricted storage, TestFlight, Google Play testing, or one-time-secret provider agreed for your review. AppShield does not sell personal information or provide it to data brokers. Information may also be disclosed when required by law, to protect the service or others, or in connection with a legitimate business transfer.

These providers may process information in countries different from yours under their own terms and safeguards.

Retention

Provider backups, security logs, or records controlled by a customer-owned folder may persist for the provider's normal retention cycle. AppShield deletes or removes active access on the schedule above but cannot erase a provider's independent legal or security records.

Security and data minimization

AppShield limits collection to the accepted scope, separates test credentials from ordinary correspondence, uses restricted sharing, and asks customers to revoke access after the recheck. No transmission or storage system is perfectly secure. Promptly report suspected unauthorized access and rotate any affected credential.

Your choices and questions

You may ask what information AppShield holds about you, request a correction, withdraw policy-update consent, or request deletion. AppShield may need to verify the request and may retain information required for payment, tax, fraud, dispute, or other legal obligations. Privacy rights vary by location, and AppShield will honor applicable rights.

The service is intended for adults acting for an app business or project. Do not submit children's personal information.

Privacy contact
awesomo913@gmail.com
Include only enough information to identify your request. Do not email credentials or review materials.

Changes to this notice

Material changes will be posted here with a new effective date. The notice in effect when a review is accepted governs that engagement unless a later change is required by law or agreed in writing.