If you are reading this, you probably have to justify a decision to a partner, a board, a practice manager, or a funder. Here is what you need.
Where your data lives
In your own cloud account, in a region you choose, in a database created in your name. UK or EU hosting is the default for UK clients.
We do not pool client data in a shared system. There is no App14 database holding your users. After handover we hold no copy of your production data.
Who owns what
| Asset | Owner | From when |
|---|---|---|
| Source code repository | You | Day one of the sprint |
| Database and backend | You | From creation |
| Apple and Google accounts | You | From setup |
| Store listings | You | From submission |
| User and customer data | You, as controller | Always |
There are no licence fees, nothing to renew, and nothing that requires our permission for you to move to a different developer.
GDPR
We build for the UK market and treat UK GDPR compliance as part of the job rather than an add-on.
What we do as standard
- Data minimisation by defaultWe collect what the app needs to work, not what might be useful later.
- Encryption in transit and at restTLS everywhere, encrypted storage.
- Consent handled properlyAnalytics and tracking gated behind opt-in, not assumed.
- Deletion and exportUsers can get their data out and have it removed.
- A privacy policy that matches the appRather than a template that describes something else.
Our own site runs the same way: consent defaults are set before any tag loads, and tracking scripts do not fire until someone opts in. It is a reasonable proxy for how we build.
For regulated sectors
If you work in healthcare, education, or professional services, the questions you will be asked are usually the same ones. We can provide, on request:
- A data processing agreement.
- Hosting region confirmation in writing.
- A description of who on our side has access during the build, and for how long.
- Confirmation of what we retain after handover, which is nothing operational.
Common questions
Where is our data stored?
In a database in your own cloud account, in a region you choose. UK or EU hosting is the default for UK clients. We do not pool client data and we do not hold a copy after handover.
Who is the data controller?
You are. It is your app, your users, and your account. During the build we act as a processor on your instructions, and we can sign a data processing agreement covering that.
Do you do penetration testing?
A security audit is included in the Advanced package. Formal third-party penetration testing is a separate engagement and we will tell you when your project genuinely warrants one.