Skip to content
opointo
  • App Builder
  • Templates
  • Docs
  • Pricing
  • How it worksFrom a drawing to an app on your phoneBlogGuides and notes on building native appsChangelogWhat shipped, and whenCompatibilityWhich iOS and Android versions are verifiedFAQRequirements, billing, what you ownAll resourcesDocs, recordings, llms.txt and more
Open the App BuilderOpen App Builder

Product

  • App Builder
  • Templates
  • Docs
  • Pricing

Resources

  • How it works
  • Blog
  • Changelog
  • Compatibility
  • FAQ
  • All resources
Open the App Builder

Legal

Privacy policy

Accounts are optional, and there are no advertising trackers. Here is everything we hold, and why.

Last updated 25 September 2026.

opointo is operated by booqend pty ltd (ACN 700 133 786), a company registered in New South Wales, Australia. We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. If you are in the UK or EU, we also honour the access, correction, erasure and objection rights described below.

The short version

You can use opointo without an account. If you sign in, we keep your name, email address and profile picture, the apps you save, and your licence key if you choose to save it, encrypted. The only cookies we set are the ones that make signing in and unlocking work. We count visits with PostHog without cookies, so we know which of our ads and posts are worth paying for without following anyone across sites or between visits. There are no advertising pixels and no session recordings. When your coding agent asks our tools for help, it sends what the question needs, such as a snippet of code to check; we use it to answer and do not keep it.

What we collect

Your account, if you create one. Signing in with Google, GitHub or Facebook gives us the name, email address and profile picture that provider shares, whether it has confirmed the address, and the provider’s own id for your account, so the next sign-in finds you. We never see your password for that provider, and we use its sign-in only to read that profile: we ask for nothing else and keep none of its access tokens.

Apps you save to your account. Signed in, the App Builder saves what you design to your account: the screens, the blocks on them, the text you typed and the settings you chose, with a small outline of it for the preview on your projects page. Only you can open them.

Your licence key, if you save it. A subscriber can keep their key on their account so the App Builder unlocks on any computer they sign in on. It is stored encrypted (AES-256-GCM), and only its last four characters are kept readable, so we can show you which key is saved.

Agent tokens, if you make them. A token you create on your account page for your coding agent is stored only as a one-way hash, with the name you gave it, its last four characters, and when it was made and last used. Revoking it or deleting your account erases it.

Your email, if you give it to us. Joining the waitlist or emailing support stores your address so we can reply or tell you when something ships. Nothing else is attached to it.

Screens you deliberately send. When you hand a design to your coding agent or to a device, that composition is stored so the agent can fetch it. It is automatically deleted after seven days and is identified only by a random id. It contains the layout you built, not your source code and not your identity.

How you found us and what you clicked. When you visit, we record which pages you open, a few actions (opening the App Builder, sharing an app with your agent, copying setup instructions, pressing a buy button) and which link brought you here, such as an ad or a newsletter. Each record also notes the browser, operating system and kind of device you use, its screen size, language and time zone. Nothing else is recorded automatically: not your other clicks, not what you type, not how far you scroll. These are tied to a random visit id kept in your browser’s session storage, which is deleted when you close the tab. Analytics use no cookies, so a visit on another day is a new, unconnected visit, and they are never joined to your account. Your IP address is used to estimate your country and then discarded.

Linking a purchase to the link that brought you. When you press a buy button, that visit id and link information go to Lemon Squeezy with your checkout and come back to us with the order, so we can tell which ad led to a subscription. If you share an app with your coding agent, the share carries the same visit id, so we can tell when an agent actually builds it.

What your coding agent sends our tools. Our MCP server answers questions from your agent, and each question carries what it needs: a snippet of your code for check_snippet to check, the names and sizes of the files in an exported app for verify_app, the list of files we supplied when an update is asked for. We use it to answer that call, and we do not store it or write it to any log. The one exception is a one-way scrambled code made from a paid call’s arguments, described under “Counting paid tool use” below, which cannot be turned back into them.

How the tools are used. Each call to our MCP server records the date, which tool was called, whether it succeeded, and how long it took. It does not include your licence key, the arguments you passed, or any code. To count how many different agents use the free tools each week, we also make a one-way scrambled code from your connection’s IP address and your agent’s name, mixed with a secret and the current week. We read the IP address to make that code and do not store it, and the code changes every week, so it cannot follow you from one week to the next. We record which kind of agent called (for example Claude Code or Cursor), never the full name it sent. We use this to learn which tools are worth keeping.

Counting paid tool use. The paid tools have a daily limit, so for each paid call we keep a running count per tool per day. The count is filed under a one-way scrambled code made from your licence key, not the key itself, and each day’s count is deleted after 45 days. So that an agent retrying the same call is not charged twice, we also keep a one-way scrambled code of that call’s arguments for 15 minutes. Neither code can be turned back into your key or your arguments.

Licence checks. When you unlock the App Builder, install a component or use a paid tool, we send your licence key to Lemon Squeezy to confirm it is valid, and hold the answer in memory for about a minute. The key is not stored on our side unless you save it to your account, as described above.

Cookies and browser storage

We set three cookies, all to make the site work, none for tracking or advertising, and none readable by scripts on the page:

  • Your sign-in, only when you sign in. It lasts 30 days from when you last used the site, 90 days at most, and signing out ends it everywhere it was copied, not just in this browser.
  • A one-time sign-in check, for the few moments you are away at Google, GitHub or Facebook. It stops anyone else finishing a sign-in you started. It expires after ten minutes and is removed when you return.
  • Your licence key, only after you unlock the App Builder, so this browser stays unlocked. It lasts 90 days.

The App Builder also keeps your work in this browser’s local storage as you go, and the site remembers small choices there, such as light or dark mode. That stays on your device.

What we do not collect

  • Your designs, unless you save or send them. Signed out, the App Builder saves only to your browser’s local storage, which never reaches us.
  • Your app’s source code as a whole. Exported code goes straight into your repository. It contains no licence check and never contacts us, before or after you cancel. The only code we ever receive is a snippet your agent sends for checking, as described above, and we do not keep it.
  • Card details. Payment is handled entirely by Lemon Squeezy. We never see your card number.
  • No advertising cookies, pixels or identifiers, no session recordings, no cross-site tracking, and no profiles of you as a person.

Who else is involved

Cloudflare hosts the site and stores your account, your saved apps, your email and shared apps. PostHog stores the visit and usage records described above, in its European Union region. Lemon Squeezy is our Merchant of Record and handles payment, invoicing, tax and licence keys under their own privacy policy. Google, GitHub and Facebook handle your sign-in if you choose one of them, under their own privacy policies. These may process data outside Australia, including in the United States and the European Union.

We do not sell personal information, and we never will.

How long we keep it

Your account and the apps saved in it are kept until you delete them. A project you delete moves to Recently deleted on your projects page, where you can restore it or erase it for good yourself, and anything still there is erased for good once 30 days have passed. That erase runs once a day, so it can happen a little after the 30 days but never before them. Deleting your account erases it straight away: your projects (including any you deleted in the last 30 days), your sign-in methods, every session and the saved licence key. Our database host keeps a rolling recovery history for up to 30 days, after which deleted data is gone from that too.

Sent compositions delete themselves after seven days. Daily paid-tool counts delete themselves after 45 days, and the retry codes after 15 minutes. Visit and usage records carry no name, email or IP address, only the random or weekly codes described above, and are kept for as long as they help us judge what to build and where to advertise. Waitlist and support email addresses are kept until you ask us to remove them.

Your choices

Signed in, the Account page shows what your account holds and lets you remove your saved licence key, disconnect a sign-in method, sign out on every device, or delete the account yourself, at once. Deleting your account does not cancel a subscription, which is billed through Lemon Squeezy (see cancellation and refunds).

For anything else, email contact@opointo.com to see what we hold about you, correct it, or have it deleted, and we will action it without argument.

You can clear App Builder data and the visit id yourself at any time by clearing this site’s storage in your browser. Nothing on the site depends on analytics, so it works the same if you block it.

Complaints

If you are unhappy with how we have handled your information, tell us first and we will try to fix it. You can also complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Changes

If we start collecting something new, this page changes at the same time, and the date at the top moves.

Contact

contact@opointo.com

opointo

Design your app visually. Get one native codebase for iOS and Android.

Product

  • App Builder
  • Templates
  • Pricing
  • Compatibility
  • Changelog

Learn

  • Docs
  • How it works
  • Blog
  • FAQ
  • Resources

Developers

  • Connect your agent
  • Components
  • llms.txt
  • AGENTS.md

Company

  • About
  • Contact

Legal

  • Terms
  • Privacy
  • Refunds

opointo is made by booqend. © 2026.