Privacy Policy

Last updated: August 5, 2026

This Privacy Policy explains how Rork, Inc. (“Rork,” “we,” “us,” or “our”) handles personal information when you visit rork.com, create an account, build or publish a project, purchase a plan, or contact us. Rork, Inc. is the controller of the personal information described here unless a different party is identified at collection.

Rork, Inc.

2261 Market Street, Suite 22999

San Francisco, CA 94114

[email protected]

1. Information we collect (notice at collection)

We collect the categories below directly from you, automatically from your browser or device, and from service providers such as payment, authentication, and security vendors.

CategoryPurposesSold or shared?Retention
Account and profile information — name, email address, authentication identifiers, avatar, account settings, plan, and organization or billing relationship.Create, secure, and support your account; provide the service you signed up for.Not sold or shared.Life of your account. Closing the account removes your profile and sign-in. You may request deletion of remaining records at [email protected]; we process requests as required by applicable law.
Projects and content — prompts, source code, assets, messages, app metadata, generated output, and other material you submit or create with Rork.Generate, host, preview, and publish your projects.Not sold or shared.Life of your account and routine backups; project data may persist after account closure. You may request its deletion, processed as required by applicable law.
Transaction information — plan, purchase, invoice, and payment status. Stripe processes payment-card details; Rork does not store complete card numbers.Process purchases, billing, taxes, and fraud prevention.Not sold or shared.As long as tax, accounting, and fraud-prevention obligations require.
Technical and usage information — IP address, browser and device information, logs, security events, page and feature interactions, performance data, and diagnostics.Security, reliability, product improvement, and — with permission — advertising measurement.Identifiers and internet activity are shared for cross-context behavioral advertising unless you opt out.Logs and diagnostics are short-lived; advertising identifiers up to 90 days in the browser and until you withdraw the choice server-side.
Communications — support conversations, feedback, survey responses, and other messages you send us.Provide support and keep records of it.Not sold or shared.As long as needed for support and dispute records.
Campaign information — referral, affiliate, and advertising parameters, collected only when the applicable consent setting permits Marketing technologies.Measure and attribute advertising and affiliate campaigns.Shared with advertising and affiliate partners unless you opt out.Up to 90 days in the browser; server-side until withdrawal or account deletion.
Apple Developer credentials, sessions, and generated keys (sensitive personal information) — the Apple Developer email, password, and resulting authenticated session you provide to sign, install, or submit your app, and the App Store Connect API key (including its private key) that the submission flow creates in your Apple account.Authenticate with Apple to perform the signing, installation, or submission you request.Not sold or shared.Password in browser memory only. Your Apple email is stored on Rork servers together with the authenticated Apple session (the session itself is stored encrypted) until you disconnect it or your account is deleted; expired sessions stop being used but remain stored until then. The generated App Store Connect API key is stored encrypted on Rork servers until your account is deleted; disconnecting deactivates it. The iPhone-install flow keeps credentials in an encrypted browser vault until Apple sign-out or browser data is cleared.

Apple Developer credentials you enter are used only to authenticate with Apple for the action you request. In the App Store submission flow, your password stays in browser memory and is never written to persistent browser storage; your Apple email is stored on Rork servers together with the resulting authenticated session, which is stored encrypted and kept until you disconnect it or your account is deleted — expired sessions stop being used but remain stored until then — so later submissions can reuse it. That flow also creates an App Store Connect API key in your Apple account and stores it, including its private key, encrypted on Rork servers so later submissions can reuse it; disconnecting deactivates the key, and it is deleted with your account. The iPhone-install flow keeps credentials and Apple sessions in an encrypted browser vault (AES-GCM with a non-exportable key) until you sign out of Apple or clear browser data.

You can opt out of the sale or sharing described above at any time through or a browser that sends the Global Privacy Control signal. The rest of this Privacy Policy, including section 9 for California residents, provides the full details.

2. Why we use information and our legal bases

  • Provide the service and perform our contract: create and secure accounts, generate and host projects, publish apps, process purchases, provide requested support, and maintain preferences.
  • Legitimate interests: prevent abuse, protect Rork and its users, diagnose reliability problems, improve core functionality, and operate our business where those interests are not overridden by your rights.
  • Consent: use optional Analytics and Marketing technologies in jurisdictions or contexts where consent is required. You can withdraw consent through .
  • Legal obligations: comply with tax, accounting, fraud-prevention, law-enforcement, and other applicable legal requirements.

We do not use browser Analytics consent as a condition of signing up, logging in, paying, or using core Rork functionality.

3. How we share information

We may disclose personal information to:

  • Service providers that support hosting, authentication, AI generation, storage, email, payments, customer support, security, error monitoring, analytics, and advertising measurement.
  • Professional advisers, auditors, insurers, and authorities when reasonably necessary or required.
  • A successor or participant in a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality protections.
  • Other parties at your direction or with your permission.

We do not sell personal information for money. We do “share” identifiers and internet-activity information with advertising and affiliate partners for cross-context behavioral advertising, as the California Consumer Privacy Act defines those terms, unless you opt out. You can opt out at any time through or a browser that sends the Global Privacy Control signal; see section 9 for California-specific details.

4. Cookies, similar technologies, and tracking signals

Rork uses cookies, local storage, session storage, pixels, and similar technologies. Necessary technologies support authentication, security, preferences, payments, and support you request. Analytics and Marketing technologies are controlled through our consent manager. The full inventory is listed below.

Cookies set from rork.com expire within one year, except the cookie that stores your consent choice, which lasts until you change it or clear browser data. Other browser storage persists until it is removed or replaced, the related consent is withdrawn, or you clear browser data.

Where opt-in consent is required, optional technologies remain off until you choose. One exception in form but not substance: Google’s tag (gtag.js) loads before a choice using Google Consent Mode v2 with every storage signal denied — in that state it sets no cookies and sends no identifiers — and switches on advertising storage and conversion measurement only after Marketing consent. In regions using a no-banner policy, the applicable regional rule is applied. We honor Global Privacy Control by denying Analytics and Marketing. We disclose the older “Do Not Track” signal but do not treat it as a consent instruction because browsers do not implement it consistently.

Open to change or withdraw your choice. Withdrawing consent removes Rork-owned optional browser state and reloads the page immediately; for signed-in users, the change is queued and synchronized with account-level tracking right afterwards. You can also clear browser storage using your browser settings, but doing so may sign you out or reset preferences.

These choices also control related account-level analytics and server-side advertising conversion delivery. Rork does not send an earlier event merely because you grant permission later. Once a signed-in user’s withdrawal is synchronized, it stops future server-side delivery.

Necessary

Required to provide authentication, security, preferences, payments, consent storage, and support you request, plus cookieless aggregate measurement that does not identify you. These cannot be disabled through the consent manager.

ProviderPurposeBrowser storage
Rork

First party

Provide authentication, security, onboarding, locale, and user-requested application preferences.
  • cookie: locale, rork_onboarded, rork-feature-flag-overrides
  • cookie: rork-geo
  • local storage
  • session storage
Rork

First party

Remember and enforce your privacy choices, using c15t consent software that runs locally in your browser. No data is sent to the software's vendor.
  • cookie: rork-consent, rork-consent-hold
  • local storage: rork-consent, rork-consent-hold, c15t:pending-consent-sync, rork-consent-pending-sync
Rork

First party

Keep the Apple Developer credentials and sessions used by the iPhone-install flow, AES-GCM encrypted with a non-exportable key, so installing your app does not require signing in to Apple every time.
  • IndexedDB: rork-ios-installer
Supabase

Third party

Authenticate users and maintain signed-in sessions.
  • cookie: sb-*-auth-token*
Sentry

Third party

Detect errors, abuse, and security or reliability problems for authenticated product use.No declared browser storage
Stripe

Third party

Securely process a payment when a user starts a purchase or billing flow.
  • cookie: __stripe_mid, __stripe_sid
Intercom

Third party

Provide customer support. Rork creates a support contact record (name, email, signup date) for each account at signup; the chat widget and its cookies load only after an eligible signed-in user opens Support, and stay active for that user afterwards so agent replies to an open conversation reach them.
  • cookie: intercom-*
  • local storage: rork-support-engaged
PostHog

Third party

Decide which product features, experiments, and lifecycle emails are enabled. Rork servers send the account identifier (and, for email eligibility, the account email) to PostHog for this configuration lookup; the browser keeps a random identifier so anonymous visitors see stable experiment variants. Both are independent of Analytics consent and are not used for event capture.
  • local storage: rork-posthog-distinct-id
PostHog

Third party

PostHog persists the visitor's Analytics allow/deny marker so its SDK honors the choice on load.
  • local storage: rork-posthog-tracking-choice
YouTube (Google)

Third party

Show a video thumbnail, and play the video in privacy-enhanced mode — automatically where your consent settings permit Marketing content, otherwise only after you press play on an embed.No declared browser storage
Cloudflare Stream

Third party

Show a video thumbnail, and play Rork's product demo videos — automatically where your consent settings permit Marketing content, otherwise only after you press play on an embed. The player stores a bandwidth estimate and reports its own diagnostics from its origin.
  • local storage: stream.estimatedBandwidth
Plausible

Third party

Count aggregate website traffic without cookies, persistent identifiers, or cross-site tracking (audience-measurement exemption).No declared browser storage
Vercel Speed Insights

Third party

Measure real-world website performance on a 10% sample, without cookies or persistent identifiers.No declared browser storage

Analytics

Helps Rork understand product usage and website performance. Off by default where opt-in is required.

ProviderPurposeBrowser storage
PostHog

Third party

Understand product usage and improve Rork after Analytics consent.
  • cookie: ph_*_posthog
  • local storage: ph_*_posthog
Amplitude

Third party

Measure product usage, sessions, and performance after Analytics consent.
  • cookie: AMP_*
  • local storage: AMP_*

Marketing

Measures advertising, affiliate referrals, and campaigns. Off by default where opt-in is required.

ProviderPurposeBrowser storage
Rork

First party

Remember campaign parameters and attach them to Rork requests after Marketing consent.
  • local storage: utm
Google

Third party

Measure Google Ads campaigns and conversions. The tag loads with Google Consent Mode v2 denied — cookieless and without identifiers — and only stores advertising cookies and measures conversions after Marketing consent.
  • cookie: _gcl_*
  • cookie: _rorkgclid, _rorkgbraid, _rorkwbraid
Meta

Third party

Measure advertising campaigns and conversions after Marketing consent.
  • cookie: _fbp, _fbc, _rorkfbc_v2
Snap

Third party

Measure Snapchat advertising campaigns and conversions after Marketing consent.
  • cookie: _scid*, _rorkscclickid
  • local storage: u_sclid*
TikTok

Third party

Measure TikTok advertising campaigns and conversions after Marketing consent.
  • cookie: _ttp, _rorkttclid, _tt_enable_cookie, ttcsid*
Tolt

Third party

Attribute affiliate referrals and register referred signups after Marketing consent.
  • cookie: tolt_referral, tolt_data

The inventory above is generated from the same registry used to configure tracker blocking, which helps keep runtime behavior and this disclosure aligned. Vendors may change implementation details; we will update the registry and the “Last updated” date above when our use materially changes.

5. International transfers

Rork is based in the United States and uses providers in the United States and other countries. When required, we use recognized transfer safeguards such as adequacy decisions, Standard Contractual Clauses, or another lawful transfer mechanism. You may contact us for more information about applicable safeguards.

6. Retention

We keep personal information only as long as reasonably needed for the purposes described above, including to provide your account, maintain project history and backups, resolve disputes, enforce agreements, and meet legal obligations. Retention varies by data type and may continue after account closure where required for security, fraud prevention, tax, accounting, or legal claims. In opt-in regions we ask for consent again after one year; in opt-out regions your choice stays effective until you replace it or clear browser data, and a recorded opt-out is never treated as expiring back into permission. Anonymous visitors’ consent choices live only in their own browser. Rork-owned optional browser analytics and campaign state remains until you withdraw the applicable choice or clear browser storage. Account-level consent event history is retained as needed to document your choices and is deleted with your account.

7. Security

We use administrative, technical, and organizational safeguards designed to protect personal information, including access controls, encryption in transit, monitoring, and service-provider review. No system is completely secure, and we cannot guarantee absolute security.

8. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal information; withdraw consent; and complain to a data protection authority. You may also unsubscribe from marketing email using the link in the message. To exercise a privacy right, email [email protected]. We may verify your identity and will respond as required by applicable law.

9. California privacy rights

This section applies to California residents and supplements the rest of this policy under the California Consumer Privacy Act (CCPA). Section 1 is our notice at collection: it maps every category we collect to its sources, purposes, sale/share status, and retention. In the preceding 12 months we collected the following statutory categories of personal information:

  • Identifiers (name, email address, account identifiers, IP address, device and advertising identifiers) — shared with advertising and affiliate partners for cross-context behavioral advertising unless you opt out; otherwise disclosed to service providers.
  • Internet or other electronic network activity (page and feature interactions, logs, campaign parameters) — shared with advertising partners unless you opt out; otherwise disclosed to service providers.
  • Commercial information (plans, purchases, payment status) — disclosed to service providers only.
  • Approximate geolocation (country and region derived from IP address) — used to apply your regional privacy policy; disclosed to service providers only.
  • Content you provide (projects, prompts, communications), which may include personal information you choose to include — disclosed to service providers only.
  • Inferences (limited product-configuration and campaign-measurement attributes) — disclosed to service providers only.
  • Sensitive personal information (Apple Developer account credentials, sessions, and generated App Store Connect API keys including their private keys) — used only to perform the Apple authentication, signing, installation, or submission you request; not sold or shared.

Because sensitive personal information is used only to provide the service you request, no “Limit the Use of My Sensitive Personal Information” link is required. We do not knowingly sell or share the personal information of consumers under 16 years of age.

California residents have the right to know and access the personal information we hold, correct it, delete it, opt out of its sale or sharing, and not be discriminated against for exercising these rights. To opt out of sharing, use — the choice applies to this browser immediately and, for signed-in users, to account-level advertising delivery — or enable Global Privacy Control, which we treat as a valid opt-out request. For access, correction, or deletion, email [email protected]. We verify requests against your account information and may ask you to confirm from the email address on your account. An authorized agent may submit a request on your behalf with your written permission. We respond within the timelines the CCPA requires.

10. Children

Rork is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. If you believe a child has provided personal information, contact us so we can review and delete it where appropriate. A higher minimum age may apply in your jurisdiction.

11. User-generated previews and third-party services

Projects and preview sandboxes may contain code, services, or trackers selected by a Rork user. Those customer-controlled technologies are outside Rork’s website tracker inventory. If you publish an app or site, you are responsible for its disclosures and lawful configuration. Links to third-party sites and services are governed by their own privacy terms.

12. Changes and contact

We may update this policy to reflect changes in our services or law. We will post the updated policy and revise the static “Last updated” date; we will provide additional notice when required. Questions or requests may be sent to [email protected] or mailed to the address at the top of this policy.