Effective 28 July 2026

Privacy Policy

This policy explains what data Mortar collects, why, and what your rights are. The short version: we collect what the service needs to work, we never sell your data, your app's code is yours, and the data inside apps you publish belongs to you and your users — we only process it to run your app.

1. Who we are

Mortar (mortar-ai.com) is an AI app-building and hosting service operated from Bulgaria. For any privacy matter, contact support@mortar-ai.com — we answer data requests from that address.

2. What we collect

  • Account data — your email address and a hashed password. We never store passwords in plain text.
  • Billing data — handled by Stripe. We store only references (customer and subscription identifiers, amounts, invoice status); your card number never touches our servers.
  • Project content — the prompts you write, the code Mortar generates for you, your project's database and uploads, and build logs. This is the product; it exists so you can preview, edit and export your app.
  • Usage & security data — credit metering per build, server logs, and email delivery signals (bounces/complaints) used to protect sending reputation.
  • Integration secrets — API keys you connect (e.g. your Stripe keys) are encrypted at rest and injected only into your running app. The AI that builds your app never sees their values.

3. Apps you publish — you are the controller

When you publish an app, the people who use it are your users, and the data they submit is your data. For that data Mortar acts as a processor on your behalf: we host it, back it up, transmit the emails your app sends, and otherwise touch it only to run the app or as you instruct (including deleting it when you destroy the app or let the retention window lapse). You are responsible for your own privacy notice and lawful basis toward your users. The subprocessors we use for this are listed in section 5.

4. AI processing

To build and edit your app, your prompts and your project's code are processed by Anthropic's Claude API under our commercial agreement — Anthropic does not use this data to train models. Your integration secrets are never included in what the AI sees.

5. Who processes data for us

  • Fly.io — servers and databases (primary region: Frankfurt, EU).
  • Stripe — payments, subscriptions and payout accounts.
  • Anthropic — AI processing of prompts and project code during builds.
  • Resend — transactional email delivery (ours and your app's).
  • DigitalOcean — encrypted object storage for project repositories and snapshots.
  • Cloudflare — DNS and network protection.
  • Porkbun — domain registration when you buy a domain.
  • Google — Safe Browsing checks of hosted-app URLs (reputation protection) and, only if you accept the analytics banner, Google Analytics usage statistics.

Some of these providers are US companies; transfers rely on their EU-approved safeguards (Data Privacy Framework participation or standard contractual clauses).

6. Cookies

By default we set only strictly necessary cookies: your session and CSRF protection. If you accept the analytics banner, Google Analytics additionally sets its measurement cookies so we can understand how the site is used — declining (or simply ignoring the banner) keeps everything working with no analytics at all, and your choice is remembered. No advertising or cross-site tracking cookies either way.

7. How long we keep things

  • Your account and projects — until you delete them.
  • A published app's data after you unpublish — kept for a limited retention window so you can come back, then deleted automatically (we warn you by email first).
  • Deleting a project permanently removes its code, data and build history.
  • Billing records — kept as long as accounting law requires.

8. Your rights

Under the GDPR you can access, correct, export or erase your data, object to or restrict processing, and complain to a supervisory authority (in Bulgaria: the CPDP). Much of this is built into the product — you can export your full source code anytime and delete projects yourself; for anything else (including full account deletion), email support@mortar-ai.com.

9. Security

Everything travels over TLS. Integration secrets are encrypted at rest. Builds run in isolated sandboxes. Each published app runs isolated from every other, and each project sends email through its own isolated identity. No system is perfectly secure, but isolation is the design principle throughout.

10. Changes

If this policy changes materially, we'll note it here and, for significant changes, tell you by email. The date at the top is the version in force.

See also the Terms of Service and, if you take payments, the Payments via Mortar — Maker Terms.