Security
AppFly writes and runs code on your behalf, so here is exactly what that means for your data — the isolation boundary, what is encrypted, what is never collected, and what happens to everything when you leave.
One app cannot reach another
Every app is issued its own Postgres database and its own login role, and the role is created with REVOKE CONNECT … FROM PUBLIC. The isolation is a property of the database, not of application code: a query written by an agent in one app cannot address another app's data even if the agent tries.
Each app also runs in its own container, with its own workspace on disk. Nothing is shared but the host.
Secrets are encrypted, and never shown whole
Provider keys, tokens and environment values are encrypted at rest with AES-256-GCM. Only a masked hint — the last four characters — is ever returned to a page, so a rendered screen or a build log cannot leak a whole credential.
Keys are written into the generated app's own .env inside its own workspace, which is the only place that can read them. We issue exactly one environment variable ourselves, the app's own database URL, because the database is ours to provision.
Your customers' data is not ours
AppFly holds accounts, store domains, prompts and generated code. It never reads the customers, orders or personal data in your store, and the access scopes we request from Shopify do not include them.
Shopify requires every app to answer three compliance webhooks, and we answer all three. The two customer-data topics are acknowledged with a log line recording that we checked and held nothing — the reply a merchant may later need us to have on record.
Deleting is the default, not a support ticket
Deleting an app removes its container, its database, its files, its deployment, its DNS record and its access. The database row goes last, so a teardown that fails partway retries rather than leaving an orphan running.
Uninstalling from Shopify erases everything belonging to your shop within 48 hours. A scheduled sweep runs every five minutes to catch anything the uninstall handler could not finish, so an interrupted teardown never resurrects as a live app.
Signing out revokes the session server-side. Closing your account deletes everything the Privacy Policy says it does.
Boundaries we hold
Every request to a signed-in page is authenticated, and API routes answer an unauthenticated call with a 401 the caller can read rather than an HTML login page.
Billing webhooks are signed and verified against the raw request body. A deployment with no webhook secret configured returns 404 for the endpoint — unsigned is unauthenticated, not open — and a bad signature is a 401.
The operator console is behind a password and a signed cookie, and its privileged host operations are a fixed list of functions with no generic shell. It is not reachable from the public site, and robots.txt disallows it.
Reporting a vulnerability
Send it to security@appfly.si with enough detail to reproduce it and an idea of the impact. We will acknowledge it, and we will tell you what we are doing about it. Please give us a reasonable window before disclosing publicly, and do not test against other tenants' data.
For anything that is not a security issue, hello@appfly.si is the right address.