01Summary
This Privacy Policy explains how personal data is handled when you use Buildhouse. It applies to the app for iPhone, iPad and Mac, the notification service behind it, and the website at buildhouse.app. These are three different things, and where a statement holds for one and not the others, we say which.
02Controller
The controller responsible for processing under Art. 4(7) GDPR and Art. 5 of the revised Swiss Federal Act on Data Protection (nFADP) is the developer named in the Imprint. You can reach the privacy contact at hello@buildhouse.app.
03Your App Store Connect API key
Buildhouse works by talking to Apple's App Store Connect API on your behalf. To do that it needs an API key — an issuer ID, a key ID and a private key — which you create in App Store Connect and paste into the app.
That key never reaches our servers. All three parts are written to your device's Keychain and are read only to sign requests that go directly from your device to Apple at api.appstoreconnect.apple.com. We operate no proxy for it and have no way to read it. The apps, workflows, builds, test results and artifacts you see in the app are fetched by your device from Apple and are not copied to us.
If you delete the key in Settings, or delete the app, it is removed from the Keychain.
04What we collect
| Category | What happens | Where it goes |
|---|---|---|
| Account data | None — there are no accounts or sign-up | — |
| Analytics / telemetry | None — the app contains no analytics, telemetry or advertising SDKs | — |
| App Store Connect API key | Held in the device Keychain; used only to sign requests sent directly to Apple | Stays on your device · Apple |
| Device identifier | A random UUID generated on first launch and kept in the Keychain, together with a public key used to authenticate your device. It is not Apple's advertising or vendor identifier and is not derived from anything about you or your hardware | Buildhouse service · RevenueCat |
| Push token | Only if you enable notifications or Live Activities. The token is uploaded with your device name and locale so notifications can be delivered and localised | Apple (APNs) · Buildhouse service |
| Xcode Cloud build events | Only for apps whose Xcode Cloud settings you have pointed at your personal webhook URL. Apple then sends us each build event — see the section below for exactly what it contains | Buildhouse service |
| Advertising identifiers | None | — |
| Subscription status | Billed by Apple; entitlement state is brokered by RevenueCat | Apple · RevenueCat |
| Crash reports | None collected by us. Apple may collect aggregate crash data if you opted in to share analytics with Apple. | Apple, per your system settings |
| Settings | Your preferences (onboarding state, notification and Live Activity toggles) are stored on the device. App icons are cached on the device so the widget can draw them | Stays on your device |
| Support emails | Only if you write to us | Mailbox of the developer |
| Website visits | The pages at buildhouse.app carry no analytics and set no cookies, but they load their web fonts from Google, which discloses your IP address and user agent to Google | Cloudflare (hosting) · Google (fonts) |
We do not ask for, and the app does not require, your name, email address or any other identifying information to function. Nothing is synchronised to iCloud — the app uses no iCloud or CloudKit service at all.
05Build events and the webhook
Notifications and Live Activities are off by default and require a Buildhouse Pro subscription. If you enable them, the app gives you a personal webhook URL containing your random device identifier, which you paste into the Xcode Cloud settings of each app you want to be notified about. Nothing is sent to us for apps you do not add.
Once added, Apple sends a webhook to us when a build is created, starts and completes. That payload is Apple's, not ours, and includes the product and workflow name, the build number and status, the repository owner and name, the branch, the commit SHA and commit message, and the display names of the commit author and committer. If your commit messages or repository names are confidential, be aware that they pass through our infrastructure in order to reach your Lock Screen.
We use these events only to compose the notification and the Live Activity we push to your devices, and to decide when to end a Live Activity. They are not sold, shared, profiled, or used to build a history of your development activity. You can stop the flow at any time by removing the webhook in App Store Connect, or by turning notifications off in the app.
07Retention
Push tokens are kept for as long as the device is registered; removing a device in Settings, or turning notifications off, deletes them. Build events are processed to send a notification and are not retained as a browsable history. Support correspondence is kept for as long as needed to answer it.
08Children
We do not knowingly collect personal data from anyone, including children under 13, and the app requires no personal data to function. If you believe a child has provided information to us (e.g. by writing to support), contact hello@buildhouse.app and we will respond promptly.
09Your rights
Under GDPR and the Swiss nFADP you have the right to access, rectify, erase, restrict, port or object to processing of your personal data, and to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) or your local supervisory authority.
In practice there is little to exercise these rights against: the only identifier we hold is a random UUID that is not linked to a name or an address, alongside any push tokens you registered and any support correspondence you have sent. You can request deletion at any time by emailing hello@buildhouse.app.
10Security
The website and the service are served over TLS. Your device authenticates to the service with a keypair generated on the device — it signs a one-time challenge, and the private half never leaves the Keychain. Your App Store Connect API key is likewise Keychain-resident and is sent only to Apple. Subscription billing is handled entirely by Apple; we never see your payment details. No security measure is perfect, and build events necessarily pass through our infrastructure in order to be delivered as notifications.
11Contact
Questions, requests or suspected breaches:
hello@buildhouse.app
See the Imprint for our postal contact.