Killion Apps

Privacy Policy

Effective September 16, 2026 · Last updated September 25, 2026

This policy explains what information Killion Apps collects, why, who we share it with, and what you can ask us to do about it. It covers our website at killionapps.com and our software, including Listing Hub and Customizer. The two products handle different information, so each has its own section.

1. Who we are

Killion Apps is an independent software studio based in Phoenix, Arizona, United States. We are the party responsible for the information described here. You can reach us at killioninvestments@gmail.com.

When you use Listing Hub, you are the owner of your own shop's data and we process it on your instructions. Where the GDPR or UK GDPR applies, you are the controller of that data and we act as your processor.

When you use Customizer, your buyers' information is processed on your instructions. You are the controller of your buyers' data and Killion Apps is the processor. We help you answer your buyers' requests about it, as section 10 describes.

2. The short version

3. Information we collect across the service

Account information

To create a Listing Hub account we collect your email address, a password (stored only as a salted cryptographic hash, never in readable form), your shop name, and your account and billing status.

Customizer has its own sign-in, on its own stack. Passwords are stored only as scrypt hashes, never in readable form, and each seller's data is kept within that seller's workspace.

Besides the password hash, a Customizer seller account holds your email address, your role in the workspace (owner or operator), and the workspace and its name. For the connected Etsy shop it holds the shop's identifier, the Etsy user ID of the shop's owner, the permissions granted, the connection's status and when it was last checked, and the shop's OAuth tokens, encrypted at rest.

If you contact support about either product, we keep that correspondence.

Text that is refused

Customizer checks the words a buyer asks to have printed against a list of slurs and hate terms, and refuses to put them on a product. When text is refused, Customizer records the text the buyer entered, which term it matched, and the time. That record exists so a wrongly refused order can be found and put right — a buyer who is refused by mistake usually just leaves, and without the record there is nothing to review.

Refusal records are deleted automatically 30 days after they are written. They are not used for anything else, and they are not shared.

A refusal is not the end of the order: the message a buyer sees tells them they can message the shop, and the shop can complete the order by hand.

Payment information

Listing Hub subscription payments are processed by our payment processor. We receive a customer reference, the plan, the amount, and whether the charge succeeded. We never receive or store your full card number. Customizer has no billing and takes no payments from you.

Technical and usage information

Our servers log IP address, browser user agent, pages or endpoints requested, and timestamps, for security, abuse prevention, and debugging. We record application errors and the actions taken in your account so we can investigate problems and show you an audit trail of what was published and when. Server logging covers buyers using Customizer's personalization pages too.

4. Listing Hub

Sales channel connections

Listing Hub only works if it can reach the places you sell. When you connect a channel — a marketplace, a social platform, or a print-on-demand fulfillment provider — you are sent to that provider's own login screen and you authorize the specific permissions involved. We receive an access token, not your credentials. Tokens are stored encrypted and are used only to perform actions you have asked for.

Through those connections we access shop and catalog information needed to build and publish listings: existing listings and product records, product and variant structures, production costs and shipping costs, fee and payout structures, order and sales volume where it is used to inform pricing, and the results of publish attempts.

Designs and listing content

We store the artwork files you upload, the mockups generated from them, and the listing content built around them — titles, descriptions, tags, prices, pricing rules, placement settings, and the version history of your edits.

Automated drafting of listing content

Listing Hub uses a third-party large language model provider to draft listing titles, tags, and descriptions. What we send is the design and product information needed for that draft — design name and description, product type, garment specs, and your own style preferences. We do not send your customer data, your account credentials, or your channel tokens. Our provider processes this to return the draft and, under our agreement, does not use it to train its models. Every draft is shown to you for review and editing before anything is published.

What Listing Hub does not collect

Listing Hub does not collect your customers' names, addresses, or payment details. It does not collect precise device location, contacts, biometric identifiers, or any special-category personal data, and we ask that you not put such information into free-text fields in the app.

5. Customizer

Customizer is in private beta. It lets a buyer personalize your design on a page linked from your Etsy listing and approve their own proof. The approved design is matched to the paid Etsy order and sent to Printify, where production begins according to your own Printify order-approval setting. Doing that means handling information about your buyers, not only about you. This section describes what that information is and what happens to it.

Customizer runs separately from Listing Hub. It is hosted on Render, keeps its database in SQLite on a persistent disk there, and stores private artwork as files on the same disk. Sections 3 and 9 describe its sign-in and security.

What the buyer supplies

The buyer personalizes your design on a Killion Apps page, not in Etsy's personalization field. They reach it from a link in your Etsy listing. Links expire, and the page keeps its own buyer session. Depending on the design, the buyer can supply:

We store what the buyer supplies and generate a proof from it. Because the page is ours, the server logging in section 3 and the cookies in section 13 apply to buyers as well as to you.

Buyer sign-in with Etsy

The buyer signs in with Etsy on the page. Customizer asks Etsy only for basic profile access (the profile_r permission), takes the buyer's numeric Etsy user ID, and discards the Etsy token. The ID is kept with the buyer session so the buyer's paid order can be matched to the proof they approved.

Text rendered by an image model

For each text element on a design, you choose how the buyer's text is rendered:

Approval

The buyer reviews the proof and approves it on the page before buying. You review order matches and any exceptions. Production begins according to your own Printify order-approval setting. Setting it to Manual is a setup precondition: Printify exposes that setting to no other software, so Customizer cannot check it or change it.

Reading Etsy orders

Customizer reads your Etsy orders through the connection you authorized. A paid order is matched to an approved proof by the buyer's numeric Etsy user ID together with the listing, variation, and quantity. From each order it keeps exactly these fields:

It does not keep the buyer's name, email address, phone number, gift message, or order note. It does not keep the order total or the payment method. Shipping details are handled separately, at fulfillment, as described next.

Sending the order to Printify

At fulfillment, Customizer reads the shipping details from the paid Etsy order and passes these eight fields to Printify with the approved print file:

No email address or phone number is sent to Printify: Etsy does not provide the buyer's, and Customizer does not put anyone else's in their place. The eight fields are passed so Printify can produce and deliver the order, and for nothing else. Customizer reads them at fulfillment and does not retain them. Printify handles them under its own privacy policy.

Payment information

Customizer does not receive or store card numbers or payment credentials. It does not store the order total or the payment method either. The only payment-related thing it keeps is whether the order is paid.

How long Customizer data is kept

DataWhat happens to it
Buyer personalization linkExpires 365 days after it is created; a test link expires after 1 day. The expired link's record is not deleted.
Buyer session, including the buyer's numeric Etsy user ID and the text and choices they enteredExpires when its link expires or after 2 days, whichever comes first. The session record is not deleted.
Refused buyer text, with the term it matchedDeleted automatically 30 days after it is written.
Buyer uploads and previewsDeleted automatically after 3 days, unless their session has been approved or is being prepared for production. Those are not deleted.
Approved final rendersAccess expires after 365 days. The file is not deleted.
Etsy order fields listed aboveNot deleted
Shipping detailsNot retained. Read at fulfillment and passed to Printify.

Two cleanups run automatically and do not wait for anyone to ask: the one that deletes buyer uploads and previews, and the one that deletes refused buyer text after 30 days. Nothing currently deletes buyer session records, the text and choices a buyer entered on the way to a proof, expired links, stored Etsy order fields, or approved final renders.

Deleting data from Customizer does not delete any copies that Etsy, Printify, OpenAI, or Sentry hold under their own policies.

Error monitoring. Customizer reports technical errors to Sentry, an error-monitoring service, so we can find and fix problems. A report says what went wrong and where: the error, the page or step it happened on, and the identifiers of the customization, order or Etsy receipt involved. It does not include your buyers’ names, shipping addresses, email addresses or payment details. Reports are built to leave out the text a buyer types; the one exception is an unexpected error whose own message quotes part of it, which is rare. Sentry receives the connecting IP address, as any web service does. It is set not to store that address, but it does keep an approximate location worked out from it: the city, region and country. We do not use Sentry for tracking or analytics.

Who else is involved

The term “Etsy” is a trademark of Etsy, Inc. This application uses the Etsy API but is not endorsed or certified by Etsy, Inc.

6. Why we process it

Where the GDPR applies, our legal bases are performance of our contract with you, your consent for optional integrations (which you may withdraw), our legitimate interest in securing and improving the service, and compliance with legal obligations.

7. Who we share information with

We do not sell personal information and we do not share it for advertising. We share it only with service providers who help us run the software, each under contract and only for that purpose. For Listing Hub:

Provider roleWhat they handle
Application hosting and databaseRuns the app and stores account and listing records
Object storageStores uploaded design files and generated mockups
Language model providerDrafts listing copy from product information
Payment processorHandles subscription billing
Email deliverySends account and support email

For Customizer:

ProviderWhat they handle
RenderHosts Customizer, and the persistent disk that holds its SQLite database and private artwork files
OpenAIRenders buyer text into a design, only for text elements set to the AI strategy
SentryReceives error reports: what failed, where, and the identifiers involved. No names, addresses, email addresses or payment details

Separately, we transmit data to the sales channels and fulfillment providers you connect, because publishing your listings and fulfilling your orders is the point of the service. For Customizer, that is your buyers' shipping names and addresses, sent to Printify as section 5 describes; no buyer email address or phone number is sent. Those platforms handle that data under their own privacy policies.

We may also disclose information if required by law or valid legal process, to protect our rights or someone's safety, or in connection with a merger or sale of the business — in which case we will tell you before your information becomes subject to a different policy.

8. Retention

DataKept for
Account, designs, and listing recordsWhile your account is active; deleted within 30 days of account deletion
Customizer personalization, proofs, and order dataAs set out in section 5
Channel access tokensUntil you disconnect the channel or delete your account; deleted immediately on disconnect
Listing Hub billing recordsAs long as tax and accounting law requires, typically 7 years
Refused buyer text30 days, deleted automatically
Server logsUp to 90 days
Customizer error reports (Sentry)Kept by Sentry for the retention period of our Sentry plan, currently 30 days, then deleted automatically
Audit trailAppend-only. Customizer's audit records cannot be changed or deleted, by us or by anyone, and are kept for as long as the account exists.
Support emailUp to 24 months

9. Security

Data is encrypted in transit using TLS. Channel access tokens and other secrets are encrypted at rest. Access to production systems is limited to the people who operate the service and is protected by multi-factor authentication. We keep dependencies patched and we log administrative actions. No system is perfectly secure, and we will not pretend otherwise — if a breach affects your information, we will notify you and any required authority without undue delay.

Customizer, on its own stack, also writes private artwork outside the web root with owner-only file permissions, encrypts provider OAuth tokens at rest, stores buyer links only as hashes that expire, and verifies incoming webhooks by signature within a timestamp window.

10. Your rights and choices

Depending on where you live, you have some or all of the following rights: to access the personal information we hold about you, to correct it, to delete it, to receive a portable copy, to object to or restrict certain processing, to withdraw consent, and not to be discriminated against for exercising any of them.

You can do most of this yourself: disconnect a channel in settings, export your listing data, or delete your account. For anything else, email killioninvestments@gmail.com and we will respond within 30 days. If you are in the EEA or UK you may also complain to your local data protection authority. We do not sell personal information or share it for cross-context behavioral advertising, so there is no such sale to opt out of.

If you bought through a Customizer page, the seller you bought from is the controller of your personalization, uploads, and order details, so send requests to access or delete them to that seller. We help the seller answer them, on the seller's instructions. If you write to us directly at killioninvestments@gmail.com, we will not turn you away: we forward your request to the seller and help them answer it. Include your Etsy order number. Buyers have no account, so that is how we find the order and its seller.

11. International transfers

We operate in the United States and our providers may process data there. If you are outside the US, your information will be transferred to and processed in the US. Where required, we rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism with our providers.

12. Children

Our software is not directed to children. Customizer's buyers are consumers of whatever age Etsy permits. We do not knowingly collect personal information from children under the age applicable law sets. If you believe a child has given us information, contact us and we will delete it.

13. Cookies

Our marketing website is static and sets no cookies. The applications set only essential cookies:

We do not use advertising, analytics, or cross-site tracking cookies.

14. Changes

If we change this policy we will update the date at the top of this page, and for material changes we will email account holders before the change takes effect. Continued use after that means you accept the revised policy.

The email commitment applies to account holders, meaning sellers. Buyers have no account, so they see the current policy at this address.

This version, effective September 16, 2026, replaces the version effective August 6, 2026. It is a material change: it adds Customizer, a second product, information about your buyers, and the processing that goes with it.

15. Contact

Killion Apps · Phoenix, Arizona, United States
killioninvestments@gmail.com