Effective: August 6, 2026 · Last updated: August 6, 2026
This policy explains how SchemaPilot collects, uses, stores, and protects information when you install, authorize, or use the SchemaPilot Webflow App, this website, or the license dashboard. Written for Webflow Marketplace transparency requirements.
This Privacy Policy applies to SchemaPilot (the “App”), operated by SchemaPilot / Appsrow (“we”, “us”, “our”), including:
Data controller: SchemaPilot (Appsrow)
Publisher: Independent Webflow Marketplace developer - not Webflow, Inc., not affiliated with or endorsed by Webflow except as a listed app publisher.
Website: https://schemapilot.appsrow.com
Support: sales@appsrow.com
(send email) ·
Support page
Your use of Webflow is also governed by Webflow’s Terms and Webflow’s Privacy Policy. App access via Webflow APIs is subject to the Webflow Developer Terms of Service and Marketplace Guidelines.
When you install from the Marketplace or use Connect Webflow, you approve OAuth on Webflow. We request only scopes required to read and write schema/SEO data:
sites:read - list and identify sitespages:read / pages:write - SEO fields and page updates you requestcustom_code:read / custom_code:write - registered JSON-LD scripts on static pagescms:read / cms:write - CMS fields for collection-item schemaauthorized_user:read - identify the Webflow user for session management and Hybrid auth
We do not request payment scopes from Webflow. Install starts at
https://api-schemapilot.appsrow.com/auth/install; callback is
https://api-schemapilot.appsrow.com/auth/webflow/callback.
Hybrid App authentication: After OAuth, the Designer Extension may call Webflow’s
webflow.getIdToken() and send the ID token to our API
(POST /auth/designer-id-token). We verify it with Webflow’s token resolve endpoint
using your stored OAuth access token, then issue a short-lived app session token for the panel UI.
This is the recommended Designer + Data Client pattern - not a password form.
We do not read, collect, or act on password, login, or other credential fields in your Webflow site content or forms.
We do not read your Webflow password. We access data needed for features you use.
safPageHealthV1) cleared on disconnectWhen you save, we write JSON-LD and related SEO fields through the official Data API. Static pages use registered inline scripts (Custom Code API). CMS items use CMS fields plus a template Embed you control. Your published site does not call our API on every visitor load, and we do not collect visitor telemetry from your site.
When you click Generate, excerpts such as page title, description, URL, and schema context may be sent to OpenAI to produce suggestions. You initiate each generation. We do not train public models on your content for our own purposes. Nothing is sent for AI until you confirm/generate.
We do not sell your personal information. We do not show ads in the App.
Where GDPR / UK GDPR applies, we process data based on:
Processors handle data to deliver the service under contractual safeguards where applicable.
POST https://api-schemapilot.appsrow.com/webhooks/uninstall with a valid app Bearer may also trigger cleanup.We use HTTPS, access controls, hashed passwords for dashboard accounts, and industry-standard practices. No online service is 100% secure. Protect your Webflow and Dashboard credentials and revoke the App when you stop using it.
Data may be processed in countries where we or our providers operate (including India and cloud regions used by Webflow, OpenAI, and Razorpay). We use appropriate safeguards where required by law.
Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing, and to lodge a complaint with a supervisory authority. Contact sales@appsrow.com.
California residents: We do not sell personal information. You may request access or deletion from the same contact; we will verify using your account email where practical.
The App and Dashboard are not directed to children under 16. We do not knowingly collect their data.
We may update this policy by posting a new version here and updating the date above. Material changes for existing users may also be noted on the website. Continued use after the effective date means you accept the updated policy.
Privacy & data requests
sales@appsrow.com