Privacy Policy
Last updated: 12 August 2026
This policy explains how Ali Ebrahimi ("we", "us", or "our") handles personal data when you use App Store Analyst.
1. Who is responsible for your data
The service is provided by Ali Ebrahimi. Privacy questions and data requests can be sent to alierhm1378@gmail.com.
2. Data we process
- Account data: your email address, a securely hashed password, session records, and OAuth authorization records.
- App Store Connect connection data: Issuer ID, Key ID suffix, optional Vendor Number, connection status, and your uploaded
.p8private key. The private key is encrypted before storage using AWS KMS envelope encryption and is never displayed after upload. - App Store data: app identifiers and metadata, download and sales report values, proceeds by currency, customer reviews, territories, and version information that you ask the service to retrieve.
- Security and diagnostic data: request identifiers, tool name, success or error code, duration, authentication events, and limited server logs. We do not intentionally store ChatGPT conversation transcripts or MCP tool arguments in audit events.
We do not request or accept your Apple ID password or Apple two-factor authentication code.
3. Why we process data
We process this data to create and secure your account, connect to App Store Connect at your direction, answer your read-only analytics requests, prevent abuse, diagnose failures, and comply with applicable law. Where applicable, the legal bases are performance of the service you request, our legitimate interests in operating and securing the service, and compliance with legal obligations.
4. How data is shared
We do not sell personal data or use it for targeted advertising. Data is disclosed only as needed to:
- query Apple's App Store Connect API using the credentials you supplied;
- operate the service on infrastructure providers, including AWS hosting and AWS KMS;
- return requested tool results to ChatGPT when you authorize the connection; OpenAI's terms and privacy policy govern ChatGPT's handling of those results; or
- protect users, investigate abuse, or comply with a valid legal requirement.
5. Retention and deletion
- Your account and connection records remain until you delete them or the service is discontinued.
- Disconnecting App Store Connect immediately deletes the stored encrypted credential and clears that tenant's in-process analytics cache.
- Deleting your account removes the active account, sessions, OAuth tokens and codes, connection credential, tenant analytics data, report state, and audit events.
- Short-lived process memory caches expire automatically: review and version responses after approximately five minutes, app lists after approximately one hour, and report metrics after approximately six hours.
- Restricted disaster-recovery database backups are rotated after approximately seven days. Deleted data may remain in a backup until that backup expires and is used only for disaster recovery.
You can delete your account from the account deletion page while signed in, or contact us for help.
6. Security
We use HTTPS, access controls, rate limits, hashed passwords and tokens, tenant isolation, redacted logs, encrypted credential storage, and least-privileged infrastructure permissions. No internet service can guarantee absolute security. Revoke the API key in App Store Connect immediately if you believe it has been compromised.
7. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of your personal data, and to complain to a data-protection authority. Contact alierhm1378@gmail.com to exercise a right. We may need to verify that the request concerns your account.
8. International use
App Store Analyst is offered worldwide. The production service is hosted in the AWS Europe (Frankfurt) region, while Apple, OpenAI, and other providers may process data in other countries under their own terms and safeguards.
9. Children
The service is intended for App Store developers and authorized business users, not children under 18. Contact us if you believe a child provided personal data.
10. Changes and contact
We may update this policy as the service changes. The date above identifies the latest version. Questions can be sent to alierhm1378@gmail.com.