Privacy Policy
What personal data ASO Atlas collects, why we process it, who we share it with, how long we keep it and the rights you have over it.
Last updated
This policy explains what personal data we collect when you use ASO Atlas, why we process it, who else sees it and what you can do about it. It applies to asoatlas.com, the ASO Atlas application for macOS and the API.
1. Who is the controller
The controller of your personal data is:
Nielogiczny Karol Labuda Luzińska 2, 84-217 Zęblewo, Poland NIP 5882505100 · REGON 526924027 Contact: [email protected]
We have not appointed a data protection officer. Write to the address above with any privacy question and a real person will answer.
2. What we collect and why
Account data
Your name, email address, a hashed password, and the date you confirmed your email. If you enable two-factor authentication or a passkey we store the secrets needed to verify it. We process this to create and secure your account, which is performance of our contract with you (Art. 6(1)(b) GDPR).
Billing data
Your subscription status, plan, billing period and the customer and subscription identifiers held by our payment processor. We never receive or store your card number - Stripe handles the card and holds it under its own policy. We process billing data to take payment and to meet accounting and tax obligations (Art. 6(1)(b) and 6(1)(c) GDPR).
Product data
The apps you track, the keywords, keyword lists and metadata drafts you create, the competitors you add and the searches you run. This is what the Service is for, so we process it to provide it to you (Art. 6(1)(b) GDPR).
Aggregated, non-identifying keyword measurements derived from public App Store data feed our shared keyword dataset. That dataset describes keywords and apps, not people, and is not linked back to your account when it is used to serve other customers.
App Store Connect integration (optional)
If you connect App Store Connect, we store the issuer ID, key ID and the private key you supply. The private key is encrypted at rest and is never sent to your browser. We use it only to fetch your own sales, subscription and analytics reports and show them back to you. Disconnecting the integration deletes the key. This is processed on the basis of your request to use the feature (Art. 6(1)(b) GDPR).
AI features (optional)
When you generate app icons, the text prompt you write is sent to our image generation provider. Do not put personal data in prompts.
Technical and log data
Your IP address, browser user agent, session records, request timestamps and error logs. We use these to keep the Service secure, prevent abuse, enforce rate limits and diagnose failures. This is our legitimate interest in a working and secure service (Art. 6(1)(f) GDPR).
Usage analytics
We use a self-hosted analytics tool on our own infrastructure. It records page views, referrers and coarse device and country information without cookies and without a cross-site identifier, and it does not build a profile of you. No usage data is sent to an advertising network. This is our legitimate interest in understanding which pages work (Art. 6(1)(f) GDPR).
Support and email
If you contact us, we keep the message and our reply so we can handle the case and any follow-up. We send transactional email such as email verification, password resets, billing notices and important service notices. These are part of the Service, not marketing.
Marketing email (consent only)
We send product updates and ASO tips only if you opted in - via the optional, unticked checkbox at registration or the toggle in your profile settings. This is based on your consent (Art. 6(1)(a) GDPR), we record when you gave it, and you can withdraw it at any time in profile settings or through the unsubscribe link in any such message. Withdrawing does not affect your account or any transactional email.
Referrals
If you arrive through a referral link we store the referral code in a cookie for 30 days, and if you register we record which account referred you so the reward can be applied. Referrers see that a referral converted, never your account details.
3. What we do not do
- We do not sell your personal data.
- We do not share it with advertising networks or data brokers.
- We do not use it to train AI models.
- We do not run behavioural or cross-site tracking.
4. Who processes data on our behalf
We share the minimum necessary with the following processors:
| Processor | Purpose | Where |
|---|---|---|
| Hetzner Online GmbH | Hosting, servers and backups | Germany |
| Cloudflare, Inc. | DNS, CDN and abuse protection in front of the site | Global, EU edge |
| Stripe, Inc. / Stripe Payments Europe | Payment processing and invoicing | EU and USA |
| PurelyMail | Transactional email delivery | USA |
| kie.ai | AI image generation for the icon generator | Outside the EEA |
We also query Apple's public App Store endpoints. Those requests carry keyword and app data, not your identity.
Where a processor is outside the European Economic Area, the transfer is covered by the European Commission's Standard Contractual Clauses or another mechanism permitted under Chapter V GDPR. We can send you details on request.
We may also disclose data where the law requires it, or to establish or defend legal claims.
5. Cookies and local storage
We do not use advertising or tracking cookies, so there is no cookie banner. The cookies we do set are strictly necessary or functional:
| Name | Purpose | Lifetime |
|---|---|---|
aso-atlas-session |
Keeps you logged in and holds the free tool's usage counter | Session, up to 2 hours idle |
XSRF-TOKEN |
Cross-site request forgery protection | Same as the session |
appearance |
Remembers light or dark mode | 1 year |
referral_code |
Attributes a referral to the person who invited you | 30 days |
Your browser's local storage also holds your appearance preference. Cloudflare may set its own security cookie to distinguish a browser from a bot.
6. How long we keep data
- Account and product data: while your account exists, then deleted or anonymised within 30 days of closure.
- Billing records: 5 years from the end of the accounting year, as Polish tax law requires.
- Logs and technical data: up to 12 months.
- Support correspondence: up to 3 years.
- Aggregated keyword measurements: kept indefinitely, since they describe keywords rather than people.
7. Your rights
Under the GDPR you can ask us to:
- give you a copy of the personal data we hold about you (access);
- correct data that is wrong (rectification);
- delete your data (erasure);
- restrict or object to processing that relies on our legitimate interests;
- send your data to you or another provider in a portable format;
- withdraw consent at any time, where processing is based on consent, without affecting what was done before.
Email [email protected] and we will respond within one month. You can delete your account yourself from account settings.
If you think we have handled your data wrongly you can complain to the Polish supervisory authority, Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, or to the authority where you live.
8. Security
Data is encrypted in transit with TLS. Passwords are stored as salted hashes and App Store Connect private keys are encrypted at rest. Access to production systems is limited to accounts that need it and protected by key-based authentication. Backups are held with our hosting provider. No system is perfectly secure; if a breach affects your data and carries a high risk to you, we will notify you and the supervisory authority as required by law.
9. Children
The Service is not intended for anyone under 18 and we do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
10. Changes to this policy
We may update this policy. Material changes are announced by email or in the application before they take effect. The date at the top of the page shows when it was last changed.