Rechtliches

Privacy Policy

What ASOsight collects, why, who else touches it, and how you get it back or get rid of it.

Zuletzt aktualisiert 24 August 2026

The short version

We collect what the product needs to work: your account, what you do in the app, and the App Store Connect analytics you choose to connect. We do not sell personal data, we run no advertising trackers, and your own analytics are never used to calibrate what other customers see unless you switch that on yourself.

Who is responsible

ASOsight is the controller for the personal data described here. The operator behind it and the postal contact are on the Legal notice page. For anything privacy-related, write to [email protected] — a person reads it.

What we collect

Account data: your email address, a hash of your password (we never store the password itself), your organisation name, your interface language, and — if you sign in with Google — the account identifier, email and display name Google returns.

Security data: sign-in timestamps and the IP address of sign-in attempts, kept for 30 days to stop credential-stuffing and abusive sign-ups.

Product usage: which features you use — searches, research jobs, keyword lookups, purchases — recorded with your user and organisation identifiers for up to 90 days so we can see what to improve.

Connected App Store Connect data: the API key you provide, encrypted with AES-256-GCM and never shown again, and the analytics it grants access to, such as impressions, product page views and downloads by day and territory.

Billing data: your plan, subscription status and credit ledger. Card details are handled by Paddle and never reach us.

Support messages: what you write to us and our replies.

What we do NOT collect

No advertising or cross-site tracking. No session recording or heat-mapping. No third-party analytics SDK in the product. No purchase of personal data from brokers.

Why we are allowed to (GDPR)

Contract: running the service you signed up for, including billing and support.

Legitimate interests: keeping the service secure, preventing abuse, and understanding aggregate product usage. We keep this proportionate — the usage record is about features, not about you as a person.

Consent: optional things you switch on yourself, such as allowing your connected analytics to inform model calibration. You can withdraw consent at any time in Settings.

Legal obligation: keeping billing records for as long as tax law requires.

Public App Store data

Alongside your own data, ASOsight processes publicly available App Store metadata and Apple's published search popularity to provide the service. Figures derived from those inputs are modeled and are labelled as estimates wherever they appear.

Who else processes it

Hosting: DigitalOcean, LLC — New York, United States — the database and application servers.

Payments: Paddle.com Market Ltd. — checkout, invoicing and tax. Paddle is the merchant of record and its own privacy policy applies to the payment itself.

Language model: OpenAI, for writing up research findings. Prompts contain the public material being analysed and your research question — not your account data, and not your connected analytics.

Email delivery, when we send you a transactional message such as a password reset.

Web search during research runs on our own self-hosted instance; your research questions are not sent to a commercial search provider.

That is the complete list. We do not add a processor that touches personal data without updating this page.

Where your data lives

Application data is stored in the United States with the hosting provider above. If you are in the EU or UK, transfers rely on the European Commission's Standard Contractual Clauses with our providers.

How long we keep it

Account and organisation data: until you delete the account, then removed within 30 days.

Sign-in attempt records: 30 days. Product usage events: 90 days. Research source material gathered for a report: up to 12 months, so a report stays auditable against what it cited.

Billing records: as long as tax law requires, typically 10 years, then deleted.

Your rights

You can access, correct, export, restrict or delete your data, and object to processing based on legitimate interests. Export and deletion are self-service in Settings; anything else, write to [email protected] and we answer within 30 days.

If you are in the EEA or the UK you can also complain to your local data protection authority.

Security

Passwords are stored as scrypt hashes. Connected credentials are encrypted with AES-256-GCM. Sessions are opaque tokens, and every state-changing request carries a CSRF token. Data is separated per organisation at the database level, so one customer's query cannot reach another's rows.

All traffic runs over TLS. If you believe you have found a vulnerability, write to [email protected] — we will respond, and we will not pursue good-faith research.

Children

The service is for professional use and is not directed at anyone under 18.

Changes

If we change this policy in a way that affects you, we email you before it takes effect. The date at the top always shows the current version.