✦ Pricing
Privacy

Privacy Policy

This policy explains which personal data AppStoreStatistics processes, why it is needed, which providers are involved, and which choices and rights are available to you.

Last updated August 19, 2026

These pages provide service information and do not constitute individual legal advice.

1. Controller and contact

The controller responsible for the processing described in this Privacy Policy is Tobias Krenn, operating the AppStoreStatistics service as a sole proprietor.

Postal address: Grolzham 25B, 4680 Weibern, Austria. Email: [email protected].

2. Data we process

The data involved depends on the features you choose to use.

  • Account data: Firebase user identifier, email address, authentication provider and session information.
  • Optional agent guest registration creates an anonymous Firebase identity without an email address. Credentials are returned only to the requesting agent and are not logged by the registration endpoint; hashed network identifiers are held transiently for abuse prevention. Guest identities do not grant paid access. Account deletion and credential revocation assistance are available through support.
  • Workspace data: watchlists, selected apps, countries, saved trackers, analyses, run states and source metadata.
  • ASO AI Agent data: prompts, assistant messages, app evidence, citations, response identifiers and token or web-search usage summaries.
  • Billing references: plan, subscription state and Stripe customer, checkout or subscription identifiers. Card details entered in Stripe Checkout are not received or stored by AppStoreStatistics.
  • Free-tool protection data: daily counters linked to cryptographically hashed account or device/network signals. The quota table does not intentionally store the raw IP address or raw user-agent string.
  • Public report data: an app metadata analysis is published only when a signed-in user explicitly creates a public share. Published reports can be revoked.
  • Technical data: request, security, error and operational logs needed to deliver and protect the service.
  • Analytics data: Google Analytics receives consent-state-aware, cookieless page-view measurements while analytics storage is denied. Full Google Analytics storage and interaction measurement, and all Ahrefs Analytics loading, require analytics consent.
  • Newsletter data: email address, double-opt-in evidence, subscription status, signup source and operational delivery, bounce or complaint events for AppStoreStatistics Weekly.
  • App-launch outreach data: app-developer contact address, a one-way email hash, related public app metadata, documented marketing-permission basis, campaign assignment and suppression or delivery status. Outreach messages are prepared only for contacts whose permission has been documented outside this service.
  • Chrome extension requests: after you click App Store Rank Insights on a supported Apple app page, the public Apple Track ID and storefront are processed to return the requested aggregate summary. The extension does not request general browsing-history access.
  • Optional Chrome extension telemetry: if you enable it, AppStoreStatistics stores only aggregate daily counts by allowlisted event name and extension version. The event payload excludes the Track ID, page URL, storefront and any persistent device identifier.
  • Voluntary discovery attribution: after registration you may tell us where you found AppStoreStatistics and, for AI sources, optionally provide the search prompt you used. The internal growth view does not expose your email address or Firebase user identifier.
  • External review activity: eligible Full Access users may receive a neutral invitation to share an experience on a configured third-party review platform. AppStoreStatistics records that the invitation was shown, dismissed or opened so it is not repeatedly displayed.

3. Purposes and legal bases

We process personal data only where a legal basis applies.

  • Contract and pre-contractual steps: accounts, paid access, saved product workflows, support and requested analyses.
  • Legitimate interests: service security, abuse prevention, rate limiting, troubleshooting and reliable operation, balanced against user rights.
  • Legitimate interests, where permitted by applicable law: minimal aggregate page-view measurement through Google Consent Mode while analytics storage remains denied, used to understand service availability and traffic trends. Optional analytics storage and interaction measurement remain consent-controlled.
  • Consent: optional Google Analytics storage and interaction measurement, and the Ahrefs Analytics script. Consent can be withdrawn through Cookie settings at any time.
  • Consent: the optional weekly newsletter. It is activated only after email confirmation and can be withdrawn through the unsubscribe link in every issue.
  • Documented marketing permission: personalized app-launch outreach where the contact has separately authorized marketing communication. Every message provides an unsubscribe option and the address is contacted at most once through this launch workflow.
  • Requested service and legitimate interests: deliver the Chrome extension summary and apply transient IP-based rate limiting to protect the public endpoint. The IP address is not written to the aggregate extension-event table.
  • Consent: optional aggregate Chrome extension telemetry. It is disabled by default and can be enabled or disabled in the extension popup.
  • Consent: optional discovery-source and AI-prompt feedback submitted after registration. Skipping the question does not restrict any feature.
  • Legitimate interests: limit the frequency of neutral external-review invitations and understand whether eligible users opened a configured review destination. Reviews are not rewarded or filtered by sentiment.
  • Legal obligations: accounting, tax, fraud-prevention and legally required records or disclosures.

4. Service providers and external sources

We use processors and external source providers where required to operate a selected feature.

  • Google Firebase for authentication and related account state.
  • Stripe for hosted checkout, payment processing and the billing portal.
  • OpenAI for the ASO AI Agent and optional source-linked web research. Requests are made server-side and use store:false where supported, but AppStoreStatistics stores the conversation needed for the product thread.
  • Cloudflare and hosting infrastructure for delivery, security and network operation.
  • Google Analytics in Consent Mode with analytics and advertising storage denied by default; full analytics storage is enabled only after consent. Ahrefs Analytics loads only after analytics consent.
  • Resend for newsletter confirmation messages, contact-list management and weekly email delivery.
  • Sender.net for app-launch marketing contact management, suppression checks and preparation of manually reviewed campaign drafts.
  • Google Chrome Web Store for distribution of the optional App Store Rank Insights browser extension. The extension communicates with AppStoreStatistics only through its narrowly scoped public summary and optional aggregate event endpoints.
  • Product Hunt only when its genuine review URL is configured and an eligible user chooses to open it. Product Hunt receives the normal connection data associated with visiting its website.
  • Apple/iTunes, Apple public Store pages, Meta and TikTok as external public or authorized data sources. Requests can disclose ordinary technical connection data to the source provider.

5. International transfers

Some providers may process data outside Austria or the European Economic Area. Where required, the relevant provider and controller rely on an applicable adequacy decision, approved contractual safeguards or another lawful transfer mechanism. Provider terms and privacy information may change independently of AppStoreStatistics.

6. Retention

We retain account and product data for as long as needed to provide the account and requested features, resolve disputes, protect the service and comply with legal obligations. Billing and accounting references may be kept for legally required periods.

ASO AI conversations remain associated with the thread until they are deleted as part of an applicable account or privacy request. Public metadata reports remain available until revoked or removed and become noindex when stale under the published report policy. Operational logs and free-tool counters are retained only as long as reasonably needed for their security or quota purpose.

Newsletter consent records and suppression status are retained while needed to document consent and prevent unwanted re-subscription. Delivery-event details are retained only for newsletter operation, deliverability and complaint handling.

App-launch outreach consent references and email hashes can be retained after a message or opt-out where necessary to prove permission, enforce the lifetime one-contact rule and prevent renewed contact. Campaign metadata is retained for compliance, troubleshooting and suppression handling.

Browser extension summary inputs are processed for the requested response and transient abuse prevention. Optional event telemetry is retained only as aggregate daily counters by event and version, without app identifiers or a device profile.

Voluntary discovery-source records may be retained to compare acquisition and paid-access outcomes. Free-text discovery prompts are removed after twelve months; source-level aggregate counts may be retained longer. Review-prompt state is retained as needed to respect dismissals and prevent repeated requests.

7. Your choices and rights

Depending on applicable law, you may request access, rectification, erasure, restriction, portability or object to processing based on legitimate interests. You may withdraw consent without affecting earlier lawful processing.

  • Send privacy requests to [email protected].
  • Include enough information to identify the relevant account, but never send a password, private key or access token.
  • You may complain to the Austrian Data Protection Authority (Datenschutzbehörde) or another competent supervisory authority.
  • Cookie preferences can be changed through Cookie settings.
  • Newsletter consent can be withdrawn through the unsubscribe link included in every issue.
  • App-launch outreach permission can be withdrawn through the Sender.net unsubscribe link or by contacting support. A withdrawal prevents further campaign inclusion.

8. Public reports and AI prompts

Do not place confidential information, third-party personal data or secrets in an ASO AI prompt. A public metadata report is discoverable only after an explicit publication action. You are responsible for ensuring that content you choose to publish may lawfully be made public.

9. Children, security and changes

The service is intended for people capable of entering a binding contract and is not directed to children. We use reasonable technical and organizational safeguards, but no internet service can guarantee absolute security.

This policy may be updated when products, providers or legal requirements change. The date at the top identifies the current version.

Questions about this page?

Contact AppStoreStatistics. Do not include passwords, access tokens or private keys.

[email protected]