Legal
Privacy Policy
Last updated 2026-07-27. What we hold, why we hold it, and how the keys to your stores are protected.
Who controls your data
One Absolute Ltd (company number 07903648), registered at London (WC2) Office, 7 Bell Yard, London, England, WC2A 2JR is the controller of the personal data described here. Contact us at privacy@oneabsolute.co.uk.
What we collect
- Account details: your email address, optional name, and a bcrypt hash of your password. We never store the password itself.
- Store credentials: the App Store Connect key or Play service account you choose to connect, encrypted before storage.
- App data we fetch on your behalf: listings, screenshots, releases and their statuses, user reviews, keyword rankings, and — if you connect an Admin-role Apple key — your App Store analytics.
- Content you create: listing drafts, uploaded binaries, screenshot designs, tracked keywords, and rejection text you paste in for decoding.
- Usage records: which AI features you used and when, for plan limits and cost control, plus an audit log of every use of a store credential.
- Billing data: handled by Stripe. We store a customer reference and your plan; card details never reach our servers.
- Email preferences and delivery outcomes for the notifications and digests you receive.
How we use it
We do not sell your data, and we do not use your app data to advertise to you or anyone else.
- To run the service you asked for: writing listings, tracking ranks, delivering builds, monitoring reviews and submissions.
- To send notifications you have not opted out of, and account emails such as password resets.
- To bill you, enforce plan limits, and prevent abuse.
- To keep the service secure and to diagnose faults.
Legal bases
Where UK or EU data protection law applies, we rely on: performance of our contract with you (running the service and billing it); our legitimate interests (security, abuse prevention, product diagnostics); and your consent where we ask for it, such as optional marketing email. You can withdraw consent at any time.
AI processing
AI features send the relevant content — your app description, listing text, screenshots, reviews, or rejection message — to our AI providers so they can produce a draft. Under their commercial API terms this content is not used to train their models.
Outputs are drafts. Nothing produced by AI is sent to a store, or to a reviewer, without your explicit approval.
How store credentials are protected
- Encrypted at rest with AES-256-GCM. The master key lives in the server environment, never in the database, so a database copy alone cannot decrypt them.
- Used only to perform actions you have initiated or scheduled, and every use is written to an audit log with the reason.
- Imports are read-only: pulling your listings, screenshots or release history writes nothing back to either store.
- Removing a connection stops all further use immediately.
Who else processes your data
We use a small number of providers to run the service. Each receives only what it needs for the purpose shown.
| Provider | Purpose | Data |
|---|---|---|
| Anthropic | AI features — listing copy, keyword research, rejection decoding, review replies | App metadata, store reviews, screenshots, and rejection text you submit |
| Google (Gemini) | Generated background artwork for screenshots | Text prompts describing your app |
| Apple (App Store Connect API) | Reading and updating your own App Store listings, releases and reviews | Requests made with the API key you connect |
| Google (Play Developer API) | Reading and updating your own Play listings, releases and reviews | Requests made with the service account you connect |
| Stripe | Subscription payments | Billing email and payment details (card details never reach our servers) |
| Postal / Amazon SES | Sending notification, digest and account emails | Your email address and the message contents |
International transfers
Some of these providers are based in the United States. Where personal data is transferred outside the UK or EEA we rely on the appropriate safeguards, such as standard contractual clauses or the UK addendum.
How long we keep things
- Account and app data: for as long as your account exists, then deleted or anonymised within a reasonable period after closure.
- Uploaded binaries: deleted seven days after delivery to the store.
- Password reset links: one hour, single use.
- Sessions: expire automatically, and are revoked entirely when you reset your password or sign out of all devices.
- Audit and billing records: kept as long as we need them for security and accounting obligations.
Cookies
We set one strictly necessary cookie to keep you signed in. Your light or dark theme preference is stored locally in your browser. We do not use advertising or third-party tracking cookies.
Your rights
You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to processing, or to receive it in a portable format. Write to us and we will respond within one month.
If you are in the UK you can also complain to the Information Commissioner's Office; in the EEA, to your local supervisory authority. We would rather you told us first so we can put it right.
Children
The service is for developers and is not intended for anyone under 16.
Changes
If we change this policy materially we will email you before it takes effect. The date at the top always reflects the current version.
Questions, or a request about your data? privacy@oneabsolute.co.uk