Last Updated: January 25, 2026
1. Introduction
This Privacy Policy explains how App Store Localization Manager ("we", "our", or "the Service") collects, uses, and protects your information.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address: For authentication and account recovery
- Display name: Optional, for personalization
- User ID (UID): Automatically generated unique identifier
2.2 API Credentials
To provide our service, you provide:
- App Store Connect Key ID: Stored in encrypted cloud database
- App Store Connect Issuer ID: Stored in encrypted cloud database
- P8 Private Key File: Stored encrypted on our server, isolated per user
2.3 Usage Data
We automatically collect:
- Access logs: IP address, browser type, timestamps
- API usage: Number of translation requests, app queries
- Session data: Authentication tokens (temporary)
2.4 App Content
During translation operations, we temporarily process:
- App descriptions and metadata
- Keywords and promotional text
- What's New content
Note: This content is not permanently stored and is only used for translation purposes.
3. How We Use Your Information
We use your information to:
- Provide the Service: Authenticate users, access App Store Connect API, perform translations
- Maintain Security: Protect against unauthorized access and fraud
- Improve the Service: Analyze usage patterns and fix bugs
- Communicate: Send service-related notifications (if implemented)
4. Data Storage and Security
4.1 Where We Store Data
- Cloud Database: Account info, Key ID, Issuer ID (encrypted)
- Server File System: P8 key files (one per user, named by UID)
- Authentication System: Email and password (hashed and encrypted)
4.2 Security Measures
We implement security measures including:
- Encryption: HTTPS for all communications, AES encryption for stored data
- Access Control: User-level isolation (you can only access your own data)
- Database Security: Prevent cross-user data access with strict rules
- File Permissions: P8 files protected from web access via .htaccess
- Authentication: Industry-standard secure authentication protocols
4.3 Data Retention
- Active Accounts: Data retained while account is active
- Deleted Accounts: Data removed within 30 days of account deletion
- Logs: Server logs retained for 90 days for security purposes
5. Third-Party Services
We use third-party services that have access to your data:
5.1 Cloud Infrastructure
- Purpose: Secure authentication and data storage
- Data Shared: Email, UID, Key ID, Issuer ID (encrypted)
- Security: Industry-leading cloud providers with SOC 2 compliance
5.2 AI Translation Provider
- Purpose: Translation services
- Data Shared: App descriptions, keywords (temporarily)
5.3 Apple App Store Connect
- Purpose: App Store Connect API access
- Data Shared: Your API credentials (via secure token)
- Note: We use your credentials to access data you already own
- Privacy Policy: Apple Privacy
6. Data Sharing and Disclosure
We do NOT:
- Sell your personal information to third parties
- Share your data with advertisers
- Use your app content for any purpose other than translation
We MAY disclose your information:
- If required by law or legal process
- To protect our rights or the safety of others
- In connection with a business transfer or merger
7. Your Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update or correct your information
- Deletion: Request deletion of your account and data
- Export: Download your data (where technically feasible)
- Opt-Out: Stop using the Service at any time
8. Cookies and Tracking
We use minimal cookies for:
- Session Management: PHP session cookies (required)
- Authentication: Firebase authentication tokens
We do NOT use tracking cookies or analytics tools.
9. Children's Privacy
This Service is not intended for users under 13 years of age. We do not knowingly collect information from children.
10. International Data Transfers
Your data may be transferred to and processed in countries other than your own. By using the Service, you consent to such transfers.
11. Changes to Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the "Last Updated" date.
12. Contact Us
For privacy-related questions or to exercise your rights, please contact the service administrator.
13. Data Protection
For users in the EU/EEA: We comply with GDPR principles including lawful processing, data minimization, and the rights of data subjects.