Store credential security
Connecting a store account can expose commercially sensitive listing and performance data. This page explains what Apptonomy processes, why we process it, who helps process it, and the controls available to you.
Last reviewed:
Your private store metrics stay scoped to your account
Apptonomy uses private connected-account metrics to analyze your apps. We do not pool private metrics into cross-customer benchmarks, resell them, or use them to build market estimates.
Benchmark ranges use public sources and documented expert judgment.
Connect only when you need to
You can analyze a public App Store or Google Play listing without connecting a store account. Connecting unlocks private performance analytics and direct publishing. You can revoke that access in your store account at any time.
How credentials are protected
Store credentials are encrypted in your browser before upload. When a stored credential is required, Apptonomy application-encrypts it for persistence using Google Cloud Key Management Service. It is decrypted only when an authorized store API request needs it; during a publish, the decrypted credential is carried in our queued publishing task, which our cloud provider encrypts at rest, until the task runs; a task is attempted at most three times in total and expires after 31 days. The queue does not log task contents.
With keyless Google Play linking, no customer service-account key is uploaded or stored. You grant an Apptonomy-managed service account access in Play Console and can revoke it by removing that account.
What access Apptonomy uses
Access depends on the store and the features you choose:
You choose the features and roles you enable. Apptonomy verifies the capabilities required for those features and reports missing or revoked access.
| Store and feature | Access | Purpose |
|---|---|---|
| Google Play public analysis | No account access | Reads the public listing |
| Google Play listing connection | View app information and Manage store presence | Reads and publishes listing metadata |
| Google Play reporting | View app information and download bulk reports (read-only) | Reads installs, crashes, ratings, and reporting files |
| App Store public analysis | No account access | Reads the public listing |
| App Store publishing | App Manager or Admin | Reads and publishes listing text and assets |
| App Store revenue analytics | Sales, Finance, or Admin, plus Vendor Number | Reads sales and proceeds reports |
| App Store performance analytics | Admin | Reads impressions, product-page views, conversion, and downloads |
Publishing stays under human control
Apptonomy creates drafts. In the product today, an authorized organization owner or administrator initiates every store publish, reviews the content, and chooses the included asset scopes, fields, and locales. Apptonomy does not schedule or initiate store publishing on its own.
AI processing and subprocessors
Some listing content and, when required for a feature, selected connected-account data are processed by named infrastructure and AI subprocessors solely to provide Apptonomy. We use commercial API services whose published terms exclude submitted API content from model training by default. Apptonomy does not intentionally opt in to provider training or data-sharing programs.
Apptonomy uses OpenAI, Anthropic, Perplexity, and Google Gemini for specific analysis tasks, and Google Cloud Vision to read text in screenshots. Most requests route through Cloudflare AI Gateway with prompt and response payload logging disabled; Anthropic requests go directly to Anthropic if the gateway fails, and sampled quality-review batches are sent directly to Anthropic. Eligible AI responses may be cached for about 30 days. Most AI request paths, including those for draft listings and screenshots, use the cache-eligible classification, so Apptonomy does not represent that connected-account-derived requests bypass gateway caching.
Retention and processing locations vary by provider and are documented in our current subprocessor list.
Authentication, logging, and encryption
- Apptonomy uses Clerk for user authentication and resolves organization and project roles on the server for protected actions; we are completing their enforcement across every operation.
- Network traffic uses TLS.
- Stored store credentials receive application-level encryption in addition to provider-managed storage encryption.
- Values written through our API and backend console loggers pass through a secret redactor before they reach a log sink.
Revoke access or request deletion
You can revoke App Store Connect keys or roles, remove the Apptonomy service account from Play Console, or revoke a bring-your-own Google key. Apptonomy reports credential failures rather than silently continuing.
For account-data access, correction, or deletion requests, see our Privacy Notice or contact the privacy address listed there. Backup and legally required retention are described in the Privacy Notice and DPA.
Independent assurance
Apptonomy does not currently have a SOC 2 report, and no SOC 2 examination is currently underway. The controls described on this page are current Apptonomy practices and have not been independently examined under SOC 2. If a SOC 2 report is mandatory for your procurement process, contact us before connecting private store data.
Security questions
Report a vulnerability or ask a security question at security@apptonomy.ai. Our vulnerability disclosure policy explains what to include and how we handle reports.
security@apptonomy.ai