Zum Inhalt springen
AppReport
ProduktPreiseWarteliste
Rechtliches
Privacy PolicyTerms of Service
Sprache
🇺🇸English🇫🇷Français🇩🇪Deutsch🇮🇹Italiano🇯🇵日本語🇰🇷한국어🇧🇷Português🇪🇸Español
ProduktPreiseWarteliste
Rechtliches
Privacy PolicyTerms of Service
🇺🇸English🇫🇷Français🇩🇪Deutsch🇮🇹Italiano🇯🇵日本語🇰🇷한국어🇧🇷Português🇪🇸Español

AppReport legal

GDPR Compliance

Zuletzt aktualisiert: September 8, 2026

How AppReport handles personal data, the services involved, and the choices and rights available to you under the General Data Protection Regulation (GDPR).

Dieses Rechtsdokument wird auf Englisch bereitgestellt. Es wurde keine übersetzte Rechtsfassung genehmigt; maßgeblich ist der englische Text.

Privacy PolicyTerms of ServiceGDPR Compliance

AppReport and your personal data

AppReport is operated by emonster, inc., a US company. This page supplements our Privacy Policy for the public website, launch waitlist, authenticated portal, and related communications. Contact [email protected] about the processing of your personal data.

emonster, inc. acts as the data controller for the information it uses to operate AppReport’s website, waitlist, account access, and communications. Connected workspaces also contain information supplied by their authorized owners and members, including report recipient details and data obtained through Apple connections.

The GDPR rights described here apply when the GDPR covers the processing concerned, including where services are offered to people in the EU. The authenticated portal is currently restricted to verified Google accounts on the exact emonster.com domain; the public waitlist is available separately.

  • Read the full AppReport Privacy Policy
  • Read the General Data Protection Regulation

The information we use and why

  • Launch waitlist: your email address, language, signup time, and records of the form notice, Terms acceptance, and optional consent choices. We use these to maintain your request, acknowledge your signup, notify you about launch, manage communication preferences, and understand demand. A valid email address and acceptance of the Terms are required to join; product news and optional analytics are separate choices.
  • Optional waitlist analytics: with your consent, we retain coarse browser and operating-system categories and major versions, device category, the landing page, limited campaign fields, and the referring website’s origin. These help us understand how people discover AppReport and use the waitlist. We do not retain a full referring URL or raw user-agent string in the signup record.
  • Security and approximate location: the request IP address is processed for rate limiting and a country/continent lookup through IPinfo. Coarse country or region information may also come from the hosting infrastructure. The lookup is separate from optional browser and campaign analytics; we retain coarse location results, not the raw IP address, in the signup record. reCAPTCHA, short-lived timing signals, and abuse records help protect the form.
  • Accounts and workspaces: Google/Firebase user identifiers, email address, verification and sign-in status, session information, workspace membership and roles, selected apps, and connection status support sign-in and access control. Language, appearance, report language, and delivery settings support your preferences.
  • Connected Apple data: account and key identifiers, vendor number where required, authorized credentials, app metadata, Apple report source files, reporting dates, supported analytics and Sales and Trends data, and derived reports support portfolio reporting. Source freshness and completeness information helps explain delayed, missing, or revised data.
  • Email and requests: recipient addresses, mailbox-verification records, report frequency and language choices, provider message identifiers, delivery events, and bounce or complaint status support requested communications and delivery management. We also process information you send in support or privacy requests to respond to them, and operational logs to diagnose and protect the service.

Consent and communication choices

We ask for your consent separately for AppReport product news and offers and for the optional waitlist analytics described above. Both are optional. Accepting the Terms to join the waitlist does not opt you into either choice.

You can withdraw consent at any time without affecting processing that was lawful before withdrawal. If you opt into product news, your signup acknowledgement includes a marketing unsubscribe link. You can also contact [email protected]. Marketing unsubscribe changes the product-news preference; contact us if you also want to leave the launch waitlist.

Use Privacy settings at the end of the footer to allow or decline optional analytics. The choice is saved in that browser and controls the optional context included in future waitlist submissions from it. Changing the browser choice does not itself delete information already submitted; contact us to exercise your rights over that information.

An Apple connection authorizes access to the developer account for reporting. It is separate from optional marketing or analytics consent and is not consent on behalf of other people whose personal data may be involved.

Service providers and recipients

The following services are involved in AppReport’s current data handling. What each receives depends on the feature used. Authorized workspace members and report recipients can receive the workspace information made available to them; emonster personnel handling waitlist, support, and privacy operations can also receive the information needed for those tasks.

  • Google and Firebase: website hosting, backend processing, authentication, database and source-file storage, secret storage, and reCAPTCHA Enterprise abuse assessment. These services handle relevant account, workspace, signup, technical, and reporting information for those functions.
  • Apple App Store Connect: the connected developer account supplies authorized app metadata and reporting data. Credentials are used to authenticate requests to Apple, including separately authorized setup of Analytics Reports requests where needed.
  • Resend: signup acknowledgements and internal signup notifications, report-recipient verification, and operational report email when delivery is enabled. Resend receives the addresses and message content needed to send mail and returns message identifiers and delivery, bounce, or complaint events.
  • IPinfo: receives the request IP address for the waitlist’s approximate country and continent lookup. AppReport stores the limited location result with the signup when available.
  • More about disclosures in our Privacy Policy

Apple connections and report recipients

Authorized workspace owners provide App Store Connect connection details. Stored reporting credentials are kept in Google Cloud Secret Manager and are not returned to the browser. Ordinary report retrieval reads Apple data. A separate owner-authorized setup can use a temporary Admin credential to create missing Analytics Reports requests; that temporary credential is not retained by the setup flow.

Apple report files and derived records support the reports for the connected workspace. AppReport preserves source dates and availability information. Disconnecting a connection stops further use through that connection; it is not the same as deleting previously stored report data.

A workspace owner may provide your address as a report recipient, so we may receive it from that owner before you interact with AppReport. The primary address is verified through sign-in; additional addresses must prove mailbox control before receiving reports. We record the verification and delivery preferences. If an invitation is unexpected, you can ignore it and contact [email protected] about your data.

Owners should select only authorized recipients. Recipient and frequency settings control operational reports where available; recurring report delivery is enabled separately from saving those settings. Public pricing does not currently provide online checkout or collect payment-card details.

Browser storage and automated processing

Browser storage remembers your language, appearance, and optional analytics choice. Firebase Authentication uses browser storage for sign-in state. You can sign out or clear local site data; clearing browser data does not delete records already held by AppReport.

The current website does not activate Google Analytics or advertising trackers. Optional waitlist analytics records the limited submission context described above. reCAPTCHA and hosting services separately process technical information for their operation and abuse protection. When reCAPTCHA runs, it uses a cookie called _GRECAPTCHA for risk analysis.

AppReport automatically validates requests, checks access, limits suspected abuse, summarizes source data, and handles email delivery events. These activities serve the functions described above. The GDPR’s separate protection for decisions made solely by automated processing concerns decisions with legal or similarly significant effects; it does not apply to every automatically generated report.

Retention and deletion

AppReport does not currently provide a complete self-service account or workspace deletion flow or self-service workspace data export. You can request access or deletion by email. Unsubscribing from marketing, disconnecting Apple, or clearing browser storage affects that specific function and does not automatically erase every related record.

  • Waitlist signup records: scheduled to expire 24 months after the original creation time. Duplicate signups do not restart that retention period.
  • Waitlist abuse records: scheduled to expire within 24 hours. Identifier-free aggregate waitlist records have a 36-month expiry measured from the end of their reporting period; groups below 10 signups are suppressed. Database time-to-live deletion is asynchronous, so physical deletion may follow the recorded expiry time.
  • Report-recipient verification: a verification link is valid for 30 minutes and can be used once. Link expiry limits verification; it does not itself mean that the address or related operational records have been deleted.
  • Other records: the Privacy Policy describes retention by purpose, including providing and protecting the service, handling requests and disputes, and keeping necessary business or legally required records. Account, workspace, source-file, report, email, support, security, and backup records may require separate handling. Contact us about the records that concern you.

Security and international processing

AppReport uses protected server operations, server-checked workspace access, restricted credential storage, verified recipient addresses, and signed email delivery events to protect the information it handles. Access and delivery checks help prevent one workspace’s information from reaching an unauthorized person.

As described in the Privacy Policy, information may be processed in the United States, Japan, Monaco, and other locations where emonster or its providers operate. Location alone does not identify the legal arrangement for a transfer. For information about the recipients and any applicable transfer safeguards relevant to your data, contact [email protected].

Your rights under the GDPR

Your rights depend on the processing concerned and the GDPR’s conditions and exceptions.

  • Information and access: find out whether your personal data is processed, obtain a copy, and understand its use, sources, and recipients.
  • Correction: request correction of inaccurate data or completion of incomplete data.
  • Erasure: request deletion where the legal grounds apply. Obligations to retain information or the establishment, exercise, or defence of legal claims may limit deletion.
  • Restriction: request limits on processing in qualifying circumstances, including while disputed accuracy is checked.
  • Portability: receive qualifying data you provided in a structured, commonly used, machine-readable format when processing is automated and based on consent or a contract; ask for direct transfer where technically feasible.
  • Objection: object on grounds relating to your situation where processing relies on legitimate interests or a public task, subject to the applicable conditions. Objection to direct marketing stops that marketing.
  • Automated decisions: protections apply to solely automated decisions with legal or similarly significant effects, subject to exceptions and safeguards, including human intervention where required.
  • European Commission: individual data protection rights

Make a privacy request

Email [email protected] with the address or workspace concerned and the right you want to exercise. Please do not send passwords or App Store Connect private keys. If there are reasonable doubts about identity, we may request proportionate information to verify it; access to workspace information also requires appropriate authority.

Under the GDPR, requests must be handled without undue delay and normally within one month of receipt. Complexity or the number of requests may justify up to two additional months, with the reason and extension communicated within the first month. Requests are generally free; a reasonable fee or refusal is permitted only under the applicable exceptions, such as manifestly unfounded or excessive requests.

If a request is refused, the GDPR requires the reasons and information about complaint and judicial-remedy rights. Where required, corrections, erasure, or restrictions must also be communicated to recipients of the affected data.

  • Email [email protected]
  • European Data Protection Board: guidance on requests

Concerns and complaints

You can contact us with a privacy concern. Where the GDPR applies, you may also complain directly to a competent data protection authority, particularly where you habitually live, work, or believe an infringement occurred. You do not have to contact us first.

  • Find a European data protection authority
AppReport

Klare Berichte nach dem App-Start für iOS-Entwickler, Studios und Teams.

emonster

Entdecken

ProduktPreiseWarteliste

Rechtliches

Privacy PolicyTerms of ServiceGDPR Compliance

DevTools

App Ads InsightsASO SignalsSubmitCheckKeyword Intelligence

Unternehmen

emonster Studioemonster Dev

Copyright © 1997–2026 emonster inc. Alle Rechte vorbehalten.