본문으로 건너뛰기
AppReport
제품요금대기자 명단
법무
Privacy PolicyTerms of Service
언어
🇺🇸English🇫🇷Français🇩🇪Deutsch🇮🇹Italiano🇯🇵日本語🇰🇷한국어🇧🇷Português🇪🇸Español
제품요금대기자 명단
법무
Privacy PolicyTerms of Service
🇺🇸English🇫🇷Français🇩🇪Deutsch🇮🇹Italiano🇯🇵日本語🇰🇷한국어🇧🇷Português🇪🇸Español

AppReport legal

Privacy Policy

최종 업데이트: September 8, 2026

This Privacy Policy explains how emonster, inc. collects, uses, discloses, and protects information when you use AppReport.

이 법률 문서는 영어로 제공됩니다. 승인된 번역본은 없으며, 영문이 우선합니다.

Privacy PolicyTerms of ServiceGDPR Compliance

Scope

AppReport is a web application and reporting service operated by emonster, inc., a US company ("emonster", "we", "us", or "our"). This policy covers appreport.dev, the AppReport launch waitlist, the authenticated AppReport portal, support communications, and related signup, recipient-verification, and operational report email (collectively, the "Service").

Access to the authenticated portal is currently limited to verified Google accounts on the exact emonster.com domain. This access boundary does not change how this policy applies to information processed through the Service.

emonster, inc. acts as the data controller for the information it uses to operate AppReport’s website, waitlist, account access, and communications.

Information we collect

  • Waitlist information, including the normalized email address you submit, language, original signup time, records of the displayed notice and Terms acceptance, and your marketing and optional analytics choices. With optional analytics consent, we also collect coarse browser, operating-system and device categories, the first-party landing path, limited campaign fields, and the referring website’s origin. Separately, we may retain approximate country, region or continent information from the hosting infrastructure or the IPinfo lookup described below.
  • Account and authentication information, including a Firebase user identifier, Google email address, email-verification and sign-in-provider status, and authentication session information.
  • Workspace information, including membership, role, lifecycle state, selected apps, connection status, and authorized report settings.
  • App Store Connect connection information, including issuer and key identifiers, vendor number where required, credentials submitted for an authorized connection or report setup, discovered app metadata, Analytics Reports request and source identifiers, and connection health details.
  • Authorized reporting information, including Apple Analytics Reports and Sales and Trends source files, supported normalized analytics data, source dates, data-completeness states, generated reporting periods, and report records.
  • Email information, including signup and report-recipient addresses, mailbox-verification records, per-recipient cadence choices, language, provider message identifiers, delivery state, and bounce or complaint status. Internal signup notifications include the submitted email, signup time, language, consent records and available country/continent context.
  • Technical and support information, including operational security and request logs, diagnostics, and information you send to support or in a privacy request.

Where information comes from

We receive information from you, authorized owners and members of your workspace, Google sign-in and Firebase Authentication, Apple through App Store Connect APIs that an authorized owner connects, Resend delivery events, and the service providers used to operate AppReport. The hosting infrastructure may supply coarse geography, and IPinfo supplies the result of a country/continent lookup using the request IP address.

A workspace owner may provide your email address as a report recipient before you interact with AppReport. We use it to verify mailbox control and manage report delivery. If the invitation is unexpected, you can ignore it and contact [email protected] about your data.

How we use information

  • Maintain the AppReport launch waitlist, acknowledge your registration, send the requested launch notification, manage your communication preferences, understand demand, and protect the form from abuse. Product news and offers require your separate optional choice. Optional browser and acquisition analytics are collected only when you allow them in Privacy settings.
  • Authenticate users and enforce AppReport access, workspace membership, and authorization boundaries.
  • Validate an authorized App Store Connect connection and retrieve the supported analytics data needed for AppReport.
  • Normalize source data, prepare and display reports, and preserve source freshness and completeness states.
  • Store report preferences and deliver opted-in operational reports to eligible recipients when report delivery is enabled.
  • Operate, secure, troubleshoot, and improve the Service; prevent misuse and cross-workspace access; respond to requests; and comply with applicable law.

App Store Connect credentials and analytics

When an authorized workspace owner submits a reporting private key for storage, AppReport sends it to a private backend and stores it in Google Cloud Secret Manager. AppReport stores a secret reference and non-secret connection metadata separately. The browser cannot read the stored private key back.

Ordinary app discovery and report retrieval read data from Apple. If Analytics Reports need to be enabled, a separate owner-authorized setup can use a temporary Admin credential to create missing reporting requests. That setup does not retain the temporary credential. AppReport does not use this process to change app releases, prices, or store listings.

Apple may provide analytics data late, provisionally, incompletely, or with later corrections. AppReport preserves available source and completeness states rather than treating every value as final. Apple source files and derived records support the connected workspace’s reports.

Authorizing an Apple connection is separate from optional marketing or analytics consent and does not provide GDPR consent on behalf of other people whose personal data may be involved.

Workspaces and report recipients

AppReport resolves workspace identity, ownership, membership, and lifecycle state on the server. Browser-supplied workspace or role values are not authoritative.

A workspace owner can configure up to three report recipients. The signed-in verified address is primary; each optional address must prove mailbox control before it can receive reports. Each recipient can have an independent daily, weekly, and monthly cadence selection. Owners are responsible for selecting only people authorized to receive that workspace's analytics information.

Signed delivery-status events from Resend may mark a report delivered, bounced, or complained. AppReport may suppress further delivery to an address after a bounce or complaint. Recurring report delivery is enabled separately from saving recipient and frequency settings.

Service providers and disclosures

We use Google and Firebase for authentication, hosting, backend functions, database and source-file storage, secret storage, and reCAPTCHA Enterprise abuse assessment. Apple supplies data through authorized App Store Connect connections. Resend sends waitlist acknowledgements, internal signup notifications, report-recipient verification messages, and operational report email when enabled, and returns delivery events. IPinfo receives the waitlist request IP address to infer its approximate country and continent; AppReport stores the limited location result with the signup when available.

Resend receives the addresses and message content needed for those emails. Authorized workspace members and report recipients can receive the workspace information made available to them. emonster personnel handling waitlist, support, and privacy operations can receive the information needed for those tasks.

We do not sell personal information. We may disclose information to the providers needed to operate the Service, when required by law, to protect the Service or the rights and safety of users and others, in connection with a business transaction, or with your consent. AppReport does not use workspace analytics for behavioral advertising.

Browser storage and technical data

AppReport uses browser local storage for language, appearance, and optional analytics preferences. Firebase Authentication uses browser storage for authentication state so a user can remain signed in until sign-out or local session data is cleared.

The current AppReport website does not activate Google Analytics or advertising trackers. Privacy settings stores your optional analytics choice in this browser; that choice controls limited context included in future waitlist submissions from it and does not delete previously submitted data.

The server separately processes the source IP address for rate limiting, hosting-provided coarse geography where available, and the IPinfo country/continent lookup. The location lookup is separate from optional browser and campaign analytics. Rotating abuse records have an expiry within 24 hours. A short-lived reCAPTCHA token and completion-timing signal help assess abuse. When reCAPTCHA runs, it uses the _GRECAPTCHA cookie for risk analysis. Raw IP addresses, raw user-agent strings, full referrers, attestation tokens and scores, and completion-timing tokens are not stored with a waitlist signup. Hosting and security providers may produce operational request, security, and diagnostic logs.

AppReport automatically validates requests, checks access, limits suspected abuse, summarizes source data, and handles email delivery events. These activities support the service functions described in this policy.

Retention, disconnection, and deletion

Waitlist signup records are scheduled to expire 24 months after their original creation time; duplicate signups do not restart that period. Short-lived waitlist abuse records are scheduled to expire within 24 hours. Identifier-free aggregate waitlist records have a 36-month expiry measured from the end of their reporting period, and aggregate slices below 10 signups are suppressed. Firestore time-to-live deletion is asynchronous and may occur after the recorded expiry time.

Report-recipient verification links are valid for 30 minutes and can be used once. Link expiry limits verification; it does not itself delete the address or related operational records.

Other information is retained for as long as reasonably necessary to provide and protect the Service, respond to requests, keep necessary business records, resolve disputes, and comply with law. Different records may be kept for different periods based on those purposes.

Disconnecting an App Store Connect connection prevents AppReport from continuing to use that connection; it does not automatically delete previously stored source files or report data. AppReport does not currently provide a complete self-service account or workspace deletion flow or self-service workspace data export. Contact us to request access, correction, disconnection, or deletion. Account, workspace, source-file, report, email, support, backup, security, audit, dispute, and legally required records may require separate handling. Unsubscribing from marketing or clearing browser storage does not automatically erase every related record.

Security

We use reasonable administrative, technical, and organizational safeguards designed to protect information. AppReport uses revocation-checked authentication in private backend functions, server-resolved workspace authorization, restricted secret access, tenant-scoped records, deterministic delivery identifiers, and cryptographically verified email webhooks. No method of transmission or storage is completely secure.

Your choices and rights

You can sign out, clear local site data, change language or appearance preferences, disconnect an authorized Apple connection where the interface permits, and manage report recipients and cadence settings when those controls are available.

A valid email address and acceptance of the Terms are required to join the waitlist. Optional product news and offers and optional waitlist analytics are separate choices; accepting the Terms does not opt you into either. You can withdraw consent at any time without affecting processing that was lawful before withdrawal.

If you opt into product news, your signup acknowledgement includes a marketing unsubscribe link. You can also contact [email protected]. Marketing unsubscribe changes the product-news preference; contact us if you also want to leave the launch waitlist. Use Privacy settings at the end of the footer to allow or decline optional analytics for future submissions from that browser. Contact us about rights over previously submitted data.

Depending on the applicable law and its conditions and exceptions, you may have rights to access, correction, erasure, restriction, portability, objection, and protection concerning solely automated decisions with legal or similarly significant effects. You can object to direct marketing at any time. Our GDPR Compliance page explains the conditions, request procedure, and direct complaint route to a competent data protection authority.

Email [email protected] with the address or workspace concerned and the right you want to exercise. Please do not send passwords or App Store Connect private keys. If there are reasonable doubts about identity, we may request proportionate information to verify it; access to workspace information also requires appropriate authority. We respond to valid requests as required by applicable law. Under the GDPR, requests must be handled without undue delay and normally within one month of receipt. Complexity or the number of requests may justify up to two additional months, with notice and reasons within the first month.

  • GDPR Compliance: rights, requests, and complaints
  • Email [email protected]

Children

AppReport is a business reporting service and is not intended for children under 13. If you believe a child provided personal information through AppReport without appropriate consent, contact [email protected].

International processing and third-party services

emonster operates internationally. Information may be processed in the United States, Japan, Monaco, and other locations where emonster or its service providers operate. Those locations may have data-protection laws different from the laws where you live.

AppReport links to or depends on services such as Google, Firebase, Apple, Resend, and IPinfo. Their applicable terms and privacy practices address their services and their own account or operational data processing. The relevant role depends on the service and processing concerned.

For information about the recipients and any applicable transfer safeguards relevant to your data, contact [email protected].

Changes and contact

We may update this Privacy Policy from time to time. The updated version will be posted on this page with a revised Last updated date.

For privacy questions or requests, contact [email protected]. For AppReport product support or general questions, contact [email protected].

AppReport

iOS 개발자, 스튜디오, 팀을 위한 명확한 출시 후 성과 보고.

emonster

둘러보기

제품요금대기자 명단

법무

Privacy PolicyTerms of ServiceGDPR Compliance

DevTools

App Ads InsightsASO SignalsSubmitCheckKeyword Intelligence

회사

emonster Studioemonster Dev

Copyright © 1997–2026 emonster inc. 모든 권리 보유.