Privacy
What RocketASO keeps, and why
RocketASO reads your own store data to show your listing's numbers. This page says what it collects, what it reads, who else touches it, and how to remove it.
Updated 2026-10-04
What you give us
- Your name and email, and a password stored only as a scrypt hash. If you sign in with Google or Apple, we keep the account id that provider returns.
- The workspaces you create and the teammates you invite by email.
- The store keys you upload: an App Store Connect API key, a Google Play service account, an Apple Search Ads key. Each is encrypted at rest with AES-256-GCM.
- Settings you choose: webhook addresses, goals, reply templates, drafts of listing copy and screenshots.
What we read from the stores
With your keys, RocketASO reads your listing copy and media, ratings and reviews, App Store Connect analytics, sales and subscription reports, Google Play reviews and vitals, the Play Console report export if you point us at it, and Apple Search Ads campaigns, search terms and popularity.
Without a key, it reads public pages only: App Store and Google Play listings, store search results and top charts for the apps you audit or watch.
How we use it
- To show your numbers, run audits, rank checks and the weekly report, and to price each fix from your own reports.
- To send alerts and the Monday brief to the email or channels you choose.
- To draft review replies, listing rewrites and translations when you ask for one.
- We do not sell your data, use it for advertising, or show it to other customers.
Who else processes it
Each of these is used only when the service is switched on for this installation, and gets only what its job needs.
- The hosting provider that runs the servers and the database.
- Resend delivers email: your address and the message.
- Anthropic writes drafts when model drafting is on: the review or listing text being drafted, sent with each request.
- Stripe takes payment. Card details are entered on Stripe's page and never reach RocketASO.
- Google and Apple, when you choose to sign in with them.
- Webhooks you add, such as Slack or Discord, receive the alerts and briefs you send them.
Cookies and browser storage
RocketASO keeps your sign-in in an httpOnly cookie or in your browser's local storage, and small preferences such as a collapsed section in local storage. There are no advertising or analytics trackers.
How long we keep it
Data stays while the account exists; store reports are kept as history so later comparisons work. Deleting the account in Settings removes the workspaces only you belong to, with their apps, reports, keyword history, rival captures, store keys, invites and members, from the live database at once. Copies in server backups expire on the backup schedule of the deployment.
Your choices
- Download: most tables have a CSV button.
- Correct: change your name, email and password in Settings.
- Revoke: Disconnect a store in Connections, and revoke the key in App Store Connect, Play Console or Apple Ads as well.
- Delete: Settings, Account, Delete the account.
Contact
Email support@rocketaso.com.