Privacy policy

Last updated 4 September 2026

AppClearance reads your App Store Connect account to find the things that get apps rejected. That means we hold a key to something that matters to you, so this page is specific rather than reassuring.

What we collect

If you only read the site

Nothing that identifies you by name. We do run one third-party analytics script, DataFast, on every page of this site: it records which page you opened, the page or link that sent you, your screen size and browser language, and a random visitor id it keeps in a cookie so that three pages read in one sitting count as one visit rather than three. Your IP address and browser user agent reach DataFast as part of those requests, which is how its reports can say roughly which country and browser a visit came from. It is analytics and not advertising: nothing is sold, and nothing follows you to other sites. Its cookies are named in full under Cookies below, with the way to switch it off. Our servers also keep ordinary request logs (IP address, page, timestamp) which are used to keep the site up and to rate-limit abuse, and are not tied to an account.

If you join the waitlist

Your email address and which page you signed up from. Nothing else, and it is used only to send the updates that page describes.

If you run a scan without an account

The scan works before you sign up. When you first connect a key we create an anonymous record and set a session cookie so the scan has somewhere to live. It holds no name and no email. If you later create an account, that record becomes yours rather than being duplicated; if you never do, and it never received a key or a completed run, it is deleted automatically.

If you create an account

Your email address and password are held by Supabase, which runs authentication for us and sends the emails that go with it; confirmation, password reset, and sign-in links. We never see or store your password. If you sign in with Google or Apple, we receive your email address and nothing else. Our own database stores your Supabase user id and which plan you are on.

If you connect App Store Connect

  • Your Issuer ID, Key ID, and your .p8 private key. The key is encrypted at rest with AES-256-GCM, is bound to your account so a copy of the record is useless anywhere else, is decrypted only in memory to make a call, and is never shown to anyone, including you, after upload. Disconnecting deletes it immediately.
  • Whatever Apple returns about your app when we ask: listing text, screenshots, build and version details, in-app purchase configuration, review information, submission history.
  • An audit log of every call we make with your key, which you can read in Settings. We only ever read. No call this service makes can change anything in your App Store Connect account.

If you connect RevenueCat

A read-only RevenueCat secret key, encrypted the same way and deleted the same way, plus the products, offerings and entitlements it returns.

What you tell us yourself

A few things no API can answer: whether your app has a login, the address of your backend if you have one, a support email. These are used by the checks that need them, and by the hosted pages if you use them.

Check results

The findings from every check you run, kept so you can see what changed between runs. Some checks are longitudinal by design; the one that notices your screenshots have not changed in two releases works by storing a fingerprint of the set, not the images.

If you subscribe

Stripe takes and holds the payment. Card numbers never reach our servers. We store your Stripe customer and subscription ids and the status Stripe reports, which is what tells us whether your plan is active.

If you publish hosted pages

The content of those pages, including any support email you put on them, is published publicly at the address you choose. That is the point of them, but it means anything you type there is public.

Who else processes it

These are every third party that receives any of the above. We do not sell data, and there is nobody on this list whose purpose is advertising.

WhoWhat they getWhy
SupabaseEmail address, password (hashed, never seen by us), sign-in activityAccounts and the emails that go with them
StripeEmail address, payment details you enter on their checkout pageTaking payment, invoices, renewals
AnthropicYour listing text, screenshots, and the text of your privacy and support pages; see belowThe checks that read meaning rather than fields
AppleOnly the requests we make with your own key, to your own accountReading your app. Apple is not given anything of yours it did not already have
RevenueCatOnly the requests we make with the key you connectedThe purchase cross-checks, if you connect it
DataFastEvery page you open here: its address, the page that sent you, your screen size and browser language, a random visitor id, and the IP address and user agent that carry the requestCounting visits, and seeing which pages bring people in
Our hosting and database providersEverything described above, at restRunning the service

We are based in Australia and several of these providers are not, so your data is stored and processed overseas, principally in the United States. That is unavoidable for a service built on them, and we would rather say it plainly than bury it.

What a model sees, and what it does not

About forty of the checks read meaning rather than fields: whether your description matches your screenshots, whether your privacy policy covers the data your app clearly collects, whether your app would look like a duplicate of something already on the store. Those send the relevant text and images to Anthropic's API: your app description, subtitle, keywords, promotional text, release notes, your store screenshots, and the published text of your privacy policy and support pages.

Three things are true about that, and they are worth stating plainly:

  • Your .p8 key, your credentials and your account details are never sent to a model. Only the listing content described above.
  • Anthropic processes it to return the answer and does not use API content to train models.
  • The results are advisory. Nothing a model returns can trigger a change to your App Store Connect account; this service makes no write calls at all.

Results are cached against a hash of the input, so an unchanged listing is not sent again on the next run.

The review-times page

Our public review wait times page is built from runs across the apps we check. Before anything is recorded, the app identifier is hashed with a secret salt, so a row cannot be traced back to an app or an account, and no breakdown is shown at all until enough apps sit behind it that no individual one is identifiable.

How long we keep things

  • Credentials: until you disconnect them, which deletes them at once, or until your account is deleted.
  • Check results and audit log: for the life of your account, because comparing runs over time is what several checks do.
  • Anonymous scans that never received a key or completed a run , deleted automatically.
  • Hosted pages: while they are published. We stop serving them when your subscription ends, and keep what you wrote so that paying again brings the same pages back.
  • Billing records: as long as tax and accounting rules require, which is longer than your account.
  • Waitlist: until you ask to come off it.

Your choices

You can disconnect a key at any time in Settings, which deletes it immediately. You can ask us for a copy of everything we hold about you, for corrections, or for the whole account and everything attached to it to be deleted . Email [email protected] from your account address and we will confirm when it is done. Deleting your account here does not cancel anything at Apple; your key stays valid until you revoke it in App Store Connect, which we would recommend doing as well.

We are an Australian company and handle personal information under the Privacy Act 1988 and the Australian Privacy Principles. If you think we have got something wrong, write to us first, and if you are not satisfied with how we deal with it, you can complain to the Office of the Australian Information Commissioner.

If you are in the UK or the EU, the lawful basis for handling your account, credentials and check data is performance of the contract between us; for the waitlist it is your consent, which you can withdraw at any time; and for keeping the service up and free of abuse it is our legitimate interest.

Cookies

One session cookie of ours, set when you sign in or start a scan, so the server knows the requests are yours. It is httpOnly, so no script on the page can read it.

DataFast sets four of its own. datafast_visitor_id is a random identifier, derived from nothing about you, and it lasts a year; datafast_visitor_first_seen_at and datafast_visitor_session_count last a year with it, and datafast_session_id lasts thirty minutes. They are what makes a returning reader one visitor instead of two. None of them are advertising cookies and none of them work on any site but this one, but they are cookies and a year is a long time, so we would rather name them than call this site cookie-free.

To switch the analytics off for your browser, set datafast_ignore to true in this site's local storage, or block datafa.st. Nothing here depends on it.

What we don't do

  • No advertising trackers, and nothing that follows you to other sites.
  • We never sell your data, and never share it for advertising.
  • We never make write calls to App Store Connect.
  • We never send your credentials to a model, or to anyone else.

Children

This is a tool for people publishing apps and is not intended for anyone under 16. We do not knowingly collect their data.

Changes

If this policy changes in a way that affects what we do with data we already hold, we will email account holders before it takes effect rather than only changing the date at the top.

Who we are

AppClearance is operated by BOTGHOST PTY LTD, a company registered in Australia. It is an independent service, not affiliated with, endorsed by, or sponsored by Apple. Apple, App Store and App Store Connect are trademarks of Apple Inc. Questions about any of the above: [email protected].