ASO.dev Security Manifest: Data Privacy & API Key Safety
At ASO.dev, we understand how important it is for you to maintain the confidentiality of your data and to work with tools you can truly trust.
Our main goal is to provide convenient solutions while maintaining the highest level of security.
Below, we will explain why ASO.dev is a platform you can confidently entrust with your work.
Direct Interaction Without Intermediaries
Section titled âDirect Interaction Without IntermediariesâDirectly From Your Device
Section titled âDirectly From Your DeviceâAll requests to App Store Connect are sent directly from your device to Appleâs servers.
Similarly, when working with Google Play, requests to the Google Play Developer API are executed directly from your device.
We do not redirect your traffic through our own servers. This means your actions remain strictly between you and Apple/Google (subject to your own network rules, e.g. a configured proxy).
Minimal Risk of Data Leakage
Section titled âMinimal Risk of Data LeakageâSince we do not process or store your actions on the ASO.dev side, any risk associated with a potential leak of confidential information is minimized.
Flexible Access System
Section titled âFlexible Access SystemâWe support different access models, so you can choose what best matches your companyâs security requirements.
Team (Shared) API Key
Section titled âTeam (Shared) API KeyâAllows multiple specialists to work together on one or more workspaces.
Provides a common set of permissions, convenient for quickly onboarding new team members.
Individual API Key
Section titled âIndividual API KeyâMakes it possible to restrict access to specific apps and/or lock the analytics and financial sections.
Ensures precise control of permissions, which is crucial for complying with the companyâs internal security policies.
Google Play Service Account
Section titled âGoogle Play Service AccountâFor Google Play, ASO.dev uses a Google service account.
Permissions are configured in Google Play Console, and you can revoke access at any time.
Bottom line: You always control who can view your data and exactly what they can do within ASO.dev.
If a key is compromised or is no longer needed, you can revoke it at any time, terminating all associated actions.
Transparent Storage and Reliable Encryption
Section titled âTransparent Storage and Reliable EncryptionâOnly in Secure Storage on Your Device
Section titled âOnly in Secure Storage on Your DeviceâAll keys, passwords, and other confidential data are stored locally on your device - we do not copy them to our servers.
Additional Protection
Section titled âAdditional ProtectionâIf desired, you can enable API key synchronization (for teamwork or using multiple devices).
In this case, API keys and/or the service account credentials are additionally encrypted with your unique code, inaccessible to ASO.dev.
No Third-Party Access
Section titled âNo Third-Party AccessâWe do not transfer or sell your data to any organizations, and you do not risk having your confidential information exposed to unauthorized parties.
Full Control Over Financial Data
Section titled âFull Control Over Financial DataâNo Need to Share Financial Metrics
Section titled âNo Need to Share Financial MetricsâASO.dev does not request or store information about your revenue, transactions, etc.
Simple Restriction for Sensitive Data
Section titled âSimple Restriction for Sensitive DataâBy using Individual API keys, you can completely restrict access to financial reports and analytical data for any user if required by your companyâs security policy.
For Google Play, the principle is the same: access is defined by the service account permissions in Google Play Console. You can scope it to specific apps or actions, or revoke it when needed.
Proxy Support for IP-Based Activity Segmentation
Section titled âProxy Support for IP-Based Activity SegmentationâA Single Control Point
Section titled âA Single Control PointâIf you need strict control over the IP addresses from which actions are performed, ASO.dev provides proxy support.
This mechanism works the same way for App Store Connect and Google Play.
Different IP Addresses for Different Workspaces
Section titled âDifferent IP Addresses for Different WorkspacesâYou can specify a separate proxy for each application or workspace, ensuring clear segmentation of activity and compliance with corporate requirements.
Compliance With Platform Requirements
Section titled âCompliance With Platform RequirementsâApple (App Store Connect)
Section titled âApple (App Store Connect)â- We use the official App Store Connect API.
- The use of the App Store Connect API in ASO.dev for making changes to usersâ apps has been approved by the App Store Review Board.
- All changes you make to your app go through mechanisms provided by Apple itself, and you control these processes by issuing API keys with the necessary permissions.
Google Play
Section titled âGoogle PlayâWe extend ASO.dev to Google Play while keeping the same security principles:
- Access is provided via a Google service account, which you configure and control.
Voluntary Usage
Section titled âVoluntary UsageâWithout an API Key
Section titled âWithout an API KeyâYou can work in ASO.dev without any API keys.
In this mode, the following features are available:
- Keyword search and market analysis
- Studying competitor apps
- Modifying public metadata and exporting data for further automation via Fastlane
With an API Key - Extended Functionality
Section titled âWith an API Key - Extended FunctionalityâIf you need to interact directly with App Store Connect (edit app data, respond to reviews), only then do you provide a key. The level of access depends entirely on you.
Working With Public Data
Section titled âWorking With Public DataâASO.dev automatically collects publicly available information (metadata, search positions, etc.).
Our servers handle analytics, but your personal information is not involved.
We never ask you for extra data, nor do we use your device to collect information about other apps.
Uncompromising Commitment to Confidentiality
Section titled âUncompromising Commitment to ConfidentialityâWe Do Not Store Unnecessary Data
Section titled âWe Do Not Store Unnecessary DataâWe do not collect or use user metadata. Any metadata you enter into ASO.dev remains solely with you.
We Do Not Sell Information
Section titled âWe Do Not Sell InformationâASO.dev is an independent platform; we have no external investors interested in buying user data.
Respect for User Rights
Section titled âRespect for User RightsâIf you have concerns or suggestions for improving security, we are always open to dialogue.
Focus on Reliability and Trust
Section titled âFocus on Reliability and TrustâWe strive to create tools that help you work with App Store Connect faster and more easily, without compromising security.
ASO.dev is built on the principles of:
- Control. All keys and access remain in your hands, not in the cloud.
- Transparency. Clear rules, open encryption mechanisms, and no hidden âgray areas.â
- Flexibility. You decide how and with whom to share access, and we provide all the necessary tools.
Conclusion
Section titled âConclusionâASO.dev is a solution that combines convenience, analytics, and automation with a high level of information security.
We understand how crucial security is for users, which is why:
- We guarantee there are no intermediaries in transmitting your data to App Store Connect.
- We guarantee the same direct-request principle when working with Google Play.
- We ensure reliable encryption and a flexible rights-segmentation system.
- We support proxy mechanisms.
- We adhere to principles of transparency and responsibility so you can use the platform without any doubts.
By choosing ASO.dev, you get a service that not only simplifies the work of developers and marketers but also meets strict corporate-level security requirements.
If you have any questions or wish to propose additional security measures, contact us or book a meeting.
We are always ready to listen and implement the best and most secure solutions for your success.