Privacy Policy
1. General provisions and operator identity
This Privacy Policy describes how ASO Copilot collects, uses, stores, shares, and protects personal data in the context of providing its services.
ASO Copilot is currently operated by an individual based in Brazil. Requests related to this Policy, privacy, LGPD, legal notices, and security matters may be sent to: support@asocopilot.app.
By using the platform, the User acknowledges the practices described in this document.
2. Personal data collected
ASO Copilot may collect and process the following personal data:
- email;
- user identifier provided by Clerk;
- authentication data;
- data related to the User's organization and permissions; and
- platform usage data.
In addition to the data above, the platform may process:
- data from the App Store Connect API, including credentials stored in encrypted form; and
- data from connected applications, including app name, metadata, and related information.
Technical and operational data may also be processed, such as:
- IP address, for security and rate limiting purposes;
- system logs, for audit, monitoring, and security purposes; and
- technical identifiers related to billing, fraud prevention, and operational events.
In the context of payments, processing is carried out through Stripe or equivalent payment partners, and the platform does not store full card details.
3. Purposes of processing
Data processed by ASO Copilot may be used for the following purposes:
- authenticate the User and manage account access;
- enable the operation of the platform and its organizations;
- process subscriptions, billing, invoicing, and billing-related events;
- enable Apple integration and import data from connected applications;
- generate and analyze content with artificial intelligence support;
- maintain logs, audits, access controls, and security mechanisms;
- comply with legal, regulatory, and contractual obligations; and
- improve the service, dataset, operational flows, and internal statistics, including through anonymized or aggregated data.
4. Data sharing and third parties
ASO Copilot may share or enable data processing with third parties strictly related to platform operation, including:
- Clerk, for authentication;
- Stripe, for payments and billing events;
- Apple, in the context of integrations and app data; and
- OpenAI and equivalent providers, for artificial intelligence features.
Data sharing occurs to the extent necessary for service provision, platform security, compliance with legal obligations, or enablement of contracted features.
5. Data retention
Data will be retained while the User's account remains active, or as long as necessary for service provision, rights protection, compliance with legal, regulatory, or contractual obligations, and legitimate security and audit purposes.
After account deletion:
- data may be retained in anonymized or aggregated form for statistical, analytical, and service improvement purposes; and
- identifiable personal data may be deleted upon User request, subject to technical limitations and legal retention requirements.
6. Storage and security
ASO Copilot adopts security measures appropriate to the nature of the processed data, including, among others:
- AES/GCM encryption for sensitive data, such as Apple keys;
- HTTPS/TLS in communications;
- webhook verification, including Stripe and Clerk webhooks;
- authentication and JWT issuance through Clerk;
- logical isolation by organization;
- role-based access control;
- IP-based rate limiting;
- operational limits by plan; and
- maintenance of billing, webhook, and security logs.
7. International data transfers
The User acknowledges that data may be processed outside Brazil by providers and technology partners used by ASO Copilot, including Clerk, Stripe, and OpenAI.
8. Data subject rights
Under LGPD and applicable law, the User may exercise, where applicable, rights related to their personal data, including:
- access;
- correction;
- deletion; and
- information about processing and sharing, where applicable.
Such requests will be reviewed according to technical feasibility, request scope, and the legal bases applicable to processing.
9. Contact
Requests related to this Privacy Policy may be sent to: support@asocopilot.app.